Encryption method and apparatus based on homomorphic encryption using odd function property
By using the properties of odd functions to perform modular reduction and bootstrapping on the ciphertext, an approximating polynomial is generated, which solves the problem of insufficient privacy protection in fully homomorphic encryption methods and improves data processing efficiency.
Patent Information
- Application Number
- CN202110380217.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-10-26
- Filing Date
- 2021-04-08
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2041-04-08
AI Technical Summary
Existing fully homomorphic encryption methods are ineffective at processing encrypted data, resulting in insufficient protection of customer privacy.
By using the property of odd functions to perform modular reduction on the ciphertext, an approximate polynomial is generated and bootstrap is performed, reducing the number of nonscalar multiplications and improving computational efficiency.
It enables efficient processing of encrypted data while protecting privacy, and improves the computational performance of homomorphic encryption.
Smart Images

Figure CN113630233B_ABST
Abstract
Description
[0001] Cross Reference to Related Applications
[0002] This application claims priority to U.S. Provisional Patent Application No. 63 / 021,761 filed on May 8, 2020, and Korean Patent Application No. 10-2020-0139479 filed in the Korean Intellectual Property Office on October 26, 2020, the disclosures of which are incorporated herein by reference in their entireties for all purposes. TECHNICAL FIELD
[0003] The following description relates to an encryption method and apparatus based on homomorphic encryption using odd function properties. BACKGROUND
[0004] Fully homomorphic encryption is an encryption scheme that enables arbitrary logical or mathematical operations to be performed on encrypted data. The fully homomorphic encryption method maintains security in data processing.
[0005] However, conventional encryption methods are difficult to process encrypted data, and thus are insufficient to protect the privacy of customers.
[0006] Fully homomorphic encryption enables customers to receive many services while protecting privacy. SUMMARY
[0007] This summary is provided to introduce a selection of concepts, which are further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in determining the scope of the claimed subject matter.
[0008] In one general aspect, an encryption method using homomorphic encryption includes generating ciphertext by encrypting data, and bootstrapping the ciphertext by performing a modulus reduction based on an odd function property with respect to a modulus corresponding to the ciphertext.
[0009] The bootstrapping can include bootstrapping the ciphertext by transforming an approximating polynomial approximating the modulus reduction based on the odd function property.
[0010] The bootstrapping the ciphertext by performing the modulus reduction based on the odd function property can include obtaining an approximating polynomial approximating the modulus reduction, generating a transformed approximating polynomial by transforming the approximating polynomial, and performing the modulus reduction based on the odd function property and the transformed approximating polynomial.
[0011] The generating the transformed approximating polynomial by transforming the approximating polynomial can include generating the transformed approximating polynomial by reducing a degree of the approximating polynomial.
[0012] Generating the transformed approximating polynomial by transforming the approximating polynomial can include determining a maximum degree of the transformed approximating polynomial based on a degree of the approximating polynomial, and generating the transformed approximating polynomial by performing a division operation on the approximating polynomial based on the maximum degree.
[0013] Generating the transformed approximating polynomial by transforming the approximating polynomial can include determining a maximum degree of the transformed approximating polynomial based on a degree of the approximating polynomial, and generating the transformed approximating polynomial by performing a division operation on the approximating polynomial based on the maximum degree.
[0014] Determining the maximum degree of the transformed approximating polynomial based on the degree of the approximating polynomial can include determining the maximum degree based on an operation depth of the approximating polynomial and a number of non-scalar multiplications used for the ciphertext.
[0015] Generating the transformed approximating polynomial by performing the division operation on the approximating polynomial based on the maximum degree can include generating the transformed approximating polynomial by performing the division operation on the approximating polynomial based on one or more polynomial bases.
[0016] The one or more polynomial bases can be bases of Chebyshev polynomials.
[0017] In another general aspect, an encryption device using homomorphic encryption includes a processor configured to generate a ciphertext by encrypting data, and bootstrap the ciphertext by performing a modulo reduction based on an odd function property for a modulus corresponding to the ciphertext, and a memory configured to store instructions to be executed by the processor.
[0018] The processor can be configured to bootstrap the ciphertext by transforming an approximating polynomial approximating the modulo reduction based on the odd function property.
[0019] The processor can be configured to obtain an approximating polynomial approximating the modulo reduction, generate a transformed approximating polynomial by transforming the approximating polynomial, and perform the modulo reduction based on the odd function property and the transformed approximating polynomial.
[0020] The processor can be configured to generate the transformed approximating polynomial by reducing a degree of the approximating polynomial.
[0021] The processor can be configured to generate the transformed approximating polynomial to have a field corresponding to a square of a field of the approximating polynomial.
[0022] The processor can be configured to determine a maximum degree of the transformed approximating polynomial based on a degree of the approximating polynomial, and generate the transformed approximating polynomial by performing a division operation on the approximating polynomial based on the maximum degree.
[0023] The processor can be configured to determine the maximum degree based on an operation depth of the approximating polynomial and a number of non-scalar multiplications used for the ciphertext.
[0024] The processor can be configured to generate the transformed approximating polynomial by performing a division operation on the approximating polynomial based on one or more polynomial bases.
[0025] The one or more polynomial bases can be bases of Chebyshev polynomials.
[0026] Other features and aspects will become apparent from the following detailed description, drawings and claims. BRIEF DESCRIPTION OF DRAWINGS
[0027] Figure 1 An example of an encryption device is shown.
[0028] Figure 2 An example of evaluating an approximating polynomial by an encryption device of Figure 1 is shown.
[0029] Figure 3 An example of an algorithm for evaluating an approximating polynomial by an encryption device of Figure 1 is shown.
[0030] Figure 4 An example of an operation of an encryption device of Figure 1 is shown.
[0031] Throughout the drawings and the specific embodiments, identical reference numerals should be understood to refer to identical elements, features, and structures. The drawings can not be to scale and the dimensions of the various elements can be exaggerated for clarity, illustration, and convenience. DETAILED DESCRIPTION
[0032] Hereinafter, examples will be described in detail with reference to the accompanying drawings. However, various changes and modifications can be made to the examples. Herein, the examples are not to be interpreted as limiting the inventive concept and the technical scope of the present disclosure. The examples should be understood to include all changes, equivalents, and substitutes included in the spirit and technical scope of the present disclosure.
[0033] The terminology used herein is for the purpose of describing particular examples only and is not intended to be limiting of examples. As used herein, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0034] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the examples belong. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.
[0035] When the examples are described with reference to the drawings, the same drawing reference numerals are used throughout the drawings and repeated descriptions are omitted. In the description of the examples, detailed descriptions of well-known related structures or functions will be omitted when it is deemed that such descriptions will cause obscuring of the present disclosure.
[0036] Further, when components of the present disclosure are described, terms such as first, second, A, B, (a), (b) can be used to describe the components. These terms are used only for the purpose of distinguishing one component from another component, and the nature, order or sequence of the components is not limited by the terms. When one component is described as being "connected," "coupled," or "attached" to another component, it should be understood that the one component can be directly connected or attached to the other component, and a third component can also be "connected," "coupled," or "attached" between the one component and the other component.
[0037] The same names can be used to describe elements included in the above-described examples and elements having common functions. Unless otherwise mentioned, the description with respect to the examples can be applied to the following examples, and thus repeated descriptions will be omitted for the sake of brevity.
[0038] Figure 1 An example of an encryption device is illustrated.
[0039] Reference Figure 1 The encryption device 10 can encrypt data. The encryption device 10 can generate encrypted data by encrypting the data. Hereinafter, the encrypted data can be referred to as ciphertext.
[0040] The encryption device 10 can perform encryption and decryption using homomorphic encryption. The encryption device 10 can provide an encryption technique for operating data encrypted using homomorphic encryption without decryption. For example, the encryption device 10 can decrypt a result obtained by operating data encrypted using homomorphic encryption, thereby obtaining the same result as an operation performed on plaintext data. The encryption device 10 can provide a homomorphic encryption operation for real or complex numbers.
[0041] The encryption device 10 can perform bootstrapping required for homomorphic encryption. The encryption device 10 can generate an approximation polynomial that approximates a function corresponding to a modulus reduction required for homomorphic encryption.
[0042] The encryption device 10 can find a minimax approximation error for each degree of an optimal minimax approximation polynomial.
[0043] The encryption device 10 can find an approximation polynomial that optimally approximates a modulus reduction function, thereby providing excellent performance in terms of a minimax approximation error of homomorphic encryption.
[0044] The encryption device 10 can generate an approximation polynomial that approximates a modulus reduction function based on approximation region information for approximating the modulus reduction function. The encryption device 10 can perform modulus reduction based on an odd function property. The encryption device 10 can perform bootstrapping by performing modulus reduction based on the odd function property.
[0045] The encryption device 10 includes a processor 100 and a memory 200.
[0046] The processor 100 can process data stored in the memory. The processor 100 can execute computer readable codes (e.g., software) stored in the memory 200 and instructions triggered by the processor 100.
[0047] The processor 100 can be a data processing device implemented by hardware including a circuit having a physical structure for performing a desired operation. For example, the desired operation can include an instruction or code included in a program.
[0048] For example, the hardware-implemented data processing device can include a microprocessor, a central processing unit (CPU), a processor core, a multi-core processor, a multi-processor, an application-specific integrated circuit (ASIC), and a field-programmable gate array (FPGA).
[0049] The processor 100 can generate ciphertext by encrypting data. The processor 100 can bootstrap the ciphertext by performing modulus reduction based on an odd function property for a modulus corresponding to the ciphertext.
[0050] The processor 100 can obtain an approximating polynomial of an approximating modular reduction function. The processor 100 can generate a transformed approximating polynomial by transforming the approximating polynomial.
[0051] The processor 100 can generate the transformed approximating polynomial by reducing a degree of the approximating polynomial. The processor 100 can generate the transformed approximating polynomial to have a field corresponding to a square of a field of the approximating polynomial.
[0052] The processor 100 can determine a maximum degree of the transformed approximating polynomial based on a degree of the approximating polynomial. The processor 100 can determine the maximum degree based on an operation depth of the approximating polynomial and a number of non-scalar multiplications used for a ciphertext.
[0053] The processor 100 can generate the transformed approximating polynomial by performing a division operation on the approximating polynomial based on the determined maximum degree. The processor 100 can generate the transformed approximating polynomial by performing a division operation on the approximating polynomial based on one or more polynomial bases. In this example, the polynomial bases can be bases of Chebyshev polynomials.
[0054] The processor 100 can perform a modular reduction based on an odd function property and the transformed approximating polynomial.
[0055] The memory 200 can store instructions (or programs) executable by the processor 100. For example, the instructions can include instructions for performing operations of the processor 100 and / or operations of each element of the processor 100.
[0056] The memory 200 can be implemented as a volatile memory device or a non-volatile memory device.
[0057] The volatile memory device can be implemented as a dynamic random access memory (DRAM), a static random access memory (SRAM), a thyristor RAM (T-RAM), a zero capacitor RAM (Z-RAM), or a dual transistor RAM (TTRAM).
[0058] The non-volatile memory device can be implemented as an electrically erasable programmable read-only memory (EEPROM), a flash memory, a magnetic RAM (MRAM), a spin-transfer torque (STT)-MRAM, a conductive-bridge RAM (CBRAM), a ferroelectric RAM (FeRAM), a phase change RAM (PRAM), a resistive RAM (RRAM), a nanotube RRAM, a polymer RAM (PoRAM), a nanofloating gate memory (NFGM), a holographic memory, a molecular electronic memory device, or a resistive-change memory of an insulator.
[0059] Hereinafter, a detailed description will be given of the processor 100 and the memory 200 with reference to the accompanying drawings. Figures 2-3The detailed description transforms the approximating polynomial.
[0060] Figure 2 An example of evaluating the approximating polynomial by Figure 1 an encryption device of Figure 3 An example of an algorithm for evaluating the approximating polynomial by Figure 1 an encryption device of
[0061] With reference to Figure 2 and Figure 3 the encryption device 10 can directly evaluate the approximating polynomial of the approximating modulo reduction function.
[0062] There can be a trade-off between the degree of the approximating polynomial and the minimax approximation error. The processor 100 can transform the approximating polynomial of the approximating modulo reduction function, thereby reducing the run-time of evaluating the approximating polynomial.
[0063] For example, the processor 100 can evaluate the modulo reduction function by changing the form of the approximating polynomial of the approximating modulo reduction function using the Paterson-Stockmeyer algorithm or the baby-step giant-step algorithm.
[0064] The processor 100 can transform the obtained approximating polynomial using the odd function property, thereby improving the evaluation rate. For the minimax approximating polynomial of the odd function, the processor 100 can use the odd function property to improve the rate of evaluating the approximating polynomial.
[0065] For bootstrap in homomorphic encryption, the processor 100 can approximate the normalized modulo reduction function on a near integer. In this example, the normalized modulo reduction function can have the odd function property.
[0066] Therefore, when obtaining the coefficients of the approximating polynomial, the processor 100 can consider only the coefficients of the odd degree terms. As such, the processor 100 can reduce the run-time of the modulo reduction.
[0067] The evaluation of the approximating polynomial can be performed on the ciphertext domain. Therefore, the run-time of evaluating the approximating polynomial can occupy a large portion of the entire encryption and decryption process. The processor 100 can perform the modulo reduction by evaluating the approximating polynomial each time bootstrap is performed.
[0068] The processor 100 can use the odd function property of the approximating polynomial to reduce the number of non-scalar multiplications. The non-scalar multiplication can include multiplication between ciphertexts.
[0069] The processor 100 can transform the approximating polynomial using two schemes. First, when applying the Paterson-Stockmeyer algorithm, the processor 100 can transform the approximating polynomial to reduce the number of non-scalar multiplications. The processor 100 can reduce the number of non-scalar multiplications by 30% using the odd function property of the approximating polynomial of the modulo reduction function.
[0070] The processor 100 can transform the approximating polynomial using Equation 1.
[0071] [Equation 1]
[0072] f(x) = xg(x 2 )
[0073] The processor 100 can generate the transformed approximating polynomial by reducing the degree of the approximating polynomial as shown in Equation 1. The processor 100 can generate the transformed approximating polynomial to have a field corresponding to the square of the field of the approximating polynomial.
[0074] The processor 100 can transform the approximating polynomial f(x) of degree 2n+1 into a polynomial g(x) of degree n using the odd function property. The coefficient of the i-th term of g(x) can be equal to the coefficient of the (2i+1)-th term of f(x).
[0075] Through the above transformation, the processor 100 can evaluate the polynomial g(x) of degree n, square x and substitute g(x), and finally multiply by x.
[0076] In this way, the processor 100 can reduce the number of non-scalar multiplications from to This reduces the number of non-scalar multiplications by 30%.
[0077] The processor 100 can consume one more depth by transforming the approximating polynomial into a higher degree approximating polynomial, thereby reducing the number of non-scalar multiplications.
[0078] Second, the processor 100 can transform the approximating polynomial using the small step large step algorithm. Through the second scheme, the processor 100 can reduce the running time of the modulo reduction without consuming any additional depth.
[0079] The processor 100 can determine the maximum degree of the transformed approximating polynomial based on the degree of the approximating polynomial. The processor 100 can determine the maximum degree based on the operation depth of the approximating polynomial and the number of non-scalar multiplications for the ciphertext.
[0080] Figure 2The operations 211 to 216 can be a process of determining the maximum degree of the transformed approximation polynomial, and the operations 217 to 227 can be a process of transforming the approximation polynomial based on the determined maximum degree. Figure 3 The algorithm 1 can correspond to Figure 2 The operations 217 to 227.
[0081] The processor 100 can determine the maximum degree before bootstrapping, and during the actual bootstrapping process, only perform the operation of performing modular reduction using the determined maximum degree. In other words, the process of the operations 211 to 216 can be performed before bootstrapping.
[0082] The processor 100 can determine the maximum degree of the transformed approximation polynomial based on the degree of the approximation polynomial. The processor 100 can determine the maximum degree based on the operation depth of the approximation polynomial and the number of non-scalar multiplications for the ciphertext.
[0083] In operation 211, the processor 100 can replace k' with 2 and replace min with ∞. In operation 212, the processor 100 can obtain m' that satisfies k'·2 m′-1 ≤ d ≤ k'·2 m′ Then, in operation 213, the processor 100 can determine whether the value of k'·2 is less than min and satisfies k'·2
[0084] In this example, the value of k'·2 represents the number of non-scalar multiplications, and represents the operation depth. In other words, the processor 100 can determine k and m by determining whether the minimum value is less than the number of non-scalar multiplications, and whether the operation depth satisfies the condition k'·2 to determine the maximum degree of the Chebyshev polynomial used for the approximation polynomial transformation.
[0085] If the condition of operation 213 is satisfied, in operation 214, the processor 100 can replace k with k' and replace m with m'. If the condition of operation 213 is not satisfied, in operation 215, the processor 100 can replace k' with k' + 2.
[0086] In operation 216, the processor 100 can determine whether If the condition of operation 216 is satisfied, operation 212 can be repeated.
[0087] If the condition of operation 216 is not satisfied (or if ), in operation 217, the processor 100 can use the relation T 2i (t) = 2Ti (t) 2 -1 pair Calculate the value.
[0088] In operation 218, processor 100 can process T3(t), T5(t), ..., T k-1 (t) Evaluation. In operation 219, processor 100 can evaluate... Evaluation. In operation 220, processor 100 can be evaluated by dividing by... Calculate the quotient q(t) and remainder r(t) of p(t).
[0089] In operation 221, processor 100 can determine whether the number of iterations of q(t) is less than k. If the condition of operation 221 is met, then in operation 222, processor 100 can utilize T1(t), T3(t), T5(t), ..., T k-1 The processor 100 evaluates q(t) in operation 223 if the condition of operation 221 is not met (or if the number of times q(t) is greater than or equal to k).
[0090] In operation 224, processor 100 can determine whether the number of times r(t) is less than k. If the condition of operation 224 is met, then in operation 225, processor 100 can utilize T1(t), T3(t), T5(t), ..., T k-1 The processor 100 evaluates r(t) in operation 226 if the condition of operation 224 is not met (or if the number of r(t) is greater than or equal to k).
[0091] If the evaluation of q(t) and r(t) is completed, then in operation 227, processor 100 can... Calculate the value.
[0092] When f is a polynomial with any number of odd-degree terms and g is a polynomial with even-degree terms, if f = gq + r satisfies the condition deg r < deg g, then q and r can both be polynomials with odd-degree terms.
[0093] When dividing the approximation polynomial by an even-degree Chebyshev polynomial, the processor 100 can recursively use the polynomial corresponding to the quotient and the polynomial corresponding to the remainder.
[0094] Since the approximation polynomial is an odd function as described above, and the Chebyshev polynomial of even degree is an even function, the polynomial corresponding to the quotient and the polynomial corresponding to the remainder can both be odd functions.
[0095] The processor 100 can divide the approximating polynomial into Chebyshev polynomials of the first kind, which are odd functions, by a number of successive divisions. Then, the processor 100 can not use Chebyshev polynomials of even degree, and thus, can not have to evaluate Chebyshev polynomials of even degree. Since the even degree terms are not calculated, the processor 100 can reduce the number of non-scalar multiplications.
[0096] In the original small step large step algorithm, the length of the small step is a power of 2. However, the processor 100 can use the odd function property of the approximating polynomial to perform the small step with a length of an arbitrary positive integer. By doing so, the processor 100 can more finely optimize the number of non-scalar multiplications without consuming additional depth.
[0097] In the odd function case, the length of the small step is limited to a positive even number, in which the large step Chebyshev polynomial must be an even function. If the degree of the approximating polynomial is d, and the length of the small step is k, then in the original small step large step algorithm, the number of non-scalar multiplications can be and the depth can be
[0098] In the odd function case, the number of non-scalar multiplications can be and the depth can be The processor 100 can reduce the number of non-scalar multiplications by up to 20% compared to the small step large step algorithm by using the odd function property of the approximating polynomial without consuming any additional depth.
[0099] Hereinafter, a process of obtaining an approximating polynomial of an approximating modulo reduction function by the processor 100 will be described in detail.
[0100] The processor 100 can obtain an approximating polynomial function of an approximating modulo reduction function. The function to be obtained by the processor 100 by approximation can be a normalized modulo reduction function defined only in a near finite number of integers, as shown in Equation 2.
[0101] [Equation 2]
[0102]
[0103] Equation 2 can represent a modulo reduction function scaled for both the domain and the range of the modulo reduction function.
[0104] The processor 100 can use a cosine function for the approximation of normod(x) to use the double-angle formula for efficient homomorphic evaluation.
[0105] If the double-angle formula is used l times, the cosine function in Equation 3 needs to be approximated.
[0106] [Equation 3]
[0107]
[0108] To approximate a piecewise continuous function including the functions in Equation 2 and Equation 3, the processor 100 can assume a general piecewise continuous function defined on the union of a finite number of closed intervals, which is given as Equation 4.
[0109] [Equation 4]
[0110]
[0111] Here, a i <b i <a i+1 <b i+1 For all i = 1, …, t - 1.
[0112] To approximate the given piecewise continuous function on D of Equation 4 using polynomials of degree less than or equal to d, the processor 100 can set a criterion for selecting new d + 2 reference points from among the plurality of extreme points.
[0113] The processor 100 can generate the approximation polynomials by using {g1, …, g n} satisfying the Haar condition on [a, b] as a basis of the polynomials. The processor 100 can obtain a min-max approximation polynomial with respect to the set of reference points for each iteration and select a new set of reference points for the next iteration.
[0114] There can be many cases in which the processor 100 selects n + 1 points from among the extreme points of the error function obtained using an arbitrary polynomial with the set of reference points. The processor 100 can consider many intervals during the encryption process, and thus there can be many candidate extreme points.
[0115] The processor 100 can select n + 1 target points from among many candidate points for each iteration to minimize the number of iterations. By so doing, the processor 100 can generate a min-max approximation polynomial by converging the approximation polynomials generated for each iteration. In this example, the final min-max approximation polynomial generated can be the above-described modulo-reduced approximation polynomial.
[0116] To set a criterion for selecting n + 1 target points, the processor 100 can define a function of Equation 5.
[0117] [Equation 5]
[0118]
[0119] Here, p(x) denotes an arbitrary polynomial obtained in each iteration, and f(x) denotes a piecewise continuous function to be approximated. For convenience, p,f may be referred to as μ below.
[0120] The processor 100 can form all the extreme points of p(x)-f(x) into a set B. B can be a finite set, and is denoted as B={x1, x2, …, xn}. The processor 100 can select a point in one interval in B. m
[0121] Assuming that B is sorted in ascending order, x1 m , then the value of μ can be 1 or -1. The number of extreme points can satisfy m≥n+1.
[0122] The processor 100 can define a set of functions as Equation 6.
[0123] [Equation 6]
[0124]
[0125] In this example, if n+1=m, then the set may include only the identity function.
[0126] The processor 100 can set three criteria for selecting n+1 extreme points.
[0127] The processor 100 can set a local extreme condition as a first condition. If E is an absolute error at a set of reference points, the condition of Equation 7 can be set.
[0128] [Equation 7]
[0129]
[0130] To satisfy the local extreme condition, if a local maximum of p(x)-f(x) is negative or a local minimum of p(x)-f(x) is positive, the processor 100 can remove the extreme point.
[0131] Second, the processor 100 can set an alternating variation condition. In other words, the condition of Equation 8 can be set. Specifically, if one of two adjacent extreme points has a local maximum, the other extreme point can have a local minimum.
[0132] [Equation 8]
[0133] μ(x σ(i) )·μ(x σ(i+1) )=-1 for i=1, …, n
[0134] Third, the processor 100 can set a maximum absolute and conditional. The processor 100 can select σ that maximizes the value of Equation 9 from among σs that satisfy the local extremum condition and the alternating variation condition.
[0135] [Equation 9]
[0136]
[0137] The absolute error value at the current reference point x1,…,x n+1 may be less than the min-max approximation error, and converges to the min-max approximation error as the number of iterations increases.
[0138] Further, the absolute error value at the current reference point can be a weighted average of the absolute error values of the approximation polynomial in the previous iteration at x1,…,x n+1 .
[0139] The processor 100 can use the maximum absolute and conditional to help the absolute error value at the current reference point quickly converge to the min-max approximation error. The processor 100 can apply the maximum absolute and conditional, thereby facilitating convergence to the min-max approximation polynomial.
[0140] The set always contains at least one element σ0 that satisfies the local extremum condition and the alternating variation condition, and can have σ0(i0) that satisfies for some i0.
[0141] The processor 100 can find the coefficients of the approximation polynomial at the current reference point with respect to the power basis for the continuous function f(x). That is, the processor 100 can generate the approximation polynomial by obtaining the values of the coefficients c j in Equation 10.
[0142] [Equation 10]
[0143]
[0144] Here, E can be unknown in the linear equation. As the degree of the basis of the approximation polynomial increases, the coefficients decrease. The processor 100 can need to set a higher precision for the coefficients of the basis of a higher degree.
[0145] Therefore, the processor 100 can effectively solve the precision problem by using the Chebyshev polynomial basis as the basis of the approximation polynomial. Because the coefficients of the polynomial using the Chebyshev basis generally have almost the same order of magnitude, the processor 100 can generate the approximation polynomial using the Chebyshev basis rather than the power basis.
[0146] Chebyshev polynomials satisfy the above Haar condition, and the processor 100 can calculate c by solving a set of d+2 linear equations of Equation 11 via using d+2 reference points j and E to obtain an approximating polynomial.
[0147] [Equation 11]
[0148]
[0149] Figure 4 An example of an operation of an encryption device of Figure 1 is shown.
[0150] Referring to Figure 4 In operation 410, the processor 100 can generate ciphertext by encrypting data. In operation 430, the processor 100 can bootstrap the ciphertext by performing a modulo reduction based on a parity function property with respect to a modulus corresponding to the generated ciphertext.
[0151] The processor 100 can obtain an approximating polynomial approximating the modulo reduction. The processor 100 can generate a transformed approximating polynomial by transforming the approximating polynomial.
[0152] The processor 100 can perform bootstrapping by approximating the modulo reduction based on the parity function property. The processor 100 can evaluate the obtained approximating polynomial based on the parity function property, thereby reducing a bootstrapping time.
[0153] The processor 100 can generate a transformed approximating polynomial by reducing a degree of the approximating polynomial. The processor 100 can generate the transformed approximating polynomial to have a field corresponding to a square of a field of the approximating polynomial.
[0154] The processor 100 can determine a maximum degree of the transformed approximating polynomial based on a degree of the approximating polynomial. The processor 100 can determine the maximum degree based on an operation depth of the approximating polynomial and a number of non-scalar multiplications used for the ciphertext.
[0155] The processor 100 can generate the transformed approximating polynomial by performing a division operation on the approximating polynomial based on the determined maximum degree. The processor 100 can generate the transformed approximating polynomial by performing a division operation on the approximating polynomial based on one or more polynomial bases. In this example, the polynomial bases can be bases of Chebyshev polynomials.
[0156] The processor 100 can perform the modulo reduction based on the parity function property and the transformed approximating polynomial.
[0157] The methods according to the above-described examples can be recorded in non-transitory computer-readable media including program instructions to implement various operations embodied by the above-described examples. The media can also include, alone or in combination with the program instructions, data files, data structures, and the like. The program instructions recorded on the media can be those specially designed and constructed for the purposes of examples, or they can be of the kind well known and available to those having skill in the computer software art. Examples of non-transitory computer-readable media include magnetic media, such as hard disks, floppy disks, and magnetic tape; optical media such as CD-ROM disks, DVDs, and / or Blu-ray disks; magneto-optical media, such as optical floppy disks; and hardware devices that are specially configured to store and perform program instructions, such as read-only memory (ROM), random access memory (RAM), flash memory (e.g., a USB flash drive, a memory card, a memory stick, and the like), and the like. Examples of program instructions include both machine code, such as produced by a compiler, and files containing a higher level code that can be executed by the computer using an interpreter. The above-described devices can be configured to act as one or more software modules in order to perform the operations of the above-described examples, or vice versa.
[0158] Software can include computer programs, code segments, instructions or some combination thereof that, when executed, instruct or configure a processing device to perform a desired operation. Software and data can be stored on computer-readable storage media, which can be any available media that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Software and data stored on the computer-readable media can be in a number of formats, including, without limitation, machine code, bytecode, object code, source code, macrocode, or some combination thereof. The software and data can be distributed over such media, and accessed by a computer for execution.
[0159] A number of examples have been described above. Nevertheless, it will be understood that various modifications can be made to the examples. For example, suitable results can be achieved if the described techniques are performed in a different order and / or if components in the described systems, architectures, devices, or circuits are combined in a different manner and / or replaced or supplemented to achieve essentially the same results.
[0160] Therefore, other implementations are within the scope of the following claims.
Claims
1. An encryption method based on homomorphic encryption using odd function properties, the encryption method comprising: generating ciphertext by encrypting data; and bootstrapping the ciphertext by performing a modulus reduction based on an odd function property for a modulus corresponding to the ciphertext, wherein the bootstrapping comprises bootstrapping the ciphertext by transforming an obtained approximating polynomial approximating the modulus reduction based on the odd function property; and performing the modulus reduction based on the odd function property and the transformed approximating polynomial.
2. The encryption method of claim 1, wherein generating a transformed approximating polynomial by transforming the approximating polynomial comprises: generating the transformed approximating polynomial by reducing a degree of the approximating polynomial.
3. The encryption method of claim 2, wherein generating the transformed approximation polynomial by reducing an order of the approximation polynomial comprises: generating the transformed approximating polynomial to have a field corresponding to a square of a field of the approximating polynomial.
4. The encryption method according to claim 1, wherein generating a transformed approximating polynomial by transforming the approximating polynomial comprises: determining a maximum degree of the transformed approximating polynomial based on a degree of the approximating polynomial; and generating the transformed approximating polynomial by performing a division operation on the approximating polynomial based on the maximum degree. determining the maximum degree based on a depth of an operation of the approximating polynomial and a number of non-scalar multiplications used for the ciphertext.
5. The encryption method of claim 4, wherein determining a maximum degree of the transformed approximating polynomial based on a degree of the approximating polynomial comprises: generating the transformed approximating polynomial by performing a division operation on the approximating polynomial based on one or more polynomial bases.
6. The encryption method of claim 5, wherein generating the transformed approximating polynomial by performing a division operation on the approximating polynomial based on the maximum number of times comprises:
7. The encryption method according to claim 6, wherein the one or more polynomial bases are bases of Chebyshev polynomials.
8. A non-transitory computer-readable storage medium storing instructions which, when executed by a processor, cause the processor to perform the encryption method according to claim 1.
9. An encryption apparatus based on homomorphic encryption using odd function properties, the encryption apparatus comprising: a processor configured to: generate ciphertext by encrypting data; and bootstrap the ciphertext by performing a modulus reduction based on an odd function property for a modulus corresponding to the ciphertext; and a memory configured to store instructions to be executed by the processor, wherein the processor is configured to: bootstrap the ciphertext by transforming an obtained approximating polynomial approximating the modulus reduction based on the odd function property; and perform the modulus reduction based on the odd function property and the transformed approximating polynomial.
10. The encryption apparatus according to claim 9, wherein the processor is configured to generate the transformed approximating polynomial by reducing a degree of the approximating polynomial.
11. The encryption apparatus according to claim 10, wherein the processor is configured to generate the transformed approximating polynomial to have a field corresponding to a square of a field of the approximating polynomial. the processor is configured to: determine a maximum degree of the transformed approximating polynomial based on a degree of the approximating polynomial; and 12. The cryptographic device of claim 9, wherein, generate the transformed approximating polynomial by performing a division operation on the approximating polynomial based on the maximum degree. 13. The cryptographic device of claim 12, wherein the processor is configured to determine the maximum degree based on an operational depth of the approximating polynomial and a number of non-scalar multiplications used for the ciphertext.
14. The cryptographic device of claim 13, wherein the processor is configured to generate the transformed approximating polynomial by performing a division operation on the approximating polynomial based on one or more polynomial bases.
15. The cryptographic device of claim 14, wherein the one or more polynomial bases are bases of Chebyshev polynomials.
Citation Information
Patent Citations
Fine dust filter for street lamp distribution box
KR1020200139479A