A Homomorphic Multiplication Hardware Computing System and Computing Method Based on the Residue Number System
By adopting a hardware computing system based on the remainder system in the all-homomorphic encryption technology, the large modulus is decomposed and parallel structures are used to accelerate the operation, the problems of high complexity and low computational efficiency are solved, and efficient homomorphic multiplication operation is achieved.
Patent Information
- Application Number
- CN202111262134.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-28
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2041-10-28
AI Technical Summary
In the existing all-homomorphic encryption technology, homomorphic multiplication has high complexity and low computing efficiency, making it difficult to deploy at the hardware level.
A homomorphic multiplication hardware computing system based on the remainder system is proposed. By storing ciphertext source data in the representation of the remainder system and participating in the calculation, decomposing large modulus, accelerating operations using parallel structures, improving operation speed and efficiency.
It realizes effective hardware acceleration for homomorphic multiplication operations, improves computing efficiency, and has good practical application value.
Smart Images

Figure CN113986199B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of homomorphic encryption computing, and in particular to a homomorphic multiplication hardware computing system and a computing method based on a residue number system. Background Art
[0002] Under the background of the information society, the issue of privacy protection has attracted much attention. For security reasons, when users outsource data to other services, they need to encrypt private data. Fully homomorphic encryption technology refers to an encryption technology in which ciphertexts satisfy homomorphic operation properties, that is, the result of performing multiplication and addition operations on ciphertexts is the same as the result obtained by directly performing the same operations on plaintexts after decryption. Fully homomorphic encryption can ensure the security of private data and the effectiveness of encrypted data processing, achieving "usable but invisible" data, so it is called the "Holy Grail" of the cryptography field.
[0003] Currently, fully homomorphic encryption technology is still in the stage of scheme exploration. The BFV (Brakerski / Fan-Vercauteren) scheme is a mainstream fully homomorphic encryption scheme with relatively good performance. However, like other traditional homomorphic encryption schemes, its ciphertext operations have problems such as large modulus, high complexity, and low operation efficiency, making it difficult to be deployed at the hardware level. Homomorphic addition and homomorphic multiplication are the most basic ciphertext operations. Among them, the complexity of homomorphic multiplication is dozens of times that of homomorphic addition. Therefore, there is an urgent need for a technology to optimize and accelerate homomorphic multiplication. Summary of the Invention
[0004] In order to solve the problems of high complexity and low operation efficiency of homomorphic multiplication in the prior art, the present invention proposes a method of deploying homomorphic multiplication calculation on hardware, decomposing large integers using a residue number system, and accelerating operations using a parallel structure to improve the speed and efficiency of homomorphic operations. To achieve the above object, the technical solution adopted by the present invention is as follows:
[0005] In a first aspect, a homomorphic multiplication hardware computing system based on a residue number system is proposed, which mainly includes: a controller, a data storage module, a read / write address generation module, a ciphertext basis expansion module, a bitwise multiplication module, a ciphertext scaling module, and a relinearization module, a total of seven modules.
[0006] In some realizable ways of the first aspect, the controller receives configuration information: the modulus t of the coefficients of the polynomial ring in the plaintext domain, the set Q of the base bases of the coefficients of the polynomial ring in the ciphertext domain = {q 1 , q 2 , …, q kq}, the set P of the extended bases = {p 1 , p 2 , …, p kp}, the basic base number \(k_q\) of the coefficients of the ciphertext domain polynomial ring, the extended base number \(k_p\), and the polynomial dimension \(n\); the controller controls the entire operation process to proceed in an orderly manner in the form of a finite state machine, sends an enable signal to other modules, and transmits configuration information.
[0007] In some implementable ways of the first aspect, the data storage module receives two BFV ciphertext source data and pre-computed parameters input externally. Each of the BFV ciphertext source data contains two polynomials on the ciphertext domain ring, and each coefficient is represented in the form of a remainder of an element in the basic base set \(Q\). The pre-computed parameters include pre-computed parameters such as base product, which is convenient for subsequent calculations. Store the two ciphertext source data in random access memories RAM_0 and RAM_1 respectively; store the pre-computed parameters in random access memory RAM_2;
[0008] In some implementable ways of the first aspect, the read / write address generation module generates read / write addresses for storage according to the enable signal sent by the controller, so as to read out the ciphertext source data and pre-computed parameters and transmit them to subsequent modules, or write back the result of the ciphertext base extension module to the memory.
[0009] In some implementable ways of the first aspect, the ciphertext base extension module reads the ciphertext source data and pre-computed parameters in the storage module, extends the ciphertext source data from the basic base representation to the extended base representation, and the calculation is completed by a modular multiplier, a modular adder, a fixed-point to floating-point converter, a lookup table, a multiplier, and an adder.
[0010] In some implementable ways of the first aspect, the bitwise multiplication module reads the ciphertext source data in the extended base representation in the storage module. After the coefficients are multiplied bitwise in the NTT domain, three intermediate results are obtained and sent to the ciphertext scaling module. The polynomial coefficients of the three intermediate results are represented in the extended base. The bitwise multiplication module is calculated by a modular multiplier and a modular adder.
[0011] In some implementable ways of the first aspect, the ciphertext scaling module consists of a first calculation module and a second calculation module. The first calculation module scales the polynomial coefficients of the three ciphertext results according to the ratio of "plaintext domain modulus: ciphertext domain modulus", and the second calculation module adjusts the scaled result to the basic base representation through base extension operation. The ciphertext scaling module is calculated by a modular multiplier, a modular adder, a fixed-point to floating-point converter, a multiplier, and an adder.
[0012] In some realizable ways of the first aspect, the relinearization module consists of a key generation module and a relinearization calculation module. The key generation module generates two keys required for relinearization, and the calculation is completed by a random number generator, an NTT transformation unit, and a modular adder. The relinearization calculation module is configured to reduce the number of ciphertext result terms according to the relinearization key, and the calculation is completed by an adder, a multiplier, and an NTT transformation unit.
[0013] The complete operation process of the homomorphic multiplication specifically includes the following steps:
[0014] Step 1: The controller receives the configuration information and controls the data storage module to receive and store the ciphertext source data and the pre-computation parameters.
[0015] Step 2: The controller enables the ciphertext basis expansion module, reads the ciphertext source data and the pre-computation parameters represented by the basic radix in the data storage module, and obtains the remainder representation of the extended radix for the coefficient x of each ciphertext source data polynomial. Write it back to the data storage module.
[0016] Step 3: The controller enables the bitwise multiplication module, reads the ciphertext source data represented by the basic radix and the extended radix in the data storage module, and after bitwise multiplication of the coefficients in the NTT domain, three intermediate results are obtained and sent to the ciphertext scaling module.
[0017] Step 4: The controller enables the ciphertext scaling module, scales the polynomial coefficients of the three intermediate results at the ratio of "plaintext domain modulus: ciphertext domain modulus", and writes it back to the data storage module.
[0018] Step 5: The controller enables the ciphertext basis expansion module again, reads the three intermediate results represented by the extended radix and the pre-computation parameters in the data storage module, and obtains the remainder representation of the basic radix for the coefficient x of each intermediate result. Write it back to the data storage module.
[0019] Step 5: The controller enables the relinearization module, reads the pre-computation parameters and the three intermediate results, generates the relinearization key and reorganizes the three intermediate results to reduce the result to two terms.
[0020] Step 6: The controller enables the output module to complete the operation process and output the homomorphic product result.
[0021] Beneficial effects:
[0022] On the one hand, a homomorphic multiplication hardware computing system based on the residue number system proposed by the present invention stores ciphertext source data in the representation form of the residue number system and participates in the calculation, decomposes large moduli, breaks large numbers into small ones, and simplifies complexity; based on the non-weight property and parallelism of the residue number system, a parallel computing architecture is built to realize parallel computing between different coefficients of the same polynomial and between different radix representations of the same coefficient;
[0023] On the other hand, in the ciphertext basis expansion module of the present invention, according to the Chinese Remainder Theorem, the coefficients of the polynomial on the ring are decomposed into two parts, and a fixed-point floating-point converter is used to round the calculation result of the floating-point part. Compared with the traditional calculation method, a faster radix transformation of the coefficients of the polynomial on the ring is realized; the resource reuse of the ciphertext scaling and subsequent basis expansion module improves the resource utilization rate and reduces the hardware overhead.
[0024] Therefore, the homomorphic multiplication hardware computing system based on the residue number system proposed by the present invention realizes effective hardware acceleration of the homomorphic multiplication operation, improves the operation efficiency, and has good practical application value. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 Schematic diagram of the top-level module of the hardware computing system designed by the present invention.
[0026] Figure 2 Schematic diagram of the architecture of the ciphertext basis expansion module in the present invention.
[0027] Figure 3 Schematic diagram of the architecture of the ciphertext scaling module in the present invention.
[0028] Figure 4 Schematic diagram of the architecture of the ciphertext basis expansion module reused after ciphertext scaling in the present invention.
[0029] Figure 5 Key generation module of the relinearization module in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0030] In the following description, numerous specific details are given to provide a more thorough understanding of the present invention. However, it will be apparent to one skilled in the art that the present invention may be practiced without one or more of these details. In other instances, some well-known technical features are not described in order to avoid obscuring the present invention.
[0031] A homomorphic multiplication hardware computing system based on the residue number system is proposed, as Figure 1 shown, the system specifically includes:
[0032] A controller, which is configured to control the orderly progress of the entire operation process in the form of a finite state machine, receive and transfer configuration information; a data storage module, which is configured to receive and store ciphertext source data and pre-computed parameters; a read / write address generation module, which is configured to generate read / write addresses for a memory; a ciphertext basis expansion module, which is configured to implement the mutual expansion of the remainder representation of the polynomial coefficients of the ciphertext between the basis basis and the extended basis; a bitwise multiplication module, which is configured to implement bitwise multiplication of the ciphertext in the NTT domain to obtain an intermediate result of a three-term homomorphic multiplication; a ciphertext scaling module, which is configured to scale the polynomial coefficients of the intermediate result in the ratio of "plaintext domain modulus: ciphertext domain modulus"; a relinearization module, which is configured to generate a relinearization key and reorganize the three-term intermediate result to reduce the result to two terms; and an output module, which is configured to output the homomorphic multiplication ciphertext result.
[0033] In a further embodiment, based on the homomorphic multiplication hardware computing system based on the residue number system proposed by the present invention, the complete operation process of a single homomorphic multiplication specifically includes the following steps:
[0034] Step 1: The controller receives configuration information and controls the data storage module to receive and store ciphertext source data and pre-computed parameters.
[0035] Step 2: The controller enables the ciphertext basis expansion module, reads the ciphertext source data and pre-computed parameters represented by the basis base number in the data storage module, and for the coefficient x of each ciphertext source data polynomial, obtains its remainder representation in the extended base number and writes it back to the data storage module.
[0036] Step 3: The controller enables the bitwise multiplication module, reads the ciphertext source data represented by the basis base number and the extended base number in the data storage module, and after bitwise multiplication of its coefficients in the NTT domain, obtains a three-term intermediate result and sends it to the ciphertext scaling module.
[0037] Step 4: The controller enables the ciphertext scaling module, scales the polynomial coefficients of the three-term intermediate result in the ratio of "plaintext domain modulus: ciphertext domain modulus", and writes it back to the data storage module.
[0038] Step 5: The controller enables the ciphertext basis expansion module again, reads the three-term intermediate result and pre-computed parameters represented by the extended base number in the data storage module, and for the coefficient x of each intermediate result polynomial, obtains its remainder representation in the basis base number and writes it back to the data storage module.
[0039] Step 5: The controller enables the relinearization module, reads the pre-computed parameters and the three-term intermediate result, generates a relinearization key and reorganizes the three-term intermediate result to reduce the result to two terms.
[0040] Step 6: The controller enables the output module to complete the operation process and output the homomorphic product result.
[0041] In a further embodiment, the pre-computed parameters of the data storage module specifically include:
[0042]
[0043]
[0044]
[0045]
[0046]
[0047]
[0048]
[0049]
[0050]
[0051] θ i = α i - ω i
[0052]
[0053]
[0054] Where:
[0055]
[0056] i = 1, 2... kq; j = 1, 2... kp,
[0057] sk_NTT is the NTT domain representation of the homomorphic encryption private key. In a further embodiment, the calculation principle of the ciphertext basis expansion module is as follows: According to the Chinese Remainder Theorem, for the coefficient x of the polynomial on the ciphertext domain ring,
[0058]
[0059] It can be known that:
[0060]
[0061] Where:
[0062] i = 1, 2... kq
[0063] j = 1, 2... kp
[0064]
[0065]
[0066] The structural schematic diagram of the ciphertext base expansion module is as shown in Figure 2 shown. The pre-computed parameters and the base radix representation x of the polynomial coefficients of the ciphertext source data i are read out from the random access memory. Then, according to the formula:
[0067]
[0068] The calculation is completed by a modular multiplier, a modular adder, a fixed-point to floating-point converter, a lookup table, a multiplier, and an adder to obtain the extended radix representation of the polynomial coefficients of the ciphertext source data and write it back to the data storage module.
[0069] In a further embodiment, the calculation principle of the ciphertext scaling module is as follows:
[0070] It can be proved according to the Chinese Remainder Theorem that for the coefficient x of the polynomial on the ciphertext domain ring,
[0071]
[0072] where:
[0073] i = 1, 2... kq
[0074] j = 1, 2... kp
[0075]
[0076] In the left expression is the large modulus of the ciphertext domain disassembled by the residue number system. The left expression is the result of scaling the polynomial coefficient x in the ratio of "plaintext domain modulus: ciphertext domain modulus". The architectural schematic diagram of the ciphertext scaling module is as shown in Figure 3 shown. The calculation is completed by a modular multiplier, a modular adder, a fixed-point to floating-point converter, a multiplier, and an adder, and the result is written back to the data storage module.
[0077] In a further embodiment, after the ciphertext scaling is completed, the controller issues an enable signal to reuse the ciphertext base expansion module, and the architectural schematic diagram is as shown in Figure 4 shown. The difference between this reuse and the first enable of the base expansion module is that the first expansion is to expand the ciphertext polynomial coefficient from the residue representation of the base base to the residue representation of the extended base, and this reuse is to expand the ciphertext polynomial coefficient from the residue representation of the extended base to the residue representation of the base base. The directions of the two expansions are opposite, so the two calculation inputs are symmetric, just as Figure 2 andFigure 4 as shown
[0078] In a further embodiment, a schematic architecture diagram of the key generation module of the relinearization module is as Figure 5 shown. This module reads precomputed parameters sk_NTT, s from the storage unit i , first generates a key rlk1 and noise e by a random number generator, and then completes the following calculations by an NTT transformation unit, a modular multiplier, and a modular adder as shown:
[0079] rlk0 = iNTT(NTT(rlk1)·sk_NTT)+e+s i
[0080] The NTT transformation unit performs a fast number-theoretic transform, that is, it mutually converts a polynomial between coefficient representation and point representation. Its hardware structure has various implementation forms and is mainly composed of a modular multiplier and a butterfly calculation unit. The forward NTT and the inverse NTT (iNTT) perform calculations respectively:
[0081]
[0082]
[0083] where M is a modular prime number, g is a primitive root of M, and N is the dimension.
[0084] After the key generation module obtains the relinearization keys rlk0 and rlk1, it reads three intermediate results from the data storage module, uses a multiplier and an adder, multiplies the last result with the relinearization key and accumulates it into the first two intermediate results to obtain the homomorphic product.
[0085] A homomorphic multiplication hardware calculation system based on the residue number system proposed by the present invention stores and participates in the calculation of ciphertext source data in the form of the residue number system, decomposes large moduli, breaks large ones into small ones, simplifies complexity; based on the non-weight property and parallelism of the residue number system, builds a parallel calculation architecture to realize parallel calculation between different coefficients of the same polynomial and between different radix representations of the same coefficient; in addition, in the ciphertext basis expansion module of the present invention, according to the Chinese Remainder Theorem, the coefficients of the polynomial on the ring are disassembled into two parts, and a fixed-point floating-point converter is used to round the calculation result of the floating-point part. Compared with the traditional calculation method, a faster radix transformation of the coefficients of the polynomial on the ring is realized; the resource reuse of the ciphertext scaling and basis expansion module improves the resource utilization rate and reduces the hardware overhead.
[0086] Therefore, the homomorphic multiplication hardware calculation system based on the residue number system proposed by the present invention realizes effective hardware acceleration of homomorphic multiplication operations, improves the operation efficiency, and has good practical application value.
Claims
1. A homomorphic multiplication hardware computing system based on the residue number system, characterized in that, it includes: A controller, which is set to control the orderly progress of the entire operation process in the form of a finite state machine, and receive and transfer configuration information; A data storage module, which is set to receive and store ciphertext source data and pre-computation parameters; A read-write address generation module, which is set to generate read-write addresses of the memory; A ciphertext basis expansion module, which is set to realize the mutual expansion of the polynomial coefficients of the ciphertext between the residue representation form of the basic basis and the residue representation form of the extended basis; A bitwise multiplication module, which is set to realize the bitwise multiplication of the ciphertext in the NTT domain to obtain an intermediate result of the three-term homomorphic multiplication; A ciphertext scaling module, which is set to scale the polynomial coefficients of the intermediate result in the ratio of "plaintext domain modulus: ciphertext domain modulus"; A relinearization module, which is set to generate a relinearization key and reorganize the three-term intermediate result to reduce the result to two terms; An output module, which is set to output the homomorphic multiplication ciphertext result.
2. The homomorphic multiplication hardware computing system based on the residue number system according to claim 1, characterized in that, The controller is further configured to receive configuration information: the modulus t of the plaintext domain polynomial ring coefficients, the set of base radices of the ciphertext domain polynomial ring coefficients , the extended radix set , the number kq of base radices of the ciphertext domain polynomial ring coefficients, the number kp of extended radices, and the polynomial dimension n; the controller controls the entire operation process to proceed orderly in the form of a finite state machine, sends an enable signal to other modules and transmits the configuration information.
3. The homomorphic multiplication hardware computing system based on the residue number system according to claim 1, characterized in that, The data storage module receives two BFV ciphertext source data and pre-computation parameters input from the outside; each BFV ciphertext source data contains two polynomials on the ciphertext domain ring, and each coefficient is represented in the form of the modulus of the elements in the basic base set Q; the pre-computation parameters include pre-computed parameters such as the product of bases, which are convenient for subsequent calculations; the ciphertext source data is stored in the random access memories RAM_0 and RAM_1; the pre-computation parameters are stored in RAM_2.
4. The homomorphic multiplication hardware computing system based on the residue number system according to claim 1, characterized in that, The ciphertext basis expansion module further includes: a modular multiplier, a modular adder, a fixed-floating converter, a lookup table, a multiplier, and an adder, which are used for the mutual expansion of the polynomial coefficients of the ciphertext between the residue representation form of the basic basis and the residue representation form of the extended basis.
5. The homomorphic multiplication hardware computing system based on the residue number system according to claim 1, characterized in that, The bitwise multiplication module reads the ciphertext source data represented by the extended base in the storage module, and the coefficients are bitwise multiplied in the NTT domain to obtain a three-term intermediate result, which is sent to the ciphertext scaling module; the polynomial coefficients of the three-term intermediate result are represented by the extended base; the bitwise multiplication module is completed by a modular multiplier and a modular adder.
6. The homomorphic multiplication hardware computing system based on the residue number system according to claim 1, characterized in that, The ciphertext scaling module is set to scale the polynomial coefficients of the three-term intermediate result in the ratio of "plaintext domain modulus: ciphertext domain modulus", and the calculation is completed by a modular multiplier, a modular adder, a fixed-floating converter, a multiplier, and an adder.
7. The homomorphic multiplication hardware computing system based on the residue number system according to claim 1, characterized in that, The relinearization module further includes: The key generation module is configured to generate two keys required for relinearization, and the calculation is completed by a random number generator, an NTT transformation unit, a modular multiplier, and a modular adder; The relinearization calculation module is configured to reduce the number of ciphertext result terms according to the relinearization key, and the calculation is completed by an adder, a multiplier, and an NTT transformation unit.
8. The homomorphic multiplication hardware calculation method is implemented based on the calculation system described in any one of claims 1 to 7. It is characterized in that it includes the following steps: Step 1: The controller receives configuration information and controls the data storage module to receive and store the ciphertext source data and pre-computation parameters; Step 2: The controller enables the ciphertext base expansion module, reads the ciphertext source data and pre-computed parameters represented by the base radix in the data storage module, and obtains the remainder representation of the extended radix for the coefficient x of each ciphertext source data polynomial, and writes it back to the data storage module; , and write it back to the data storage module; Step 3: The controller enables the bitwise multiplication module, reads the ciphertext source data represented by the base radix and the extended radix in the data storage module, and after the coefficients are bitwise multiplied in the NTT domain, three intermediate results are obtained and sent to the ciphertext scaling module; Step 4: The controller enables the ciphertext scaling module, scales the polynomial coefficients of the three intermediate results in the ratio of "plaintext domain modulus: ciphertext domain modulus", and writes them back to the data storage module; Step 5: The controller enables the ciphertext base expansion module again, reads the three intermediate results and pre-computed parameters represented by the expansion radix in the data storage module, and obtains the remainder representation of the base radix for the polynomial coefficient x of each intermediate result, and writes it back to the data storage module. , and write it back to the data storage module; Step 6: The controller enables the relinearization module, reads the pre-computation parameters and the three intermediate results, generates the relinearization key and reorganizes the three intermediate results to reduce the result to two items; Step 7: The controller enables the output module to complete the operation process and output the homomorphic product ciphertext.
Citation Information
Patent Citations
Homomorphic processing method of data
CN110519039A
KR20210116299A