A non-interactive homomorphic encryption method for large plaintext space

CN117879784BActive Publication Date: 2026-09-18NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410096877.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-23
Publication Date
2026-09-18
Estimated Expiration
2044-01-23

AI Technical Summary

Technical Problem

对于指数级别的明文空间(关注明文空间的尺寸,忽略明文的表达形式),还需要设计plan-ahead的可否认全同态加密算法,即在加密阶段提前指定面向强权威胁时可以否认的明文集合,且该明文集合是多项式级别,严重影响可否认明文集合的灵活性

Benefits of technology

[0012] Compared with existing fully homomorphic encryption methods, this invention, in the process of calculating ciphertext using a fully homomorphic encryption algorithm, can prevent a powerful adversary from coercing the data owner to open the plaintext and random numbers used to generate the ciphertext. It can deny that the fully homomorphic encryption algorithm can provide "fake" plaintext and random numbers, making the powerful adversary believe they are genuine plaintext and random numbers, thus effectively protecting the privacy of the data owner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117879784B_ABST
    Figure CN117879784B_ABST
Patent Text Reader

Abstract

The present application provides a kind of big plaintext space-oriented undeniable homomorphic encryption method, comprising: plaintext in polynomial or exponential level plaintext space is arranged according to its subscript, through permutation function, it is expressed as 0-1 vector of polynomial level;In weak undeniable homomorphic encryption wDFHE and undeniable homomorphic encryption DFHE, the two-way denial of the ciphertext of 0 and the ciphertext of 1 is realized.The present application supports data owner to output "fake" plaintext and random number, so that the strong enemy believes that it is the real plaintext and random number;Meanwhile, the defects that all plaintexts need to participate in the calculation process of the encryption algorithm of the undeniable homomorphic encryption, and the limitation problem of plan-ahead to the undeniable set in exponential level plaintext space are solved, and the undeniable theory facing strong threat in the calculation process of ciphertext data is enriched.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of fully homomorphic encryption technology, and more specifically, to a repudiable fully homomorphic encryption method for large plaintext spaces. Background Technology

[0002] Fully homomorphic encryption not only encrypts data, effectively protecting data privacy, but also allows direct addition and multiplication operations on the ciphertext. Furthermore, decrypting the ciphertext after these operations yields the same result as performing the same operations on the plaintext, i.e., Dec(f(c)) = f(m), where Dec is the decryption algorithm, f is the ciphertext operation function, c is the fully homomorphic ciphertext, and m is the corresponding plaintext. This superior property has led to widespread attention for fully homomorphic encryption both domestically and internationally. Therefore, since Gentry constructed a fully homomorphic encryption algorithm on an ideal lattice based on bootstrapping techniques and the cycle security assumption, research on fully homomorphic encryption algorithms has largely focused on this approach, achieving indistinguishable security under chosen-plaintext attacks.

[0003] Fully homomorphic encryption is a key and effective cryptographic technology for addressing big data privacy protection issues in open environments. In practical applications of ciphertext computation, such as cloud computing, the Internet of Things, artificial intelligence, and e-health, data owners only need to upload the fully homomorphic ciphertext of their data to a server. The semi-honest server then performs computation on the ciphertext and returns the processed ciphertext to the data owner, who can then decrypt it to obtain the processed plaintext, greatly avoiding the process of storing and computing the ciphertext. However, in real-world scenarios such as counter-espionage and the presence of foreign intelligence agents, or electronic voting with malicious candidates, if an external adversary, such as a coercion, forces the data owner to open the plaintext and random number generated during the encryption phase, otherwise endangering the data owner's personal safety, then fully homomorphic encryption can no longer guarantee data confidentiality.

[0004] Repudiable fully homomorphic encryption is a cryptographic primitive that can effectively protect data privacy against powerful adversaries during ciphertext computation. It allows the data owner to output "fake" plaintext and random numbers during fully homomorphic ciphertext transmission, making the adversary believe these are genuine plaintext and random numbers, while being unable to distinguish between the "fake" and genuine cases. Agrawal et al. (Agrawal S, Goldwasser S, Mossel S. Deniable fullyhomomorphic encryption from learning with errors. Advances in Cryptology-CRYPTO. 2021: 641-670.) gave a formal definition of repudiable fully homomorphic encryption and designed a post-quantum-secure repudiable fully homomorphic encryption algorithm, achieving weak and complete repudiation in a single-bit, polynomial-level plaintext space.

[0005] However, for polynomial-level plaintext spaces, the performance of repudiable fully homomorphic encryption algorithms is linearly related to the size of the plaintext space, requiring all plaintext to participate in the computation. For exponential-level plaintext spaces (focusing on the size of the plaintext space and ignoring the plaintext's representation), a plan-ahead repudiable fully homomorphic encryption algorithm is also needed. This involves pre-defining the set of plaintexts that can be repudiated in the face of tyrannical threats during the encryption phase, and this set is polynomial-level, severely impacting the flexibility of the repudiable plaintext set. Therefore, designing a repudiable fully homomorphic encryption method for large plaintext spaces has high practical value and application prospects. It can avoid the limited repudiable set in the plan-ahead encryption phase and the situation where all plaintext participates in the repudiable fully homomorphic encryption algorithm, enriching the theory of repudiation in the computation of encrypted data in the face of tyrannical threats. Summary of the Invention

[0006] To address the issue of data owners being forced by powerful adversaries to reveal the plaintext and random numbers generated during the encryption phase of ciphertext computation, thereby endangering their personal safety and highlighting the data owner's need for privacy protection, this invention provides a repudiable fully homomorphic encryption method for large plaintext spaces. This method allows data owners to output "fake" plaintext and random numbers, convincing powerful adversaries that these are genuine. Simultaneously, it resolves the shortcomings of encryption algorithms requiring all plaintext to participate in the repudiable fully homomorphic computation process, as well as the need for a plan-ahead constraint on the repudiable set in an exponentially large plaintext space. This enriches the repudiable theory for encrypted data computation in the face of powerful threats.

[0007] This invention provides a repudiable fully homomorphic encryption method for large plaintext spaces, characterized by comprising:

[0008] (1) Arrange the plaintext in the polynomial or exponential plaintext space according to its subscript, and after the permutation function, represent it as a polynomial-level 0-1 vector;

[0009] (2) In the weak, repudiable, fully homomorphic encryption wDFHE, utilizing and To achieve bidirectional denial of ciphertext 0 and ciphertext 1, where, This represents a bitwise XOR operation; the weak, deniable, fully homomorphic encryption wDFHE includes a key generation algorithm wKeyGen, an encryption algorithm wEnc, a fake encryption algorithm wDEnc, a fake algorithm wFake, a ciphertext operation algorithm wEval, and a decryption algorithm wDec.

[0010] (3) In the repudiable fully homomorphic encryption DFHE, using η x l ∈{0,1}, the result of its modulo 2 operation Choose the appropriate x, which can be either 0 or 1. l It achieves bidirectional denial of ciphertext with 0 and ciphertext with 1 (here η is squared to the probability of DFHE being fake); the denialable fully homomorphic encryption DFHE includes a key generation algorithm KeyGen, an encryption algorithm Enc, a fake algorithm Fake, a ciphertext operation algorithm Eval, and a decryption algorithm Dec.

[0011] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:

[0012] Compared with existing fully homomorphic encryption methods, this invention, in the process of calculating ciphertext using a fully homomorphic encryption algorithm, can prevent a powerful adversary from coercing the data owner to open the plaintext and random numbers used to generate the ciphertext. It can deny that the fully homomorphic encryption algorithm can provide "fake" plaintext and random numbers, making the powerful adversary believe they are genuine plaintext and random numbers, thus effectively protecting the privacy of the data owner.

[0013] Compared with existing fully homomorphic encryption methods: (1) In this invention, the invention is oriented towards a large plaintext space of polynomial level, which solves the defect that all plaintext must participate in the calculation of the denial fully homomorphic encryption algorithm. The amount of computation and communication depends on logu, not u, where u is the size of the plaintext space; (2) In this invention, the invention is oriented towards a large plaintext space of exponential level, and any plaintext can be used as a denial object, avoiding the limitation of specifying the set of denialable plaintexts in the encryption stage in the plan-ahead stage.

[0014] This invention can be used in practical application scenarios such as electronic voting where there is malicious candidate vote-buying, and counter-espionage where foreign intelligence personnel steal intelligence, and has high theoretical value and application prospects. Attached Figure Description

[0015] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 This is a schematic diagram illustrating the differences between FHE, DFHE, and wDFHE in an embodiment of the present invention.

[0017] Figure 2 This is a schematic diagram illustrating the working modes of the encryption and spoofing algorithms in wDFHE and DFHE in the embodiments of the present invention.

[0018] Figure 3 This is a schematic diagram of the wDFHE spoofing algorithm in an embodiment of the present invention.

[0019] Figure 4 This is a schematic diagram of the DFHE spoofing algorithm in an embodiment of the present invention. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0021] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.

[0022] Example

[0023] Define the following algorithms:

[0024] Definition 1, Fully Homomorphic Encryption (FHE):

[0025] Fully homomorphic encryption (FHE) includes the key generation algorithm KeyGen, the encryption algorithm Enc, the ciphertext operation algorithm Eval, and the decryption algorithm Dec, which are explained in detail below:

[0026] The key generation algorithm KeyGen is represented as (pk, sk, evk) ← KeyGen(K): It takes the security parameter κ as input and outputs the public key pk, the private key sk and the operation key evk;

[0027] The encryption algorithm Enc is represented as c←Enc(pk, m, r): input plaintext m and random number r, output ciphertext c;

[0028] The ciphertext operation algorithm Eval is represented as f(c1, c2, ..., c...). β )←Eval(evk,f,c1,c2,…,c β Input operation key evk, function f, and any β ciphertexts c1, c2, ..., c β Output the ciphertext f(c1, c2, ..., c) after the operation. β );

[0029] The decryption algorithm Dec is represented as m←Dec(sk, c): it outputs the plaintext m corresponding to the ciphertext c.

[0030] Decryption correctness: For any plaintext m∈M, Dec(sk, c)=m, where M is the plaintext space and Enc(pk, m)=c. Furthermore, if the ciphertext is the processed ciphertext, it must satisfy Dec(sk, f(c1, c2, …, c)). β ))=f(m1,m2,…,m β ), where Dec(sk, c i ) = m i , i∈[β].

[0031] Security: For any plaintext m i For m2∈M, Enc(pk,m1) and Enc(pk,m2) are computationally indistinguishable. The security here refers to indistinguishability under chosen-plaintext attacks.

[0032] Definition 2, Deniability of Fully Homomorphic Encryption (DFHE) and wDFHE:

[0033] Deniable fully homomorphic encryption (DFHE) includes the key generation algorithm KeyGen, the encryption algorithm Enc, the spoofing algorithm Fake, the ciphertext manipulation algorithm Eval, and the decryption algorithm Dec. For example... Figure 1 As shown, compared to FHE in Definition 1, DFHE only has one more algorithm, Fake; the other algorithms are described the same as FHE, as detailed below:

[0034] The fake algorithm is represented by r. * ←Fake(m, m) *(r): Input plaintext m, random number r, and plaintext m to be forged. * Output a random number r * Such that Enc(pk, m, r) = Enc(pk, m) * r * ).

[0035] For the correctness and security of decryption, see Definition 1.

[0036] Repudiation: For any plaintext m, m * ∈M, there is a triple (m * ,r,Enc(pk,m * ,r)) and (m * r * Enc(pk, m, r)) is computationally indistinguishable, where r * ←Fake(m, m) * ,r).

[0037] Weakly deniable fully homomorphic encryption (wDFHE) includes a key generation algorithm (wKeyGen), an encryption algorithm (wEnc), a fake encryption algorithm (wDEnc), a fake encryption algorithm (wFake), a ciphertext operation algorithm (wEval), and a decryption algorithm (wDec). For example... Figure 1 As shown, compared to DFHE, wDFHE has an additional fake encryption algorithm wDEnc, and the fake algorithm has been changed. The descriptions of other algorithms are the same as DFHE (only the symbols are different for distinction), as detailed below:

[0038] The fake encryption algorithm wDEnc is represented as c←wDEnc(pk, m, r): input plaintext m and random number r, output ciphertext c.

[0039] The fake algorithm wFake is represented as r * ←wFake(m,m * (r): Input plaintext m, random number r, and plaintext m to be forged. * Output a random number r * Such that wDEnc(pk, m, r) = wEnc(pk, m) * r * ).

[0040] The decryption accuracy and security are the same as DFHE.

[0041] Repudiation: For any plaintext m, m * ∈M, random number There are triples (m) * ,r,wEnc(pk,m* ,r)) and The calculation is indistinguishable, where,

[0042] Definition 3, Modified BGV:

[0043] The difference between the modified BGV and the BGV algorithm lies only in the decryption algorithm; its key generation algorithm, encryption algorithm, and ciphertext operation algorithm are the same as the BGV algorithm. The BGV algorithm (Brakerski Z, Gentry C, Vaikuntanathan V (Leveled) Fully homomorphic encryption without bootstrapping. Proceedings of the 3rd Innovations in Theoretical Computer Science Conference, ACM. 2012: 309-325.) is a typical fully homomorphic encryption algorithm, with a plaintext space of Z² and a ciphertext space of Z². The decryption algorithm is the inner product of the ciphertext and the private key modulo q, modulo 2.<c,sk> mod q mod 2, where <·> is the inner product operation, c is the ciphertext, and sk is the private key.

[0044] In fact,<c,sk> mod q = m + 2e, where m is the plaintext and e is the noise (whose infinity norm is bounded above, denoted as B). Therefore, the decryption algorithm for the modified BGV is: calculate...<c,sk> Mod q determines whether its infinity norm is less than 2B. If it is, output 0; otherwise, output 1.

[0045] Definition 4, Bootstrap Algorithm:

[0046] The bootstrap algorithm uses Fully Homomorphic Encryption (FHE) and homomorphically calls the decryption circuit during ciphertext computation. This is typically used to reduce noise in the ciphertext and is written as Boot(c) = Eval(evk, Dec, c), where Dec represents the decryption circuit. However, another easily overlooked property of the bootstrap algorithm is that the output of Boot(c) is still ciphertext. It is particularly important to note that if the ciphertext c is randomly selected from the ciphertext space, then there are ciphertexts with a bootstrap result of 0, i.e., Boot(c) = Enc(0). This invention primarily utilizes this property to design a repudiable fully homomorphic encryption method for large plaintext spaces.

[0047] Definition 5, Extraction Algorithm:

[0048] Let the plaintext space be M = {m1, m2, ..., m} u}, where u is an integer of exponential or polynomial level. The extraction algorithm is described as follows:

[0049] Given any index i ∈ [u], the extraction algorithm outputs the plaintext m corresponding to that index. i That is, Extra(i) = m i .

[0050] This extraction algorithm is easy to implement. For example, using a private information retrieval protocol, if the input is FHE ciphertext i, the final extraction algorithm outputs m. i FHE ciphertext.

[0051] like Figure 2 , Figure 3 , Figure 4 As shown, this embodiment proposes a repudiable fully homomorphic encryption method for large plaintext spaces, with the following approach:

[0052] (1) Arrange the plaintext in the polynomial or exponential plaintext space according to its subscript, and after the permutation function, represent it as a polynomial-level 0-1 vector;

[0053] (2) In the weak, repudiable, fully homomorphic encryption wDFHE, utilizing and To achieve bidirectional denial of ciphertext 0 and ciphertext 1, where, This represents a bitwise XOR operation;

[0054] (3) In the repudiable fully homomorphic encryption DFHE, using η x l ∈{0,1}, the result of its modulo 2 operation Choose the appropriate x, which can be either 0 or 1. l This achieves bidirectional denial of ciphertexts of 0 and 1, where η is quadratically related to the falsification probability of DFHE.

[0055] Let plaintext space M = {m1, m2, ..., m} u}, where u is a polynomial or exponential integer. Fully homomorphic encryption (FHE) uses a variant of BGV from Definition 3, where 1 is one of the plaintexts of the variant BGV.

[0056] The weak, repudiable, fully homomorphic encryption wDFHE is described as follows:

[0057] (wdpk, wdsk, wdevk)←wKeyGen(κ): Takes the security parameter κ as input and performs the following operation:

[0058] (1) Run the modified BGV key generation algorithm to generate public key pk, private key sk and operation key evk;

[0059] (2) Run a modified BGV encryption algorithm on the private key sk to generate the ciphertext c of the private key.sk ;

[0060] (3) Output public key wdpk = (pk, c sk Private key wdsk = sk, operation key wdevk = evk.

[0061] C←wEnc(wdpk,m i Rand α ): plaintext m i The encryption process (i∈[u]) under the public key wdpk is described as follows:

[0062] (1) Plaintext m f Replace the subscript:

[0063] (a) A bijective τ(i) = j, where j ∈ [u];

[0064] (b) Perform bit decomposition on j, denoted as σ(j) = (j1, j2, ..., jj) v )∈{0,1} v ,in,

[0065] (c) Output (j1, j2, ..., j) v ).

[0066] (2) For all j α (α∈[v]) and plaintext m i Encrypt:

[0067] (a) Uniformly random selection of Rand α =(R α,1 R α,2 R α,3 r α,4 r α ), where R α,1 R α,2 R α,3 For the ciphertext randomly selected from the ciphertext space of the modified BGV, r α,4 r α The random number space from the encryption algorithm derived from a variant of BGV. For plaintext 1 and random number r... a,4 Run the BGV encryption algorithm to compute the ciphertext R of 1. α,4 =Enc(1, r α,4 ); for plaintext m i and random number r α Run the BGV encryption algorithm and calculate m. i ciphertext c i =Enc(m i r α );

[0068] (b) Run the bootstrap algorithm of the modified BGV to calculate here It is the XOR operation of the ciphertext in the modified BGV;

[0069] (c) Output ciphertext C = (C[1], C[2], ..., C[v], c i ), where C[α] represents the α-th component of C, and α∈[v], i∈[u].

[0070] C←wDEnc(wdpk,m i Rand α ): plaintext m i The encryption process for (i∈[u]) under the public key wdpk is described as follows:

[0071] (1) Plaintext m f Replace the subscript:

[0072] (a) A bijective τ(i) = j, where j ∈ [u];

[0073] (b) Perform bit decomposition on j, denoted as σ(j) = (j1, j2, ..., jj) v )∈{0,1} v ,in,

[0074] (c) Output (j1, j2, ..., j) v ).

[0075] (2) For all j α (α∈[v]) and plaintext m i Encrypt:

[0076] (a) Uniformly random selection of Rand α =(r α,1 r α,2 r α,3 R α,4 r α ), where r α,1 r α,2 r α,3 r α The random number space R from the encryption algorithm derived from the modified BGV α,4 The ciphertext is randomly selected from the ciphertext space of the modified BGV. For plaintext 1 and the random number r... α,1 r α,2 r α,3 Run the modified BGV encryption algorithm separately to calculate the ciphertext R of 1. α,1 =Enc(1, rα,1 ), R α,2 =Enc(1, r α,2 ), R α,3 =Enc(1, r α,3 ); for plaintext m i and random number r α Run the BGV encryption algorithm and calculate m. i ciphertext c i =Enc(m i r α );

[0077] (b) Run the bootstrap algorithm of the modified BGV to calculate here It is the XOR operation of the ciphertext in the modified BGV;

[0078] (c) Output ciphertext C = (C[1], C[2], ..., C[v], c i ), where C[α] represents the α-th component of C, and α∈[v], i∈[u].

[0079] The input is m i m k ∈M, where m k If you want to falsify plaintext, do the following:

[0080] (1) Represent the plaintext m i m k Subscript permutations of each distinct component of στ(i) and στ(k):

[0081] (a)στ(i)=(j1,j2,…,j v )∈{0,1} v ,στ(k)=(y1,y2,…,y v )∈{0,1} v ,in, j, y∈[u];

[0082] (b) For any α∈[v], if Output set

[0083] (2) Implement all j α to y α The denial, where α∈A:

[0084] (a) Uniformly random selection of Rand α =(r α,1r α,2 r α,3 R α,4 ), where r α,1 r α,2 r α,3 R represents the random number space derived from the encryption algorithm of the modified BGV. α,4 For the ciphertext randomly selected from the ciphertext space of the modified BGV, the plaintext 1 and the random number r are... α,1 r α,2 r α,3 Run the modified BGV encryption algorithm separately to calculate the ciphertext R of 1. α,1 =Enc(1, r α,1 ), R α,2 =Enc(1, r a,2 ), R α,3 =Enc(1, r a,3 );

[0085] (b) If i = k, for any α ∈ [v], let

[0086] (c) If i ≠ k, for all α in set A, let

[0087] (d) Output Where α∈A.

[0088] f(c1, c2, ..., c) β )←wEval(wdevk,f,c1,c2,…,c β Input operation key wdevk, function f, ciphertext c1, c2, ..., c β Run the ciphertext operation algorithm of the modified BGV and output the ciphertext f(c1, c2, ..., c) after the operation. β ).

[0089] m←wDec(wdsk, c): Runs the decryption algorithm of the modified BGV and outputs the plaintext m corresponding to the ciphertext c.

[0090] The DFHE algorithm is described as follows:

[0091] (dpk, dsk, devk)←KeyGen(κ): Takes the security parameter κ as input and performs the following operation:

[0092] (1) Run the modified BGV key generation algorithm to generate public key pk, private key sk and operation key evk;

[0093] (2) Run a modified BGV encryption algorithm on the private key sk to generate the ciphertext c of the private key.sk ;

[0094] (3) Output public key dpk = (pk, c sk ), private key dsk=sk, operation key devk=evk.

[0095] C←Enc(dpk,m) i Rand α ): plaintext m i The encryption process (i∈[u]) under the public key dpk is described as follows:

[0096] (1) Plaintext m f Replace the subscript:

[0097] (a) A bijective τ(i) = j, where j ∈ [u];

[0098] (b) Perform bit decomposition on j, denoted as σ(j) = (j1, j2, ..., jj) v )∈{0,1} v ,in,

[0099] (c) Output (j1, j2, ..., j) v ).

[0100] (2) For all j α (α∈[v]) and plaintext m i Encrypt:

[0101] (a) Uniformly random selection of x α,1 x α,2 , ..., x α,η ∈{0,1}, such that

[0102] (b) For any l∈[η], if x α,l =1, uniformly randomized selection of random number r a,l , where r a,l The random number space of the encryption algorithm derived from the modified BGV; if x α,l =0, uniformly and randomly select ciphertext R α,l , where R α,l Ciphertext space from a modified BGV; uniformly randomized selection of random number r i For plaintext m i and random number r i Run the BGV encryption algorithm and calculate m. i ciphertext c i =Enc(m i r i ).

[0103] (c) Record Rand α =(Rand α [1], Rand α [2], ..., Rand α [η], r i ), where Rand α [l] indicates Rand α The l-th component, and l∈[η];

[0104] (d) When x α,l When = 1, for plaintext 1 and random number r α,l Run the modified BGV encryption algorithm separately to calculate the ciphertext R of 1. α,l =Enc(1, r α,l );

[0105] (e) Run the bootstrap algorithm of the deformed BGV to calculate j α ciphertext here This is an XOR operation on the modified BGV ciphertext. Run the extraction algorithm in Definition 5, based on all j... α The ciphertext, calculate m i ciphertext c i =Enc(m i r i );

[0106] (f) Output ciphertext C = (C[1], C[2], ..., C[v], c i ), where C[α] represents the α-th component of C, and C[α] = c α , α∈[v], i∈[u].

[0107] The input is m i m k ∈M, where m k If you want to falsify plaintext, do the following:

[0108] (1) Represent the plaintext m i m k Subscript permutations στ(i) and στ(k) represent each distinct component.

[0109] (a)στ(i)=(j1,j2,…,j v )∈{0,1} v ,στ(k)=(y1,y2,…,y v )∈{0,1} v ,in j, y∈[u];

[0110] (b) For any α∈[v], if Output set

[0111] (2) Implement all j α to y α The denial, where α∈A:

[0112] (a) Uniformly random selection of Rand α =(Rand α [1], Rand α [2], ..., Rand α [η], r i ),in, r α,l The random number space R comes from a modified BGV encryption algorithm. α,l Cipherspace from the modified BGV. When x α,l When = 1, for plaintext 1 and random number r α,l Run the modified BGV encryption algorithm separately to calculate the ciphertext R of 1. α,l =Enc(1, r α,1 );

[0113] (b) If i = k, there is a set Output

[0114] (c) If i ≠ k, for all α in set A, select x that equals 1. α,l , recorded as

[0115] If x does not exist α,l =1, output ⊥;

[0116] If x exists α,l =1, choose one of the α, denoted as make For plaintext 1 and random number r α,l Run the modified BGV encryption algorithm to calculate the ciphertext of 1. For any make

[0117] (d) Output Where α∈A.

[0118] f(c1, c2, ..., c) β )←Eval(devk,f,c1,c2,…,c β Input operation key devk, function f, ciphertext c1, c2, ..., c βRun the ciphertext operation algorithm of the modified BGV and output the ciphertext f(c1, c2, ..., c) after the operation. β );

[0119] m←Dec(dsk, c): Runs the decryption algorithm of the modified BGV and outputs the plaintext m corresponding to the ciphertext c.

[0120] As can be seen from the above, compared with the existing fully homomorphic encryption methods, in the process of calculating ciphertext using the fully homomorphic encryption algorithm, if a powerful adversary coerces the data owner to open the plaintext and random numbers used to generate the ciphertext, the fully homomorphic encryption algorithm can deny that it can provide "fake" plaintext and random numbers, and make the powerful adversary believe that they are real plaintext and random numbers, thus effectively protecting the privacy information of the data owner. Therefore: (1) In this invention, facing a large plaintext space of polynomial level, the defect that all plaintext must participate in the calculation of the deniable fully homomorphic encryption algorithm is solved. The amount of computation and communication depends on logu, not u, where u is the size of the plaintext space; (2) In this invention, facing a large plaintext space of exponential level, any plaintext can be used as a deniable object, avoiding the limitation of specifying the set of deniable plaintexts in the encryption stage in the plan-ahead stage. This invention can be used in practical application scenarios such as electronic voting where there is malicious candidate vote-buying and selling, and counter-espionage where there is foreign intelligence personnel stealing intelligence, and has high theoretical value and application prospects.

[0121] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A non-interactive homomorphic encryption method for large plaintext space, characterized by, include: (1) Arrange the plaintext in the polynomial or exponential plaintext space according to its subscript, and after the permutation function, represent it as a polynomial-level 0-1 vector; (2) Implement bidirectional denial of ciphertexts of 0 and ciphertexts of 1 in a weak denial-prohibit fully homomorphic encryption wDFHE; the weak denial-prohibit fully homomorphic encryption wDFHE includes a key generation algorithm wKeyGen, an encryption algorithm wEnc, a fake encryption algorithm wDEnc, a fake algorithm wFake, a ciphertext operation algorithm wEval, and a decryption algorithm wDec. (3) Implement bidirectional denial of ciphertexts of 0 and ciphertexts of 1 in the repudiable fully homomorphic encryption DFHE; the repudiable fully homomorphic encryption DFHE includes a key generation algorithm KeyGen, an encryption algorithm Enc, a fake algorithm Fake, a ciphertext operation algorithm Eval, and a decryption algorithm Dec; The weakly deniable fully homomorphic encryption wDFHE is represented as wdpk , wdsk , wdevk ) wKeyGen(κ), which takes a security parameter κ as input and performs the following operations: (1) Run the modified BGV key generation algorithm to generate a public key. pk private key sk Sum operation key evk ; (2) Regarding the private key sk Run the modified BGV encryption algorithm to generate the ciphertext of the private key. ; (3) Output the public key wdpk =( pk , ), private key wdsk = sk Operation key wdevk=evk ; Let plain text space ,and u is a polynomial or exponential integer; the fully homomorphic encryption FHE uses a modified BGV, and 1 is one of the plaintexts of the modified BGV; the encryption algorithm wEnc in the weakly repudiable fully homomorphic encryption wDFHE is represented as... wEnc( wdpk , ), that is, plaintext In public key wdpk The encryption process is described below: (1) Plaintext Replace the subscript: (a) Double shot ,in, , u It is a polynomial or an exponential integer; (b) Perform bit decomposition, denoted as ,in, , ; (c) Output ; (2) For all He Mingwen Encrypt: (a) Uniform random selection ,in, The ciphertext is randomly selected from the ciphertext space of the modified BGV. Random number space from a modified BGV encryption algorithm; for plaintext 1 and random number Run the modified BGV encryption algorithm to calculate the ciphertext of 1. ; for plaintext and random numbers Run the BGV encryption algorithm and calculate ciphertext ; (b) Run the bootstrap algorithm of the modified BGV to calculate , ,here It is the XOR operation of the ciphertext in the modified BGV; (c) Output ciphertext ,in, express The Each component, and , .

2. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 1, characterized in that, The false encryption algorithm wDEnc in the weak, repudiable, fully homomorphic encryption wDFHE is represented as follows: wDEnc( wdpk , ), that is, plaintext In public key wdpk The encryption process for the fake code is described as follows: (1) Plaintext Replace the subscript: (a) Double shot ,in ; (b) Perform bit decomposition, denoted as ,in, , ; (c) Output ; (2) For all He Mingwen Encrypt: (a) Uniform random selection ,in, The random number space of the encryption algorithm derived from the modified BGV. The ciphertext is randomly selected from the ciphertext space of the modified BGV; for plaintext 1 and the random number Run the BGV encryption algorithm separately to calculate the ciphertext of 1. ; for plaintext and random numbers Run the BGV encryption algorithm and calculate ciphertext ; (b) Run the bootstrap algorithm of the modified BGV to calculate , ,here It is the XOR operation of the ciphertext in the modified BGV; (c) Output ciphertext ,in, express The Each component, and , .

3. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 2, characterized in that, The falsification algorithm wFake in the weak, repudiable, fully homomorphic encryption wDFHE is represented as follows: wFake( ), that is, the input is ,in, If you want to falsify plaintext, do the following: (1) Express the plaintext Subscript substitution Each different component: (a) ,in, , , ; (b) For any ,like Output set ; (2) Achieve all arrive The denial, among which, : (a) Uniform random selection ,in, This represents the random number space derived from the encryption algorithm of the modified BGV. For the ciphertext randomly selected from the ciphertext space of the modified BGV, the plaintext 1 and the random number are... Run the BGV encryption algorithm separately to calculate the ciphertext of 1. ; (b) If For any ,make ; (c) If For sets All ,make ; (d) Output ,in, .

4. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 3, characterized in that, The ciphertext operation algorithm wEval in the weak, repudiable, fully homomorphic encryption wDFHE is represented as follows: f ( ) wEval( wdevk , f , ), that is, input the operation key wdevk ,function f ciphertext Run the ciphertext processing algorithm of the modified BGV and output the processed ciphertext. f ( ).

5. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 4, characterized in that, The decryption algorithm wDec in the weak, repudiable, fully homomorphic encryption wDFHE is represented as follows: m wDec( wdsk , c This means running the decryption algorithm of the modified BGV and outputting the ciphertext. c Corresponding plaintext m .

6. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 1, characterized in that, The key generation algorithm KeyGen in the repudiable fully homomorphic encryption DFHE is represented as ( dpk , dsk , devk ) KeyGen(κ): Takes the security parameter κ as input and performs the following operations: (1) Run the modified BGV key generation algorithm to generate a public key. pk private key sk Sum operation key evk ; (2) Regarding the private key sk Run the modified BGV encryption algorithm to generate the ciphertext of the private key. ; (3) Output the public key dpk =( pk , ), private key dsk = sk Operation key devk=evk .

7. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 6, characterized in that, Let plain text space ,and u It is a polynomial or exponential integer. The fully homomorphic encryption FHE uses a modified BGV, and 1 is one of the plaintexts of the modified BGV; the encryption algorithm Enc in the repudiable fully homomorphic encryption DFHE is represented as... Enc( dpk , ): Plain text In public key dpk The encryption process is described below: (1) Plaintext Replace the subscript: (a) Double shot ,in ; (b) Perform bit decomposition, denoted as ,in, , ; (c) Output ; (2) For all He Mingwen Encrypt: (a) Uniform random selection , making ; (b) For any ,like Uniformly and randomly select random numbers ,in, The random number space of the encryption algorithm derived from the modified BGV; if Uniformly and randomly select ciphertext ,in, Ciphertext space from modified BGV; uniformly randomized selection of random numbers For plaintext and random numbers Run the BGV encryption algorithm and calculate ciphertext ; (c) Record ,in, express The Each component, and , ; (d) when At that time, for plaintext 1 and random number Run the BGV encryption algorithm separately to calculate the ciphertext of 1. ; (e) Run the bootstrap algorithm of the deformed BGV to calculate ciphertext ,here It is an XOR operation on the modified BGV ciphertext; run the extraction algorithm, based on all The ciphertext, calculation ciphertext ; (f) Output ciphertext ,in, express The Each component, and .

8. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 7, characterized in that, The fake algorithm in the repudiable fully homomorphic encryption DFHE is represented as follows: Fake ): Input is ,in, If you want to falsify plaintext, do the following: (1) Express the plaintext Subscript substitution Each different component; (a) ,in , , ; (b) For any ,like Output set ; (2) Achieve all arrive denial, among which : (a) Uniform random selection ,in, , The random number space derived from the modified BGV encryption algorithm, Cipherspace from the modified BGV; when At that time, for plaintext 1 and random number Run the BGV encryption algorithm separately to calculate the ciphertext of 1. ; (b) If There is a set Output ; (c) If For sets All Select the ones that equal 1 , recorded as : If it does not exist Output ⊥; If it exists Choose one , recorded as ,make For plaintext 1 and random number Run the modified BGV encryption algorithm to calculate the ciphertext of 1. For any ,make ; (d) Output ,in, .

9. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 8, characterized in that, The ciphertext operation algorithm Eval in the repudiable fully homomorphic encryption DFHE is expressed as: f ( ) Eval( devk , f , ): Input operation key devk ,function f ciphertext Run the ciphertext processing algorithm of the modified BGV and output the processed ciphertext. f ( ).

10. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 9, characterized in that, The decryption algorithm Dec in the repudiable fully homomorphic encryption DFHE is represented as follows: m Dec dsk , c This means running the decryption algorithm of the modified BGV and outputting the ciphertext. c Corresponding plaintext m .

11. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 10, characterized in that, The key generation algorithm, ciphertext encryption algorithm, and ciphertext operation algorithm in the modified BGV are the same as those in the original BGV algorithm; the decryption algorithm of the modified BGV is: calculate Determine whether its infinity norm is less than 2. B If yes, output 0; otherwise, output 1. It's an inner product operation. It is ciphertext. It's the private key. B This is the upper bound of the infinite norm of the noise.

12. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 11, characterized in that, The bootstrap algorithm is represented as Boot( c =Eval( evk Dec, c Here, Dec represents the decryption circuit; if the ciphertext c If the ciphertext is randomly selected from the ciphertext space, then there is a ciphertext whose result after bootstrapping is 0, i.e., Boot( c =Enc(0).

13. The repudiable fully homomorphic encryption method for large plaintext spaces according to claim 12, characterized in that, Extraction algorithms refer to algorithms that extract any index. The extraction algorithm outputs the plaintext corresponding to the index. ,Right now .

Citation Information

Patent Citations

  • BGV type multi-key fully homomorphic encryption method with directional decryption function

    CN111342950A

  • Fully homomorphic encryption method and device and computer readable storage medium

    US20210243005A1