Encryption method and apparatus using homomorphic encryption

By generating a target approximation polynomial to bootstrap the ciphertext, the privacy protection and computational efficiency problems of existing encryption methods when processing encrypted data are solved, and the confidentiality and data processing efficiency are improved.

CN113630234BActive Publication Date: 2026-07-31SAMSUNG ELECTRONICS CO LTD +2
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2021-04-14
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing encryption methods struggle to process encrypted data while protecting customer privacy, and are unable to effectively perform logical or mathematical operations.

Method used

By generating the target approximation polynomial corresponding to the approximation modulus reduction, and using the Chebyshev polynomial basis to bootstrap the ciphertext, the approximation and bootstrap operations on the ciphertext are realized.

Benefits of technology

It enables logical and mathematical operations on encrypted data while maintaining data confidentiality, thus improving the efficiency and security of data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113630234B_ABST
    Figure CN113630234B_ABST
Patent Text Reader

Abstract

The present application provides an encryption method and apparatus using homomorphic encryption and an apparatus performing a homomorphic encryption scheme. The encryption method using homomorphic encryption can include generating ciphertext by encrypting data, and bootstrapping the ciphertext by performing a modulo reduction based on a selection of one or more target points with respect to a modulus corresponding to the ciphertext.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references to related applications

[0002] This application claims priority to U.S. Provisional Patent Application No. 63 / 021,761, filed May 8, 2020, and Korean Patent Application No. 10-2020-0139444, filed October 26, 2020, with the Korean Intellectual Property Office, the entire disclosure of which is incorporated herein by reference for all purposes. Technical Field

[0003] The following description relates to encryption methods and apparatuses using homomorphic encryption. Background Technology

[0004] Fully homomorphic encryption is an encryption scheme that allows arbitrary logical or mathematical operations to be performed on encrypted data. Fully homomorphic encryption methods maintain security during data processing.

[0005] However, conventional encryption methods struggle to process encrypted data, thus failing to adequately protect customer privacy.

[0006] Fully homomorphic encryption enables customers to receive a variety of services while protecting their privacy. Summary of the Invention

[0007] This summary is provided to introduce, in a simplified form, the selection of concepts further described in the detailed embodiments below. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to help determine the scope of the claimed subject matter.

[0008] In one general aspect, an encryption method using homomorphic encryption includes: generating ciphertext by encrypting data; and bootstrapping the ciphertext by performing modulo reduction on a selection of one or more target points based on a modulus corresponding to the ciphertext.

[0009] Bootstrapping can include bootstrapping the ciphertext by approximating a function corresponding to modulo reduction.

[0010] Bootstrapping the ciphertext by approximating the function corresponding to the modular reduction can include generating a target approximation polynomial that approximates the function corresponding to the modular reduction.

[0011] Generating a target approximation polynomial may include: determining one or more reference points based on the degree of the target approximation polynomial; determining an arbitrary polynomial based on the one or more reference points; and generating the target approximation polynomial based on one or more extreme points selected according to the arbitrary polynomial.

[0012] The determination may include: determining a piecewise continuous function passing through one or more reference points; and determining the arbitrary polynomial by generating a polynomial such that the absolute value of the error between the polynomial and the piecewise continuous function at the one or more reference points is a predetermined value.

[0013] Determining the arbitrary polynomial by generating a polynomial may include: determining the arbitrary polynomial by generating a polynomial such that: the error at a first reference point included in the one or more reference points has a different sign than the error at a second reference point adjacent to the first reference point, and the absolute values ​​of the errors at the first reference point and the second reference point are the predetermined values.

[0014] Generating a target approximation polynomial based on one or more extreme points selected according to the arbitrary polynomial may include: determining candidate points whose absolute values ​​are greater than or equal to a predetermined value from among the extreme points of the error between the arbitrary polynomial and a piecewise continuous function passing through the one or more reference points; selecting target points from among the candidate points, wherein the number of target points is based on the degree of the target approximation polynomial; and generating the target approximation polynomial based on the target points.

[0015] Selecting the target point may include: selecting from the candidate points a target point that alternates between the maximum and minimum values.

[0016] Selecting the target point may include: selecting a target point that maximizes the sum of the absolute values ​​of the errors between the arbitrary polynomial and the piecewise continuous function.

[0017] Generating a target approximation polynomial based on one or more extreme points selected according to the arbitrary polynomial may include: generating a polynomial for the case where the relative error between the maximum and minimum values ​​among the absolute values ​​of the one or more extreme points is less than a threshold, as the target approximation polynomial.

[0018] The basis of the target approximation polynomial can be the basis of Chebyshev polynomials.

[0019] A non-transitory computer-readable storage medium that can store instructions, when executed by one or more processors, configuring the one or more processors to perform the method described above.

[0020] In another general aspect, an encryption device using homomorphic encryption includes: one or more processors configured to: generate ciphertext by encrypting data, and bootstrap the ciphertext by performing modulo reduction on a selection of one or more target points based on a modulus corresponding to the ciphertext.

[0021] The encryption device may further include a memory configured to store instructions. The one or more processors may also be configured to execute the instructions to configure the one or more processors to perform the following operations: generating ciphertext by encrypting data, and bootstrapping the ciphertext by performing modulo reduction on a selection of one or more target points based on a modulus corresponding to the ciphertext.

[0022] The one or more processors may be configured to bootstrap the ciphertext by approximating a function corresponding to the modulo reduction.

[0023] The one or more processors can be configured to generate a target approximation polynomial that approximates the function corresponding to the modulo reduction.

[0024] The one or more processors may be configured to: determine one or more reference points based on the degree of the target approximation polynomial; determine an arbitrary polynomial based on the one or more reference points; and generate the target approximation polynomial based on one or more extreme points selected according to the arbitrary polynomial.

[0025] The one or more processors may be configured to: determine a piecewise continuous function passing through the one or more reference points; and determine the arbitrary polynomial by generating a polynomial such that the absolute value of the error between the polynomial and the piecewise continuous function at the one or more reference points is a predetermined value.

[0026] The one or more processors may be configured to determine the arbitrary polynomial by generating a polynomial such that the error at a first reference point included in the one or more reference points has a different sign than the error at a second reference point adjacent to the first reference point, and the absolute values ​​of the errors at the first reference point and the second reference point are the predetermined values.

[0027] The one or more processors may be configured to: determine candidate points whose absolute values ​​are greater than or equal to predetermined values ​​from the extreme points of the error between the arbitrary polynomial and a piecewise continuous function passing through the one or more reference points; select target points from the candidate points, wherein the number of target points is based on the degree of the target approximation polynomial; and generate the target approximation polynomial based on the target points.

[0028] The one or more processors can be configured to select a target point from the candidate points such that the maximum and minimum values ​​alternate.

[0029] The one or more processors can be configured to select a target point that maximizes the sum of the absolute values ​​of the errors between the arbitrary polynomial and the piecewise continuous function.

[0030] The one or more processors can be configured to generate a polynomial for the case where the relative error between the maximum and minimum values ​​of the absolute values ​​of the one or more extreme points is less than a threshold, as the target approximation polynomial.

[0031] The basis of the target approximation polynomial can be the basis of Chebyshev polynomials.

[0032] In another general aspect, an apparatus configured to perform a fully homomorphic encryption scheme includes: one or more processors configured to: generate ciphertext by encrypting data; bootstrap the ciphertext by performing an approximation of a function corresponding to modulo reduction on a selection of one or more target points based on a modulus corresponding to the ciphertext; and generate a target approximation polynomial configured to approximate the function corresponding to the modulo reduction.

[0033] The target approximation polynomial can be generated using the Chebyshev transformation theorem.

[0034] The one or more processors may also be configured to: determine one or more reference points based on the degree of the target approximation polynomial; determine an arbitrary polynomial based on the one or more reference points; and generate the target approximation polynomial based on one or more extreme points selected according to the arbitrary polynomial.

[0035] Other features and aspects will become clear from the following detailed description, drawings and claims. Attached Figure Description

[0036] Figure 1 An example of an encryption device is shown.

[0037] Figure 2A It shows the method for passing through Figure 1 An example of an algorithm for generating a target approximation polynomial using an encryption device.

[0038] Figure 2B It shows the method for passing through Figure 1 An example of an algorithm for generating a target approximation polynomial using an encryption device.

[0039] Figure 2C It shows the way Figure 1 An example of an encryption device generating a target approximation polynomial.

[0040] Figure 3 It shows the way Figure 1 An example of an encryption device searching for extreme points.

[0041] Figure 4A It shows the method for passing through Figure 1 An example of an algorithm for selecting a target point in an encryption device.

[0042] Figure 4B It shows the way Figure 1 An example of an encryption device selecting a target point.

[0043] Figure 5 It shows Figure 1 An example of the overall operation of the encryption device.

[0044] Throughout the accompanying drawings and detailed embodiments, unless otherwise described or provided, the same reference numerals shall be understood to refer to the same elements, features, and structures. The drawings may not be drawn to scale, and for clarity, illustration, and convenience, the relative dimensions, scale, and depiction of elements in the drawings may be enlarged. Detailed Implementation

[0045] The following detailed description is provided to assist the reader in gaining a comprehensive understanding of the methods, apparatus, and / or systems described herein. However, various changes, modifications, and equivalents of the methods, apparatus, and / or systems described herein will be apparent upon understanding the disclosure of this application. For example, the order of operations described herein is merely illustrative and is not limited to those set forth herein, but may be changed as will become apparent upon understanding the disclosure of this application, except for operations that must occur in a specific order. Furthermore, for clarity and conciseness, descriptions of features known upon understanding the disclosure of this application may be omitted.

[0046] The features described herein may be embodied in different forms and should not be construed as limited to the examples described herein. Rather, the examples described herein are provided merely to illustrate some of the many possible ways of implementing the methods, apparatus, and / or systems described herein, which will become apparent upon understanding the disclosure of this application.

[0047] Throughout the specification, when an element such as a layer, region, or substrate is described as being "on," "connected to," or "coupled to" another element, it may be directly "on," directly "connected to," or "coupled to" the other element, or there may be one or more other elements in between. Conversely, when an element is described as being "directly on," "directly connected to," or "directly coupled to" another element, there may be no other elements in between.

[0048] As used in this article, the term "and / or" includes any combination of any one and any two or more of the listed items.

[0049] Although terms such as “first,” “second,” and “third” may be used herein to describe various components, assemblies, regions, layers, or parts, these components, assemblies, regions, layers, or parts are not limited by these terms. Rather, these terms are used only to distinguish one component, assembly, region, layer, or part from another. Thus, without departing from the teachings of the examples described herein, a first component, assembly, region, layer, or part mentioned in the examples may also be referred to as a second component, assembly, region, layer, or part.

[0050] For ease of description, spatially related terms such as “above,” “upper,” “below,” and “lower” may be used herein to describe the relationship between one element and another, as shown in the accompanying drawings. These spatially related terms are intended to cover different orientations of the device in use or operation, in addition to those depicted in the drawings. For example, if the device in the drawings is flipped, an element described as “above” or “upper” relative to another element will become “below” or “lower” relative to that other element. Therefore, depending on the spatial orientation of the device, the term “above” covers both upper and lower orientations. The device may also be oriented in other ways (e.g., rotated 90 degrees or in other orientations), and the spatially related terms used herein should be interpreted accordingly.

[0051] The terminology used herein is for the purpose of describing various examples only and is not intended to limit this disclosure. The articles “a,” “an,” and “the” are intended to include the plural form unless the context clearly indicates otherwise. The terms “comprising,” “including,” and “having” indicate the presence of the stated features, numbers, operations, components, elements, and / or combinations thereof, but do not preclude the presence or addition of one or more other features, numbers, operations, components, elements, and / or combinations thereof.

[0052] It will be apparent upon understanding the disclosure of this application that the features of the examples described herein can be combined in various ways. Furthermore, while the examples described herein have multiple configurations, it will be apparent upon understanding the disclosure of this application that other configurations are also possible.

[0053] Figure 1 An example of an encryption device is shown.

[0054] exist Figure 1In this document, encryption device 10 can encrypt data. Encryption device 10 can generate encrypted data by encrypting data. In the following text, the encrypted data may be referred to as ciphertext. The term "may" (e.g., what an example or embodiment may include or implement) is used with respect to examples or embodiments to indicate the existence of at least one example or embodiment that includes or implements such a feature, but all examples are not limited thereto.

[0055] Encryption device 10 can provide encryption techniques for performing operations in a computer and / or server (e.g., performing computations on data encrypted using fully homomorphic encryption without first decrypting it). The result of the operation is in encrypted form, and when the output of the operation is decrypted, the output is identical to the output obtained by performing the operation on unencrypted data. Encryption device 10 allows data confidentiality to be maintained even when data is shared with a third party, because the data can remain encrypted when the third party uses the data or performs computations on the data.

[0056] Encryption device 10 can provide encryption techniques for performing operations (e.g., computations) on data encrypted using homomorphic encryption without first decrypting it. In the example, encryption device 10 can decrypt the result obtained by operating on data encrypted using homomorphic encryption, thereby obtaining the same result as if the data were plaintext. Encryption device 10 can provide homomorphic encryption operations for real or complex numbers.

[0057] The encryption device 10 can perform the bootstrapping required for homomorphic encryption. The encryption device 10 can generate a target approximation polynomial that approximates the function corresponding to the modulo reduction required for homomorphic encryption.

[0058] The encryption device 10 can find the minimum-maximum approximation error for each degree of the optimal minimum-maximum approximation polynomial.

[0059] The encryption device 10 can find the optimal approximation polynomial by the target approximation polynomial, thereby providing excellent performance in terms of minimum-maximum approximation error in homomorphic encryption.

[0060] The encryption device 10 can generate a target approximation polynomial that approximates the modulo-reducing function based on the approximation region information used to approximate the modulo-reducing function.

[0061] The encryption device 10 includes a processor 100 and a memory 200.

[0062] Processor 100 can process data stored in memory. Processor 100 can execute computer-readable code (e.g., software) stored in memory 200 and instructions triggered by processor 100.

[0063] The processor 100 can be a data processing device implemented in hardware, which includes circuitry having a physical structure for performing desired operations. For example, the desired operations may include instructions or code included in a program.

[0064] For example, hardware-implemented data processing devices may include microprocessors, central processing units (CPUs), processor cores, multi-core processors, multiprocessors, application-specific integrated circuits (ASICs), and field-programmable gate arrays (FPGAs).

[0065] Processor 100 can generate ciphertext by encrypting data. Processor 100 can bootstrap the ciphertext by performing modulo reduction on the modulus corresponding to the generated ciphertext.

[0066] Processor 100 can bootstrap the ciphertext by approximating a function corresponding to the modular reduction. Processor 100 can generate a target approximating polynomial that approximates the function corresponding to the modular reduction.

[0067] The processor 100 can determine one or more reference points based on the degree of the target approximation polynomial.

[0068] Processor 100 can obtain an arbitrary polynomial based on one or more determined reference points. Processor 100 can obtain a piecewise continuous function passing through the one or more reference points. Processor 100 can obtain the arbitrary polynomial by generating a polynomial such that the absolute value of the error between the polynomial and the piecewise continuous function at the one or more reference points is a predetermined value.

[0069] The processor 100 can obtain an arbitrary polynomial by generating a polynomial in which the error at a first reference point included in one or more reference points has a different sign than the error at a second reference point adjacent to the first reference point, and the absolute values ​​of the errors at the first reference point and the second reference point are predetermined values.

[0070] The processor 100 can generate a target approximation polynomial based on one or more extreme points selected according to an arbitrary polynomial. Specifically, the processor 100 can obtain candidate points whose absolute values ​​are greater than or equal to predetermined values ​​from the extreme points of the error between the arbitrary polynomial and a piecewise continuous function passing through one or more reference points.

[0071] Processor 100 can select a target point from the obtained candidate points, wherein the number of target points is based on the degree of the target approximation polynomial. Processor 100 can select a target point from the candidate points such that the maximum and minimum values ​​alternate. Processor 100 can select a target point such that the sum of the absolute values ​​of the errors between any polynomial and a piecewise continuous function passing through one or more reference points is maximized.

[0072] Processor 100 can generate a target approximation polynomial based on the selected target point. Processor 100 can generate a polynomial as the target approximation polynomial for the case where the relative error between the maximum and minimum values ​​of the absolute values ​​of one or more extreme points is less than a threshold.

[0073] In this example, the basis of the target approximation polynomial can be the basis of Chebyshev polynomials.

[0074] The memory 200 may store instructions (or programs) that can be executed by the processor. For example, the instructions may include instructions for performing operations of the processor and / or operations of each element of the processor.

[0075] The memory 200 can be implemented as a volatile memory device or a non-volatile memory device.

[0076] Volatile memory devices can be implemented as dynamic random access memory (DRAM), static random access memory (SRAM), thyristor RAM (T-RAM), zero-capacitor RAM (Z-RAM), or dual-transistor RAM (TTRAM).

[0077] Non-volatile memory devices can be implemented as electrically erasable programmable read-only memory (EEPROM), flash memory, magnetic RAM (MRAM), spin-transfer torque (STT)-MRAM, conductive bridged RAM (CBRAM), ferroelectric RAM (FeRAM), phase change RAM (PRAM), resistive RAM (RRAM), nanotube RRAM, polymer RAM (PoRAM), nanofloating gate memory (NFGM), holographic memory, molecular electronic memory devices, or insulator resistance-changing memory.

[0078] In the following text, reference will be made to Figures 2A to 2C The process of performing encryption and bootstrapping via encryption device 10 will be described in more detail. Specifically, the encryption operation performed via encryption device 10 will be described, followed by a more detailed description of the bootstrapping process.

[0079] Figure 2A and Figure 2B It shows the method for passing through Figure 1 Examples of algorithms for generating target approximation polynomials using encryption devices, and Figure 2CIt shows the way Figure 1 An example of an encryption device generating a target approximation polynomial.

[0080] exist Figures 2A to 2C In this processor 100, the data can be encrypted.

[0081] The symbols used to describe the encryption operations of processor 100 will be described below.

[0082] and Let C[D] represent the set of integers, the set of rational numbers, the set of real numbers, and the set of complex numbers, respectively. Let C[D] represent the set of continuous functions over the field D. Let [d] represent the set of positive integers less than or equal to d. For example, [d] could be {1, 2, ..., d}.

[0083] round(x) represents the function that outputs the integer closest to x. For M (which is a power of 2), Φ M (X)=X N +1 represents the Mth cyclotomic polynomial, where M = 2N.

[0084] and They represent and This represents the Mth cyclotomic field.

[0085] For a positive real number α, Defined as The distribution in the variance α, where the terms can be independent of the variance α. 2 The discrete Gaussian distribution is sampled.

[0086] Denotes {0, ±1} with Hamming weight h. N A subset of. Represents {0, ±1} N The distribution in the equation, where the terms can be independently sampled using the probability ρ / 2 for each term in ±1 and the probability 1-ρ for zero.

[0087] Chebyshev polynomial T n (x) via cos nθ=T n (cosθ) is defined. The base of the logarithm described below is 2.

[0088] The encryption operations performed by processor 100 will be described below.

[0089] Processor 100 can support several operations on encrypted data, whether real or complex. Because encryption device 10 typically processes real numbers, noise that ensures the security of the encryption scheme can be contained outside the significant digits of the data.

[0090] Several independent messages can be encoded into a polynomial using canonical embedding before encryption. Canonical embedding σ can... Embedded into Among the elements, and The element can be in Φ M The value of a is obtained at the distinct roots of (X).

[0091] Φ M The roots of (X) can be odd powers of the Mth root of unity, and

[0092] It can be And π can be from arrive The natural projection of σ. The range of σ can be...

[0093] When N / 2 complex numbers constitute When dealing with elements in a dataset, each coordinate can be called a slot. The encoding and decoding processes are given below.

[0094] For vectors The encoding Ecd(z; Δ) can return the value of Equation 1.

[0095] [Formula 1]

[0096]

[0097] Here, Δ is the scaling factor, and This means that π -1 (z) becomes Discretization or rounding operations of elements.

[0098] For polynomials Decoding Dcd(m; Δ) can return a vector. For j∈{0, 1, ..., N / 2-1}, the term with index j satisfies Where ζ M It can be the Mth unit root.

[0099] Encryption device 10 can generate a key. For a given security parameter λ, encryption device 10 can choose a power of 2 M, an integer h, an integer P, a positive real number α, or the new ciphertext modulus q. LAnd the largest ciphertext, Q, will be the largest ciphertext.

[0100] The new ciphertext can be encrypted data that has not been processed or data that has been encrypted for the first time.

[0101] The processor 100 can set the public key pk and the private key sk, as shown in Formula 2.

[0102] [Formula 2]

[0103]

[0104] Here, s, a, and e represent respectively and

[0105] The processor 100 can set an evaluation key, as shown in Formula 3.

[0106] [Formula 3]

[0107]

[0108] a′ and e′ respectively represent and

[0109] Processor 100 can execute code Return the result of Formula 4.

[0110] [Formula 4]

[0111] c = v·pk + (m + e0, e1) mod q L

[0112] Here, v, e0, and e1 can be sampled, such as by... and As shown.

[0113] Processor 100 can perform decoding return

[0114] Processor 100 can perform addition on two ciphertexts Return the result of Formula 5.

[0115] [Formula 5]

[0116] c add =c1+c2 mod q l

[0117] Processor 100 can perform multiplication on two ciphertexts c1 = (b1, a1) and c2 = (b2, a2). Return the result of Formula 6.

[0118] [Formula 6]

[0119]

[0120] Here, (d0, d1, d2) := (b1b2, a1b2+a2b1, a1a2) mod q l .

[0121] Furthermore, the processor 100 can execute Return the result of Formula 7.

[0122] [Formula 7]

[0123]

[0124] Each ciphertext can have a maximum number of levels (levels) l representing the possible multiplications without bootstrapping. The modulus q for each ciphertext at level l... l It can have the value p l q0, where p is the scaling factor and q0 is the base modulus.

[0125] In addition, the processor 100 can perform rotation operations and complex conjugate operations, which are used for homomorphic linear transformations in bootstrapping.

[0126] The bootstrapping operation performed by the encryption device 10 will be described below.

[0127] The purpose of bootstrapping can be to refresh the ciphertext of level 0, which can no longer perform multiplication, into a new ciphertext of level L with the same message.

[0128] Ciphertext can be encrypted data. The level of ciphertext can be the number of possible multiplications without bootstrapping.

[0129] Bootstrapping can include four operations. First, bootstrapping can include a modulus increase operation. Second, bootstrapping can include a homomorphic linear transformation operation. Third, bootstrapping can include a homomorphic modulus reduction operation. Fourth, bootstrapping can include a homomorphic linear transformation operation.

[0130] Processor 100 can perform modulo-enhancing operations. To describe a modulo-enhancing operation, level 0 ciphertext can be used as... elements instead Element.

[0131] Level 0 ciphertext can be in<ct,sk> The state is approximately m mod q0. Here, ct represents the ciphertext, and sk represents the private key. When processor 100 attempts to decrypt the ciphertext, for a given... Ciphertext can have<ct,sk> It is in the form of ≈m+q0Imod Q.

[0132] Here, the coefficient of sk includes small numbers, so the absolute value of the coefficient of I can be very small. For example, the absolute value of the coefficient of I can be less than 12.

[0133] Processor 100 can generate a sequence of ciphertexts satisfying level 0 by bootstrapping the ciphertext.<ct′,sk> ≈m mod q L ct′. Therefore, processor 100 can perform homomorphic linear transformations and homomorphic evaluations of modulo-decreasing functions.

[0134] The homomorphic linear transformation performed by processor 100 will be described below. The ciphertext ct after modulo enhancement can be considered as ciphertext encrypted with m+q0I. Processor 100 can homomorphically perform modulo reduction on the coefficients of the message polynomial.

[0135] These operations are performed on positions, not on the coefficients of the message polynomial. Therefore, in order to perform meaningful operations on the coefficients, the processor 100 can convert ct into ciphertext that encrypts its coefficients based on the position of m+q0I.

[0136] After evaluating the homomorphic modulo reduction function, processor 100 can inversely transform this ciphertext into another ciphertext ct′, which ciphertext ct′ encrypts the position of the message according to the coefficients of the previous ciphertext. In the following text, these transformation and inverse transformation operations are referred to as COEFFTOSLOT and SLOTTOCOEFF, respectively.

[0137] The two transformation operations described above can be viewed as homomorphic evaluation of message encoding and decoding, which can be achieved through Φ M Linear transformations of some variants of the Vandermonde matrix of the roots of (x). Furthermore, the transformation operations can be performed using general homomorphic matrix multiplication or operations similar to FFT.

[0138] Processor 100 can perform homomorphic modulo reduction (or modulo subtraction) operations. Specifically, processor 100 can use a homomorphic modulo reduction function to perform modulo reduction operations.

[0139] After performing the COEFFTOSLOT transformation, processor 100 can homomorphically perform modulo reduction at each position in modulo q0. This process may be referred to as EVALMOD in the following text.

[0140] By limiting the range of the message to make m / q0 sufficiently small, the processor 100 can restrict the approximation region to a multiple of q0. This range limitation allows the processor 100 to perform modulo reduction more efficiently.

[0141] The following text will describe it in detail. Figure 2A The algorithm.

[0142] Processor 100 can be used Figure 2A Algorithm 1 finds a minimax approximation polynomial for any continuous function on the interval [a, b] to generate the target approximation polynomial. Processor 100 can use the Chebyshev transform theorem to generate the target approximation polynomial that satisfies the isooscillation condition.

[0143] Processor 100 can generate basis functions {g1, ..., g...} n The objective approximation polynomial satisfies the Haar condition. To generate an objective approximation polynomial of degree d, processor 100 can use the power basis {1, x, ..., x}. d Choose basis functions {g1, ..., g} n Here, n = d + 1.

[0144] Processor 100 can initialize a set of reference points that converge to the extrema of a minimax approximation polynomial. Processor 100 can obtain the minimax approximation polynomial with respect to the set of reference points. Since the set of reference points is a finite set of points in [a, b], it can be a closed subset of [a, b]. Therefore, the Chebyshev transformation theorem can be satisfied for the set of reference points.

[0145] When f(x) is a continuous function on [a, b], the minimum-maximum approximation polynomial on the set of reference points can be a polynomial with a basis {g1, ..., g2} that satisfies the conditions of E in Formula 8 for some E. n The generalized polynomial p(x) of}.

[0146] [Formula 8]

[0147] p(x i )-f(x i )=(-1) i Ei = 1, ..., d+2

[0148] Processor 100 can obtain any polynomial p(x) using Equation 8. According to Equation 8, a system of linear equations with n+1 equations, n coefficients of p(x), and n+1 variables of E, and the linear equations being non-singular according to the Haar condition, can be used by processor 100 to obtain a polynomial p(x) that satisfies the conditions of Equation 8.

[0149] Processor 100 can obtain in x i With x i+1 The n zeros z of p(x)-f(x) between i The condition is that z0 = a, z n+1=b and i = 1, 2, ..., n, and can be obtained in each [z i-1 , z i The n+1 extreme points y1, ..., y of p(x)-f(x) in the equation. n+1 .

[0150] If p(x) i )-f(x i If ) < 0, processor 100 can be selected in [z i-1 , z i The minimum point of p(x)-f(x) in ]; and if p(x i )-f(x i If ) > 0, you can choose to [z] i-1 , z i [The maximum point of p(x)-f(x) in the graph].

[0151] Through this operation, the processor 100 can select new extreme points y1, ..., y2. n+1 The set of candidate points is used as the target approximation polynomial. If these candidate points satisfy the iso-oscillatory condition, the processor 100 can generate the target approximation polynomial by returning the minimax approximation polynomial according to the Chebyshev transform theorem.

[0152] Furthermore, the processor 100 can utilize the new extreme points y1, ..., y1 obtained through the above process. n+1 The set of reference points is replaced by the set of reference points, and the above polynomial generation process is performed iteratively.

[0153] Figure 2A Algorithm 1 shown can be extended to multiple subintervals of an interval. When applying Algorithm 1 extended to multiple subintervals, the following can be modified: Figure 2A Steps 3 and 4.

[0154] For each iteration, the processor 100 can obtain all local extrema of the error function pf, and its absolute error value can be greater than the absolute error value at the current reference point.

[0155] Then, processor 100 can select n+1 new extreme points from all the obtained local extreme points that satisfy the following two criteria:

[0156] 1. The sign of the error value changes alternately.

[0157] 2. The new set of extreme points includes global extreme points.

[0158] The two criteria mentioned above can guarantee convergence to a minimal maxima generalized polynomial.

[0159] Figure 2B and Figure 2C It shows that according to Figure 2A The algorithm modifies the polynomial generation method. The processor 100 can modify the method for selecting a new extremum from all local extrema.

[0160] Figure 2B The algorithm can be shown as Figure 2C The flowchart is shown. In operation 210, the processor 100 can set d+2 points in the approximation region. These d+2 points can be one or more of the aforementioned reference points.

[0161] Processor 100 can obtain any polynomial based on these d+2 reference points. For example, in operation 220, processor 100 can find the values ​​of polynomial p(x) and E that satisfy Equation 8.

[0162] In operation 230, processor 100 can obtain points whose absolute value is greater than or equal to E from the local maxima and local minima of p(x)-f(x). Here, the value of E can be the predetermined value mentioned above, and the obtained local maxima and local minima can be the candidate points mentioned above.

[0163] In operation 240, processor 100 can select d+2 points from the obtained points that cause the maximum and minimum values ​​to alternate, wherein these d+2 points can be selected to maximize the sum of the absolute values ​​of p(x) - f(x). These d+2 points that maximize the sum of absolute values ​​can be the aforementioned target points. (Refer to...) Figure 4A and Figure 4B Describe in detail the process of selecting d+2 points that maximize the sum of their absolute values.

[0164] In operation 250, processor 100 can determine whether the relative error between the maximum and minimum absolute values ​​of the selected d+2 target points is less than δ. δ can be the aforementioned threshold.

[0165] In operation 260, if the relative error between the maximum and minimum absolute values ​​corresponding to the target point is less than δ, then processor 100 can output any polynomial p(x) as the target approximation polynomial. Otherwise, processor 100 can iteratively execute operations 220 to 250.

[0166] The following text will describe this in more detail. Figure 2B and Figure 2C The operation.

[0167] The function that can be approximated by processor 100 can be a normalized modulo-decreasing function defined only in a nearly finite number of integers, as shown in Equation 9.

[0168] [Formula 9]

[0169]

[0170] Formula 9 can represent a modulo-reducing function scaled for both the domain and the range of the modulo-reducing function.

[0171] Processor 100 can use a cosine function to approximate normod(x) to use double-angle formulas for efficient homomorphic evaluation.

[0172] If the double-angle formula is used l times, then the cosine function in Formula 10 needs to be approximated.

[0173] [Formula 10]

[0174]

[0175] In order to approximate piecewise continuous functions, including those in Equations 9 and 10, processor 100 may assume a general piecewise continuous function defined on the union of a finite number of closed intervals, which is given as Equation 11.

[0176] [Formula 11]

[0177]

[0178] Here, a i <b i <a i +1<b i+1 This holds true for all i = 1, ..., t-1.

[0179] In order to approximate a given piecewise continuous function on D in Equation 11 using a polynomial of degree less than or equal to d, the processor 100 may set a criterion for selecting new d+2 reference points from a plurality of extrema.

[0180] Processor 100 can use {g1, ..., g} that satisfy the Haar condition on [a, b]. n The reference points are used as a basis to generate the target approximation polynomial. The processor 100 can obtain a minimax approximation polynomial for each iteration with respect to the set of reference points, and select a new set of reference points for the next iteration.

[0181] There can be many cases in which the processor 100 selects n+1 points from the extrema of the error function obtained using an arbitrary polynomial derived from the set of reference points. The processor 100 can consider many intervals during the encryption process, so there may be many candidate extrema.

[0182] Processor 100 can select n+1 target points from a number of candidate points for each iteration to minimize the number of iterations. By doing so, processor 100 can generate a minimax approximation polynomial by converging the approximation polynomial generated for each iteration.

[0183] To set the criteria for selecting n+1 target points, processor 100 can define a function according to formula 12.

[0184] [Formula 12]

[0185]

[0186] Here, p(x) denotes any polynomial obtained in each iteration, and f(x) denotes the piecewise continuous function to be approximated. For convenience, μ p,f It may be referred to as μ in the following text.

[0187] Processor 100 can form a set B of all the extreme points of p(x)-f(x). B can be a finite set and is represented as B = {x1, x2, ..., x}. m Processor 100 can select a point within an interval of B.

[0188] Assume B is sorted in ascending order, x1 < x2 < ... < x m If μ = 1, then the value of μ can be 1 or -1. The number of extreme points can satisfy m ≥ n + 1.

[0189] Processor 100 can define a set of functions. As shown in Formula 13.

[0190] [Formula 13]

[0191]

[0192] In this example, if n+1 = m, then the set It may include only the identity function.

[0193] The processor 100 can be configured with three criteria for selecting n+1 extreme points.

[0194] Processor 100 can set the local extremum condition as the first condition. If E is the absolute error at the set of reference points, then the condition of Equation 14 can be set.

[0195] [Formula 14]

[0196]

[0197] In order to satisfy the local extremum condition, if the local maximum value of p(x)-f(x) is negative or the local minimum value of p(x)-f(x) is positive, then the processor 100 can remove the extremum points.

[0198] Secondly, the processor 100 can set alternating conditions. In other words, the conditions of Formula 15 can be set. Specifically, if one of two adjacent extreme points has a local maximum, then the other extreme point may have a local minimum.

[0199] [Formula 15]

[0200] μ(x σ(i) )·μ(x σ(i+1) ) = -1 for i = 1, ..., n

[0201] Third, the processor 100 can set a maximum absolute sum condition. The processor 100 can select the σ that maximizes the value of formula 16 from among the σ that satisfy the local extremum condition and the alternation condition.

[0202] [Formula 16]

[0203]

[0204] At the current reference point x1, ..., x n+1 The absolute error value at the point can be smaller than the minimum-maximum approximation error, and as the number of iterations increases, it converges to the minimum-maximum approximation error.

[0205] Furthermore, the absolute error value at the current reference point can be the approximation polynomial in the previous iteration at x1, ..., x n+1 The weighted average of the absolute error values ​​at each point.

[0206] Processor 100 can use the maximum absolute sum condition to help the absolute error value at the current reference point converge quickly to the minimum maximum approximation error.

[0207] Local extremum conditions and alternation conditions can be applied to Figure 2A The algorithm and Figure 2B Both algorithms, and the condition for maximum absolute sum can be applied. Figure 2B Algorithm 2. Processor 100 can apply the maximum absolute sum condition, thereby promoting convergence to the minimax approximation polynomial.

[0208] gather It always contains at least one element σ0 that satisfies the local extremum condition and the alternation condition, and can have an element σ0 that satisfies the following condition for some i0: σ0(i0).

[0209] Processor 100 can execute more efficiently. Figure 2BSteps 2, 3, and 4 of Algorithm 2 are described below. Processor 100 can find the coefficients of the approximating polynomial at the current reference point for a continuous function f(x) using a power basis.

[0210] That is, processor 100 can obtain the coefficient c in formula 17. j The value of is used to generate the target approximation polynomial.

[0211] [Formula 17]

[0212]

[0213] Here, E may be unknown in the linear equation. As the degree of the basis of the approximating polynomial increases, the coefficients decrease. Processor 100 may need to set higher precision for the coefficients of higher-degree bases.

[0214] Therefore, processor 100 can effectively solve the accuracy problem by using the basis of Chebyshev polynomials as the basis of the target approximation polynomial. Since the coefficients of polynomials using Chebyshev bases usually have almost the same order of magnitude, processor 110 can use Chebyshev bases instead of power bases to generate the target approximation polynomial.

[0215] The Chebyshev polynomial satisfies the Haar condition described above, and the processor 100 can compute c by solving the system of d+2 linear equations of Equation 18 using d+2 reference points. j And E, to obtain the target approximation polynomial.

[0216] [Formula 18]

[0217]

[0218] Figure 3 It shows the way Figure 1 An example of an encryption device searching for extreme points.

[0219] exist Figure 3 In this process, processor 100 can obtain an arbitrary polynomial based on a reference point and search for extreme points of the error between the arbitrary polynomial and the piecewise continuous function passing through the reference point. Processor 100 can then obtain candidate points whose absolute values ​​are greater than or equal to predetermined values ​​from among the extreme points of the error between the arbitrary polynomial and the piecewise continuous function passing through the reference point. The process of obtaining candidate points by processor 100 searching for extreme points will be described below.

[0220] Processor 100 can obtain the extreme points of increasing and decreasing exchange by scanning the error p(x)-f(x) between an arbitrary polynomial and a piecewise continuous function using a small scan step size.

[0221] Generally, a small scan step size can improve the accuracy of finding extreme points, but it will result in a longer scan time. More specifically, this will take up 2... l The time required is proportional to the time required to obtain the extreme point with 1 bit precision.

[0222] However, by using the search operation described below, the processor 100 can achieve this in linear time instead of 2. l Search for extreme points within a given timeframe.

[0223] Processor 100 can use binary search to reduce the search time for extreme points of increasing and decreasing swaps. In the following text, the error between an arbitrary polynomial and a piecewise continuous function can be expressed as r(x) = p(x) - f(x), and sc represents the scan step size.

[0224] The processor 100 can search for x0 that satisfies μ(x0)r(x0)≥|E| and (r(x0)-r(x0-sc))(r(x0+sc)-r(x0))≤0, and obtain the i-th extreme point by continuously executing the process of formula 19 l times.

[0225] [Formula 19]

[0226]

[0227] Through the process of Formula 19, the processor 100 can obtain the extreme point with an accuracy of O(log(sc)+1) bits.

[0228] The process of obtaining candidate points through the above extreme point search will be described in detail below. In operation 310, processor 100 can obtain the minimum point x in the approximation region. In operation 320, if x is the maximum value, processor 100 can determine whether r(x) is greater than or equal to the absolute value of E; and if x is the minimum value, determine whether r(x) is less than or equal to the value obtained by multiplying the absolute value of E by -1.

[0229] If the condition of operation 320 is met, then in operation 321, processor 100 can add x0 to array B. If the condition of operation 320 is not met, then in operation 330, processor 100 can replace x with x+sc.

[0230] Then, in operation 340, processor 100 can determine whether x is included in the approximation region. If x is included in the approximation region, then in operation 350, processor 100 can determine whether r(x)-r(x-sc) and r(x+sc)-r(x) are different in sign.

[0231] If x is not included in the approximation region, then in operation 341, processor 100 can replace x with the maximum value in the corresponding interval. In this case, in operation 342, if x is the maximum value, processor 100 can determine whether r(x) is greater than or equal to the absolute value of E; and if x is the minimum value, determine whether r(x) is less than or equal to the value obtained by multiplying the absolute value of E by -1.

[0232] If the condition of operation 342 is met, then in operation 343, processor 100 can add x0 to array B. If the condition of operation 342 is not met, then in operation 344, processor 100 can determine whether x is the maximum value in the approximation region. In this example, if x is the maximum value in the approximation region, processor 100 can terminate the operation. If x is not the maximum value in the approximation region, then in operation 345, processor 100 can replace x with the minimum value in the subsequent interval.

[0233] If r(x)-r(x-sc) and r(x+sc)-r(x) have the same sign, then processor 100 may execute operation 330 again. If r(x)-r(x-sc) and r(x+sc)-r(x) have different signs, then in operation 360, processor 100 may substitute 1 with 0 and t with sc / 2.

[0234] In operation 370, processor 100 can determine whether the value of r(x) - r(x - sc) is greater than 0. If the condition of operation 370 is met, then in operation 371, processor 100 can select the term with the maximum value of r(x) from xt, x, and x+t, and replace x with the selected term. Then, in operation 372, processor 100 can replace l with l+1 and replace t with t / 2.

[0235] In operations 373 and 374, processor 100 can determine whether l is a precision value. If l is not a precision value, processor 100 can execute operation 371 again. If the condition of operation 370 is not met or l is not a precision value in operation 374, processor 100 can select the term with the minimum value of r(x) from xt, x, and x+t in operation 375, and replace x with the selected term. Then, in operation 376, processor 100 can replace l with l+1 and replace t with t / 2.

[0236] If the conditions of operation 373 and operation 374 are met, then processor 100 can execute operation 320 again. Finally, processor 100 can obtain the extreme points in array B as candidate points.

[0237] If the value of sc is small enough, then |r(x)| can be operated on similarly to a(xx). * ) 2 +b(a>0 and b is close to x) * Through such calculations, if b is close to x... * ,|x1-x * |>|x2-x * Then processor 100 can guarantee |r(x1)|>|r(x2)|; and if |x1-x * |<|x2-x * If |, then processor 100 can guarantee |r(x1)|<|r(x2)|.

[0238] By obtaining candidate points through the above-described extreme point search, the processor 100 can achieve this in linear time 1 instead of 2. l Search for extreme points with 1-bit precision within the range to obtain candidate points.

[0239] Figure 4A It shows the method for passing through Figure 1 An example of an algorithm for selecting a target point in an encryption device, and Figure 4B It shows the way Figure 1 An example of an encryption device selecting a target point.

[0240] exist Figure 4A and Figure 4B In the middle, processor 100 can be obtained from through Figure 3 The target point is selected from the candidate points obtained by the search operation, where the number of target points is based on the degree of the target approximation polynomial.

[0241] Processor 100 can select from candidate points a target point that alternates between maximum and minimum values, and a target point that maximizes the sum of the absolute values ​​of the errors. The target point can be a new reference point in subsequent iterations.

[0242] The process of obtaining the target point will be described in detail below. The processor 100 may use a naive method to select points that satisfy the local extremum condition, the alternation condition, and the maximum absolute sum condition to find the target point (or a new reference point).

[0243] The naive method selects the n+1 points with the largest absolute sum by calculating the absolute sum of all n+1 points satisfying the alternation condition. If there are m local extrema, the naive method may need to examine all of them. point.

[0244] Compared to the naive method, processor 100 can... Figure 4A and Figure 4BThis operation reduces the time spent selecting target points. The following section describes the operation for efficiently selecting target points.

[0245] Processor 100 can eliminate some elements from candidate points for each iteration, eventually obtaining n+1 target points. If m > n+1, at least one element may be excluded from the target points.

[0246] pass Figure 4A The algorithm allows processor 100 to select a target point within time O(m log m). In other words, processor 100 can select a target point in quasi-linear time.

[0247] Whenever an element in the sorted set B is removed, the remaining elements can be sorted and their indices can be relabeled in ascending order.

[0248] When in Figure 4A In Algorithm 3, when comparing values ​​to remove some extreme points, the compared values ​​may be equal, or there may be more than one smallest element. In this case, the processor 100 can randomly remove these elements.

[0249] Figure 4B The flowchart shows Figure 4A The sequence of operations in the algorithm. Through Figure 4A and Figure 4B Through this operation, processor 100 can obtain array B with target points as elements.

[0250] In operation 410, processor 100 can substitute 1 for i. In operation 420, processor 100 can determine x. i and x i+1 Are either the maximum or minimum value?

[0251] If the condition of operation 420 is met, then in operation 421, processor 100 can remove x from the array. i and x i+1 The term with the smaller |r(x)| is selected, and the remaining elements in the array are rearranged. The value of |r(x)| can be the value of the error between any of the above polynomials and the piecewise continuous function. If the condition of operation 420 is not met, then in operation 422, processor 100 can replace i with i+1.

[0252] After the rearrangement, in operation 430, processor 100 can determine x. i Is it the maximum point in array B? If x i If it is not the maximum point, then processor 100 can execute operation 420 again.

[0253] Operations 410 to 430 can correspond to Figure 4A The operations in steps 1 to 7 of algorithm 3.

[0254] If x i If the target point is the maximum, then in operation 440, processor 100 can determine whether the number of elements in B is d+2. If the number of elements in B is d+2, processor 100 can terminate the operation of selecting the target point.

[0255] If the number of elements in B is not d+2, then in operation 450, processor 100 can insert the sum of the |r(x)| values ​​of every two neighboring points into array T and arrange array T. That is, |r(x1)|+|r(x2)|, |r(x2)|+|r(x3)|, |r(x3)|+|r(x4)|, ... can be inserted into T, and T can be arranged.

[0256] Operations 440 and 450 can correspond to Figure 4A The operations in steps 9 and 10 of algorithm 3.

[0257] In operation 460, processor 100 can determine whether the number of elements in B is d+3. If the number of elements in B is d+3, then in operation 461, processor 100 can remove x1 and x2 from the array. d+3 The element with the smaller |r(x)| is rearranged in the array, and the operation is terminated.

[0258] In operation 470, processor 100 can determine whether the number of elements in B is d+4. If the number of elements in B is d+4, then in operation 471, processor 100 can... Add to T and rearrange T. After this, in operation 472, processor 100 can remove the two points from B that correspond to the minimum value in T, rearrange B, and terminate the operation.

[0259] If the number of elements in B is not d+4, then in operation 480, processor 100 can determine whether one of the two endpoints is included in the two points corresponding to the minimum value in T. If the condition of operation 480 is met, then in operation 481, processor 100 can remove one of the two endpoints from B and rearrange B. If the condition of operation 480 is not met, then in operation 482, processor 100 can remove both points corresponding to the minimum value in T from B and rearrange B.

[0260] Following this, in operation 490, processor 100 can remove values ​​from T, including those of the removed elements, add the sum of the values ​​of |r(x)| of the two new neighboring points to T, rearrange T, and then execute operation 460 again. Operations 460 to 490 can correspond to Figure 4A The operations in steps 11 to 23 of algorithm 3.

[0261] exist Figure 4A The last part of the algorithm describes an example of removing the extreme point x2. T = {|r(x1)| + |r(x2)|, |r(x2)| + |r(x3)|, |r(x3)| + |r(x4)|, ...} can be changed to T = {|r(x1)| + |r(x3)|, |r(x3)| + |r(x4)|, ...}.

[0262] pass Figure 4A and Figure 4B The process of selecting a target point allows the processor 100 to select a target point from candidate points in quasi-linear time.

[0263] The processor 100 can generate an optimal approximation polynomial that approximates the modulus reduction function based on the selected target point. In other words, the processor 100 can generate a polynomial of degree d passing through the selected target point as the target approximation polynomial.

[0264] Figure 5 It shows Figure 1 An example of the overall operation of the encryption device.

[0265] Processor 100 can encrypt data using homomorphic encryption. In operation 510, processor 100 can generate ciphertext by encrypting data.

[0266] In operation 530, processor 100 can bootstrap the ciphertext by performing modulo reduction on the selection of one or more target points based on the modulo corresponding to the generated ciphertext.

[0267] Processor 100 can bootstrap the ciphertext by approximating a function corresponding to modular reduction. Processor 100 can generate a target approximating polynomial that approximates the function corresponding to modular reduction.

[0268] Processor 100 can determine one or more reference points based on the degree of the target approximation polynomial. Processor 100 can obtain any polynomial based on the determined one or more reference points.

[0269] Specifically, processor 100 can obtain a piecewise continuous function passing through one or more reference points; and obtain an arbitrary polynomial by generating a polynomial such that the absolute value of the error between the polynomial and the piecewise continuous function at one or more reference points is a predetermined value.

[0270] The processor 100 can obtain an arbitrary polynomial by generating a polynomial such that the error at a first reference point included in one or more reference points has a different sign than the error at a second reference point adjacent to the first reference point, and the absolute values ​​of the errors at the first reference point and the second reference point are predetermined values.

[0271] Processor 100 can generate a target approximation polynomial based on one or more extreme points selected from the obtained arbitrary polynomial. Processor 100 can obtain candidate points whose absolute values ​​are greater than or equal to predetermined values ​​from the extreme points of the error between the arbitrary polynomial and a piecewise continuous function passing through one or more reference points.

[0272] Processor 100 can select target points from the obtained candidate points, wherein the number of target points is based on the degree of the target approximation polynomial. Specifically, processor 100 can select target points from the candidate points such that the maximum and minimum values ​​alternate. Processor 100 can select target points such that the sum of the absolute values ​​of the errors between any polynomial and the piecewise continuous function is maximized.

[0273] Processor 100 can generate a target approximation polynomial based on the selected target point. Processor 100 can generate a polynomial as the target approximation polynomial for the case where the relative error between the maximum and minimum values ​​of the absolute values ​​of one or more extreme points is less than a threshold.

[0274] In this example, the basis of the target approximation polynomial can be the basis of Chebyshev polynomials.

[0275] By way of non-exhaustive example only, the terminals described herein may be: mobile devices, such as cellular phones, smartphones, wearable smart devices (e.g., rings, watches, glasses, bracelets, anklets, belts, necklaces, earrings, hairbands, helmets, or devices embedded in clothing); portable personal computers (PCs) (e.g., laptops, notebook computers, netbooks or ultra-portable PCs (UMPCs), tablet PCs (tablet computers), tablet phones, personal digital assistants (PDAs), digital cameras, portable game consoles, MP3 players, portable / personal multimedia players (PMPs), handheld devices, etc. E-books, GPS navigation devices, or sensors; or fixed devices, such as desktop PCs, high-definition televisions (HDTVs), DVD players, Blu-ray players, set-top boxes, or home appliances; or any other mobile or fixed device configured to perform wireless or network communications. In one example, a wearable device is a device designed to be directly worn on a user's body, such as a pair of glasses or a bracelet. In another example, a wearable device is any device worn on a user's body using an attachment device, such as a smartphone or tablet computer attached to a user's arm using an armband or hanging from a user's neck using a lanyard.

[0276] Perform the operations described in this application Figures 1 to 5The encryption device 10, processor 100, and memory 200 are implemented by hardware components configured to perform the operations described in this application. Examples of hardware components that may be used to perform the operations described in this application, when appropriate, include: controllers, sensors, generators, drivers, memories, comparators, arithmetic logic units, adders, subtractors, multipliers, dividers, integrators, and any other electronic components configured to perform the operations described in this application. In other examples, one or more hardware components performing the operations described in this application are implemented by computing hardware (e.g., by one or more processors or computers). The processor or computer may be implemented by one or more processing elements, such as logic gate arrays, controllers and arithmetic logic units, digital signal processors, microcomputers, programmable logic controllers, field-programmable gate arrays, programmable logic arrays, microprocessors, or any other device or combination of devices configured to respond to and execute instructions in a defined manner to obtain desired results. In one example, the processor or computer includes or is connected to one or more memories storing instructions or software executed by the processor or computer. Hardware components implemented by a processor or computer can execute instructions or software, such as an operating system (OS) and one or more software applications running on the OS, to perform the operations described in this application. In response to the execution of instructions or software, the hardware component can also access, manipulate, process, create, and store data. For simplicity, the singular terms "processor" or "computer" may be used in the description of the examples described in this application; however, in other examples, multiple processors or computers may be used, or a processor or computer may include multiple processing elements, or multiple types of processing elements, or both. For example, a single hardware component or two or more hardware components may be implemented by a single processor, or two or more processors, or a processor and a controller. One or more hardware components may be implemented by one or more processors, or a processor and a controller, and one or more other hardware components may be implemented by one or more other processors, or another processor and another controller. One or more processors, or a processor and a controller, may implement a single hardware component, or two or more hardware components. Hardware components can have any one or more different processing configurations, examples of which include single processor, discrete processor, parallel processor, single instruction single data (SISD) multiprocessing, single instruction multiple data (SIMD) multiprocessing, multiple instruction single data (MISD) multiprocessing, and multiple instruction multiple data (MIMD) multiprocessing.

[0277] Perform the operations described in this application Figures 1 to 5The methods illustrated are executed by computing hardware (e.g., by one or more processors or computer hardware implemented as described above to execute instructions or software to perform the operations performed by the methods described in this application). For example, a single operation or two or more operations can be executed by a single processor, or two or more processors, or a processor and a controller. One or more operations can be executed by one or more processors, or a processor and a controller, and one or more other operations can be executed by one or more other processors, or another processor and another controller. One or more processors, or a processor and a controller, can execute a single operation, or two or more operations.

[0278] Instructions or software for controlling computing hardware (e.g., one or more processors or computers) to implement hardware components and perform the methods described above can be written as computer programs, code segments, instructions, or any combination thereof to individually or collectively instruct or configure one or more processors or computers to operate as machines or special-purpose computers to perform operations performed by the hardware components and methods described above. In one example, the instructions or software include machine code that is directly executed by one or more processors or computers, for example, machine code generated by a compiler. In another example, the instructions or software include high-level code that is executed by one or more processors or computers using an interpreter. The instructions or software can be written using any programming language based on the block diagrams and flowcharts shown in the accompanying drawings and the corresponding description in the specification (which discloses algorithms for performing operations performed by the hardware components and methods described above).

[0279] Instructions or software for controlling computing hardware (e.g., one or more processors or computers) to implement hardware components and perform the methods described above, as well as any associated data, data files, and data structures, may be recorded, stored, or fixed in or on one or more non-transitory computer-readable storage media. Examples of non-transitory computer-readable storage media include: read-only memory (ROM), random access memory (RAM), flash memory, CD-ROM, CD-R, CD+R, CD-RW, CD+RW, DVD-ROM, DVD-R, DVD+R, DVD-RW, DVD+RW, DVD-RAM, BD-ROM, BD-R, BD-RLTH, BD-RE, magnetic tape, floppy disk, magneto-optical data storage device, optical data storage device, hard disk, solid-state disk, and any other device configured to store instructions or software, as well as any associated data, data files, and data structures, in a non-transitory manner and to provide said instructions or software, as well as any associated data, data files, and data structures, to one or more processors or computers so that said one or more processors or computers can execute said instructions. In one example, the instructions or software, and any associated data, data files, and data structures, are distributed across a network-coupled computer system to enable the instructions and software, and any associated data, data files, and data structures to be stored, accessed, and executed in a distributed manner via one or more processors or computers.

[0280] While this disclosure includes specific examples, it will be clear upon understanding the disclosure of this application that various changes in form and detail may be made to these examples without departing from the spirit and scope of the claims and their equivalents. The examples described herein should be understood as descriptive only and not for limiting purposes. The description of features or aspects in each example should be considered applicable to similar features or aspects in other examples. Suitable results may be obtained if the described techniques are performed in a different order and / or if components in the described system, architecture, device, or circuit are combined in a different manner and / or replaced or supplemented by other components or their equivalents. Therefore, the scope of this disclosure is not limited by the specific embodiments but by the claims and their equivalents, and all variations within the scope of the claims and their equivalents should be construed as being included in this disclosure.

Claims

1. A processor-implemented encryption method using homomorphic encryption, the encryption method comprising: Ciphertext is generated by encrypting the data; as well as The ciphertext is bootstrapping by performing modulo reduction on the selection of one or more target points based on the modulo corresponding to the ciphertext; The bootstrapping process includes: bootstrapping the ciphertext by approximating a function corresponding to the modulo reduction. The process of bootstrapping the ciphertext by approximating the function corresponding to the modular reduction includes: generating a target approximation polynomial that approximates the function corresponding to the modular reduction. The generation of the target approximation polynomial includes: Based on the degree of the target approximation polynomial, one or more reference points are determined; Determine an arbitrary polynomial based on the one or more reference points; and The target approximation polynomial is generated based on one or more extreme points selected according to the arbitrary polynomial.

2. The encryption method of claim 1, wherein, Determining an arbitrary polynomial based on one or more reference points includes: Determine the piecewise continuous function passing through the one or more reference points; and The arbitrary polynomial is determined by generating a polynomial such that the absolute value of the error between the polynomial and the piecewise continuous function at one or more reference points is a predetermined value.

3. The encryption method according to claim 2, wherein determining the arbitrary polynomial by generating a polynomial comprises: The arbitrary polynomial is determined by generating a polynomial such that: the error at a first reference point included in the one or more reference points has a different sign than the error at a second reference point adjacent to the first reference point, and the absolute values ​​of the errors at the first reference point and the second reference point are the predetermined values.

4. The encryption method according to claim 1, wherein generating the target approximation polynomial based on one or more extreme points selected according to the arbitrary polynomial comprises: From the extreme points of the error between the arbitrary polynomial and the piecewise continuous function passing through the one or more reference points, determine candidate points whose absolute value is greater than or equal to a predetermined value. Select a target point from the candidate points, wherein the number of target points is based on the degree of the target approximation polynomial; as well as Generate the target approximation polynomial based on the target point.

5. The encryption method of claim 4, wherein selecting the target point comprises: Select the target point from the candidate points such that the maximum and minimum values ​​alternate.

6. The encryption method of claim 4, wherein selecting the target point comprises: Choose a target point that maximizes the sum of the absolute values ​​of the errors between the arbitrary polynomial and the piecewise continuous function.

7. The encryption method according to claim 1, wherein generating the target approximation polynomial based on one or more extreme points selected according to the arbitrary polynomial comprises: Generate a polynomial for the case where the relative error between the maximum and minimum values ​​of the absolute values ​​of the one or more extreme points is less than a threshold, and use this polynomial as the target approximation polynomial.

8. The encryption method of claim 1, further comprising: The basis of the target approximation polynomial is the basis of Chebyshev polynomials.

9. A non-transitory computer-readable storage medium for storing instructions, which, when executed by one or more processors, configure the one or more processors to perform the encryption method according to claim 1.

10. An encryption device using homomorphic encryption, the encryption device comprising: One or more processors are configured as follows: Ciphertext is generated by encrypting the data; as well as The ciphertext is bootstrapping by performing modulo reduction on the selection of one or more target points based on the modulo corresponding to the ciphertext; The one or more processors are further configured to: bootstrap the ciphertext by approximating a function corresponding to the modulo reduction. The one or more processors are further configured to: generate a target approximation polynomial that approximates the function corresponding to the modulo reduction. The one or more processors are further configured to: Based on the degree of the target approximation polynomial, one or more reference points are determined; Determine an arbitrary polynomial based on the one or more reference points; and The target approximation polynomial is generated based on one or more extreme points selected according to the arbitrary polynomial.

11. The encryption apparatus of claim 10, wherein, The one or more processors are further configured to: Determine the piecewise continuous function passing through the one or more reference points; and The arbitrary polynomial is determined by generating a polynomial such that the absolute value of the error between the polynomial and the piecewise continuous function at one or more reference points is a predetermined value.

12. The cryptographic device of claim 11, wherein, The one or more processors are further configured to: The arbitrary polynomial is determined by generating a polynomial such that: the error at a first reference point included in the one or more reference points has a different sign than the error at a second reference point adjacent to the first reference point, and the absolute values ​​of the errors at the first reference point and the second reference point are the predetermined values.

13. The cryptographic device of claim 10, wherein, The one or more processors are further configured to: From the extreme points of the error between the arbitrary polynomial and the piecewise continuous function passing through the one or more reference points, determine candidate points whose absolute value is greater than or equal to a predetermined value. Select a target point from the candidate points, wherein the number of target points is based on the degree of the target approximation polynomial; and Generate the target approximation polynomial based on the target point.

14. The cryptographic device of claim 13, wherein, The one or more processors are further configured to select a target point from the candidate points such that the maximum and minimum values ​​alternate.

15. The cryptographic device of claim 13, wherein, The one or more processors are further configured to select a target point that maximizes the sum of the absolute values ​​of the errors between the arbitrary polynomial and the piecewise continuous function.

16. The cryptographic device of claim 10, wherein, The one or more processors are further configured to generate a polynomial for the case where the relative error between the maximum and minimum values ​​of the absolute values ​​of the one or more extreme points is less than a threshold, as the target approximation polynomial.

17. The encryption device of claim 10, wherein the basis of the target approximation polynomial is a basis of Chebyshev polynomials.