Computer implementation method based on accurate homomorphic encryption framework and system based on accurate homomorphic encryption framework
The EHE framework addresses scalability issues in quantum homomorphic encryption by using multivariate polynomials and quantum gates to securely perform computations on encrypted data, ensuring post-quantum security and efficient execution on classical processors.
Patent Information
- Application Number
- JP2025005797
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-16
- Filing Date
- 2025-01-15
- Publication Date
- 2025-08-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing homomorphic encryption techniques face scalability barriers due to noise accumulation and the need for large-scale quantum operations, particularly in quantum homomorphic encryption, which consumes a significant number of qubits and is not accessible with current quantum computers.
A computer-implemented method based on the framework of exact homomorphic encryption (EHE) using multivariate polynomials and elementary quantum gates to encode and encrypt data, allowing computations on encrypted data without decryption, leveraging fault-tolerant quantum computation principles.
Enables secure and scalable computations on encrypted data, providing post-quantum security and efficient execution on classical processors without the need for quantum computers, ensuring the integrity and confidentiality of computations.
Smart Images

Figure 2025114498000001_ABST
Abstract
Description
[Technical Field]
[0001] This disclosure relates generally to methods for building methods based on the framework of exact homomorphic encryption, and more particularly to methods based on the framework of exact homomorphic encryption for encryption and computation. [Background technology]
[0002] Related Applications This application claims priority to U.S. Provisional Patent Application No. 63 / 621,188, filed January 16, 2024, the entire disclosure of which is incorporated herein by reference.
[0003] Homomorphic encryption (HE) allows users to perform computations on encrypted messages without prior decryption, thereby providing a high level of security for data processing. Improvements to homomorphic encryption (HE) remained relatively limited over the next 30 years until Gentry's proposal in 2009. Gentry's paper made arbitrary cryptographic computation theoretically possible, subject to unlimited resources. However, noise accumulation poses an obstacle to the implementation of this technique. This problem is particularly pronounced due to the exponential increase of noise with the number of multiplications.
[0004] Quantum computing has recently attracted a great deal of attention due to its significant impact on data processing as well as information security. An interesting research area related to security risks is quantum public key encryption (QPKE). Its basic approach involves generating a one-way function to generate a quantum state that acts as a public key for encrypting a message. The main obstacle to QPKE is that it requires large-scale quantum operations, which falls under the challenge of scaling quantum computers.
[0005] Quantum homomorphic encryption (QHE) is another research area that has received increasing attention for protecting data operations. Typically, encrypted computations are performed using fault-tolerant Clifford+T circuits. Specifically, physical qubits outnumber logical qubits by at least several hundred times, which negates the accessibility of QHE. An alternative form replaces current HE with its quantum version. In addition to suffering from the drawbacks of the HE schemes mentioned above, the method under consideration consumes a large number of qubits and, as a result, faces the scalability barrier of quantum computers.
[0006] The series of episodes reveals a structure called a Quotient Algebra Partition (QAP), which exists universally in finite-dimensional unitary Lie algebras. Assuming that this structure carries over to all stabilizer codes, a general methodology for fault-tolerant quantum computation in QAP (abbreviated as QAPFTQC) derives an algorithmic procedure that ensures that all actions in all error-correcting codes are fault-tolerant. Fault-tolerant quantum computation is therefore derived by applying this encoding to codewords. [Prior art documents] [Non-patent literature]
[0007] [Non-Patent Document 1] "A FULLY HOMOMORPHIC ENCRYPTION SCHEME", Craig Gentry, A DISSERTATION SUBMITTED TO THE DEPARTMENT OF COMPUTER SCIENCE AND THE COMMITTEE ON GRADUATE STUDIES OF STANFORD UNIVERSITY IN PARTIAL FULFILLMENT OF THE REQUIREMENTS FOR THE DEGREE OF DOCTOR OF PHILOSOPHY Summary of the Invention [Means for solving the problem]
[0008] Therefore, the inventors of the present concept introduce a computer-implemented method based on the framework of exact homomorphic encryption and a system for encryption and computation in the frame of exact homomorphic encryption that stems from the concept of QAPFTQC. An exact homomorphic encryption (EHE) framework is proposed to allow computation on encrypted data. Message encryption and computation encryption in EHE can be considered similar to the fault-tolerant counterparts of quantum state ciphertexts and computation in QAPFTQC.
[0009] The inventive concept provides a computer-implemented method based on the framework of Exact Homomorphic Encryption (EHE), which includes:
[0010] S10. Multivariate polynomials in k variables
number
number
number
[0011] S20. Elementary gates for k qubits
number
number
[0012] S30. Applying elementary gates to quantum states;
[0013] S40. Applying elementary gates to the variables to generate multivariate polynomials over the binary field Z2, formulated as the following transformation rules:
[0014]
number
[0015] where x s ∈Z2 is a binary variable,
number
[0016] S50. A first encryption mapping R is a sequential product of randomly selected elementary gates. en defining; and
[0017] S60. First encryption operator R en to generate a set of w multivariate polynomials that serve as public encryption keys for encoding a k-qubit plaintext into a w-qubit ciphertext, where w≧k, for message encryption.
[0018] According to the concept of the present invention, the basic gates include negation, CNOT, Toffoli, and multi-controlled gates.
[0019] According to the inventive concept, the method may further comprise:
[0020] S70. Introduce a desired operation M of n qubits (n>w), where M is represented as a circuit composed of n qubit elementary gates;
[0021] S80. Second encryption mapping R cv Define where R cv is the ordered product of randomly chosen n-qubit elementary gates;
[0022] S90. Encoding a desired operation M into a cryptographic action, where the desired operation M is a first cryptographic operator R en and a second encryption operator R cv Encrypted through the encryption action U;
[0023] S100. Generating an encrypted polynomial set from the encrypted action U; and
[0024] S110. Evaluate the encrypted polynomial set on the ciphertext to obtain an encrypted computation.
[0025] According to the concept of the present invention, step S40 may further include:
[0026] S41. Give a second binary string ζ, where the second binary string ζ determines how the variables interact in the monomial;
[0027] S42. Based on the second binary string ζ, we find the monomial x θ Modified form
number
[0028] S43. Equation 1 is expressed as
[0029]
number
[0030] where s∈[k] and
number
number
[0031] According to the concept of the present invention, step S50 may further include:
[0032] S51. First encryption operator R en Define R as a product operation R, which is a k-qubit ordered product of elementary gates, as follows:
[0033]
number
[0034] where:
number
number
[0035] S52. Inverse product operation
number
number
[0036]
number
[0037] S53. For each basic state |x>, multiplication operation R and its inverse
number
[0038]
number
number
[0039] According to the concept of the present invention, step S50 may further include:
[0040] S54. Initial set P of multivariate polynomials in {g j (x)|j∈[w]}, where g j (x) corresponds to each of f(x), and g j Each of (x) is expressed as follows:
[0041]
number
[0042] where c τ,j ∈Z2 is a binary coefficient;
[0043] S55.Initial polynomial set P in For each polynomial in R en applying the
[0044] S56. An ordered set of polynomials that serves as a public encryption key
number
[0045] According to the concept of the present invention, step S60 may further include:
[0046] S61. Providing a plaintext |m>, where the plaintext consists of k qubits; and
[0047] S62. Encode the plaintext into ciphertext |c>, where the ciphertext is the public encryption P w,k (R en ;x), such that:
[0048] |c>=|f1(m)f2(m)…f w (m)>
[0049] where:
number
number
[0050] According to the inventive concept, the number of distinct polynomial sets generated by all permutations of the elementary gates that make up an operator R is the smallest number in h!, where h is the size of the largest set of pairwise non-commutative gates in R.
[0051] According to the concept of the present invention, step S60 may further include:
[0052] S63. First encryption mapping R en The w-qubit ciphertext |c> is
number
[0053] According to the inventive concept, the method may further comprise:
[0054] S120. Encrypted Action U cv Define where:
number
number
[0055] S130. Second encryption operator R cv and given a w-qubit ciphertext |c> of a k-qubit plaintext |m> derived from an n-qubit action M (n=w≧k), generate the following set of encrypted polynomials:
[0056]
number
[0057] where:
number
number
number
number
[0058] According to the inventive concept, the method may further comprise:
[0059] S140. First encryption operator R en and given a w-qubit ciphertext |c> of a k-qubit plaintext |m> derived from an n-qubit action M (n>w≧k), generate the following set of encrypted polynomials:
[0060]
number
[0061] Here, β i (z) is P n,w (U cv ;z) is the i-th polynomial (
number
[0062] According to the inventive concept, the method may further comprise:
[0063] S150.U cv e sections that make up the encryption circuit U cv,q parallelize (q∈[e]);
[0064] S160. Generate successive evaluations of the following encryption polynomial sets:
[0065]
number
[0066] The inventive concept further provides a system for encryption and computation in the framework of exact homomorphic encryption, the system including:
[0067] a program for executing a computer-implemented method based on the framework of exact homomorphic encryption according to the inventive concept; and
[0068] A computing architecture comprising a processing unit, where a program is deployed on the computing architecture.
[0069] In accordance with an inventive concept, a program for performing a computer-implemented method includes software for exact homomorphic encryption, where the software includes first code and second code.
[0070] According to the inventive concept, the first code is for message encryption.
[0071] According to the inventive concept, the second code is for executing a computer-implemented method based on the framework of exact homomorphic encryption.
[0072] In accordance with the inventive concept, the computing architecture includes a CPU, a GPU, or a combination thereof. [Brief explanation of the drawings]
[0073] [Figure 1] FIG. 1 is a schematic flow diagram according to an embodiment of the inventive concept. [Figure 2] 1 is a schematic diagram of the basic gates used in the algorithm according to the inventive concept; [Figure 3] FIG. 10 is a schematic flow diagram according to another embodiment of the inventive concept. [Figure 4] FIG. 10 is a schematic flow diagram according to another embodiment of the inventive concept. [Figure 5] FIG. 10 is a schematic flow diagram according to another embodiment of the inventive concept. [Figure 6] FIG. 10 is a schematic flow diagram according to another embodiment of the inventive concept. [Figure 7] FIG. 10 is a schematic flow diagram according to another embodiment of the inventive concept. [Figure 8]FIG. 1 illustrates (a) a process for an embodiment of the inventive concept in which messages and computations are mapped to the same space, and (b) a process for another embodiment of the inventive concept in which messages and computations are mapped to different encryption spaces. [Figure 9] FIG. 1 is a block diagram according to an embodiment of the inventive concept. [Figure 10] FIG. 10 illustrates test data for message encryption according to an embodiment of the inventive concept. [Figure 11] 10A-10C illustrate test data for cryptovaluations according to another embodiment of the inventive concepts. DETAILED DESCRIPTION OF THE INVENTION
[0074] The concept of the present invention is described by the following specific embodiments. After reading the disclosure of this specification, those skilled in the art can easily understand other advantages and functions of the concept of the present invention. Any changes or adjustments made to their relative relationships without changing the substantial technical content are also considered to be within the scope that can be implemented by the concept of the present invention.
[0075] Moreover, the words "exemplary" or "embodiment" are used herein to mean serving as an example, example, or illustration. Any aspect or design described herein as exemplary or an embodiment is not necessarily to be construed as preferred or advantageous over other aspects or designs. Rather, use of the words "exemplary" or "embodiment" is intended to illustrate concepts and techniques.
[0076] As used in this application, the word "or" is intended to mean an inclusive "or" rather than an exclusive "or." That is, unless otherwise specified or clear from the context, "X uses A or B" is intended to mean any of the natural inclusive permutations. That is, if X uses A, X uses B, or X uses both A and B, then "X uses A or B" is satisfied under any of the foregoing examples. Additionally, the articles "a" and "an," as used in this application and the appended claims, should generally be construed to mean "one or more" unless otherwise specified or clear from the context that the singular form is intended.
[0077] Please refer to Figure 1, which is a schematic flow diagram according to a method embodiment of the inventive concept. The inventive concept provides a computer-implemented method based on an Exact Homomorphic Encryption (EHE) framework. The method may include:
[0078] S10. Multivariate polynomials in k variables
number
[0079] According to the concept of the present invention, f(x) is a function of the coefficient c τ Monomial x of degree ≦ k with ∈Z2 τ Each monomial x τ teeth,
number
number
[0080] According to the inventive concept, the formula provides a basic representation of polynomials in the binary field Z2.
[0081] The polynomial f(x) can serve as the basis for encrypting and transforming data in the EHE framework.
[0082] According to the inventive concept, the method may further comprise:
[0083] S20. Elementary gates for k qubits
number
number
[0084] According to the inventive concept, elementary gates can operate on k-qubit quantum states, and the gates perform the transformation
number
number
[0085] According to the concept of the present invention, basic gates can include negation, CNOT, Toffoli, and multi-controlled gates, as shown in FIG.
[0086] All elementary gates are one-dimensional preserving transformations that map one underlying quantum state to another, see FIG. 2 for a schematic illustration. This set guarantees computational universality because AND and OR can be rephrased as Toffoli gates involving ancilla qubits. These gates can operate on quantum states to enable transformations within the EHE framework. The method of the inventive concept utilizes elementary quantum operations to manipulate data securely and allows for flexible transformations through the inclusion of these gates.
[0087] Each of the elementary gates used in the inventive concept is one-dimensionally conserving. This design avoids the large memory requirements associated with simulating a full quantum state and allows for execution on CPUs and GPUs without the need for a quantum computer.
[0088] According to the inventive concept, the method may further comprise:
[0089] S30. Applying elementary gates to quantum states;
[0090] S40. Applying elementary gates to the variables to generate multivariate polynomials over the binary field Z2, formulated as the following transformation rules;
[0091]
number
[0092] where x s ∈Z2 is a binary variable,
number
[0093] In accordance with the inventive concept, these steps can provide a precise mechanism for transforming a quantum state into a multivariate polynomial over a binary field Z2.
[0094] According to the inventive concept, the method may further comprise:
[0095] S50. A first encryption mapping R is a sequential product of randomly selected elementary gates. en and
[0096] S60. First encryption operator R en to generate a set of w multivariate polynomials that serve as public encryption keys for encoding a k-qubit plaintext into a w-qubit ciphertext, where w≧k, for message encryption.
[0097] The first encryption mapping is constructed to encode plaintext into ciphertext by applying a transformation to an input polynomial. In accordance with the inventive concept, the output can be a set of w multivariate polynomials that can form a public encryption key.
[0098] The mapping in Equation 1 effectively reveals a polynomial representation of the elementary gates. When this mapping is applied, the variable x s If the sth qubit is identical to the target bit, then the product x θ If the shift is not successful, the system will remain in place. In actual operation, elementary gates operate on monomial variables.
number
[0099] Please refer to FIG. 3, which is a schematic flow diagram according to another embodiment of the method of the inventive concept.
[0100] According to the inventive concept, the method may further comprise:
[0101] S70. Introduce a desired operation M of n qubits (n>w), where M is represented as a circuit composed of n qubit elementary gates.
[0102] According to the inventive concept, an operation can be represented as a circuit composed of n-qubit elementary gates and can serve as a computation that is homomorphically encrypted and executed.
[0103] According to the inventive concept, the method may further comprise:
[0104] S80. Second encryption mapping R cv Define where R cv is the ordered product of randomly chosen n-qubit elementary gates.
[0105] According to the inventive concept, the second encryption mapping R cv can introduce cryptographic complexity.
[0106] According to the inventive concept, the method may further comprise:
[0107] S90. Encoding a desired operation M into a cryptographic action, where the desired operation M is a first cryptographic operator R en and a second encryption operator R cv It is encrypted to the encryption action U through.
[0108] According to the inventive concept, the process ensures that the operation M is converted into a secure encrypted form that is compatible with ciphertext computation.
[0109] According to the inventive concept, the method may further comprise:
[0110] S100. Generating an encrypted polynomial set from the encrypted action U; and
[0111] S110. Evaluate the encrypted polynomial set on the ciphertext to obtain an encrypted computation.
[0112] According to the inventive concept, an encrypted action U can allow a computation to be performed in the encrypted domain, and a polynomial set can act as an intermediary for evaluating the encrypted operation.
[0113] The computation can be performed homomorphically without decrypting the ciphertext, thanks to the inventive concept. An evaluation process called cryptographic evaluation establishes a duality between polynomial evaluation and state computation, allowing the integrity of the encrypted computation to be verified.
[0114] Please refer to FIG. 4, which is a schematic flow diagram according to a method embodiment of the inventive concept.
[0115] According to the concept of the present invention, step S40 may further include:
[0116] S41. Give a second binary string ζ, where the second binary string ζ determines how the variables interact in the monomial;
[0117] S42. Based on the second binary string ζ, we find the monomial x θ Modified form
number
[0118] S43. Equation 1 is expressed as
[0119]
number
[0120] where s∈[k] and
number
number
[0121] According to the concept of the present invention, a second binary string ζ is introduced to modify the interaction of the monomials through control bits. The second binary string ζ can be used to extend the role of the control bits by introducing an additional degree of freedom in the modification of variables.
[0122] According to the concept of the present invention, the monomial x θ is the modified form
number
[0123]
number
[0124] where x i ∈Z2 can represent variables, and ζ i ∈Z2 can change the interaction of each variable based on its binary value, and ε i can determine the control bit configuration.
[0125] According to the inventive concept, the most general definition of an elementary gate of k variables over Z2 can be written as Equation 2.
[0126] According to the concept of the present invention, extending Equation 1 to Equation 2 is a generalization of the transformation rule, where:
number
[0127] In accordance with the inventive concept, generalization can generalize more complex polynomial transformations and enhance the framework's ability to represent and process non-linear relationships.
[0128] Please refer to FIG. 5, which is a schematic flow diagram according to a method embodiment of the inventive concept.
[0129] According to the concept of the present invention, step S50 may further include:
[0130] S51. First encryption operator R en Define R as a product operation R, which is a k-qubit ordered product of elementary gates, as follows:
[0131]
number
[0132] where:
number
number
[0133] According to the inventive concept,
number
[0134] According to the inventive concept, an ordered product R can encapsulate the successive applications of these gates into an encrypted representation of the state.
[0135] According to the inventive concept, basic gates, such as negation, CNOT, and Toffoli, can be used as building blocks for cryptographic mappings.
[0136] According to the concept of the present invention, step S50 may further include:
[0137] S52. Inverse product operation
number
number
[0138]
number
[0139] In this embodiment, the inverse operation can ensure symmetry, facilitating the invariant properties important to the encryption and decryption processes in the method of the present concept.
[0140] According to the concept of the present invention, step S50 may further include:
[0141] S53. For each basic state |x>, multiplication operation R and its inverse
number
[0142]
number
number
[0143] According to the concept of the present invention, an elementary gate of k qubits
number
[0144]
number
[0145] where r∈[k], θ=ε1ε2…ε k , and
number
[0146] The equation in Equation 3 can be viewed as an evaluation duality between a state and its associated polynomial. In particular,
number
number
number
number
number
number
number
[0147] R and its reciprocal
number
[0148] According to the inventive concept, successive applications of gates in R can introduce layers of complexity that exploit the non-commutative properties of basic gates for enhanced security.
[0149] equivalence
number
[0150] Please further refer to Figure 5. According to the concept of the present invention, step S50 may further include:
[0151] S54. Initial set P of multivariate polynomials in {g j (x)|j∈[w]}, where g j (x) corresponds to each of f(x), and g j Each of (x) is expressed as follows:
[0152]
number
[0153] where c τ,j ∈Z2 are binary coefficients,
number
[0154] According to the inventive concept, the polynomial set can be structured to be compatible with subsequent cryptographic transformations.
[0155] According to the concept of the present invention, step S50 may further include:
[0156] S55.Initial polynomial set P in For each polynomial in R en applying the
[0157] S56. An ordered set of polynomials that serves as a public encryption key
number
[0158] In this embodiment, the first encryption operator R en P in Each polynomial g in j (x) can be applied to the transformation
number
[0159] Polynomials can be transformed into a secure form while preserving structural integrity.
[0160] The algorithm isw,k (R en x), a first encryption operator R comprising a certain number of multi-controlled gates of higher rank ≥ 2 for the purpose of generating polynomials of higher degree; en Priority is given to R en Within the configuration of
number
number
[0161] In this embodiment, w≧k ensures sufficient encryption power of the plaintext. w,k (R en ;x) can serve as a reusable key for encoding plaintext into ciphertext.
[0162] Please refer to FIG. 6, which is a schematic flow diagram according to a method embodiment of the inventive concept.
[0163] According to the concept of the present invention, step S60 may further include:
[0164] S61. Providing a plaintext |m>, where the plaintext consists of k qubits; and
[0165] S62. Encode the plaintext into ciphertext |c>, where the ciphertext is the public encryption P w,k (R en ;x), such that:
[0166] |c>=|f1(m)f2(m)…f w (m)>
[0167] where:
number
number
[0168] In this embodiment, the plaintext |m> can serve as the data to be encrypted using the EHE framework of the inventive concept, and the public encryption P w,k (R en ;x) can serve as a functional basis for encoding plaintext into ciphertext. In particular, the ciphertext |c> is a multivariate polynomial set given a public key P w,k (R en ;x) rating.
[0169] According to the inventive concept, the number of distinct polynomial sets generated by all permutations of the elementary gates that make up an operator R is the smallest number in h!, where h is the size of the largest set of pairwise non-commutative gates in R.
[0170] In an embodiment of the inventive concept, the notion of a maximal set of pairwise non-commutative gates in R is introduced to ensure that the pairwise non-commutative gates satisfy A·B ≠ B·A and their order affects the resulting transformation. Additionally, the size of the maximal set is denoted as h, which captures the structural complexity of R.
[0171] As a result, there exists a public key P generated by an encryption mapping R whose maximal set of pairwise non-commutative gates is of size h. w,k (R en ;x) costs a combinatorial complexity comparable to h!
[0172] An encryption mapping R constructed from multiple disjoint subsets of mutually non-commutative gates. en About h l !·h l-1 The total complexity is given by !...h1! (h r , r∈[l]). This allows us to establish a cryptographic complexity criterion based on the structural properties of the cryptographic operator R. This result allows us to directly quantify the security strength of the cryptographic mapping of the inventive concept.
[0173] Please further refer to Figure 6. According to the concept of the present invention, step S60 may further include:
[0174] S63. First encryption mapping R en The w-qubit ciphertext |c> is
number
[0175] Due to duality, ciphertext
number
number
number
number
number
number
[0176] According to the concept of the present invention, the duality relation and R en The accuracy of the decryption is provided by the reversibility of the elementary gates used in (2), whereby the plaintext can be recovered exactly from the ciphertext without error, and in this respect the method of the inventive concept can be distinguished from noisy decryption methods of conventional systems.
[0177] The complexity of attacking a w-qubit reversible message encryption IME is determined by the complexity criterion T de-NC >T ICRP >T XL >2 W where T de-NC is the complexity of the decomposition non-commutativity of this IME, and T ICRP is the complexity of solving the reversible circuit reconstruction problem (ICRP) of this IME, and T XL is the complexity of attacking this IME via the XL algorithm, and 2 W is the complexity of attacking this IME via brute force methods.
[0178] The IME complexity criterion suggests that attacking the encryption key is more difficult than cracking the public key or the ciphertext.
[0179] Based on the complexity criterion, the security strength of the IME can be easily increased with little effort, and its maximum strength grows linearly with the length of the input plaintext.
[0180] Based on the complexity criteria, the public key P w,k (R en The security of IME using ;x) is based on post-quantum standard 2 128 , which exceeds the proposed threshold for hyper-quantum resistance of 2 1024 Further achieve this.
[0181] The security requirements of the IME meet advanced privacy demands beyond post-quantum standards.
[0182] The security requirements of the IME protect information from quantum attacks, including Grover's algorithm, quantum annealing, and quantum Groebner basis algorithms.
[0183] Please refer to FIG. 7, which is a schematic flow diagram according to a method embodiment of the inventive concept.
[0184] According to the inventive concept, the method may further comprise:
[0185] S120. Encrypted Action U cv Define where:
number
number
[0186] S130. Second encryption operator R cv Given a w-qubit ciphertext |c> of a k-qubit plaintext |m> derived from an n-qubit action M (n=w≧k), generate the following set of encrypted polynomials:
[0187]
number
[0188] where:
number
number
number
number
number
[0189] The inventive concept borrows the mechanism of QAPFTQC to encrypt the computation.
[0190] The k-qubit plaintext is then subjected to a first encryption operator R en Suppose that the second encryption operator R is encoded into w qubit ciphertext via a set of multivariate polynomials generated by cv With this, the n-qubit operation M, which is the circuit of the elementary gate, performs the encryption action
number
number
[0191] This encryption action is a simplified form of the fault-tolerant encoding in QAPFTQC. cv We rewrite the circuit in R as a set of n multivariate polynomials. Based on poetic duality, we obtain the cryptographic evaluation by evaluating this set of polynomials on the ciphertext. Finally, cvcan serve as a private cryptographic evaluation key to decrypt the encrypted calculations.
[0192] First, consider w = n. In this scenario, messages and computations are mapped into the same cryptographic space as shown in Figure 8(a).
[0193] In this embodiment, the public key of the reversible message encryption (IME) is R cv The polynomial set P generated by w,k (R cv ;x) encodes |m> into ciphertext |c>. In the strength of the binary relation, this ciphertext can instead be written as
number
number
number
number
number
number
number
[0194] Related States
number
number
number
number
number
number
[0195] According to the inventive concept,
number
number
number
[0196] In addition, the encryption action U cv enables secure computation by maintaining a cryptographic state throughout the process and keeping data confidential.
[0197] Further refer to Figure 7. According to the inventive concept, the method may further include:
[0198] S140. First encryption operator R en Given a w-qubit ciphertext |c> of a k-qubit plaintext |m> derived from an n-qubit action M (n>w≧k), generate the following set of encrypted polynomials:
[0199]
number
[0200] Here, β i (z) is the encryption polynomial ∈P n,w (U cv ;z) is the ith polynomial in (
number
[0201] Here, encryption
number
number
number
[0202] The proof is similar to that above, but
number
number
number
number
number
number
number
number
[0203] According to the inventive concept, the method may further comprise:
[0204] S150.U cv e sections that make up the encryption circuit U cv,q parallelize (q∈[e]); and
[0205] S160. Generate successive evaluations of the following encryption polynomial sets:
[0206]
number
[0207] In an embodiment of the inventive concept, the first encryption mapping R en The ciphertext |c>, a w-qubit ciphertext derived from U, encodes the k-qubit plaintext |m>, where |c> can serve as the input for an encrypted computation action. Then, U cv can further transform the ciphertext |c> in the encryption domain. Then, the encrypted polynomial set P n,w (U cv ;z) is generated, where each β i (z) is U cv The transformed variable z under the action of i It can respond to.
[0208] In another embodiment of the inventive concept, the encrypted action U cv e sections of the encryption circuit U cv,q The circuit can be divided into sections, each of which can handle a subset of the computation independently, facilitating parallel execution. cv Each of these is stored in the encrypted domain as a variable z i can be applied to.
[0209] For every circuit q, the encrypted polynomial set P n,w (U cv,q ;z) is generated,
number
[0210] All section circuits U cv,q are applied, the resulting polynomial sets can be successively combined. n,w (U cv,q ;z) into a final encrypted polynomial set to complete the computation.
[0211] More specifically, depending on the computing environment, the number e ranges from n / 2 to 4n for a single CPU and from n / 8 to n for multiple cores. Due to this division, the circuit has e component actions U q Product U of (q∈[e]) cv =U e U e-1 ...is factorized into U2U1. e sections, each containing randomly generated elementary gates, are cryptographic operators R q By arbitrarily choosing , each element Uq is, for 2 ≤ q ≤ e-1,
number
number
[0212]
number
[0213] Encrypted polynomial set P n,w (U cv,q :z) is the encrypted circuit U sv,q This allows for highly parallel generation of polynomial sets.
number
number
number
number
[0214] The complexity of attacking a computational encoding, which is a cryptographic evaluation of n qubits against a w-qubit ciphertext, is higher than 2W.
[0215] In cryptography, attacking a private key is more difficult than cracking a public key or ciphertext.
[0216] In cryptographic evaluation, security strength can be easily increased with little effort, and the maximum strength grows linearly with the length of the input ciphertext.
[0217] In cryptographic evaluation, security is evaluated based on the post-quantum standard 2 128 , which exceeds the proposed threshold for hyper-quantum resistance of 2 1024 Further achieve this.
[0218] The security requirements of the cryptographic evaluation meet advanced privacy demands beyond post-quantum standards.
[0219] The security requirements of the cryptographic evaluation protect information from quantum attacks, including Grover's algorithm, quantum annealing, and quantum Groebner basis algorithms.
[0220] See Figure 9. The inventive concept further provides a system 10 for encryption and computation in the framework of exact homomorphic encryption, the system including:
[0221] a program 11 for executing a computer-implemented method based on the framework of exact homomorphic encryption according to the inventive concept; and
[0222] Computational architecture 12. Here, the program 11 is deployed on the computational architecture 12.
[0223] In accordance with the inventive concept, the computing architecture 12 may include a processing unit 121. The processing unit may be, for example, but not limited to, a CPU, a GPU, a tensor processing unit, a field programmable gate array, an application specific integrated circuit, a quantum processing unit, a neural processing unit, a trusted platform architecture, a high bandwidth memory, etc., or a combination thereof.
[0224] According to the concept of the present invention, a program 11 for performing a computer-implemented method includes software 110 for exact homomorphic encryption, where the software 110 can include first code 111 and second code 112.
[0225] According to the inventive concept, the first code 111 can be used for message encryption.
[0226] According to the inventive concept, the second code 112 can be used to perform a computer-implemented method based on the framework of exact homomorphic encryption.
[0227] In an embodiment of the inventive concept, a system for encryption and computation in an exact homomorphic encryption framework may include a program including EHE software for performing a method based on the exact homomorphic encryption framework according to the inventive concept, and a 64-bit computing architecture, where the program is deployed on the computing architecture.
[0228] In this embodiment, the EHE software can consist of two pieces of code: the first piece of code can be for the IME, and the second piece of code can be for performing the EHE, including encryption of both messages and computations.
[0229] See FIG. 10, which illustrates test data for message encryption according to an embodiment of the inventive concept.
[0230] In this embodiment, the public key P w,k (R en ;x) The two parameters of P are put into the pair (k,w). As shown in Table 1, t kg-sc , t kg-mc , and t kg-sg represents the key generation time, and t en-sc , t en-mc , and t en-sg represents the encoding time, and t de-sc , t de-mc , and t de-sg represents the decoding time for single-CPU, multi-CPU, and single-node GPU, respectively. The duration of data reading and exchange is absorbed, which accounts for about 4% for key generation, 90% for encoding, and 2% for decoding.
[0231] Due to their significantly higher degree of parallelism, larger memory capacity, and faster data transfer rates, multi-CPU and single-node GPU platforms can achieve approximately a 10x to 20x increase in key generation and encoding efficiency compared to single-CPU systems. Nevertheless, for the decryption process, which involves linearly numbered elementary gates in w operating on the ciphertext, this exhibits short and comparable execution times across all three platforms.
[0232] In this embodiment, a case is presented with the maximal parameter pair (6400, 6440) that provides robust encryption with a high level of security that remains a challenge to achieve for existing post-quantum cryptographic systems. Implemented within reasonable time increments for key generation and encoding, the section strategy is expected to be equally well suited to message encryption, further increasing the level of security.
[0233] See FIG. 11, which illustrates test data for a cryptography evaluation according to another embodiment of the inventive concept.
[0234] Regarding the section cryptographic evaluation governed by the second code, the triplet (k, w, n) is the encrypted polynomial set P n,w (U cv,q ;z). To enable blind computation, it is important that the encrypted functions remain indistinguishable during the computation process. To achieve this, the execution times for generating the encrypted polynomials are carefully calibrated to be nearly identical.
[0235] In this embodiment, the number of sections is in the range n / 2≦e≦4n for single CPUs, and n / 8≦e≦n for multi-CPUs and single-node GPUs.
[0236] T kg-sc , T kg-mc , and T kg-sg represents the longest task span of polynomial generation between sections, and Tevl-sc , T evl-mc , and T evl-sg represents the evaluation time, and T de-sc , T de-mc , and T de-sg represent the decoding times for a single CPU, multiple CPUs, and a single-node GPU, respectively.
[0237] The overall timeline covers data read and communication times, which follow the same ratio as that of IME. As shown in Figure 10, the increased parallelism, memory capacity, and bandwidth of the multi-CPU and single-node GPU platforms result in a 10-20x performance boost for generating encrypted polynomial sets and performing polynomial evaluations compared to the baseline single-CPU system. Existing homomorphic encryption (HE) systems struggle to achieve similar efficiency gains because their parallelism is heavily constrained by the inherently sequential properties of recursive noise reduction.
[0238] In this embodiment, the decoding times are comparable across the three computing platforms, with the parameter triplets reaching maximum values of (256, 280, 400) on a single CPU, (1536, 1560, 2400) on multiple CPUs, and (1024, 1050, 1600) on a single-node GPU, respectively.
[0239] Methods and systems based on the exact homomorphic encryption framework of the inventive concept demonstrate clear advantages over the limitations of existing HE systems in handling significantly larger sizes of encrypted computations.
[0240] According to the inventive concept, when blindness is increased from the cryptographic evaluation of a linear k-function performed in a simpler encryption using fewer sections, key generation and encoding time can be reduced by a factor of 10 or more, and plaintext size undergoes a minimal expansion of 1.5 times.
[0241] Further improvements in processing speed and memory efficiency can be achieved by using exact single-bit operations rather than 64-bit computational units.
[0242] It is clear that the performance of the inventive concept increases with increasing problem size, significantly outperforming existing HE systems. This superiority stems from the inventive concept's ability to exploit inherent parallelism across multiple stages, including circuit segmentation, polynomial generation, polynomial evaluation, and monomial computation. In addition, at the fundamental level of machine code, the use of reversible gates has been found to be highly suitable for developing energy-efficient systems.
[0243] Experimental findings demonstrate that EHE possesses the ability to perform large-scale encrypted computations and the sophistication to a wide range of functions.
[0244] The present invention provides a method and system based on the framework of exact homomorphic encryption (EHE) that integrates the two concepts of quantum computation and encryption. Quantum gates are introduced in EHE to replace the irreversible logical operations used in finite computation. Each quantum gate not only operates on quantum states as in the conventional case, but also on variables to generate polynomials. This approach allows for the implementation of message and computation encryption through cryptographic transformations constructed from randomly selected products of quantum gates.
[0245] Due to the simple duality relationship of the EHE framework, the ciphertext is generated by evaluating a set of polynomials on the input plaintext, while the encrypted computation result is obtained by evaluating a set of encrypted polynomials on the ciphertext. Completely different from the lengthy ciphertexts of the two major existing post-quantum encryption systems, the size of the ciphertext provided by the inventive concept is compact.
[0246] The success of methods and systems based on the EHE framework of the inventive concept lies in two functional properties of quantum gates: reversibility and non-commutativity. Unlike existing noisy schemes of homomorphic encryption, the inventive concept achieves exact encrypted computation through the use of reversible gates, ensuring precise decryption that surpasses the noisy decryption methods of current encryption systems.
[0247] Furthermore, blindness in homomorphic encryption computations is achieved through the indistinguishability of the encoded functions, thereby protecting both data and computations, an achievement that is not achievable with current HEs. In the face of quantum adversarial attacks, the inventive concept achieves a quantum-resistant threshold of 2. 128 Beyond the proposed hyper-quantum-resistant benchmark2 1024 Since each activated gate is dimension-preserving, i.e., one-dimensionally preserving, the inventive concept can be seamlessly implemented in a conventional computing environment without requiring a quantum computer.
[0248] Through a joint effort with multinational corporations, it is proposed to build dedicated hardware for the EHE that provides massive parallelism, large amounts of memory, fast data access transfers, cores that provide minimal functionality, and single-bit accurate calculations.
[0249] The EHE framework can be deployed in a wide range of fields, including but not limited to military defense, government operations, financial services, trusted AI, medical healthcare, next-generation communications, low earth orbit (LEO), unmanned aerial vehicles (UAVs), etc. EHE's strengths in each subject are greatly enhanced by dedicated hardware in mobile devices developed through miniaturization technology based on Taiwan's cutting-edge semiconductor industry.
[0250] The above description of the detailed embodiments is presented only to disclose the features and functions of the inventive concept, and is not intended to limit the scope of the inventive concept. Those skilled in the art will understand that all modifications and variations according to the spirit and principles of the disclosure of the inventive concept are within the scope of the appended claims.
Claims
1. 1. A computer-implemented method based on an Exact Homomorphic Encryption (EHE) framework, the method comprising: S10. Multivariate polynomials of k variables [Equation 1] where f(x) is a function of the coefficient c τ ∈Z 2 monomial x of degree ≦k with τ is a linear combination of each monomial x τ teeth, [Equation 2] where x r ∈Z 2 , [Equation 3] , and r∈[k], where [k] represents the set of positive integers from 1 to k; S20. Elementary gates for k qubits [Equation 4] where the integer r represents the rth qubit as the target qubit of the elementary gate, and the k-bit binary string [Equation 5] where the non-zero entities of indicate the positions of the qubits that serve as control bits, and S30. Applying elementary gates to quantum states; S40. Apply elementary gates to variables to create a binary field Z, which is formulated as the following transformation rule: 2 generating a multivariate polynomial over [Equation 6] Here, x s ∈Z 2 is a binary variable, [Equation 7] is a monomial in k variables; S50. A first encryption mapping R is a sequential product of randomly selected elementary gates. en and S60. First encryption operator R en to generate a set of w multivariate polynomials that serve as public encryption keys for encoding a k-qubit plaintext into a w-qubit ciphertext, where w≧k, for message encryption; 10. A computer-implemented method comprising:
2. A computer-implemented method based on the exact homomorphic encryption framework of claim 1, comprising: The basic gates include negation, CNOT, Toffoli, and multi-controlled gates; 10. A computer-implemented method comprising:
3. A computer-implemented method based on the exact homomorphic encryption framework of claim 2, comprising: The method comprises: S70. Introducing a desired operation M of n qubits (n>w), where M is represented as a circuit composed of n qubit elementary gates; S80. Second encryption mapping R cv and defining R cv is the ordered product of randomly selected n-qubit elementary gates; S90. Encoding a desired operation M into a cryptographic action, said desired operation M being a function of said first cryptographic operator R en and the second encryption operator R cv Encryption action U via encoding; S100. Generate an encrypted polynomial set from the encrypted action U; S110. Evaluating the encrypted polynomial set on the ciphertext to obtain an encrypted computation; 20. The computer-implemented method of claim 19, further comprising:
4. A computer-implemented method based on the exact homomorphic encryption framework of claim 3, comprising: Step S40 S41. Providing a second binary string ζ, the second binary string ζ determining how variables interact within a monomial; S42. Based on the second binary string ζ, the monomial x θ Modified form [Equation 8] and changing it to S43. Formula 1 is [Equation 9] where s∈[k] and [Equation 10] teeth [0011] and extending, which is defined as 20. The computer-implemented method of claim 19, further comprising:
5. A computer-implemented method based on the exact homomorphic encryption framework of claim 4, comprising: Step S50 S51. First encryption operator R en as a product operation R that is a k-qubit ordered product of elementary gates, as follows: [0012] where: [0013] is the control string [0014] Using the rth i represents the i-th elementary gate acting on a qubit of S52. Inverse product operation [Equation 15] to define [0016] is the reverse order product of R and is defined as follows: [Equation 17] S53. For each basic state |x>, multiply R and its inverse [Equation 18] The following equation between [Equation 19] where: [Equation 20] and 20. The computer-implemented method of claim 19, further comprising:
6. A computer-implemented method based on the exact homomorphic encryption framework of claim 5, comprising: Step S50 S54. Initial set P of multivariate polynomials in {g j (x) | j∈[w]}, where g j (x) corresponds to each of f(x), and g j Each of (x) is expressed as follows: [0000] Here, c τ,j ∈Z 2 is a binary coefficient, and S55. initial polynomial set P in For each polynomial, multiplication operation R en and S56. An ordered set of polynomials that serves as a public encryption key [Equation 22] where w≧k is the number of polynomials; and 20. The computer-implemented method of claim 19, further comprising:
7. A computer-implemented method based on the exact homomorphic encryption framework of claim 6, comprising: Step S60 S61. Providing a plaintext |m>, the plaintext consisting of k quantum bits; S62. Encoding plaintext into ciphertext |c>, wherein the ciphertext is a public encryption P w,k (R en x), where: |c>=|f 1 (m)f 2 (m)…f w (m)> Equation 4 where: [Equation 23] 、 [0000] , and f j (m)∈Z 2 is the j-th polynomial f on the plaintext j (x)∈P w,k (R en x), where 1≦j≦w; 20. The computer-implemented method of claim 19, further comprising:
8. A computer-implemented method based on the exact homomorphic encryption framework of claim 7, comprising: The number of distinct polynomial sets generated by all permutations of the elementary gates that make up the operator R is the smallest number in h!, where h is the size of the largest set of pairwise non-commutative gates in R.
10. A computer-implemented method comprising:
9. A computer-implemented method based on the exact homomorphic encryption framework of claim 7, comprising: Step S60 S63. The first encryption mapping R en The w-qubit ciphertext |c> is [Equation 25] to recover the plaintext m; 20. The computer-implemented method of claim 19, further comprising:
10. 10. A computer-implemented method based on an exact homomorphic encryption framework as claimed in claim 9, comprising: S120. Encrypted Action U cv to define [Equation 26] where: [0000] is the reverse order product of M(n≧w), and I is the identity operator of n−w qubits; S130. Second encryption operator R cv and a w-qubit ciphertext |c> of a k-qubit plaintext |m> derived from an n-qubit action M, where n=w≧k, generating the following set of encrypted polynomials: [0000] [0000] is the encryption action, [Equation 30] and α i (z) is [Equation 31] is the i-th polynomial of ( [Equation 32] ), generating 20. The computer-implemented method of claim 19, further comprising:
11. A computer-implemented method based on the exact homomorphic encryption framework of claim 10, comprising: The method comprises: S140. First encryption operator R en and a w-qubit ciphertext |c> of a k-qubit plaintext |m> derived from an n-qubit action M, where n>w≧k, generating the following set of encrypted polynomials: [Equation 33] β i (z) is P n,w (U cv ; z) is the i-th polynomial ( [Equation 34] ), generating, 20. The computer-implemented method of claim 19, further comprising:
12. A computer-implemented method based on the exact homomorphic encryption framework of claim 11, comprising: The method comprises: S150.U cv e section encryption circuits U cv,q Parallelizing (q∈[e]) S160. Generating successive evaluations of the following encrypted polynomial sets: [Equation 35] 20. The computer-implemented method of claim 19, further comprising:
13. 1. A system for encryption and computation in a framework of exact homomorphic encryption, comprising: The system comprises: a program for executing a computer-implemented method based on the framework of exact homomorphic encryption according to any one of claims 1 to 12; a computing architecture comprising a processing unit, the program being deployed on the computing architecture; A system comprising:
14. 14. A system for encryption and computation in the framework of exact homomorphic encryption according to claim 13, comprising: the program for performing the computer-implemented method includes software for exact homomorphic encryption; the software includes first code and second code; A system characterized by:
15. 15. A system for encryption and computation in the framework of exact homomorphic encryption according to claim 14, comprising: the first code is for encrypting the message; A system characterized by:
16. 15. A system for encryption and computation in the framework of exact homomorphic encryption according to claim 14, comprising: the second code is for executing the computer-implemented method based on an exact homomorphic encryption framework. A system characterized by:
17. 14. A system for encryption and computation in the framework of exact homomorphic encryption according to claim 13, comprising: the computing architecture includes a CPU, a GPU, or a combination thereof; A system characterized by:
Citation Information
Patent Citations
Encryption device, decryption device, cipher method, decryption method, encryption program, and decryption program
JP2022077754A
Design method for public key system in QAP-based homomorphic encryption
JP2023063201A
Error reduction and, or, correction in analog computing including quantum processor-based computing
US20220019929A1
Method of Designing of Multi-Party System in QAP-Based Homomorphic Encryption
US20230188343A1
Cited By
Smart contract environment-based homomorphic encryption quantitative verification server and method for operating the same
KR102989963B1