Encryption calculation method, method for representing a calculated ciphertext, device, and storage medium
By representing the mask polynomial in the Fourier domain of the number theory transform and operating the ciphertext directly in the Fourier domain, the problems of increasing multiplication noise and low key storage efficiency in homomorphic encryption are solved, and efficient homomorphic encryption calculation and key management are realized.
Patent Information
- Application Number
- CN202280082207.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-12-13
- Filing Date
- 2022-11-07
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2042-11-07
AI Technical Summary
In the polynomial multiplication operation, the noise increase leads to difficulty in decryption and low efficiency in bootstrap key storage and transmission.
By representing the mask polynomial in the Fourier domain of the number theory transform, the ciphertext is generated and operated directly in the Fourier domain, avoiding the conversion of the ciphertext to the Fourier domain, reducing the problem of noise increase, and storing the ciphertext through the seed of the pseudo-random number generator to reduce the storage size of the key.
It realizes efficient polynomial multiplication operation in homomorphic encryption, reduces noise levels, improves key storage and transmission efficiency, and supports programmable bootstrap operations.
Smart Images

Figure CN118402204B_ABST
Abstract
Description
Technical Field
[0001] The presently disclosed subject matter relates to a computer-implemented cryptographic computing method, a computer-implemented method for computing a representation of a ciphertext, a corresponding device, and a computer-readable medium. Background Art
[0002] Homomorphic cryptography allows one to perform cryptographic computations: the computation (e.g., circuit evaluation) is performed on encrypted data by a party that cannot decrypt it. For example, input data and computation results can be received and returned in encrypted form. Intermediate data (e.g., the internal state of the computation) can also be in encrypted form.
[0003] Even if the result of the computation is returned in encrypted form, at decryption, the output is expected to be the same or very close to that of performing the operation on unencrypted data. Homomorphic encryption can be used for privacy-preserving outsourced storage and computation. This allows data to be encrypted and outsourced to a cloud environment for processing and / or storage while encrypted.
[0004] For example, homomorphic cryptography can be applied in fields such as healthcare where privacy regulations may make it difficult to share plaintext data, but computation on encrypted medical data may be allowed. For example, a medical model developed for classifying medical data can be configured to receive medical data in encrypted form from a third party (e.g., a hospital). The medical model can, for example, classify the medical data as, for example, normal or abnormal, or as having a certain specific medical syndrome, disease, or other condition. Using homomorphic encryption, the medical model can be applied to receive medical data in encrypted form. This means that the party providing the medical model cannot access the plaintext medical data corresponding to the encrypted medical data. The user of the service can decrypt the result of the application of the medical model.
[0005] In particular, there are homomorphic cryptographic techniques that can be used, at least in principle, for any function that computes on encrypted data. Such techniques are referred to as “fully homomorphic encryption” (FHE) techniques.
[0006] For security reasons, known implementations of FHE use noisy ciphertexts. For example, the encryption of a data item can include mapping the data item to a point in a key-related lattice and adding noise to that point. In particular, many known implementations of FHE use ciphertexts based on generalized learning with errors (GLWE), such as ring learning with errors (RLWE) ciphertexts, whose security depends on the cryptographic hardness of the generalized learning with errors problem, in particular the ring learning with errors (RLWE) problem for RLWE-based ciphertexts. Such “GLWE-based” or “GLWE-type” ciphertexts can include one or more masked polynomials plus a body polynomial derived from the masked polynomials and the plaintext and containing noise.
[0007] When a data item is freshly encrypted, the noise is low - the encryption is recent. For example, the amount of noise is low such that if the data item were to be decrypted, the noise could be removed at some point during the decryption process, e.g., by rounding. On the other hand, the noise should be high enough to make attacks on the system sufficiently difficult. For example, in the absence of noise, many homomorphic encryption schemes may be vulnerable to attacks by linear algebra or other efficient algorithms (e.g., lattice reduction algorithms). When a data item is encrypted, selected noise is added such that attacks are difficult while still allowing homomorphic operations to be performed.
[0008] Most homomorphic operations increase the noise inherent in homomorphically encrypted data items. When many such operations are performed, the noise may reach a level where unique decryption is no longer possible. In general, techniques known as bootstrapping are used to reduce the noise of homomorphically encrypted values. Bootstrapping can use a public key called a bootstrapping key. By using bootstrapping to reduce noise when needed, any desired number of homomorphic operations can, in principle, be computed.
[0009] A special class of fully homomorphic encryption schemes is the TFHE class of homomorphic encryption schemes. Such schemes are described in "TFHE: Fast fully homomorphic encryption over the torus" by I. Chillotti et al., J. Cryptol., 33(1):34 - 91, 2020 (incorporated herein by reference). TFHE - class schemes differ from other FHE schemes in that they support a relatively very efficient technique for bootstrapping. This bootstrapping technique can reduce the noise in an LWE - encrypted input value by homomorphically evaluating the LWE decryption in the exponent of a GLWE - encrypted monomial, resulting in an LWE - encrypted output value with a noise amount independent of the noise in the LWE - encrypted input value. TFHE bootstrapping is also programmable because the output value can be the result of applying a function to the input value. An example of such programmable bootstrapping is described in "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks", Cyber Security Cryptography and Machine Learning (CSCML 2021), volume 12716 of Lecture Notes in Computer Science, pages 1 - 19, Springer, 2021 (incorporated herein by reference).
[0010] TFHE programmable bootstrapping relies on the computation of the so-called outer product of a GGSW-type (Generalized GSW type, e.g., (RGSW type)) ciphertext C and a GLWE-based ciphertext c. Generally, the GGSW-type ciphertext C encrypting the plaintext (e.g., as described in "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks") includes multiple corresponding GLWE-based ciphertexts c i , and the ciphertexts encrypt the corresponding values of the plaintext. The computation of the outer product involves multiplying the corresponding GLWE-based ciphertext c i by the corresponding multiplicand polynomials of the GLWE-based ciphertext c, and computing the GGSW-type ciphertext using the GLWE-based ciphertext c. To perform these polynomial multiplications efficiently, TFHE employs the Fast Fourier Transform (FFT) for complex numbers, using the roots of unity ω j , where and ω M = 1, where 1 ≤ j < M. The outer product yields the encryption of the product of the GGSW-type ciphertext C and the GLWE-based ciphertext c. Programmable bootstrapping is based on a bootstrapping key that includes multiple such GGSW-type encryptions and involves repeatedly computing the outer product using these GGSW-type ciphertexts.
[0011] Since the bootstrapping key for programmable bootstrapping contains a large number of GGSW-type ciphertexts, which in turn contain a large number of GLWE-based ciphertexts, the storage and transmission of the bootstrapping key are relatively large. For example, for typical TFHE parameters, the bootstrapping key size can be approximately 62 MB. However, this size can be reduced by defining the coefficients of the masking polynomial as the output of a pseudorandom function, in which only the seed then needs to be stored. When using the key, the pseudorandom function is then evaluated to obtain the coefficients of the masking polynomial, and this representation is converted to the complex evaluation of the masking polynomial for the roots of unity of the complex numbers for performing the FFT. For example, when using ring LWE, for typical parameters, the size of the bootstrapping key can be reduced by approximately twofold to around 31 MB. Summary of the Invention
[0012] According to one aspect of the present invention, there is provided a computer-implemented encryption computing method as defined in the claims. According to another aspect of the present invention, there is provided a computer-implemented method for computing a representation of a ciphertext as defined in the claims. According to other aspects, there are provided devices for these computer-implemented methods as defined in the claims. According to another aspect, there is provided a computer-readable medium as defined in the claims.
[0013] The computational method may involve polynomial multiplication of GLWE-based ciphertexts, for example, performed as part of the outer product of GGSW-type ciphertexts including the ciphertexts. The ciphertext may include one or more random masked polynomials, and a body polynomial derived from the masked polynomials and the plaintext. The polynomial multiplication may involve multiplying the masked polynomials and the body polynomial of the ciphertext by corresponding multiplicand polynomials, for example, by a common multiplicand polynomial.
[0014] The ciphertext may be stored as data in a memory. For example, the data may be retrieved from a persistent memory (such as a hard disk), or the data may be stored in a volatile memory (e.g., RAM), which has been previously received from another party (e.g., the party that has computed the ciphertext). In any case, it is desirable if the stored data is as small as possible. As discussed above, if the party computing the ciphertext uses a pseudorandom number generator (PRNG; preferably a cryptographic PRNG) to generate the coefficients of the masked polynomials, the ciphertext can be stored relatively efficiently. Then, instead of including the masked polynomials in the stored data, the seed can be stored. However, in order to compute polynomial multiplication efficiently using FFT, it is first necessary to transform the coefficients of the masked polynomials to the Fourier domain, i.e., to the evaluations of these polynomials at the complex roots of unity.
[0015] The inventors have two important insights. First, the stored data of the ciphertext can also be defined such that the PRNG does not generate the masked polynomials in terms of the conventional coefficients of the masked polynomials, but rather generates the representations of the masked polynomials in the Fourier domain, for example, as the evaluations of the polynomials in a set of evaluations. To this end, when encrypting the plaintext, the body polynomial can be computed such that the ciphertext is the correct encryption of the plaintext for the masked polynomials generated in the Fourier domain according to the PRNG, rather than the correct encryption of the plaintext for the masked polynomials obtained from the PRNG for their coefficients.
[0016] Specifically, to perform the encryption, the PRNG can be applied according to the seed to generate the representations of the masked polynomials in the Fourier domain. These representations can be transformed to their conventional coefficient representations. The coefficient representations can be used to encrypt the plaintext based on the random masked polynomials that are themselves known, thereby producing the body polynomial in coefficient representation. Then the body polynomial can be transformed back to the Fourier domain and output together with the seed as the representation of the ciphertext.
[0017] To perform polynomial multiplication on ciphertext represented in this way, it suffices to extend the representation by directly generating a representation of the masked polynomial in the Fourier domain using a pseudorandom number generator according to a seed. The polynomial product of the masked polynomial and the body polynomial with the corresponding multiplicand polynomials can then be efficiently computed in the Fourier domain. The polynomial product may yield a representation of the computed polynomial product in the Fourier domain. These representations can then be output, for example, in their Fourier domain representation, or converted back to the coefficient representation as needed. Interestingly, there is no longer a need to transform the ciphertext to the Fourier domain during use, enabling more efficient use of the ciphertext. This transformation is now effectively done during the ciphertext encryption process. However, by storing the seed, the ciphertext can be stored efficiently. Since once encrypted, such ciphertext can be reused multiple times and / or by many different parties, for example, when used for bootstrapping keys or the like, this is a worthwhile tradeoff.
[0018] A second important insight of the inventors is that, for security reasons, it is beneficial to use the Fourier domain of a number-theoretic transform rather than the Fourier domain of a complex FFT as in current TFHE-like schemes. A number-theoretic transform is a technique known per se for performing efficient multiplication in a polynomial ring. To perform polynomial multiplication using the NTT, the polynomial can be represented in the Fourier domain representation of the NTT. Generally, the Fourier domain representation of a polynomial includes multiple corresponding evaluations of the polynomial at multiple corresponding evaluation points. When the Fourier domain representation is adopted, polynomials can be multiplied efficiently, for example, by pointwise multiplication of the evaluations. Additionally, using the NTT, the Fourier domain representation of a polynomial can be efficiently computed from its coefficient representation (by applying the number-theoretic transform itself), and the coefficient representation can be efficiently computed from the Fourier domain representation (using the inverse number-theoretic transform).
[0019] Multiple number-theoretic transforms are known per se, including the discrete Fourier transform (defined in its standard form as the quotient polynomial X n -1 and prime power modulus q, where n|q - 1), see, for example, in J. von zur Gathen and J. Gerhard's "Modern Computer Algebra", Cambridge University Press, 3rd edition, 2013, Chapter 8 (as far as the description of the discrete Fourier transform is concerned, incorporated herein by reference), For the algorithms and the Nussbaumer algorithm, see “Multidigit multiplication for mathematicians” by D.J. Bernstein, unpublished manuscript (available at https: / / cr.yp.to / papers.html#m3) (incorporated herein by reference for the description of these two algorithms). Thus, performing polynomial multiplication “using number-theoretic transforms” can generally refer to performing polynomial multiplication in the Fourier domain of a number-theoretic transform, optionally in combination with using the NTT and / or its inverse to transform a polynomial from or into such Fourier domain representation.
[0020] An advantage of using number-theoretic transforms is that randomly generating a Fourier domain representation of a number-theoretic transform and converting it to a polynomial may result in a random polynomial, in other words, a polynomial that is as random as when the coefficients are generated randomly individually. This is not the case for the complex FFT, where the Fourier representation of a uniformly random polynomial is not uniformly distributed.
[0021] Thus, using a PRNG to generate a representation of a masked polynomial in the Fourier domain of a number-theoretic transform may result in a ciphertext having the same probability distribution as a ciphertext constructed in the conventional way with randomly generated coefficients, while this is not the case for the complex FFT. Thus, the problem that the distribution of the ciphertext may leak information about the underlying plaintext can be avoided. In this way, a securely and compactly represented ciphertext can be obtained while allowing efficient polynomial multiplication.
[0022] Generalizing from GLWE, the techniques provided apply to “GLWE-class” ciphertexts, meaning ciphertexts that include a randomly masked polynomial and a body polynomial. The techniques can apply to cases where the masked polynomial and the body polynomial of such GLWE-class ciphertexts are to be multiplied by corresponding multiplicand polynomials. Specifically, the techniques provided apply to cryptographic computing techniques that use a stored key material that includes such ciphertexts, where the key material is used by multiplying it by a corresponding polynomial.
[0023] In one embodiment, the technique is applied to "TFHE-like" encrypted computations. Such TFHE-like encrypted computations are characterized by the use of programmable bootstrapping operations, which are evaluated based on the decryption of the exponents of encrypted monomials. Specifically, programmable bootstrapping may include blind rotation, which produces an encrypted polynomial product of a test polynomial and a bootstrapping monomial, where the bootstrapping monomial represents a plaintext value as an exponent. This evaluation is computed using the outer product of GGSW-type ciphertexts of the bootstrapping key. Such GGSW-type ciphertexts may include multiple GLWE-type ciphertexts, and the computation of the outer product may involve multiplying the corresponding ciphertexts of the GGSW-type ciphertexts by corresponding polynomials. In such a TFHE-like setting, the bootstrapping keys are relatively large, so it is very important to be able to store and transmit them more efficiently. At the same time, programmable bootstrapping is an important and relatively computationally intensive operation, so it is also very important to be able to execute it efficiently. Using the provided technique, the bootstrapping keys can be stored more efficiently while still allowing the efficient application of programmable bootstrapping.
[0024] In one embodiment, the technique is used to obliviously select a first GLWE ciphertext or a second GLWE ciphertext based on GGSW ciphertexts. Such oblivious selection can be performed by computing the outer product of the GGSW ciphertext and the difference between the first GLWE ciphertext and the second GLWE ciphertext. Then the first GLWE ciphertext can be added to the computed product. This operation is also known as a controlled selector gate or a controlled multiplexer, CMux. The CMux operation can be part of programmable bootstrapping, but can also be used directly as a gate in, for example, homomorphic circuit evaluation.
[0025] In one embodiment, the coefficients of the corresponding multiplicand polynomial can be obtained, and a number-theoretic transform can be applied to transform the coefficients of the corresponding multiplicand polynomial into the Fourier domain. In this way, a GLWE-based ciphertext can be multiplied by the multiplicand polynomial available in coefficient form. Generally, multiplication in the Fourier domain is implemented more efficiently than multiplication in the coefficient domain, even when such a transformation is included. There can be additional operations between the transformation to the Fourier domain and the polynomial multiplication. For example, addition or multiplication (by a constant or a polynomial represented in another Fourier domain) can be applied to the multiplicand polynomial in the Fourier domain before the multiplication.
[0026] In one embodiment, an inverse number-theoretic transform can be applied to transform the representation of the computed polynomial product in the Fourier domain into the coefficients of the computed polynomial product. In this way, a coefficient representation can be obtained, which can be used for subsequent computations, such as sample extraction, key switching, etc. Additionally, here, additional operations such as addition or multiplication can be performed in the Fourier domain between the computation of the product and the application of the inverse number-theoretic transform.
[0027] In one embodiment, the extended stored data representing the GLWE-based ciphertext can be kept in memory. The extended stored data can be used to compute additional polynomial products of the masked polynomial and the body polynomial with another multiplicand polynomial. Thus, for these additional polynomial products, there is no need to re-extend the stored data, resulting in increased efficiency. Nevertheless, when it is desired to store the GLWE-based ciphertext again, or when it is desired to reduce its memory footprint, this can be achieved by discarding the masked polynomials and storing only the seeds used to generate them.
[0028] In general, the polynomials described herein (such as the body polynomial and the masked polynomial) can be defined as polynomials modulo a quotient polynomial p(X). For example, the polynomials can be defined over a ring by defining them as elements of the polynomial quotient ring R[X] / (p(X)). Alternatively, the polynomials can be defined over a (discrete) torus (note ) over by defining them as polynomials in . Specifically, any polynomial (where ) can be associated with a polynomial (where ) where Generally, it is desirable for the quotient polynomial p(X) to be an irreducible polynomial, as this is typically beneficial for cryptographic security.
[0029] In one embodiment, the quotient polynomial p(X) divided by the polynomial X M -1 of a positive integer M, for example, is equal to X M -1, or is a lower-degree polynomial that divides it strictly. The number of elements q of the set over which the polynomials are defined (such as or ) can be chosen such that includes the M-th roots of unity. In this case, polynomial multiplication in the Fourier domain can be implemented particularly efficiently because polynomial multiplication modulo X n -1 can be implemented as a pointwise multiplication of the evaluations of the multiplicand polynomials in the set of powers of the roots of unity. Throughout this specification, the term "roots of unity" is defined as in J. von zur Gathen and J. Gerhard's "Modern Computer Algebra" (Cambridge University Press, 3rd edition, 2013) (for which purpose it is incorporated herein by reference). Other efficient polynomial multiplication implementations in the Fourier domain include the Nussbaumer method or Method; interestingly, for these variants, the conditions on the parameters M and q translate to being invertible modulo q.
[0030] For example, the quotient polynomial can be any polynomial p(X) that divides X M - 1, and the Fourier representation of the polynomial can be defined as the set of evaluations of the polynomial in the set of powers of the Mth primitive root of unity. The Fourier representation can be multiplied by the pointwise multiplication of the evaluations of the corresponding powers of the Mth primitive root of unity. For efficient conversion between the coefficient representation and the Fourier domain representation, it is advantageous if M contains one or more powers of 2 and / or one or more powers of 3. For example, M is a power of 2 or M is a power of 3.
[0031] In some cases, the Fourier representation of a polynomial can include the evaluations of each power of the root of unity. However, this is not necessary. In many cases, using a subset of the powers is sufficient, resulting in a more efficient Fourier domain representation. If the quotient polynomial is equal to (X M - 1) / (X d - 1), this is especially true, where M = hd and d = M - N (so N = M - d = (h - 1)d). For example, for the case of H = 2, the quotient polynomial can be (X 2d - 1) / (X d - 1) = (X d + 1) = (X N + 1), or for the case of h = 3, the quotient polynomial can be (X 3d - 1) / (X d - 1) = (X 2d + X d + 1) = (X N + X N / 2 + 1). In this case, the Fourier domain representation of the polynomial can be defined as the evaluations of the polynomial only in a subset of the powers of the Mth primitive root of unity ω. For example, for the case of h = 2, the powers ω, ω 3 , …, ω 2d-1 , and for the case of h = 3, the powers (ω, ω 2 ), (ω 4 , ω 5 ), …, (ω 3d-2 , ω 3d-1 ). To multiply polynomials, it is sufficient to evaluate only this subset of the powers of the root of unity, resulting in more efficient polynomial multiplication. Nevertheless, efficient number theoretic transforms and inverses are possible.
[0032] For example, the quotient polynomial X N + 1 can be used in conjunction with the 2Nth primitive root of unity. For example, the number of elements q can be chosen such that the ring is a prime field with the number of elements q ≡ 1 mod 2N The quotient polynomial X N + 1 (especially where N is a power of 2) is beneficial because many known homomorphic encryption schemes (such as the TFHE scheme) are defined according to this quotient polynomial and can thus be easily combined with the proposed technology. Choosing the prime q = 2 64 - 2 32 + 1 is particularly beneficial because the operations in this field can be implemented particularly efficiently on a computer processor using 32 - bit and / or 64 - bit integer arithmetic.
[0033] The quotient polynomial X N + X N / 2 + 1 can be used in combination with an even number of elements q (such as a power of 2). This is beneficial because it allows for efficient arithmetic and because some applications require the use of a power of 2.
[0034] In one embodiment, multiple GLWE - based ciphertexts can be generated to generate GGSW - type ciphertexts. For example, multiple such GGSW - type ciphertexts can be generated to generate a bootstrapping key for TFHE - type programmable bootstrapping, e.g., by generating corresponding GGSW - type ciphertexts that encrypt corresponding parts of the decryption key. Generally, a GGSW - type ciphertext can be defined as a ciphertext that includes multiple GLWE - based ciphertexts, where the GLWE - based ciphertexts encrypt corresponding values based on a plaintext. In this case, the multiple GLWE - based ciphertexts can be based on the same seed, e.g., the same seed can be used to generate corresponding different random mask polynomials for the corresponding ciphertexts. Thus, for example, it is sufficient to store only one seed for each GGSW - type ciphertext or even for each bootstrapping key, thereby further reducing storage requirements.
[0035] The techniques provided for improving the computation on encrypted data can be applied to a wide range of practical applications. Such practical applications include the encrypted evaluation of software programs without access to the plaintext data. For example, one can evaluate medical diagnostic software regarding medical data without actually accessing the medical data. The medical data can include medical images. The medical images can include, for example, multi - dimensional image data acquired by a variety of acquisition methods, such as two - dimensional (2D), three - dimensional (3D), or four - dimensional (4D) images, where the variety of acquisition methods include but are not limited to standard X - ray imaging, computed tomography (CT), magnetic resonance imaging (MRI), ultrasound (US), positron emission tomography (PET), single - photon emission computed tomography (SPECT), and nuclear medicine (NM).
[0036] In one embodiment, the techniques provided can be used to evaluate a neural network with respect to encrypted inputs. The party evaluating the neural network may or may not have access to the training parameters of the neural network, such as weights and biases, in plaintext. Generally, the techniques provided herein (e.g., improved polynomial multiplication, programmable bootstrapping, and outer products) improve the efficiency of evaluating a neural network and / or reduce the storage and transmission requirements for the ciphertext or key material used.
[0037] One embodiment of the method can be implemented on a computer as a computer-implemented method, or in dedicated hardware, or in a combination of both. The executable code for one embodiment of the method can be stored on a computer program product. Examples of computer program products include memory devices, optical storage devices, integrated circuits, servers, online software, etc. Preferably, the computer program product includes non-transitory program code stored on a computer-readable medium for performing one embodiment of the method when the program product is executed on a computer. In one embodiment, the computer program includes computer program code that, when the computer program runs on a computer, is adapted to perform all or part of the steps of one embodiment of the method. Preferably, the computer program is implemented on a computer-readable medium. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Further details, aspects, and embodiments will be described with reference to the accompanying drawings and by way of example only. The elements in the figures are illustrated for simplicity and clarity and are not necessarily drawn to scale. In the figures, elements corresponding to those already described may have the same reference numerals. In the accompanying drawings,
[0039] Figure 1a an embodiment of an implementation of a device for performing encrypted computations and / or representations of computations on ciphertext is schematically illustrated;
[0040] Figure 1b an embodiment of an implementation of an encrypted computing system is schematically illustrated;
[0041] Figure 2 an embodiment of an encryption unit is schematically illustrated;
[0042] Figure 3a an embodiment of an encrypted multiplication unit is schematically illustrated;
[0043] Figure 3b an embodiment of an encrypted multiplication unit is schematically illustrated;
[0044] Figure 4a an embodiment of an outer product calculation unit is schematically illustrated;
[0045] Figure 4bAn embodiment of a bootstrap unit is schematically shown;
[0046] Figure 5a An embodiment of an implementation of a computer-implemented encryption calculation method is schematically shown;
[0047] Figure 5b An embodiment of an implementation of a computer-implemented method for calculating a representation of a ciphertext is schematically shown;
[0048] Figure 5c A computer-readable medium having a writable portion is schematically shown, the writable portion including a computer program according to an implementation;
[0049] Figure 5d A representation of a processor system according to an implementation is schematically shown. Detailed Description
[0050] Although the presently disclosed subject matter may be implemented in many different forms, one or more specific implementations are shown in the drawings and will be described in detail herein. It is to be understood that the present disclosure is to be considered an exemplification of the principles of the presently disclosed subject matter and is not intended to limit it to the specific implementations shown and described.
[0051] In the following, for ease of understanding, several elements of the implementation are described in the context of an operation. However, it is obvious that the corresponding elements are arranged to perform the functions described for them to perform.
[0052] Furthermore, the presently disclosed subject matter is not limited to the implementations, but also includes combinations of each other feature described herein or recited in mutually different dependent claims.
[0053] The techniques provided use ciphertexts that include one or more masking polynomials and a body polynomial. The masking polynomial and the body polynomial can be defined as polynomials modulo a quotient polynomial p(X), e.g., R[X] / (p(X)), where R is a ring or can be associated with a ring, e.g., or A typical choice for the quotient polynomial is p(X) = X N + 1, where N is a power of 2, or another irreducible polynomial p(X). The masking polynomial can be chosen uniformly at random, e.g., can have coefficients uniformly randomly chosen from R. The body polynomial can be a function of the masking polynomial, the plaintext polynomial to be encrypted, and an error polynomial. For example, the function can be an inner product of the masking polynomial with a key element and add the plaintext and error polynomials to this inner product, although the techniques provided are also applicable to other functions.
[0054] As a specific example, the ciphertext can be calculated as where a i is a masking polynomial, b is the body polynomial, μ is the plaintext, and e is the error polynomial. The error can be sampled from a noise distribution associated with a potential cryptographic problem. The key s′ can be sampled according to a key distribution associated with a potential cryptographic problem, for example as a polynomial with binary coefficients, such as where and In a more general case, the key s′ can be sampled over R[X] / (p(X)) for a ring R, see for example European patent application EP21290025 (incorporated herein by reference).
[0055] In the above embodiment, s′ is a symmetric key, for example, a key that can be used for both encryption and decryption. Throughout this specification, symmetric keys are used as examples, in which case the key is used as both an encryption key and a decryption key. The ciphertext can also be used in an asymmetric setting, for example, by using s′ as the private key (e.g., the decryption key) and providing zero encryption as the public key (e.g., the encryption key), for example using the technique of R. Rothblum, "Homomorphic encryption: From private-key to public-key", Theory of Cryptography (TCC 2011), Lecture Notes in Computer Science Volume 6597, pages 219 - 234, Springer, 2011 (incorporated herein by reference). However, in this case, in order to compute the compressed representation of the ciphertext from the plaintext according to the provided technique, the private decryption key s′ is typically used.
[0056] For example, the ciphertext can be a GLWE - based ciphertext in the sense that their security is based on the hardness of the generalized learning with errors (GLWE) problem. The special case k = 1 (e.g., using one masking polynomial) is also called the ring learning with errors (RLWE) problem. The dimension of the polynomial ring used is greater than one, e.g., the GLWE - based ciphertexts used herein are not learning with errors (LWE) ciphertexts.
[0057] Specifically, the polynomial can be defined over a discrete torus, e.g., for a positive integer q, For example, the polynomial can be an element of, e.g., where N > 1, e.g., a power of 2. Encrypting the plaintext The ciphertext can include k + 1 elements from the polynomial ring (e.g., k masking polynomials and one body polynomial), and thus can be an element of. The masking polynomial can be from chosen uniformly at random. The error polynomial can be a random Gaussian error defined over .
[0058] Such polynomials on the discrete torus can be multiplied by multiplicand polynomials from the corresponding polynomial quotient ring. More precisely, the masked and body elements of and can be multiplied by multiplicand polynomials from R[X] / (p(X)), where and For example, such multiplications can be performed on TFHE bootstrapping keys. By identifying the elements of the torus and For If and (outer) product can be defined by letting where where and letting Thus, the multiplication corresponds to the multiplication of two polynomials over the ring , i.e., the calculation of h = fg in
[0059] Discrete tori are often used in so-called TFHE-like schemes, which are meant to support programmable bootstrapping operations. In such a scheme, encryption computations can be performed on LWE-based ciphertexts, e.g., GLWE-based ciphertexts where the masked and body polynomials are scalar values. As part of such computations, programmable bootstrapping can be applied to such LWE-based ciphertexts, as described elsewhere. Such programmable bootstrapping may involve GGSW-type ciphertexts encrypting digital numbers (e.g., bits of an LWE key), which can be defined on a discrete torus, e.g., as described above.
[0060] The programmable bootstrapping operations in TFHE-like schemes make them an attractive choice for a wide range of applications. Since bootstrapping is relatively efficient compared to many other FHE schemes, it is more feasible to perform relatively complex computations (e.g., computations with a multiplication depth of at least 10, at least 50, or at least 100). Specifically, the cryptographic parameters of TFHE-like schemes can be selected based on the required precision and the resulting computational cost and independently of the number of homomorphic operations and their circuit depth. In contrast, in other FHE schemes, the bootstrapping efficiency is very low, such that these schemes are typically applied in a hierarchical manner in practice, which means that their parameters are selected depending on the given computation such that it can be performed without bootstrapping. However, this hierarchical approach is not feasible for more complex computations, and thus TFHE-like schemes are particularly useful in such cases.
[0061] For example, the bootstrapping key of a TFHE-like encryption scheme can include n GGSW-type ciphertexts that encrypt key digits of an LWE key, where n is typically at most 1000 or at most 640, e.g., n = 630. The GGSW-type ciphertexts can include, for example, l = 3 GLWE-based ciphertexts, each including k = 1 masked polynomial (e.g., RLWE can be used) and a body polynomial. The dimension of the polynomial ring can be chosen as N = 1024, and the base q associated with the polynomial can be, for example, q = 2 64 。
[0062] However, other parameters can also be known per se. Generally, the security of GLWE-based ciphertexts is based on the distribution of the key, as well as three main parameters: n = kN, where N is the polynomial ring dimension, k is the number of random elements of the ciphertext, and n is the key length; q, which is the cardinality of the set on which the polynomial is defined; and σ, the statistical parameter of the noise, e.g., its standard deviation. Given these parameters, it is known per se how to evaluate the level of security provided, see, e.g., M. Albrecht et al., “On the concrete hardness of Learning with Errors”, Journal of Mathematical Cryptology, 9(3): 169 - 203, 2015 (incorporated herein by reference).
[0063] In the embodiments of the present document, the parameters of the TFHE-like ciphertexts based on LWE and GLWE used can be selected based on the desired security level and based on the desired arithmetic precision (such as, for example, the linear combination of LWE ciphertexts and / or the application of programmable bootstrapping, in other words, the noise level generated by applying these operations). Interestingly, in the TFHE setting, the security parameter can be selected independently of the computational complexity (e.g., independently of the multiplication depth of the computation). This is different from non-TFHE-like schemes, in which the security parameter is typically selected to limit or eliminate bootstrapping.
[0064] Specifically, the LWE-based ciphertexts and / or GLWE-based ciphertexts used in the TFHE setting in the present document can use relatively small moduli, such as moduli of at most 32 bits, at most 64 bits, or at most 128 bits. This modulus is typically selected independently of the computation to be performed, e.g., it is selected based on the desired precision and / or efficiency. The parameters N, k, and / or σ can be selected to achieve the desired security level, typically also independently of the computation to be performed. For example, N can be set to at least 512 and / or at most 2048 or 4096, e.g., 1024. For example, in one embodiment, RLWE is used, where N is at least 512 and / or at most 2048 or 4096 (e.g., 1024), and k = 1. Such values of N are generally not used in non-TFHE-like encryption schemes, in which such values would severely limit the computations that can be performed; instead, in non-TFHE-like schemes, q and N are typically selected based on the desired security level, and thus q can be much larger.
[0065] Figure 1a An example of an embodiment of a device 110 for performing encrypted computations, such as for computing a representation of a ciphertext, or for performing an encrypted computation using such a ciphertext, is schematically shown.
[0066] The device 110 can include a processor system 130, a memory 140, and a communication interface 150. The memory 140 can include local memory, e.g., a local hard drive or electronic memory. The memory 140 can include non-local memory, e.g., cloud memory. In the latter case, the memory 140 can include a memory interface to the non-local memory. For example, the memory 140 can be used to store the plaintext to be encrypted, and / or data representing the ciphertext encrypting the plaintext. Such a ciphertext can include one or more random masked polynomials, and a body polynomial derived from the masked polynomials and the plaintext. The ciphertext can be stored in the memory 140 in the form of a seed of a pseudo-random number generator and the Fourier domain representation of the body polynomial, as discussed in more detail elsewhere.
[0067] Device 110 can communicate internally and communicate with other devices, external memories, input devices, output devices, and / or one or more sensors via a computer network. The computer network can be the Internet, an intranet, a LAN, a WLAN, etc. The computer network can be the Internet. The device may optionally include a connection interface 150 arranged to communicate with other devices as required. For example, the connection interface may include connectors, such as, for example, a wired connector (e.g., an Ethernet connector, an optical connector, etc.) or a wireless connector (e.g., an antenna, such as, for example, a Wi-Fi, 4G, or 5G antenna). Communication (e.g., internal communication) may use other communication protocols or media, such as an internal data bus.
[0068] In device 110, the communication interface 150 can be used to send or receive digital data. For example, device 110 can be configured to receive or send data representing ciphertext, such as a seed and a body polynomial in the Fourier domain representation. For example, the device can be configured to generate and send data, or receive data and use it for cryptographic computations, such as as part of a bootstrapping key.
[0069] The execution of device 110 can be implemented in a processor system 130 (e.g., one or more processor circuits, such as, for example, a microprocessor), embodiments of which are shown herein. Device 110 may include multiple processors, which may be distributed at different locations. For example, device 110 can use cloud computing.
[0070] Device 110 can be used to compute a representation of ciphertext from stored plaintext. In this case, the processor system 130 can be configured to generate the ciphertext. To this end, the processor system 130 can be configured to obtain a seed of a pseudorandom number generator. The processor system 130 can further be configured to randomly generate a masking polynomial using the pseudorandom number generator based on the seed to generate a representation of the masking polynomial in the Fourier domain of the number-theoretic transform. The processor system 130 can further be configured to apply the inverse of the number-theoretic transform to the evaluation of the masking polynomial to determine the coefficients of the masking polynomial. The processor system 130 can further be configured to use the plaintext to determine the coefficients of the body polynomial such that the ciphertext encrypts the plaintext. The processor subsystem 130 can further be configured to apply the number-theoretic transform to the coefficients of the body polynomial to determine the representation of the body polynomial in the Fourier domain. The processor system 130 can further be configured to output the representation of the ciphertext. The representation can include the seed and the representation of the body polynomial in the Fourier domain. For example, the representation can be output by storing the representation on the memory 130 and / or sending it to another party via the communication interface 150.
[0071] As an alternative to the computational representation, device 110 can be used to perform cryptographic computations using such representation. In this case, the processor system 130 can be configured to obtain the respective multiplicand polynomials for multiplication with the mask polynomial and the body polynomial, e.g., as a result of a previous operation of the cryptographic computation being performed. The processor system 130 can further be configured to expand the stored data representing the ciphertext. The stored data can include the seed of a pseudorandom number generator and the representation of the body polynomial in the Fourier domain of a number theoretic transform. The expansion can include using the pseudorandom number generator according to the seed to generate the representation of the mask polynomial in the Fourier domain. The processor system 130 can further be configured to compute the polynomial products of the mask polynomial and the body polynomial with the respective multiplicand polynomials. The polynomial products can be computed in the Fourier domain, resulting in the computed polynomial products being represented in the Fourier domain. The processor system 130 can further be configured to output the computed polynomial products, e.g., for the remainder of the cryptographic computation.
[0072] The functional units shown in some of the figures can be functional units of the processor system. For example, the figures can be used as a blueprint for a possible functional organization of the processor system. In most of the figures, the processor circuitry is not shown separately from the units. For example, Figure 2 , Figure 3a , Figure 3b , Figure 4a and Figure 4b The functional units shown (see below) in can be implemented, in whole or in part, by computer instructions stored at a device (such as device 110), e.g., stored in the electronic flash memory of device 110 and executable by the microprocessor of device 110. In a hybrid implementation, the functional units are implemented partly in hardware (e.g., as a coprocessor, such as an arithmetic and / or cryptographic coprocessor) and partly in software stored and executed on device 110.
[0073] For example, device 110 can be a device for performing cryptographic computations. The cryptographic computations can employ homomorphic encryption cryptography. For example, device 110 can be used to perform cryptographic computations, e.g., even if the data is received in encrypted form (e.g., from a data provider), and even if device 110 cannot decrypt the data, the device can perform the computations. The computations can involve multiplying ciphertexts with respective polynomials as described herein, e.g., as part of programmable bootstrapping.
[0074] For example, the memory 140 may store encrypted data items, such as data items received from one or more data providers, or data items generated as intermediate or final results (e.g., outputs) of computations. Generally, most or all of the data items on which the device 110 performs computations are encrypted with a key (or keys) unknown to the device 110 - that is, the device 110 may not be configured to obtain the plaintext data items corresponding to the encrypted data items (e.g., stored in the memory 140). The decryption key in plaintext form is secret to the device 110, although the encryption / decryption key may be available in encrypted form. For example, the processor system may be configured to perform a series of homomorphic encryption operations, which may include arithmetic operations on encrypted values, such as addition and multiplication, but may also include arithmetic operations on encrypted polynomials. Homomorphic operations may also include operations such as key switching, bootstrapping, etc.
[0075] Figure 1b An embodiment of an implementation of the encrypted computing system 100 is schematically illustrated. The system 100 is configured to perform encrypted computations using homomorphic encryption (e.g., fully homomorphic encryption).
[0076] The system 100 in this embodiment includes a key generation device 111, a data provider device 160, and an encrypted computing device 112. The key generation device 111 and the data provider device 160 may be combined in a single device. The device 112 may be configured to receive encrypted data items from the data provider 160. At least one or more data items may be received in encrypted form. One or more data items may be received in plaintext format. Computations are run on the received data items, and computations may also be run on the stored data items. Interestingly, computations can be performed on the encrypted data without the need to decrypt the data (e.g., without the need to convert the encrypted data items to data in plaintext format).
[0077] The device 111 and / or 112 in this embodiment may each be based on Figure 1a the device 110, and for example may each include Figure 1a a processor system 130, a memory 140, and / or a communication interface 150.
[0078] In this embodiment, the device 111 includes a key generation unit 131, such as a key generation unit 131 implemented by the processor system of the device 111. The key generation unit 131 is configured to generate a bootstrap key 156 for use by the encryption computing device 112. The bootstrap key 156 may include a plurality of GLWE-type ciphertexts. The key generation unit 131 may be configured to generate these ciphertexts using the techniques provided herein to determine the bootstrap key 156. The device 111 may provide the bootstrap key 156 to the device 112, for example, by sending the bootstrap key 156 via the computer network 150, uploading the bootstrap key 156 to a shared memory, and so on.
[0079] In this embodiment, the device 112 includes an encryption computing unit 132, such as an encryption computing unit 132 implemented by the processor system of the device 112. The encryption computing unit 132 may be configured to perform encryption computations. The encryption computations may involve the bootstrapping of encrypted values, particularly programmable bootstrapping. To perform bootstrapping, the encryption computing unit 132 may use the bootstrap key 156 that it obtains from the device 111 (e.g., received via the network 150 or retrieved from a shared memory). Bootstrapping may involve multiplying the mask and body polynomials of the GLWE-based ciphertexts of the bootstrap key 156 with the corresponding multiplicand polynomials. The encryption computing unit may perform these multiplications as described herein. The encryption computations may include many other operations, as is known per se. For example, the device 112 may be configured to evaluate arithmetic circuits, evaluate neural networks on encrypted data, and so on.
[0080] Although not shown in this figure, the encryption computing system 100 may include a plurality of encryption computing devices, such as two, three, or more than three. The encryption computations may be distributed among the plurality of encryption computing devices. The encryption computing devices may exchange intermediate computation results (usually encrypted) with each other. Each encryption multiplication device may be implemented like the encryption computing device 112 and may perform the multiplication of ciphertexts and polynomials as described herein.
[0081] Homomorphic encryption schemes can be applied in many settings. For example, the encryption computing device 112 may be operated by a cloud provider. The cloud provider may provide computing as well as storage services to its customers. By adopting homomorphic encryption, Figure 1b a data provider device 160 (e.g., a client of the cloud provider) can send its data in encrypted form. The cloud provider can still perform the required computations and / or the required storage, but cannot know the corresponding plaintext data. For example, the data provider device 160 may encrypt data items using an encryption key of a type corresponding to the particular homomorphic encryption system being used. When the data provider 160 receives the computation result from the encryption computing device 112, the encrypted data items can be decrypted using the corresponding decryption key. The encryption key and the decryption key may be the same and usually are.
[0082] For example, the encrypted computing system 100 can be configured to train a machine learning model (e.g., an image classifier, such as a medical model), while the encrypted computing device has no access to the plaintext data items. For example, linear regression can be performed on the input data, possibly even without bootstrapping. For example, backpropagation can be performed on the input data, possibly leveraging bootstrapping. The resulting model parameters can be returned to the entity that owns the decryption key. This enables multiple providers of medical data to pool their data by sending it to a cloud provider. The cloud provider then returns the model parameters without accessing the plaintext data. The encryption key can be equal to the decryption key.
[0083] After the model has been trained, the encrypted computing system 100 can be used to provide the model, e.g., for use with medical data. This can be done using plaintext model parameters or encrypted model parameters, in both cases using encrypted data (e.g., encrypted input data, intermediate data, and output data). Using plaintext model parameters is generally more efficient. In both cases, one effect of the system is to perform computations (e.g., image classification, such as medical image classification) without the computer knowing the plaintext data items. For example, a mammogram can be used to evaluate for cancer without the image ever being presented in plaintext on the encrypted computing device 112 and without any encrypted computing device 112 or coalition of such devices knowing the result of the cancer evaluation. From a privacy perspective, it may be acceptable to operate on plaintext models on encrypted privacy-sensitive data, while it may be unacceptable to operate on plaintext privacy-sensitive data.
[0084] Other applications involve database services, e.g., finding encrypted data in an encrypted database; e.g., the computation may be a comparison between an input item and a database item. For example, multiple computations can be combined to produce a database index that matches an index. For example, the database can be a genomic database and the input can be a gene sequence. For example, the system 100 can be used for protective control of a device. For example, a device (even a large device such as a power plant) can send sensor values to the encrypted computing device 112 and receive an encrypted control signal in return. The control signal is calculated based on the sensor signal. An attacker of the system can determine the data content going in and out of one or more encrypted computing devices 112 or even gain access to the intermediate data of these devices, but since the data is encrypted, this will be of no help to them. Since the decryption key is unknown to these devices, even fully cracking all the encrypted computing devices 112 of the system 100 will not leak the data. Calculating the control signal can involve mathematical operations such as linear algebra, averaging, matrix multiplication, polynomial evaluation, etc., all of which can be performed using homomorphic encryption operations.
[0085] For example, a pool of encrypted data items can be maintained in an encrypted computing system; a subset of them can be received, and another subset can be the result of encrypted computations, e.g., intermediate results. For example, the encrypted computing device 112 can be configured to apply homomorphic encryption operations to one, two, or more encrypted data items in the pool, e.g., a set of input values and / or intermediate values and / or output values. The result may be a new encrypted data item that can be stored in the pool. The pool can be stored in the memory of the encrypted computing system. This can be local memory or distributed memory. In the latter case, one or more encrypted data items may be represented multiple times in the pool. For example, if the value of an encrypted data item is needed elsewhere, the encrypted data item can be sent from one computing device to another. The pool can be implemented in various ways, e.g., as a register file, an array, various data structures, etc.
[0086] Encrypted data items can represent various data. For example, an encrypted data item can represent numbers that need to be averaged, or numbers for linear regression, etc. For example, an encrypted data item can represent an image. For example, each pixel of an image can correspond to one or more encrypted data items. For example, a grayscale pixel can be represented by a grayscale level, which in turn can be represented by a single encrypted data item. For example, 256 grayscale levels can be encoded in a single encrypted data item. For example, a color pixel can be represented as multiple color levels, e.g., RGB levels, which in turn can be represented by a tuple of encrypted data items. For example, three 256-level colors can be encoded in three encrypted data items. How many encrypted data items are used to represent a type of data depends on the capacity of the homomorphic encryption scheme. For example, a more restrictive homomorphic encryption scheme may only be able to encode one bit per encrypted data item. In this case, a color pixel may require 24 encrypted data items.
[0087] A set of homomorphic encryption operations can be defined for a computation. For example, based on the homomorphic encryption operations, an operation network or circuit can be constructed, which together perform the computation, e.g., through an external compiler device or through the computing device itself. For example, the operations can include Boolean operations. The way the homomorphic encryption operations are combined (e.g., which operation is applied to which operand in the pool) determines the computation being performed. For example, a computation can be represented as a list of homomorphic encryption operations to be performed and indications of on which encrypted data items they are to be performed. The network or circuit can indicate to the encrypted computing device 112 when to perform programmable bootstrapping, or the encrypted computing device 112 can initiate programmable bootstrapping when it finds that the noise in the encrypted values is too large or will become too large.
[0088] Figure 2An embodiment of an implementation of a method for calculating the polynomial product of two polynomials f(X) and g(X) is schematically illustrated. The two polynomials in this embodiment are defined modulo a quotient polynomial p(X). Several embodiments described for this figure are known per se and are described, for example, in Chapter 8 of "Modern Computer Algebra" by J. von zur Gathen and J. Gerhard, Cambridge University Press, 2003 (incorporated herein by reference). This figure shows the product of polynomials in coefficient form, and the result is the product of polynomials in coefficient form. This multiplication has several components: number-theoretic transform, inverse of the number-theoretic transform, and Fourier-domain multiplication. Various implementations of other figures may use the components of this figure, but in different configurations.
[0089] The figure shows, for example, f(X) = ∑ i f i X i modulo p(X) with coefficients f i and g(X) = ∑ i g i X i modulo p(X) with coefficients g i representing two polynomials f, 241 and g, 243.
[0090] To multiply polynomials, the number-theoretic transform NTT 233 can be applied to transform the polynomials into the Fourier domain. The figure shows the Fourier-domain representation 242 of polynomial 241 and the Fourier-domain representation 244 of polynomial 243. Generally, the Fourier-domain representations of polynomials 241, 243 include evaluations of polynomials at powers of a primitive root of unity from a finite ring (e.g., the ring from which the coefficients of polynomials 241, 243 are chosen or to which they correspond). As demonstrated by the following embodiments, the Fourier-domain representation can include, for example, all M powers of an M-th primitive root of unity, or only a strict subset of the powers. In some embodiments, there is a one-to-one correspondence between the coefficient representation 241 of a polynomial modulo p(X) and the Fourier representation 242, but this is not necessary; for example, NTT233 can map a set of coefficients to a subset of the possible Fourier representations 242.
[0091] Given the Fourier-domain representations 242, 244, the polynomial product of the polynomials can be calculated in the Fourier domain with operation Mul, 238. This is typically implemented as pointwise multiplication of the evaluations of the polynomials. Pointwise multiplication can correspond to, for the value n, the polynomial X MThe corresponding polynomial of taking the modulo of -1, where the value n corresponds to the quotient polynomial, as emphasized in the following embodiments. As a result, a Fourier domain representation 246 of the product of the polynomials f and g can be obtained, for example, as the evaluation of the quotient polynomial in the set of powers of the primitive unit root.
[0092] The inverse INTT, 234 of the number - theoretic transform 233, can be applied to the Fourier domain representation 246 of the product polynomial to obtain a representation 245 of the product polynomial in the form of coefficients h(X) = ∑ i h i X i mod p(X). Interestingly, the INNT 234 can have the property that randomly generating a Fourier representation, for example, randomly generating the corresponding evaluations included therein, and then applying the inverse number - theoretic transform 234, produces a random polynomial 245, for example, having the same distribution as the randomly generated corresponding coefficients h i This may be the case especially when there is a one - to - one mapping between the Fourier domain representation 246 and the coefficient representation 245, for example, when the Fourier domain representation includes a number of elements equal to the number of coefficients of the polynomial (e.g., equal to the order of the quotient polynomial). As shown in the following embodiments, this may also be the case when the Fourier domain representation is larger, for example, the number of Fourier domain representations 246 that map to a given polynomial 245 modulo p(X) in the coefficient representation can be the same for each polynomial 245.
[0093] Generally, various number - theoretic transforms are known per se and can be used in combination with the techniques described herein (e.g., the discrete Fourier transform in its standard form), algorithms and the Nussbaumer algorithm.
[0094] Now, several specific embodiments of the number - theoretic transform and its corresponding Fourier domain representation are provided. Generally, these embodiments relate to polynomials over a finite ring or a torus. A correspondence between random polynomials and random Fourier domain representations may exist, as explained below. On the other hand, when using the classical Fourier transform instead of the number - theoretic transform as in the TFHE scheme, such as "TFHE: fast fully homomorphic encryption over the torus", an infinite - size domain of complex numbers is used instead of a finite set. In this case, since the ciphertext has a finite representation, such a correspondence does not exist in a specific implementation.
[0095] Example 1: Quotient polynomial X M -1
[0096] Generally, let R be a ring. Also, let ω ∈ R be a primitive M - th root of unity, where the integer M>1. Given two polynomials f,g ∈ R[X] / (XM -1), and their product can be computed by means of the number-theoretic transform (also known as the discrete Fourier transform). Details can be found in Chapter 8 of “Modern Computer Algebra”.
[0097] When applying the number-theoretic transform, a polynomial f of degree < M: = f(X) = f0 + f1X + … + f M-1 X M-1 ∈ R[X] can be identified with its coefficient vector (f0, f1, …, f M-1 ) ∈ R M The number-theoretic transform 233 of the polynomial f, regarded as a vector in R M can compute the vector that consists of the evaluations of f at the successive powers of ω:
[0098]
[0099] For example, for two polynomials f, g ∈ [X] of degree < n, it holds that
[0100] DFT ω (f * g) = DFT ω (f) · DFT ω (g)
[0101] where * denotes polynomial convolution and · denotes pointwise multiplication of vectors; see Lemma 8.11 of “Modern Computer Algebra”.
[0102] Now consider polynomials f, g ∈ R[X] / (X M -1) (and thus of degree < M). Since multiplication modulo X M -1 is convolution (e.g., fg ≡ f * g (mod X M -1)), the product h: = fg ∈ [X] / (X M -1) can be obtained as
[0103] h = DFT ω -1 (DFT ω (f) · DFT ω (g))
[0104] where DFT ω -1 denotes the inverse number-theoretic transform 234 and DFT ω (f). DFT ω (g) is the pointwise multiplication Mul, 238. Interestingly, for any polynomial h ∈ R[X] of degree < M the inverse DFT can be computed as Refer to Theorem 8.13 of "Modern Computer Algebra".
[0105] In this embodiment, when the ring R is finite, there is a one-to-one correspondence between a polynomial and its Fourier domain representation. Therefore, a uniformly random polynomial can correspond to a uniformly random Fourier domain representation.
[0106] Example 2: The quotient polynomial p(X) | X M -1
[0107] In this embodiment, the quotient polynomial p := p(X) can be any polynomial p(X) that is divisible by X M - 1. Again, ω ∈ R can be a primitive M-th root of unity. In this case, the product of two polynomials f, g ∈ R[X] / (p) can be obtained as follows:
[0108] - Perform NTT 233 as in the above embodiment, and f and g are regarded as polynomials in R[X] / (X M - 1);
[0109] - Perform Mul 238 as in the above embodiment, and calculate the Fourier representation of h' := fg (mod X M - 1) as h' = DFT ω -1 (DFT ω (f) · DFT ω (g))
[0110] - Perform INTT 234 by calculating the coefficient representation of h' as above and returning h = h' mod p as the product of f and g in R[X] / (p).
[0111] It is not necessary to perform the reduction h = h' mod p in INNT 234. For example, the coefficients modulo the polynomial X M - 1 can be returned. In this case, for security purposes, it may be advisable to add a random multiple r(X)p(X) of the quotient polynomial to the returned coefficient representation to randomize it.
[0112] In addition, note that when performing NTT 233 on polynomials f, g, a random multiple of the quotient polynomial can be added to f and / or g to randomize the obtained Fourier domain representations 242, 243.
[0113] In this embodiment, p(X) can be a proper divisor of X M - 1. For example, it can have an order less than M, but p(X) = X M - 1 can also be regarded as an embodiment of this case.
[0114] Let the order of p(X) be N. Then the coefficient representation of the polynomial can include N elements, while the Fourier domain representation can include M elements. For M = N, there is a one-to-one mapping between the Fourier domain representation and the coefficient representation of the polynomial modulo p(X). If M > N, there is a one-to-one mapping between the Fourier domain representation and the polynomial modulo (X M - 1), but there is no one-to-one mapping between the Fourier domain representation and the polynomial modulo p(X). However, interestingly, the operation h = h′ mod p in INTT 234 can ensure that each coefficient representation 245 of the polynomial modulo p(X) has an equal number of corresponding Fourier domain representations 246.
[0115] In the following embodiments, a quotient polynomial of the form (X M - 1) / (X d - 1) is discussed, where M = hd and d = M - N. As described above, in the following embodiments, R can be finite and ω can be a primitive M-th root of unity. Although the techniques of the above embodiments can be used for such quotient polynomials, interestingly, more efficient polynomial multiplication is also possible by defining a Fourier representation that includes only the evaluations in a subset of the powers of the n-th primitive root of unity. The following is proven for the cases of h = 2 and h = 3, but this embodiment can be easily generalized to higher values of h. However, the smaller the value of h, the greater the reduction in the size of the Fourier representation, which is why the cases of h = 2 and h = 3, especially h = 2, are preferred.
[0116] Example 3: M = 2N, p(X) = X N +1
[0117] Given f, g ∈ R[X] / (X N + 1), write where f j ∈ R, and where g j ∈ R. Define f * (X) = f(ωX) and g * (X) = g(ωX). From (ωX) N + 1 = -X N + 1, it can be seen that
[0118]
[0119] where
[0120] Similarly, where It can be noted that η := ω 2 ∈ is an N-th primitive root of unity. Since modulo X NMultiplication modulo - 1 is convolution (so f * g * ≡ f * * g * (mod X N - 1)), so the product h * : = f * g * can be obtained as:
[0121] h * = DFT η -1 (DFT η (f * ) · DFT η (g * ))
[0122] where
[0123] Let Then the product polynomial h: = fg ∈ R[X] / (X N + 1) is given by where
[0124] is given.
[0125] Thus, in this embodiment, the NTT operation 233 can be implemented as an operation that takes as input a polynomial 241 in R[X] / (X N + 1) and returns its Fourier representation 242. Given f ∈ R[X] / (X N + 1), this operation 233 can be implemented as
[0126]
[0127] where η = ω 2 , for example
[0128]
[0129] The inverse operation 234 can be expressed as where the multiplication operation 238 corresponds to the calculation of DFT η (f * ) · DFT η (g * ).
[0130] It can be noted that in this embodiment, there is a one - to - one correspondence between the coefficient representations 241, 243, 245 and the Fourier - domain representations 242, 244, 246: Specifically, a uniformly random Fourier - domain representation corresponds to a uniformly random polynomial.
[0131] Example 4: M = 3N / 2 (N is even), p(X) = X N + X N / 2 + 1
[0132] Given \(f, g\in\mathbb{R}[X] / (X N +X N / 2 +1)\), write where \(f j \in\mathbb{R}\), and where \(g j \in\mathbb{R}\). For \(i\in\{1,2\}\), define and Note that \(\omega M - 1=(\omega N / 2 - 1)(\omega N +\omega N / 2 + 1)=0\), whence \(\omega N +\omega N / 2 + 1 = 0\), since \(\omega\) is a primitive \((3N / 2)\)-th root of unity, and the polynomial \(X N +X N / 2 + 1\) can be written as \(X N +X N / 2 + 1=(X N / 2 -\omega N / 2 )(X N / 2 -\omega N )=((\omega 2 X) N / 2 - 1)((\omega X) N / 2 - 1)\). Thus it can be seen that
[0133]
[0134] and
[0135]
[0136] Similarly, let where and it holds that where
[0137] Let \(\eta:=\omega 3 \), which is a primitive \((N / 2)\)-th root of unity. For \(i\in\{1,2\}\), can be computed as
[0138]
[0139] For \(i\in\{1,2\}\), the polynomial \(h i := f i g i \bmod((\omega 3-i X) N / 2 - 1)\) can be recovered as:
[0140] Among them Applying the Chinese Remainder Theorem, the product polynomial h := fg ∈ R[X] / (X N + X N / 2 + 1) can be obtained as
[0141]
[0142] Therefore, in this case, the number-theoretic transform operation 233 can be implemented as using the polynomials 241, 243 in R[X] / (X N + X N / 2 + 1) as input and returning their Fourier representations 242, 244. For example, given f ∈ R[X] / (X N + X N / 2 + 1), the Fourier representation can be calculated as
[0143]
[0144] where η = ω 3 ; or equivalently
[0145]
[0146] The inverse operation 234 can be expressed as where the polynomial 238 is implemented as
[0147] Furthermore, in this embodiment, it can be noted that there is a one-to-one correspondence between the coefficient representations 241, 243, 245 and the Fourier domain representations 242, 244, 246: Specifically, the uniformly random Fourier domain representation corresponds to the uniformly random polynomial.
[0148] Figure 3a An embodiment of the implementation of the encryption unit 331 for calculating the representation 344 - 345 of the ciphertext by encrypting a given plaintext is schematically shown. For example, the encryption unit 331 can be used in the key generation unit 131 of the key generation device 111 or in another encryption calculation device 110.
[0149] The ciphertext can include one or more masked polynomials and a body polynomial. For example, the ciphertext can be a GLWE-based ciphertext. The calculated representation 344 - 345 can be used in an encryption calculation method, for example, as described with respect to Figure 1b , Figure 3b , Figure 4a and Figure 4bAs discussed. As also discussed elsewhere, such an encrypted computing method may involve multiplying a masking polynomial and a body polynomial by corresponding multiplicand polynomials. As demonstrated in the embodiment of Figure 2 , if the masking polynomial and the body polynomial are represented in the Fourier domain of the number-theoretic transform, such polynomial multiplication can be performed efficiently. Therefore, it is desirable to provide a representation of the ciphertext that is compressed but can be efficiently expanded into such a Fourier domain representation while still ensuring that the ciphertext complies with the probability distribution of the encryption scheme. Such a representation can be provided by the encryption unit 331.
[0150] Shown in the figure is the plaintext m, 347 to be encrypted. The plaintext can be a polynomial from a polynomial ring in which the masking polynomial and the body polynomial are defined. For example, the plaintext can be one or more numbers, bits, characters, strings, etc. encoded as polynomials.
[0151] The figure also shows the encryption unit Enc, 336. The encryption unit can take as input the masking polynomial a1,…,a k , 341 and the plaintext m, 347, and can determine the body polynomial b, 343. The encryption unit 336 can also take the key as input and encrypt the plaintext 347 using the key (not shown in this figure). The encryption unit 336 can determine the coefficients 343 of the body polynomial such that the ciphertext formed by the masking polynomial 341 and the body polynomial 343 encrypts the plaintext 347. The encryption unit 336 can be a conventional encryption unit. For example, the unit can calculate where a j is the masking polynomial, s′ j is the key, μ is the plaintext, and e is noise sampled according to an error distribution. Although the encryption unit 336 can be conventional, interestingly, the masking polynomials 341 are not generated in a conventional manner. For example, they are not generated by separately randomly generating the corresponding coefficients.
[0152] Also shown is the seed S, 345 of the pseudorandom number generator. The seed 345 can be included in the representation of the ciphertext being determined. As shown in the figure, the seed can be randomly generated by a random number generator Rnd, 337, such as a hardware random number generator or a pseudorandom number generator (preferably, an encryption PRNG). However, the seed can also be obtained in a different way. For example, the seed can be received from another device, or the seed can represent the state of the pseudorandom number generator, for example, after the pseudorandom number generator has previously been used to generate other random numbers.
[0153] Also shown is a pseudo-random number generator (PRNG) Gen, 335. The PRNG 335 can be configured to determine a series of random values given a seed 345. The PRNG is preferably a cryptographically secure pseudo-random number generator (CPRNG). The PRNG can be used according to the seed 345 to randomly select a masked polynomial by generating a representation 342 of the masked polynomial in the Fourier domain of a number-theoretic transform (e.g., uniformly randomly from the Fourier domain). For example, the representation of the masked polynomial can include multiple evaluations of the masked polynomial in the evaluation set. The PRNG 335 can sequentially generate corresponding evaluations. For example, with respect to Figure 2 Embodiments of the Fourier domain representation of the number-theoretic transform are discussed. The PRNG can be used to sample the Fourier domain representation using techniques known per se (e.g., by sampling bits from the PRNG and deriving random evaluations from those bits, e.g., by rejection sampling). Any cryptographically secure pseudo-random number generator can be used, such as a stream cipher, a block cipher in counter mode, Yarrrow, or Foruna PRNG, etc.
[0154] Also shown is an INTT unit 334. The INNT unit 334 can be configured to apply the inverse of the number-theoretic transform (INTT) to the evaluations 342 of the masked polynomial to determine the coefficients 341 of the masked polynomial, e.g., as discussed with respect to Figure 2 Interestingly, the inverse number-theoretic transform can have the property that generating a uniformly random Fourier domain representation and applying the INNT results in a uniformly random polynomial, in other words, a polynomial with uniformly random coefficients. For example, there can be a one-to-one mapping between the Fourier domain representation 342 of the polynomial and the coefficient representation 341. Thus, generating 335 the Fourier domain representation and applying the INNT 334 can result in a masked polynomial having the same randomness characteristics as the corresponding coefficients of a randomly generated masked polynomial, as can be done conventionally.
[0155] The figure also shows an NTT unit 333. The NTT unit 333 can be configured to apply the number-theoretic transform (NTT) to the coefficients 343 of the body polynomial to determine the representation 344 of the body polynomial in the Fourier domain, e.g., as discussed with respect to Figure 2 The Fourier domain representation 344 and the seed 345 can be used to represent the ciphertext. By storing the body polynomial in the Fourier domain, it can be directly used for Fourier domain multiplication. The body polynomial can also be stored in coefficient form, in which case the conversion to the Fourier domain can be performed where multiplication is needed.
[0156] By repeatedly using the encryption unit 331, multiple ciphertexts can be generated. For example, the encryption unit 331 can be used to generate a GGSW type ciphertext including multiple generated ciphertexts, also as discussed with respect to Figure 4aAs discussed. In this case of generating multiple ciphertexts, these ciphertexts can be based on the same seed 345. For example, a random seed generated by unit 337 or otherwise obtained can be used to initialize the PRNG 335 once, and then the PRNG can be used to generate the masked polynomials 342 of the corresponding ciphertexts based on the same seed 345. Thus, in this case, the representations of multiple ciphertexts share a common seed 345, and when storing and / or transmitting a set of multiple ciphertexts, this seed only needs to be stored and / or transmitted once, thereby further reducing the storage and transmission bandwidth requirements.
[0157] Numerous detailed embodiments for determining the representations 344 - 345 are now given. These embodiments describe the generation of encrypted representations of the bootstrapping key, but can be easily adapted to the generation of encrypted representations of any other value.
[0158] First Embodiment: Quotient Polynomial X N + 1
[0159] This embodiment is based on the corresponding embodiment regarding Figure 2 discussed. The polynomial to be represented can be an element of or, using a related ring, as an element of Let
[0160] This embodiment uses the 2N - th primitive root of unity ω. As discussed regarding Figure 2 in this case, a particularly efficient multiplication based on the number - theoretic transform is possible.
[0161] The modulus q can be chosen such that contains such a root of unity. Specifically, 2 can be a unit in R, so q can be odd. Possible choices for R include prime fields where q ≡ 1 (mod 2N). For example, a Solinas prime q = 2 64 - 2 32 + 1 can be used so that efficient 64 - bit arithmetic can be used. More generally, q can be chosen such that λ(Q) ∝ 2N, where λ is Carmichael’s totient function and gcd(q, 2N) = 1.
[0162] Shown below is how the encryption unit 331 can be used to generate the bootstrapping key for TFHE programmable bootstrapping. Such a bootstrapping key can include GGSW - type ciphertexts of multiple parts of the key. The GGSW - type ciphertexts themselves can consist of GLWE - based encryptions with exponents (i, r) and encrypting the corresponding values Details can be found in Figure 4a . The bootstrapping key can be generated as follows:
[0163] 1. Generate a positive integer q such that has a 2N-th primitive root of unity, and select such a 2N-th primitive root ω modulo q;
[0164] 2. In the Rnd operation 337, uniformly and randomly draw a common seed σ in {0,1} κ , where κ is the security parameter;
[0165] 3. In the Gen operation 335, use an encryption pseudo-random number generator
[0166]
[0167] to obtain, for 1 ≤ i ≤ n and vector 342
[0168]
[0169] as the output of CPRNG(σ);
[0170] 4. For 1 ≤ i ≤ n and
[0171] - Apply the inverse number-theoretic transform 334 to construct the polynomial mask 341, where for 1 ≤ j ≤ k,
[0172] - Obtain the 336 matching polynomial body 343 such that the ciphertext encrypts the plaintext 347, where e(i,j) is the Gaussian error on, and by convention, s′ k+1 :=-1;
[0173] - Calculate 344 by applying the number-theoretic transform 333.
[0174] 5. Return the representation of the bootstrapping key, which includes the common seed σ, 345, and the representation of the body polynomial (where 1 ≤ i ≤ n and ), 344.
[0175] Second Embodiment: Quotient Polynomial X N +X N / 2 +1
[0176] This embodiment is based on the corresponding embodiment discussed with respect to Figure 2 . In this embodiment, the body polynomial and the mask polynomial are defined over or are defined over using the relevant ring. Let is the corresponding ring.
[0177] One advantage of using this quotient polynomial is that it can be used in combination with even values of q, especially when q is a power of 2. This is advantageous for various cryptographic applications.
[0178] In this embodiment, q is chosen such that 3 is a unit in R, and the primitive root of unity ω is chosen to be a primitive (3N / 2)-th root of unity, for example, where N / 2 is a power of 3. As discussed with respect to Figure 2 , in this case, particularly efficient multiplication of polynomials in R[X] / (X N +X N / 2 +1) is possible.
[0179] Using the notation of the foregoing embodiment, a representation of the bootstrap key can be generated as follows:
[0180] 1. Choose a positive integer q such that R contains a primitive (3N / 2)-th root of unity; N even. Choose a primitive (3N / 2)-th root of unity modulo q. For example, q can be chosen such that λ(q) ∝ 3N / 2, where λ is the Carmichael function; and gcd(q, 3N / 2) = 1.
[0181] 2. In the Rnd operation 337, uniformly and randomly draw a seed σ, 345 from {0, 1} κ .
[0182] 3. Use the cryptographic pseudorandom number generator 335,
[0183]
[0184] to obtain, for 1 ≤ i ≤ n and of the form vectors 342, as the output of CPRNG(σ);
[0185] 4. For 1 ≤ i ≤ n and
[0186] - Construct the polynomial mask 341 by applying the inverse number-theoretic transform 334, where for 1 ≤ j ≤ k,
[0187] - In the encryption operation 336, obtain the matching polynomial body 343, where e(i, j) is the Gaussian error over such that the ciphertext encrypts the plaintext 347;
[0188] - By applying the number - theoretic transform 333, calculate 344;
[0190] 5. Return the bootstrap key through the Fourier - domain representation of the seed and the body polynomial The bootstrap key includes the representation σ of the corresponding ciphertext, (where 1 ≤ i ≤ n and ), 344 - 345, all of which have the common seed σ, 344.
[0191] Example 3: The quotient polynomial p(X) | X M -1
[0192] In this embodiment, the technology of the corresponding embodiment of Figure 2 can be used. When performing INNT 334, the coefficient representation a i (x), 341, modulo p(X) can be obtained, and the encryption Enc, 336, modulo p(X) can be calculated. As discussed with respect to Figure 2 , when performing NTT 333, a random multiple of p(X) can be added to b(X) to randomize the Fourier - domain representation 344, but this is not necessary.
[0193] As an alternative, the reduction modulo p(X) can also be avoided for INNT 334. Thus, the polynomial 341 returned by INNT can be a polynomial modulo X M - 1. This may be more computationally efficient in some cases. In this case, the encryption Enc, 336, can also be calculated modulo X M - 1 to obtain the body polynomial b(X), 343, modulo X M - 1, and the NTT 333 can be applied to this body polynomial. In this case, it is desirable to randomize the obtained Fourier - domain representation 344 by adding a random multiple of p(X) to b(X) in the coefficient domain before applying NTT or in the Fourier - domain after applying NTT.
[0194] Figure 3b An embodiment of the implementation of the encryption multiplication unit 332 (e.g., the encryption multiplication unit 332 for the encryption computing device 110) is schematically shown.
[0195] The encrypted multiplication unit 332 can act on ciphertexts that include one or more random masked polynomials and body polynomials derived from the masked polynomials and plaintexts. For example, the ciphertext can be a GLWE-based ciphertext as described herein. The encrypted multiplication unit 332 can act on ciphertexts represented in a compressed manner by a seed 345 of a pseudorandom number generator and a representation 344 of the body polynomial in the Fourier domain of a number-theoretic transform. For example, the representations 344-345 of the ciphertext may have been previously determined by Figure 3a the encryption unit 331, which is typically part of a device different from the encrypted multiplication unit 332.
[0196] The encrypted multiplication unit 332 can be used to multiply the masked polynomials and body polynomials of the ciphertext by corresponding multiplicand polynomials. For example, the encrypted multiplication unit 332 can be used in encrypted computations to calculate outer products, also as discussed with respect to Figure 4a or in various other operations of encrypted computations, such as multiplying the ciphertext by a known polynomial. The figure shows the corresponding multiplicand polynomials 351 for multiplying with the masked polynomials and body polynomials of the ciphertext. For example, the corresponding multiplicand polynomials 351 can all be different, or the corresponding multiplicand polynomials 351 can all be equal to a common multiplicand polynomial.
[0197] In the illustrated embodiment, the multiplicand polynomials are obtained in coefficient representation 351, and the number-theoretic transform unit NTT, 333 is used to apply a number-theoretic transform to convert the coefficients 351 of the corresponding multiplicand polynomials to a Fourier domain representation 352. The NTT unit can be as Figure 2 or Figure 3a described. The unit 332 is not required. For example, the multiplicand polynomials may have been obtained in Fourier domain representation, e.g., as a previous output of the multiplication unit 332 or otherwise.
[0198] To obtain the representations 344-345 of the ciphertext on which multiplication can be performed, the representations 344-345 can be extended. To this end, a pseudorandom number generator (PRNG) Gen, 335 can be used according to the seed 335 to generate a representation 342 of the masked polynomial in the Fourier domain. The PRNG can be as Figure 2 or Figure 3a described.
[0199] Given the Fourier domain representations of the masked polynomial 342, the body polynomial 344, and the multiplicand polynomial 352, the multiplication unit 338 can be used to calculate the polynomial product of the masked polynomial 342 and the body polynomial 344 with the corresponding multiplicand polynomial 352 in the Fourier domain. As a result, a Fourier domain representation 354 of the calculated polynomial product in the Fourier domain can be obtained. For example, the multiplication unit 338 can be Figure 2The multiplication unit 238. Generally, the Fourier domain representation includes the evaluation of the corresponding polynomials in the set of evaluations, and the multiplication 338 can be implemented by the pointwise multiplication of the polynomial evaluations known per se.
[0200] The encrypted multiplication unit 332 can output the computed polynomial product in various formats as needed. For example, the polynomial product can be output in its Fourier domain representation 354, or as shown in the figure, the INNT unit 334 can be used to apply the inverse number theory transform in order to convert the representation 354 of the partially or fully computed polynomial product in the Fourier domain into the coefficient representation 353. The INNT unit 334 can, for example, for Figure 2 or Figure 3a as described.
[0201] In the case where there is no one-to-one correspondence between the Fourier domain representation 354 and the coefficient domain representation 353, in some cases, additional randomization can also be performed as regarding Figure 2 discussed. Specifically, if the encrypted multiplication unit 332 outputs the Fourier domain representation 354, randomization can be performed such that a random Fourier domain representation 354 of the product is output. For example, when using the quotient polynomial p(X)|X M −1, it can be achieved by adding a random multiple r(X)p(X) of the quotient polynomial p(X) to the Fourier domain representation, for example generating it in the coefficient domain and using the FFT to transform it to the Fourier domain.
[0202] As discussed for Figure 2 the INTT 234, in the case of using the quotient polynomial p(X)|X M −1, it is also possible to output the coefficient domain representation 353, which is not reduced modulo p(X) and is thus represented by a polynomial modulo the modulus X M −1. In this case, it is also desirable to add a random multiple r(X)p(X) of the quotient polynomial to the output coefficient domain representation 353 to randomize it. The random multiplier can be added in the Fourier domain before applying the INTT 334, or in the coefficient domain after applying the INTT.
[0203] The encrypted multiplication unit 332 can be used to repeatedly perform polynomial multiplication on the same encryption 344 - 345. In this case, the extended representations 342, 344 of the ciphertext can be stored in memory and then used to compute further polynomial multiplications without having to apply the PRNG 335 again at this time, thus improving the efficiency of further multiplications. However, to save memory, it is also possible to delete the Fourier domain representations 342 of the masked polynomials and regenerate them as needed.
[0204] Figure 4aAn embodiment of an encryption multiplication unit 432 (e.g., the encryption multiplication unit 432 for the encrypted computing device 110) is schematically shown. In this figure, the encryption multiplication unit 432 is used to calculate the outer product of the GGSW type ciphertext 456 and the GLWE-based multiplicand ciphertext 455.
[0205] Generally speaking, the GGSW type ciphertext 456 for encrypting the plaintext M(X) may include a set of corresponding GLWE-based ciphertexts that encrypt the corresponding values based on the plaintext. The GGSW type ciphertext including the RLWE-based ciphertext may also be referred to as the RGSW ciphertext. The GGSW type ciphertext defined on the discrete torus (e.g., ) may also be referred to as the TGSW, TGGSW, or TRGSW ciphertext.
[0206] For example, the TGGSW encryption of according to the private key s′ can be defined as a set of GLWE-based ciphertexts for the corresponding value h(r)
[0207]
[0208] See "CONCRETE:Concrete Operates oN CiphertextsRapidly by Extending TfhE" by I.CHillotti et al. (available at https: / / homomorphicencryption.org / wp-content / uploads / 2020 / 12 / wahc20_demo_damien.pdf and incorporated herein by reference).
[0209] Note that in the literature, the GGSW type ciphertext is sometimes also described as GLWE encryption based on zero, where the value based on the plaintext is added. Such a GGSW type ciphertext is also regarded as a GGSW type ciphertext including GLWE-based ciphertexts. For example, the TGGSW ciphertext of "TFHE:fast fully homomorphic encryption over the torus" is a GGSW type ciphertext including GLWE ciphertexts. That is, the TGGSW type ciphertext is defined in this reference as where
[0210]
[0211] and
[0212] G T = diag(g T ,…,g T )(k + 1 times), where is the so-called gadget matrix. The integer B≥2 is a system parameter such that for example or more generally In this embodiment, the rows of the TGGSW ciphertext are of GLWE type encryption. That is, in the "TFHE" reference, the rows of the GGSW type ciphertext are described as the sum of the encryption of zeros and vectors, for example in the calculation of Z+m·G T Among them. By regarding the masking polynomial that generates the sum as a random mask and the body polynomial as encrypting a value that depends on the vector added to the encryption of zero, such a row can also be regarded as a TGLWE ciphertext. For example, the TGGSW encryption described above can be regarded as a series of GLWE-based ciphertexts as follows. See also the reference "CONCRETE:Concrete Operates oN Ciphertexts Rapidly by Extending TfhE". Let
[0213]
[0214] be the TGGSW ciphertext. Let represent the TGLWE encryption of 0 in row #r of C. Write where and 1≤h:=h(r)≤k+1 and Row #r of C can be described as
[0215]
[0216] where where 1 is in position #h. It can be noted that the above expression (*) satisfies:
[0217] 1. If 1≤h≤k, then
[0218] 2. If h=k+1, then Therefore, the TGGSW ciphertext C can be regarded as a series of ciphertexts. By setting s' k+1 =-1, the ciphertext represents a value that depends on the plaintext m to be encrypted:
[0219]
[0220] Figure 456 shows the representation of the GGSW type ciphertext. The GLWE-based ciphertext of the GGSW type ciphertext can be represented by the corresponding seed 445 of the pseudo-random number generator (PRNG) and the representation 444 of the body polynomial in the Fourier domain of the number-theoretic transform, as discussed elsewhere. For example, this representation may already be by Figure 3ais determined by the encryption unit 331. As shown in the figure, ciphertexts based on GLWE can share a common seed 445. For example, a PRNG can be seeded with the seed 445.
[0221] To compute the outer product, the representation 444-445 of the GLWE-based ciphertext of the GGSW type ciphertext 456 can be extended. To this end, a pseudorandom number generator 435 (e.g., Figures 3a to 3b the PRNG 335) can be used to generate the representation in the Fourier domain of the masked polynomial of the GLWE-based ciphertext 444, either according to the common seed 445 or according to the respective seeds. This is done as Figure 3b described. As shown in the figure, an extended representation of the GGSW type ciphertext in the Fourier domain can be obtained, including the Fourier representation 442 of the respective masked polynomial, and the Fourier representation 444 of the respective body polynomial.
[0222] As is known per se, the outer product of the GGSW type ciphertext 456 and the GLWE-based multiplicand ciphertext 455 can be computed by multiplying the masked polynomial and the body polynomial of the respective GLWE-based ciphertext 444 by the respective multiplicand polynomial 451 of the GLWE-based multiplicand ciphertext.
[0223] For the case of the outer product described (e.g., as described in "CONCRETE:Concrete Operates oN Ciphertexts Rapidlyby Extending TfhE"), the determination of the multiplicand polynomial 451 is shown in detail in the figure. In this case, the multiplicand polynomial is obtained by determining the so-called gadget decomposition GDec,439 of the GLWE-based multiplicand ciphertext 455. Computing the gadget decomposition can include applying a radix decomposition by coefficients to the polynomial of the ciphertext 455, thereby obtaining a multiplicand polynomial with small coefficients (e.g., small coefficients in the range [-B / 2,B / 2]). As shown in the figure, where the masked polynomial a1 of the ciphertext 455 is radix decomposed into polynomials the body polynomial b is radix decomposed into polynomials etc. In general, a respective multiplicand polynomial 451 can be obtained for each GLWE encryption of the GGSW type ciphertext 456.
[0224] As Figure 2 and Figure 3b shown, to perform the multiplication of the multiplicand polynomial 451, the multiplicand polynomial can be transformed into the representation 452 in the Fourier domain of the number-theoretic transform by the NTT unit 433. Then the multiplication can be performed in the Fourier domain by the multiplication unit 438. The multiplication unit 438 can be based on Figure 2 and Figure 3bmultiplication unit, but in this case, applicable to the multiplicand polynomial 452 vector of size and the polynomials 442, 444 representing the GGSW type ciphertext 456 matrix-vector multiplication of a matrix of size.
[0225] In this embodiment, both the masked polynomial and the body polynomial of the GLWE-based encryption 444 are multiplied by the common multiplicand polynomial of the multiplicand polynomial 452, but different multiplicand polynomials can also be used for different polynomials of the GLWE-based encryptions 442, 444 if needed.
[0226] The multiplication 438 can produce the masked polynomial and the body polynomial of the GLWE-based ciphertext 454 represented in the Fourier domain. The ciphertext 454 can represent the encryption of the product of the values encrypted by the GLWE-based ciphertext 455 and the GGSW type ciphertext 456. This product is also called the outer product. Optionally, the encryption can be converted to the coefficient form 453 by the INTT unit 434 that applies the inverse of the number theoretic transform, as in Figure 2 , Figure 3a and Figure 3b .
[0227] The outer product has various applications. For example, the outer product can be used for the evaluation of GLWE encrypted values by the GGSW encryption circuit, such as using circuit bootstrapping described in "TFHE: Fast Fully Homomorphic Encryption over the Torus".
[0228] Another important application is to calculate the encrypted CMux gate, also known as the controlled selector gate or the controlled multiplexer. By calculating the product of the difference between the GGSW type ciphertext and the first GLWE ciphertext and the second GLWE ciphertext and adding the first GLWE ciphertext to the calculated product, the CMux gate can obliviously select the first GLWE-based ciphertext or the second GLWE-based ciphertext based on the GGSW type ciphertext. Mathematically, this can be described as: where c0, c1, c′ are GLWE-based ciphertexts, C is the GGSW type ciphertext, represents the outer product.
[0229] Specifically, the outer product can be used for the programmable bootstrapping operation of the homomorphic encryption scheme of the TFHE class. The programmable bootstrapping can use the bootstrapping key including the GGSW type ciphertext 456. Since the bootstrapping key usually contains many GGSW type ciphertexts used in such outer products, the technology provided in this case is particularly advantageous. Regarding Figure 4b a specific embodiment of the programmable bootstrapping is described.
[0230] In general, a TFHE bootstrapping key can include TGGSW encryptions of the parts of the key (e.g., the respective bits). Programmable bootstrapping can evaluate the decryption function using this key under encryption by computing the outer product of the TGGSW encryptions. This is described, for example, in "Programmable Bootstrapping Enables Efficient Homomorphic Inference of Deep Neural Networks". As a detailed example, let denote the discrete torus of positive integer q, and let denote the adjoint polynomial module, where N is a power of 2; also let If denotes a private TLWE key, the bootstrapping key can include the encryption:
[0231] where 1 ≤ j ≤ n, where (where ) is the key, and where n, N, k, are system parameters. In a more general case, for a ring R, the key s′ can be sampled over R[X] / (p(X)).
[0232] Based on the above bootstrapping key, the improved storage and bandwidth requirements due to the compressed representation 456 of the GGSW type ciphertext will be illustrated. In the above example, the bootstrapping key totals in polynomials, i.e., of elements. The elements of are of the form a ∈ Z / qZ and can thus be encoded with bits. As a result, the above example bootstrapping key can use
[0233]
[0234] bits for storage and transmission. Typical parameters are n = 630, k = 1, N = 1024, and q = 264. In this case, the total size of the example bootstrapping key is approximately 62 megabytes.
[0235] The compressed representation allows representing GLWE-based ciphertexts using less storage. A GLWE-based ciphertext can include k + 1 elements: k masked polynomials a uniformly and randomly drawn (e.g., from j plus an additional polynomial, e.g., called the body polynomial in Using the provided technique, a ciphertext based on GLWE can be represented as a pair where 444 is the Fourier domain representation of the body polynomial, σ ∈ {0, 1} λ , 445 is the random seed, where λ is the security parameter.
[0236] The pseudorandom number generator 435 can be used to recover the mask from the seed, for example, from
[0237]
[0238] For 1 ≤ j ≤ k, the Fourier domain representation of the mask polynomial can be set to
[0239] Thus, using the same seed σ, 445 to generate the Fourier domain representations of the TGLWE ciphertexts that form n bootstrapping keys, which can be represented by
[0240]
[0241] bits, the initial memory requirement is roughly divided by a factor of (k + 1). Using the above example parameters n = 630, k = 1, N = 1024, q = 2 64 and λ = 128, the total size of the bootstrapping key becomes 247,726,208 bits, i.e., approximately 31 megabytes.
[0242] Figure 4b An embodiment of the bootstrapping unit 460 (e.g., the bootstrapping unit 460 for the encrypted computing device 110) is schematically shown. The bootstrapping unit 460 can apply a programmable bootstrapping operation to the LWE encryption 461 to obtain the output LWE encryption 469. The output LWE encryption 459 can contain a noise amount independent of the noise in the input encryption 461. Thus, the unit 460 can be used to reduce the noise in the input encryption 461. The output encryption 469 can encrypt the same value as the input encryption, but interestingly, it can also encrypt the result of applying a function to the input encryption 461. Such programmable bootstrapping is known, for example, from "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks" (the "Programmable Bootstrapping" section of this paper is incorporated herein by reference).
[0243] As shown in the figure, the programmable bootstrap may include a blind rotation operation 464. The blind rotation operation may evaluate LWE decryption in the exponent of a GLWE encrypted monomial (referred to herein as a bootstrap monomial). Specifically, the blind rotation may result in the encrypted polynomial product of a test polynomial and a bootstrap monomial. The bootstrap monomial may represent a plaintext value as an exponent. The blind rotation operation 464 may be implemented according to an outer product, and may calculate the outer product through, for example, the encrypted multiplication unit 432 as described herein. Specifically, the blind rotation 464 may include calculating the outer product of one or more GGSW type ciphertexts included in the bootstrap key 456 (e.g., the encryption of the bits or other parts of the decryption key of the input encryption 461) and the GLWE-based multiplicand ciphertext based on the input encryption 461. By using the provided techniques, the calculation of the outer product can be improved as described herein. For example, the outer product may be calculated as part of a controlled multiplexer of the blind rotation 464 to inadvertently select a GLWE-based ciphertext for a zero bit of the LWE decryption key or a GLWE-based ciphertext for a one bit of the LWE decryption key using the GGSW encryption of the bits of the LWE decryption key of the bootstrap key 456. Figure 4a The outer product may be calculated by the encrypted multiplication unit 432 as described herein. Specifically, the blind rotation 464 may include calculating the outer product of one or more GGSW type ciphertexts included in the bootstrap key 456 (e.g., the encryption of the bits or other parts of the decryption key of the input encryption 461) and the GLWE-based multiplicand ciphertext based on the input encryption 461. By using the provided techniques, the calculation of the outer product can be improved as described herein. For example, the outer product may be calculated as part of a controlled multiplexer of the blind rotation 464 to inadvertently select a GLWE-based ciphertext for a zero bit of the LWE decryption key or a GLWE-based ciphertext for a one bit of the LWE decryption key using the GGSW encryption of the bits of the LWE decryption key of the bootstrap key 456.
[0244] As shown in the figure, a modulus switching operation may be performed before the blind rotation 464, in which the input encryption 461 is scaled to obtain a scaled input encryption 463. For example, as is known per se, using the quotient polynomial p(X)=X N +1, a scaling of the domain [0, 2N) may be applied. For example, the components of the ciphertext may be scaled by 2N / q. For example, each component may be subject to an operation of the form , where the input ciphertext 461 is defined modulo q. In this case, the result 463 may be an LWE type ciphertext modulo 2N. More generally, also when using other quotient polynomials for a given M divided by X M -1, the input ciphertext 461 may be scaled to the domain [0, M). As is known per se, the input ciphertext 461 may be such that, for example, by ensuring that the most significant bit of the input is set to zero or a similar value, the scaled ciphertext 463 may take at most N possible values.
[0245] As is known per se, the blind rotation 464 may use a test polynomial. Essentially, the function evaluated by the programmable bootstrap may be recognized as having a lookup table with pairs (i, T[i]) for 0 ≤ i ≤ N - 1. The lookup table may be used to define the test polynomial. For example,
[0246] v(X)=v0 + v1X + … + v N-1 X N-1 , where v i =T[i].
[0247] By computing the product of a bootstrapping monomial (e.g., the plaintext 's ) and a test polynomial (e.g., v(X)), GLWE encryption 465 can be obtained, which takes the result of programmable bootstrapping as the value of the fixed coefficient. A sample extraction operation 466 can be obtained to extract the coefficients of the GLWE ciphertext 465 generated by blind rotation, thereby obtaining the LWE ciphertext 467 of the desired coefficient. Optionally, a key-switching operation 468 can be performed after the sample extraction 466 to obtain the output LWE ciphertext 469, although the LWE ciphertext 467 can also be used as the output. For example, the output ciphertext 467 or 469 can be an encryption based on the same key as the input ciphertext 461, although this is not required.
[0248] The programmable bootstrapping described in "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks" is for polynomials modulo the cyclotomic polynomial X N + 1, where N is a power of 2. Interestingly, the inventors realized that programmable bootstrapping can also be used in combination with other quotient polynomials. To this end, a test polynomial can be used in the blind rotation 464, which is configured to multiply the test polynomial modulo the quotient polynomial with the bootstrapping monomial corresponding to the plaintext, and take the desired function output of the plaintext as its constant (or other fixed) coefficient.
[0249] Specifically, to determine the test polynomial, the techniques disclosed in European patent application EP 21290080.7, filed by Zama SAS on December 7, 2021, titled "ENCRYPTED COMPUTATION COMPRISING A BLIND ROTATION" (incorporated herein by reference) can be used. As described there, general techniques can be used to determine the test polynomial given a quotient polynomial, for example, as discussed in the referenced section "Example test polynomial 4. Other quotient polynomials / coefficient" (incorporated by reference). Also as described in the reference, in the case where the fixed coefficient is the leading coefficient or the constant coefficient, and / or in the case where the quotient polynomial is the trinomial X N ±∈X N / 2 + 1, the test polynomial can be determined particularly efficiently.
[0250] Specifically, to program the constant coefficient, the coefficients of the test polynomial can be set to where p iare the coefficients of the quotient polynomial p(x), and K j is the corresponding expected output value. To program the leading coefficient, the coefficients of the test polynomial can be set similarly to This is also described in the above references in the sections "Example testpolynomial 1: fixed coefficient is constant coefficient" and "Example testpolynomial 2: fixed coefficient is leading coefficient" (incorporated herein by reference).
[0251] In the case where the quotient polynomial p(X) is a trinomial of the form p(X) = X N + ∈X N / 2 + 1, where N is even and ∈ ∈ {-1, 1}, a test polynomial with the following coefficients can be used to program the s-th coefficient, s < N / 2:
[0252]
[0253] This is also described in the above references in the section "Example test polynomial 3: quotient polynomialisX N ±X N / 2 + 1" (incorporated herein by reference).
[0254] When the quotient polynomial is not equal to X N + 1, additional details and other embodiments of programmable bootstrap are found in the above references and are incorporated by reference insofar as they relate to determining the quotient polynomial.
[0255] Figure 5a An embodiment of an implementation of a computer-implemented cryptographic computing method 500 is schematically shown.
[0256] Method 500 may include storing data representing a ciphertext. The ciphertext may include one or more random masked polynomials and a body polynomial derived from the masked polynomials and the plaintext. Method 500 may include obtaining 520 corresponding multiplicand polynomials for multiplying with the masked polynomials and the body polynomial. Method 500 may include expanding 530 the stored data representing the ciphertext. The stored data may include a seed of a pseudorandom number generator and a representation of the body polynomial in the Fourier domain of a number-theoretic transform. The expansion may include using the pseudorandom number generator according to the seed to generate a representation of the masked polynomial in the Fourier domain. Method 500 may include computing 540 the polynomial products of the masked polynomials and the body polynomial with the corresponding multiplicand polynomials. The polynomial products may be computed in the Fourier domain. The computation may produce a representation of the computed polynomial products in the Fourier domain. Method 500 may include outputting 550 the computed polynomial products.
[0257] Figure 5b An embodiment of an implementation of a computer-implemented method 600 for computing a representation of a ciphertext is schematically shown. The representation may be used for an encryption computation method according to any one of the preceding claims. Method 600 may include obtaining 610 a plaintext to be encrypted. Method 600 may include generating 620 a ciphertext. The ciphertext may include one or more masked polynomials and a body polynomial. Generating 620 may include obtaining 621 a seed for a pseudorandom number generator. Generating 620 may include randomly selecting 622 masked polynomials using the pseudorandom number generator according to the seed to generate a representation of the masked polynomials in the Fourier domain of a number-theoretic transform. Generating 620 may include applying 623 the inverse of the number-theoretic transform to the evaluation of the masked polynomials to determine the coefficients of the masked polynomials. Generating 620 may include using the plaintext to determine 624 the coefficients of the body polynomial such that the ciphertext encrypts the plaintext. Generating 620 may include applying 625 the number-theoretic transform to the coefficients of the body polynomial to determine a representation of the body polynomial in the Fourier domain. Method 600 may include outputting 630 a representation of the ciphertext, where the representation includes the seed and a representation of the body polynomial in the Fourier domain.
[0258] Many different ways of performing methods 500, 600 are possible, as will be apparent to those skilled in the art. For example, the order of the steps may be performed in the order shown, but the order of the steps may vary, or some steps may be performed in parallel. Additionally, other method steps may be inserted between the steps. The inserted steps may represent a refinement of the method, as described herein, or may be unrelated to the method. For example, some steps may be performed at least partially in parallel. Additionally, a given step may not be fully completed before the next step begins.
[0259] Embodiments of the described method can be implemented using software that includes instructions for causing a processor system to perform method 500 or 600. The software can include only those steps taken by a particular sub-entity of the system. The software can be stored in a suitable storage medium (such as a hard disk, floppy disk, memory, optical disc, etc.). The software can be sent wired or wirelessly as a signal, or using a data network (such as the Internet). The software can be available on a server for download and / or remote use. Embodiments of the method can be implemented using a bitstream arranged to configure programmable logic (such as a field-programmable gate array (FPGA)) to perform the method.
[0260] It will be understood that the presently disclosed subject matter also extends to a computer program, particularly a computer program on or in a carrier, adapted to put the presently disclosed subject matter into practice. The program can be in the form of source code, object code, intermediate source and object code (such as in a partially compiled form), or any other form suitable for use in implementing an embodiment of the method. An embodiment related to a computer program product includes computer-executable instructions corresponding to each processing step of at least one of the stated methods. These instructions can be subdivided into subroutines and / or stored in one or more files that can be statically or dynamically linked. Another embodiment related to a computer program product includes computer-executable instructions corresponding to each device, unit, and / or part of at least one of the stated systems and / or products.
[0261] Typically, the devices described herein (such as Figures 1a to 1b the devices in) include one or more microprocessors that execute appropriate software stored in the system; for example, the software may have been downloaded and / or stored in the corresponding memory, such as volatile memory such as RAM or non-volatile memory such as flash memory. Alternatively, the system can be implemented in whole or in part in programmable logic, such as as a field-programmable gate array (FPGA). The system can be implemented in whole or in part as a so-called application-specific integrated circuit (ASIC), such as an integrated circuit (IC) customized for its particular use. For example, the circuit can be implemented in CMOS using a hardware description language such as Verilog, VHDL, etc. Specifically, the system can include a circuit for evaluating cryptographic primitives. The processor circuit can be implemented in a distributed manner, such as as a plurality of sub-processor circuits. Storage can be distributed over a plurality of distributed sub-stores. Part or all of the memory can be electronic memory, magnetic memory, etc. For example, the memory can have volatile and non-volatile parts. Part of the storage may be read-only.
[0262] Figure 5cA computer-readable medium 1000 having a writable portion 1010 is shown, as well as a computer-readable medium 1001 that also has a writable portion. The computer-readable medium 1000 is shown in the form of an optically-readable medium. The computer-readable medium 1001 is shown in the form of an electronic memory, in this case a memory card. The computer-readable media 1000 and 1001 can store data 1020, where, according to one embodiment, the data can indicate instructions that, when executed by a processor system, cause the processor system to perform an embodiment of a method for performing calculations on LWE encrypted values.
[0263] Conversely or additionally, the data 1020 can represent ciphertext. The ciphertext can include one or more masked polynomials and a body polynomial derived from the masked polynomials and the plaintext. The data 1020 can include a seed of a pseudorandom number generator for generating a representation of the masked polynomials in the Fourier domain of a number-theoretic transform and a representation of the body polynomial in the Fourier domain. Specifically, the data 1020 can represent a bootstrapping key for programmable bootstrapping, where the bootstrapping key includes a plurality of corresponding such ciphertexts, e.g., ciphertexts encrypting corresponding values based on the key for programmable bootstrapping.
[0264] The data 1020 can be implemented on the computer-readable medium 1000 as a physical mark or by magnetization of the computer-readable medium 1000. However, any other suitable implementation is also conceivable. Additionally, it will be understood that although the computer-readable medium 1000 is shown here as an optical disc, the computer-readable medium 1000 can be any suitable computer-readable medium, such as a hard disk, solid-state memory, flash memory, etc., and can be non-recordable or recordable. The computer program 1020 includes instructions for causing the processor system to perform the method for performing calculations on LWE encrypted values.
[0265] Figure 5dProcessor system 1140 is shown in a schematic representation according to one embodiment of a device for performing cryptographic computations or computing a representation of a ciphertext. The processor system includes one or more integrated circuits 1110. The architecture of the one or more integrated circuits 1110 is schematically shown in FIG. 6b. Circuit 1110 includes a processing unit 1120 (e.g., a CPU) for running computer program components to execute a method according to one embodiment and / or implement its modules or units. Circuit 1110 includes a memory 1122 for storing programming code, data, etc. A portion of the memory 1122 may be read-only. Circuit 1110 may include communication elements 1126, e.g., an antenna, a connector, or both. Circuit 1110 may include an application-specific integrated circuit 1124 for performing some or all of the processing defined in the method. The processor 1120, the memory 1122, the application-specific integrated circuit 1124, and the communication elements 1126 may be connected to each other via an interconnect 1130 (e.g., a bus). The processor system 1110 may be arranged for contact and / or contactless communication, using an antenna and / or a connector, respectively.
[0266] For example, in one embodiment, the processor system 1140 (e.g., a device for performing cryptographic computations or computing a representation) may include a processor circuit and a memory circuit, the processor being arranged to execute software stored in the memory circuit. For example, the processor circuit may be an Intel Core i7 processor, an ARM Cortex-R8, etc. In one embodiment, the processor circuit may be an ARM Cortex M0. The memory circuit may be a ROM circuit, or a non-volatile memory (e.g., flash memory). The memory circuit may be a volatile memory (e.g., SRAM memory). In the latter case, the device may include a non-volatile software interface (e.g., a hard disk, a network interface, etc.) arranged to provide the software.
[0267] Although device 1110 is shown as including one of each of the described components, multiple components may be repeated in multiple embodiments. For example, the processor 1120 may include multiple microprocessors configured to independently execute the methods described herein or configured to execute steps or subroutines of the methods described herein such that multiple processors cooperate to achieve the functions described herein. Additionally, in the case where device 1110 is implemented in a cloud computing system, multiple hardware components may belong to separate physical systems. For example, the processor 1120 may include a first processor in a first server and a second processor in a second server.
[0268] It should be noted that the above-mentioned embodiments illustrate rather than limit the presently disclosed subject matter, and those skilled in the art will be able to design many alternative embodiments.
[0269] In a claim, any reference signs in parentheses shall not be construed as limiting the claim. The use of the verb “comprise” and its variants does not exclude the presence of elements or steps other than those stated in the claim. The article “a” or “an” preceding an element does not exclude the presence of a plurality of such elements. When an expression such as “at least one” is placed before a list of elements, it means any selection of all the elements or any subset of the elements from the list. For example, the expression “at least one of A, B and C” shall be understood to include only A, only B, only C, both A and B, both A and C, both B and C, or all of A, B and C. The presently disclosed subject matter may be implemented by hardware comprising several different elements, and by a suitably programmed computer. In a device claim enumerating several components, several of these components may be implemented by the same item of hardware. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.
[0270] In a claim, the reference signs in parentheses refer to reference symbols in the drawings of an exemplary embodiment or to the formula of an embodiment, thus enhancing the intelligibility of the claim. These reference signs shall not be construed as limiting the claim.
Claims
1. A computer-implemented encryption calculation method (500), comprising: - A memory (510) stores data representing a ciphertext, where the ciphertext includes one or more masking polynomials and a body polynomial derived from the masking polynomials and a plaintext; - Obtain (520) corresponding multiplicand polynomials for multiplying with the masking polynomials and the body polynomial; - Expand (530) the stored data representing the ciphertext, where the stored data includes a seed of a pseudorandom number generator and a representation of the body polynomial in the Fourier domain of a number-theoretic transform, and where the expansion includes using the pseudorandom number generator according to the seed to generate a representation of the masking polynomial in the Fourier domain; - Compute (540) polynomial products of the masking polynomials and the body polynomial with the corresponding multiplicand polynomials, where the polynomial products are computed in the Fourier domain, thereby producing a representation of the computed polynomial products in the Fourier domain; And - Output (550) the computed polynomial products.
2. The method (500) according to claim 1, wherein the method includes performing programmable bootstrapping according to a bootstrapping key, wherein the bootstrapping key includes a GGSW type ciphertext, and wherein the execution of the programmable bootstrapping includes the calculation of an outer product.
3. The method (500) according to claim 2, wherein performing the programmable bootstrapping includes performing blind rotation according to a test polynomial, wherein the blind rotation calculates the GLWE type encryption of a monomial multiplied by the test polynomial modulo a quotient polynomial, wherein the quotient polynomial is a polynomial with a leading coefficient of 1 and different from X N +1, where X is a variable and N is a positive integer.
4. The method (500) according to any one of claims 1-3, including calculating the outer product of a GGSW type ciphertext and a GLWE-based multiplicand ciphertext, wherein the GGSW type ciphertext includes a plurality of GLWE-based ciphertexts, and wherein the method includes multiplying the mask polynomial and the body polynomial of the corresponding GLWE-based ciphertext by the corresponding multiplicand polynomial based on the GLWE-based multiplicand ciphertext.
5. The method (500) according to claim 4, wherein the method includes inadvertently selecting the first GLWE-based ciphertext or the second GLWE-based ciphertext based on the GGSW type ciphertext by calculating the outer product of the difference between the GGSW type ciphertext and the first GLWE-based ciphertext and the second GLWE-based ciphertext, and adding the first GLWE-based ciphertext to the calculated outer product.
6. The method (500) according to any one of claims 1-3, including obtaining the coefficients of the corresponding multiplicand polynomial and applying a number-theoretic transform to transform the coefficients of the corresponding multiplicand polynomial into the Fourier domain, and / or applying an inverse number-theoretic transform to transform the representation of the calculated polynomial product in the Fourier domain into the coefficients of the calculated polynomial product.
7. The method (500) according to any one of claims 1-3, further including saving the extended storage data representing the ciphertext in a memory and using the extended storage data to calculate further polynomial products of the mask polynomial and the body polynomial with additional multiplicand polynomials.
8. The method (500) according to any one of claims 1 - 3, wherein the polynomial is defined modulo a quotient polynomial, where the quotient polynomial is divided by X M −1, where X is a variable and M is a positive integer.
9. The method (500) according to claim 8, wherein the quotient polynomial is (X M −1) / (X d −1), where M = hd and d = M - N, where h > 1, and d and N are positive integers.
10. The method (500) according to claim 9, wherein the quotient polynomial is X N +1 or X N + X N / 2 +1.
11. The method (500) according to claim 9, wherein the polynomial is defined over a set of base 2 64 −2 32 +1 or a set of bases equal to a power of 2.
12. A computer - implemented method (600) for computing a representation of a ciphertext, where the representation is used for an encryption - computing method according to any one of claims 1 - 10, the method comprising: - Obtain (610) a plaintext to be encrypted; - Generate (620) a representation of the ciphertext through the following steps, where the ciphertext includes one or more masking polynomials and a body polynomial: - Obtain (621) a seed for the pseudorandom number generator; - Randomly select (622) the masking polynomials by using the pseudorandom number generator according to the seed to generate a representation of the masking polynomials in the Fourier domain of a number-theoretic transform; - Apply (623) the inverse of the number-theoretic transform to the evaluation of the masking polynomials to determine the coefficients of the masking polynomials; - Use the plaintext to determine (624) the coefficients of the body polynomial such that the ciphertext encrypts the plaintext; And - Apply (625) the number-theoretic transform to the coefficients of the body polynomial to determine a representation of the body polynomial in the Fourier domain; - Output (630) the representation of the ciphertext, where the representation includes the seed and the representation of the body polynomial in the Fourier domain.
13. The method (600) according to claim 12, comprising generating a GGSW - type ciphertext by generating a plurality of ciphertexts having one or more masked polynomials and a body polynomial.
14. The method (600) according to claim 13, wherein the plurality of ciphertexts are based on the same seed.
15. A device (110, 112) for performing encryption computations, the device comprising: - A memory (140) stores data representing a ciphertext, where the ciphertext includes one or more masking polynomials and a body polynomial derived from the masking polynomials and a plaintext; - A processor system (130) is configured to: - Obtain corresponding multiplicand polynomials for multiplying with the masking polynomials and the body polynomial; - Expand the stored data representing the ciphertext, where the stored data includes a seed of a pseudorandom number generator and a representation of the body polynomial in the Fourier domain of a number-theoretic transform, and where the expansion includes using the pseudorandom number generator according to the seed to generate a representation of the masking polynomial in the Fourier domain; - Compute polynomial products of the masking polynomials and the body polynomial with the corresponding multiplicand polynomials, where the polynomial products are computed in the Fourier domain, thereby producing a representation of the computed polynomial products in the Fourier domain; And - Output the computed polynomial products.
16. An apparatus (110, 111) for computing a representation of a ciphertext, wherein the representation is for use in an encryption computing method according to any one of claims 1 to 11, the apparatus comprising: - A memory (140) stores the plaintext to be encrypted; - A processor system (130), the processor system being configured to: - Generate a representation of the ciphertext by the following steps, where the ciphertext includes one or more masked polynomials and a body polynomial: - Obtain a seed for a pseudorandom number generator; - Randomly select the masked polynomials by using the pseudorandom number generator according to the seed to generate a representation of the masked polynomials in the Fourier domain of a number-theoretic transform; - Apply an inverse of the number-theoretic transform to an evaluation of the masked polynomials to determine coefficients of the masked polynomials; - Use the plaintext to determine coefficients of the body polynomial such that the ciphertext encrypts the plaintext; And - Apply the number-theoretic transform to the coefficients of the body polynomial to determine a representation of the body polynomial in the Fourier domain; - Output the representation of the ciphertext, where the representation includes the seed and the representation of the body polynomial in the Fourier domain.
17. A non - transitory or transitory computer - readable storage medium (1000), comprising data representing: - instructions which, when executed by a processor system, cause the processor system to execute the method according to any one of claims 1 to 11 and / or execute the method according to any one of claims 12 to 14; and / or - a ciphertext, wherein the ciphertext includes one or more masked polynomials and a body polynomial derived from the masked polynomials and a plaintext, wherein the data includes a seed of a pseudo - random number generator for generating a representation of the masked polynomials in the Fourier domain of a number - theoretic transform, and a representation of the body polynomial in the Fourier domain.
Citation Information
Patent Citations
Encrypted computation comprising a blind rotation
EP4195577A1
Method and processing device for performing a lattice-based cryptographic operation
US20190312728A1