Privacy protection method, device and system based on cross-relinearization
By introducing cross-relinearization technology into MLWE fully homomorphic encryption, the computational efficiency of the complex vector Hadamard product is improved, solving the problems of insufficient computational complexity and hardware performance in existing technologies, and achieving a significant performance improvement.
Patent Information
- Application Number
- CN202411381589.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-09-30
AI Technical Summary
Existing fully homomorphic encryption algorithms based on MLWE have significant shortcomings in terms of computational complexity and hardware performance, especially in the inefficiency of computing the Hadamard product of complex vectors, making it difficult to fully utilize the parallel capabilities of hardware such as GPUs.
By introducing cross-relinearization, the computational efficiency of the Hadamard product is improved by negotiating homomorphic encryption parameters and operating on the ciphertext using the cross-relinearization key and the rank reduction key, thus avoiding the need for the executor to obtain the Hadamard product of complex vectors.
It significantly improves the computational efficiency of the MLWE-based fully homomorphic encryption algorithm, especially when performing homomorphic multiplication on GPUs, achieving a 3.61x performance improvement and reducing the computation time of the relinearization algorithm.
Smart Images

Figure CN119598501B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of privacy protection, and particularly relates to a privacy protection method, device and system based on cross-relinearization. BACKGROUND
[0002] With the introduction of the national data security law, cloud computing service providers will face growing privacy protection needs when processing user sensitive data. Full homomorphic encryption is one of the powerful tools to solve this problem, which allows service providers to perform calculations on user encrypted data, thereby ensuring user privacy and security throughout the data transmission chain. However, current full homomorphic encryption algorithms often consume a large amount of computing resources and time, which greatly limits the practicality of homomorphic encryption. Currently, full homomorphic encryption is mainly divided into two technical routes: full homomorphic encryption based on arithmetic circuits (such as BGV, CKKS) and full homomorphic encryption based on Boolean circuits (such as TFHE, FHEW). The former has strong SIMD characteristics and can greatly improve the throughput of calculations, while the latter can support more flexible function evaluation and faster boot operations. For privacy-protected machine learning and other tasks with high parallel requirements, homomorphic encryption based on arithmetic circuits is a more common choice.
[0003] To address the performance issues of full homomorphic encryption, many implementations have started using special hardware such as GPUs, FPGAs, etc. As a widely used hardware device for AI acceleration, GPUs provide significant speedup for traditional cryptography algorithms such as RSA and ECC, with performance over 1000 times that of CPU platforms. However, in the field of full homomorphic encryption, this performance improvement is not obvious, with only about 200 times performance improvement in some recent work. GPUs provide considerable on-chip memory, with each stream processor typically containing 64 thousand 32-bit registers and 48-228 kB of shared memory, but full homomorphic encryption algorithms often struggle to fully utilize the parallel capabilities of GPUs. For example, the CKKS algorithm based on the RLWE difficulty problem requires the use of large-scale polynomial operations, and the degree of these polynomials is often as high as 2 15 or 2 16 . Such large-scale operations require reliance on low-speed global memory, which is mainly due to the presence of a large number of cross-thread collaborations in the calculation.
[0004] Although most of the current homomorphic encryption algorithms rely on the RLWE difficulty problem, more and more researches begin to turn to the fully homomorphic encryption algorithm based on the MLWE difficulty problem. Compared with RLWE, the homomorphic encryption algorithm based on MLWE has better hardware-friendly characteristics while improving security. It allows us to adjust the security by rank without changing the polynomial degree of the difficulty problem to adapt to the homomorphic encryption parameters required by the current task. However, the fully homomorphic encryption based on MLWE has unacceptable computational complexity. For example, when the rank used by MLWE is 2, the scheme based on MLWE has a 1.7 times performance loss compared with the scheme based on RLWE at the same circuit depth, and this performance loss will further increase with the increase of the rank. In addition, the scheme based on MLWE also has a larger scale of keys. SUMMARY
[0005] In view of the above problems, the application provides a privacy protection method, device and system based on cross-relinearization, which can not only prevent the calculation execution party from obtaining the Hadamard product between complex vectors, but also improve the calculation efficiency of the Hadamard product.
[0006] To achieve the above-mentioned purposes, the technical scheme of the application includes the following contents.
[0007] A privacy protection method based on cross-relinearization is applied to a calculation execution method, and the method comprises the following steps.
[0008] Negotiating homomorphic encryption parameters with a data holder, wherein the homomorphic encryption parameters comprise a polynomial degree n, a rank r, an approximate scaling coefficient Δ, a maximum multiplication layer L and a corresponding ciphertext modulus Q L ;
[0009] Obtaining ciphertext ct1, ciphertext ct2, cross-relinearization keys and rank reduction keys sent by the data holder, wherein the ciphertext ct1 and the ciphertext ct2 are respectively generated based on complex vectors and ;
[0010] Calculating the Kronecker product between the ciphertext ct1 and the ciphertext ct2 wherein c0 is the first polynomial in the Kronecker product ct, is a polynomial vector composed of r polynomials after the polynomial c0, is a polynomial vector composed of r(r+1) / 2 polynomials after the vector ;
[0011] Based on the cross-relinearization keys and the rank reduction keys, the polynomial vector The cross-relinearization operation and the rank reduction operation are sequentially performed to obtain a cross-relinearization result and a rank reduction result and a polynomial vector pair the cross-relinearization result and the rank reduction result performing homomorphic addition;
[0012] After performing the rescaling operation on the homomorphic addition result ct', the rescaling result ct'' is transmitted to the data holder, so that the data holder obtains a complex vector and a complex vector Hadamard product based on the rescaling result ct'' which cannot be obtained by the calculation execution method.
[0013] Further, the ciphertext ct1 and the ciphertext ct2 are respectively generated based on a complex vector and a complex vector , comprising:
[0014] The data holder generates a public-private key pair
[0015] Encode the complex vector and the complex vector into polynomials m1(X) and m2(X) respectively, so that wherein the encoding mapping Ecd: the mapping function τ: The mapping maps the polynomial m(X) to the complex vector denotes the complex number field, denotes the real number field;
[0016] Encrypt the polynomials m1(X) and m2(X) using the public key pk to obtain the ciphertexts ct1 and ct2 respectively.
[0017] Further, the process of generating the cross-relinearization key comprises:
[0018] Introducing a temporary special modulus Defining a gadget vector used by the cross-relinearization key wherein K is a positive integer constant, p i is a small modulus coprime, the special modulus k is a positive integer constant, μ is a small constant, and and For 0≤j<μ, q i is an RNS base consisting of the ciphertext modulus;
[0019] Introducing temporary rank And generate a temporary private key vector in, ring of polynomials with integer coefficients Regarding the cycloid polynomial X n +1 quotient ring;
[0020] From matrix space Sampling in a uniform distribution Sample noise vector from noise distribution For 0 ≤ j < μ;
[0021] Output cross-relinearization key crlk={crlk j} 0≤j<μ ; where the j-th component
[0022] Furthermore, the process of generating the rank-down key includes:
[0023] Define the gadget vector used for the rank descent key in α is a small constant, and we have and For 0≤j′ <d;
[0024] From matrix space Sampling in a uniform distribution Sample noise vector from noise distribution For 0≤j′ <d;
[0025] Output rank-decreasing key rdk = {rdk j′} 0≤j′<d ; where the j′-th component
[0026] Furthermore, based on the cross-relinearization key and the rank-decreasing key pair, the polynomial vector is... Perform the cross-relinearization operation and the rank descent operation sequentially to obtain the cross-relinearization result. Rank decrease results include:
[0027] For polynomial vectors Performing the inverse number-theoretic transformation yields a polynomial vector.
[0028] For polynomial vectors Perform gadget decomposition to obtain a polynomial. in 0≤i<μ;
[0029] Performing number theoretic transformation on the polynomial C μ , we get the polynomial
[0030] Computing the formal inner product of the cross-relinearization key and the polynomial , we get
[0031] Performing inverse number theoretic transformation on the formal inner product , we get the polynomial
[0032] Computing modulus reduction on the polynomial , we get the polynomial vector wherein is the first polynomial in the polynomial vector , and is the polynomial vector composed of the last polynomials in the polynomial vector ;
[0033] Computing NTT transformation on the 0th polynomial to the rth polynomial in the polynomial vector , we get the cross-relinearization result
[0034] Computing gadget decomposition on the r+1th polynomial to the th polynomial in the polynomial vector , we get the polynomial wherein the ith polynomial in the polynomial C d is for 0≤i
[0035] Performing number theoretic transformation on the polynomial C d , we get the polynomial
[0036] Computing the formal inner product of the rank reduction key and the polynomial , we get
[0037] Performing inverse number theoretic transformation on the formal inner product , we get the polynomial
[0038] Computing modulus reduction on the polynomial , we get the polynomial
[0039] Performing number theoretic transformation on the polynomial , we get the rank reduction result
[0040] Further, the data holder obtains a Hadamard product of complex vectors and based on the re-scaling result ct"
[0041] decrypts the re-scaling result ct" with a private key to obtain a plaintext m'(X);
[0042] decodes the plaintext m'(X) based on the approximate scaling coefficient Δ and a mapping function τ to obtain a Hadamard product of complex vectors and .
[0043] Further, after negotiating the homomorphic encryption parameters with the data holder, the method further comprises:
[0044] obtaining a security strength λ corresponding to the homomorphic encryption parameters;
[0045] judging whether the security strength λ is greater than a set threshold value;
[0046] in a case where the security strength λ is less than the set threshold value, returning to the negotiating the homomorphic encryption parameters with the data holder to negotiate new homomorphic encryption parameters;
[0047] in a case where the security strength λ is greater than the set threshold value, jumping to the obtaining the ciphertext ct1, the ciphertext ct2, the cross-relinearization key and the rank-reduction key sent by the data holder.
[0048] A privacy protection device based on cross-relinearization, the device comprising:
[0049] a negotiation module configured to negotiate homomorphic encryption parameters with a data holder, the homomorphic encryption parameters comprising: a polynomial degree n, a rank r, an approximate scaling coefficient Δ and a maximum multiplication layer number L and a corresponding ciphertext modulus Q L ;
[0050] an obtaining module configured to obtain a ciphertext ct1, a ciphertext ct2, a cross-relinearization key and a rank-reduction key sent by the data holder; wherein the ciphertext ct1 and the ciphertext ct2 are respectively generated based on complex vectors and .
[0051] a first calculating module configured to calculate a Kronecker product between the ciphertext ct1 and the ciphertext ct2, wherein c0 is a first polynomial in the Kronecker product ct, is a polynomial vector composed of r polynomials after the polynomial c0, is a vector r(r+1) / 2 polynomials after c0 form a polynomial vector;
[0052] the second computing module is configured to perform cross-relinearization and rank reduction operations on the polynomial vector in sequence to obtain cross-relinearization results and rank reduction results and a Hadamard product of the polynomial vector pair the cross-relinearization results and the rank reduction results perform homomorphic addition;
[0053] the third computing module is configured to perform a re-scaling operation on the homomorphic addition result ct' and transmit a re-scaling result ct" to the data holder, so that the data holder obtains a complex vector and a Hadamard product of the complex vector .
[0054] A privacy protection system based on cross-relinearization, the system comprising a computing execution party and at least one data holder;
[0055] the computing execution party is configured to:
[0056] negotiate homomorphic encryption parameters with the data holder, the homomorphic encryption parameters comprising a polynomial degree n, a rank r, an approximate scaling coefficient Δ, a maximum multiplication layer number L and a corresponding ciphertext modulus Q L ;
[0057] obtain a ciphertext ct1, a ciphertext ct2, a cross-relinearization key and a rank reduction key sent by the data holder, wherein the ciphertext ct1 and the ciphertext ct2 are generated based on a complex vector and a complex vector .
[0058] calculate a Kronecker product between the ciphertext ct1 and the ciphertext ct2 wherein c0 is the first polynomial in the Kronecker product ct, is a polynomial vector composed of r polynomials after c0, is a polynomial vector composed of r(r+1) / 2 polynomials after ;
[0059] perform cross-relinearization and rank reduction operations on the polynomial vector in sequence to obtain cross-relinearization results and rank reduction result and polynomial vector cross-relinearization result and rank reduction result performing homomorphic addition; transmitting the re-scaling result ct'' to the data holder after performing a re-scaling operation on the homomorphic addition result ct';
[0060] the data holder, configured to:
[0061] negotiate homomorphic encryption parameters with the data holder, the homomorphic encryption parameters comprising: a polynomial degree n (a power of 2), a rank r, an approximate scaling coefficient Δ, and a maximum multiplication layer number L and a corresponding ciphertext modulus Q L ;
[0062] generate a cross-relinearization key and a rank reduction key;
[0063] based on the complex vector and the complex vector generate ciphertext ct1 and ciphertext ct2;
[0064] send the ciphertext ct1, the ciphertext ct2, the cross-relinearization key, and the rank reduction key to the computation execution party;
[0065] obtain the complex vector and the complex vector Hadamard product based on the re-scaling result ct'' returned by the computation execution party.
[0066] An electronic device, comprising: a processor and a memory storing computer program instructions; the processor implements the privacy protection method based on cross-relinearization of any one of the above when executing the computer program instructions.
[0067] Compared with the prior art, the present application first introduces a homomorphic rank transformation in the full homomorphic encryption based on MLWE, provides better performance for the full homomorphic encryption realized based on hardware, so that the computation execution party cannot obtain the Hadamard product between the complex vectors. BRIEF DESCRIPTION OF DRAWINGS
[0068] Figure 1 is a flowchart of the privacy protection method based on cross-relinearization of the present application.
[0069] Figure 2 is a block diagram of the homomorphic multiplication operation using cross-relinearization of the present application. DETAILED DESCRIPTION
[0070] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be analyzed and expressed more comprehensively and completely. Obviously, the described embodiments are only part of the embodiments of the present invention. For further explanation of the present invention, to enable those skilled in the art to clearly and thoroughly understand the present invention, it is not used to limit the present invention.
[0071] The privacy protection method based on cross-linearization of the present invention is implemented in fully homomorphic encryption based on MLWE. The generalized MLWE key conversion technology aims to convert a polynomial vector encrypted with a private key into an MLWE ciphertext ct encrypted with a private key where r1 and r2 are positive integers. This technology relies on a pre-generated evaluation key swk. First, define the gadget vector as g = (g0,..., g d-1 ), where and q i is the RNS basis that makes up the ciphertext modulus. For 0 ≤ j < d, d is called the decomposition size. This key is generated as follows: Given the private keys and sample a matrix A′ from the uniform distribution of the matrix space and sample a vector from the noise distribution. Output swk = {swk j}, where the j-th component is 0≤j<d , where the j-th component is
[0072]
[0073] On the premise of publicly disclosing the above evaluation key, given an encrypted vector This key conversion algorithm performs the following steps:
[0074] · Calculate the gadget decomposition: where
[0075] · Calculate the inner product:
[0076] · Modulus reduction: ct = [P -1 · ct up .
[0077] The ciphertext output by this algorithm satisfies For the convenience of the following description, denote this key conversion algorithm as
[0078] The above-mentioned related definitions also include: for a positive integer power n of 2, define a polynomial ring and its modulo q quotient ring Definition The module of the above rank r is The first layer of the ciphertext modulus where q j are pairwise prime, is the current number of homomorphic ciphertext layers, L is the maximum number of layers that can be evaluated, 0≤l≤L. The special modulus where p i are pairwise prime, and are pairwise prime with any q j , k is a positive integer constant. An MLWE ciphertext of rank r has the form
[0079] In one embodiment, the privacy computing of the approximate value of the Hadamard product of two complex vectors is calculated as the target, where represents the set of all complex vectors of length n / 2. Where the data holder does not want the computing executor to know the input and output of the calculation. is a flowchart of a cross-relinearization-based privacy protection method of this embodiment, including the following steps 1 to 5. Figure 1
[0080] Step 1: The computing executor and the data holder negotiate homomorphic encryption parameters.
[0081] The data holder and the computing executor negotiate a set of homomorphic encryption parameters, including the polynomial degree n, the rank r, the maximum number of multiplication layers L, the maximum ciphertext modulus Q L =∏ 0≤j≤L q j , the approximate scaling coefficient Δ. Where q j is the RNS base that makes up the ciphertext modulus.
[0082] In a preferred embodiment, the application also obtains the security strength λ corresponding to the above homomorphic encryption parameters, and judges whether the security strength λ is greater than a set threshold value: in the case where the security strength λ is less than the set threshold value, return to negotiating the homomorphic encryption parameters with the data holder to negotiate new homomorphic encryption parameters; in the case where the security strength λ is greater than the set threshold value, jump to obtaining the ciphertext ct1, the ciphertext ct2, the cross-relinearization key and the rank reduction key sent by the data holder.
[0083] Step 2: The computing executor obtains the ciphertext ct1, the ciphertext ct2, the cross-relinearization key and the rank reduction key sent by the data holder.
[0084] (1) Generation of ciphertext ct1 and ciphertext ct2.
[0085] The ciphertexts ct1 and ct2 of this invention are based on complex vectors by the data holder. and complex vectors The main steps include:
[0086] Step 2.1.1: Generate encryption key.
[0087] The data holder generates an encrypted private key. And use this to calculate the public key used for encryption and decryption.
[0088]
[0089] in, Indicates r in the business cycle A vector set consisting of the elements on the vector. The modulus is Q L The business environment, Represents r×r units in the commerce ring A vector set consisting of elements of the polynomial matrix A uniformly sampled on the quotient ring. noise vector Sampled from noise distribution.
[0090] Step 2.1.2: Convert the complex vector and complex vectors The encodings are respectively encoded as polynomials. and polynomial
[0091] This invention encodes two complex vectors into polynomials, such that...
[0092]
[0093] Here the encoding is mapped to Ecd: Where τ: The mapping maps the polynomial m(X) to By evaluating m(X) in The values of these points, ξ, are primitive roots of order 2n. Here, two vectors are encoded as m1(X) and m2(X) respectively.
[0094] Step 2.1.3: Pair the polynomial with the encryption key and polynomial Encrypt it.
[0095] The data holder computes the public key encryption of two plaintext polynomials. Samples are taken separately. With noise vector Encryption of plaintext m(X) is calculated using this: noise vector Sampling from the noise distribution
[0096]
[0097] Here two plaintexts are encrypted into ciphertexts and where b is the first polynomial in ciphertext ct, is the polynomial vector consisting of the last r polynomials in ciphertext ct.
[0098] (2) Generation of cross-relinearization key and rank-reduction key.
[0099] The present application uses twice key-switching technique to realize the relinearization algorithm. In the first time, the rank of ciphertext is raised by using low-cost key-switching algorithm, and in the second time, the rank is reduced by using key-switching algorithm. For this purpose, the algorithm needs to generate two evaluation keys in advance: cross-relinearization key crlk and rank-reduction key rdk.
[0100] For the cross-relinearization key, the key aims to relinearize the ciphertext while obtaining a ciphertext with a higher rank. The gadget vector used by the key is defined as where μ is a small constant. In addition, a temporary special modulus is introduced where K is a positive integer constant, p i is a small modulus that is co-prime. In order to maintain the security of the key under the modulus , a temporary rank is used. At the same time, the private key generation function generates a temporary private key vector Given the original private key and the temporary private key vector The cross-relinearization key is generated by the following way: sampling from the uniform distribution in sampling from the noise distribution Output crlk = {crlk j} 0≤j<μ , where the j-th component is
[0101]
[0102] For the rank-reduction key, the key uses the original gadget vector and the special modulus P, and is generated by the following way: sampling from the uniform distribution in sampling from the noise distribution Output rdk = {rdk j} 0≤j<d , where
[0103]
[0104] Given the two keys described above, we can use the following steps to implement the relinearization operation on the MLWE ciphertext :
[0105] • Compute:
[0106] • Compute:
[0107] • Output:
[0108] The ciphertext output by this algorithm satisfies
[0109] Step 3: The computing party computes the Kronecker product between the ciphertext ct1 and the ciphertext ct2.
[0110] The Kronecker product between the ciphertext ct1 and the ciphertext ct2 is composed of three parts. c0 is the first polynomial in the Kronecker product ct, is a polynomial vector composed of the r polynomials after c0, is a polynomial vector composed of the r(r+1) / 2 polynomials after the vector .
[0111] Step 4: The computing party combines the cross-relinearization key and the rank reduction key to perform cross-relinearization, rank reduction, and homomorphic addition operations on the ciphertext obtained by the Kronecker product to realize the relinearization of the ciphertext.
[0112] The present application is based on the cross-relinearization key and the rank reduction key to perform the cross-relinearization operation and the rank reduction operation on the polynomial vector in turn, to obtain the cross-relinearization result and the rank reduction result and perform homomorphic addition on the polynomial vector pair the cross-relinearization result and the rank reduction result .
[0113] As shown in Figure 2 , the overall flow of the homomorphic addition of the present application includes the following steps 4.1 to step 4.3.
[0114] Step 4.1: Calculate the cross-relinearization.
[0115] The calculation process of cross-relinearization mainly includes the following steps 4.1.1 to 4.1.7.
[0116] Step 4.1.1: For polynomial vectors Performing the inverse number-theoretic transformation yields a polynomial vector.
[0117] Step 4.1.2: For polynomial vectors Perform gadget decomposition to obtain a polynomial. in For 0 ≤ i < μ.
[0118] Step 4.1.3: For polynomial C μ By performing number theory transformations, we obtain the polynomial.
[0119] Step 4.1.4: Calculate the cross-relinearization key and the polynomial. Formal inner product
[0120] Step 4.1.5: Apply the formal inner product By performing the inverse transformation of number theory, we obtain the polynomial.
[0121] Step 4.1.6: For the polynomial The modulus descent is used to obtain the polynomial vector. in, It is a polynomial vector The first polynomial in the equation, It is a polynomial vector After A polynomial vector composed of 3 polynomials.
[0122] Step 4.1.7: Calculate the polynomial vector The NTT transformation from the 0th polynomial to the rth polynomial yields the cross-relinearization result.
[0123] Step 4.2: Calculate rank descent.
[0124] The calculation process for rank descent mainly includes the following steps 4.2.1 to 4.2.6.
[0125] Step 4.2.1: Calculate the polynomial From the (r+1)th to the th Gadget decomposition of a polynomial yields a polynomial Among them, polynomial C d The i-th polynomial in for 0≤i
[0126] Step 4.2.2: Perform number theoretic transformation on the polynomial C d to obtain the polynomial
[0127] Step 4.2.3: Calculate the rank-reduced key and the inner product of the form
[0128] Step 4.2.4: Perform inverse number theoretic transformation on the inner product of the form to obtain the polynomial
[0129] Step 4.2.5: Calculate the modulus reduction on the polynomial to obtain the polynomial
[0130] Step 4.2.6: Perform number theoretic transformation on the polynomial to obtain the rank-reduced result
[0131] Step 4.3: The calculation execution party performs homomorphic addition and returns the ciphertext.
[0132] The calculation execution party first calculates the homomorphic addition and outputs
[0133] Step 5: The calculation execution party performs the rescaling operation on the homomorphic addition result ct' and transmits the rescaling result ct'' to the data holding party, so that the data holding party obtains the Hadamard product of the complex vector and the complex vector based on the rescaling result ct''.
[0134] The calculation execution party first calculates the ct' rescaling result Finally, the ciphertext ct'' is transmitted to the data holding party.
[0135] The data holding party first calculates the decryption of the ciphertext ct'', to obtain the plaintext Then calculate the decoding of the plaintext m'(X) is the expected result, that is, the approximate value of the Hadamard product of the complex vector and the complex vector
[0136] To verify the present application, an experimental verification of one homomorphic ciphertext multiplication was performed on an NVIDIA RTX4090. Among them, the polynomial degree is 2 14 , and the rank is 4. The CKKS algorithm based on the traditional MLWE takes 31.36 ms to calculate, while the algorithm provided by the present application takes 8.686 ms to calculate, which has a performance advantage of 3.61 times compared with the traditional operation. This advantage will further expand as the rank increases.
[0137] In summary, the homomorphic multiplication and the relinearization algorithm related thereto are the performance bottlenecks of the homomorphic encryption algorithm based on MLWE. By using the technology provided by the present application, the calculation time of the relinearization algorithm can be effectively reduced.
[0138] Other embodiments of the present disclosure will be readily apparent to those skilled in the art upon considering the specification and practice of the present disclosure. The present disclosure is intended to cover any variations, uses or adaptive changes of the present disclosure following the general principles of the present disclosure and including common knowledge or conventional technical means in the technical field of the present disclosure not disclosed by the present disclosure. The specification and examples are only regarded as exemplary, and the present disclosure is also not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof.
Claims
1. A privacy protection method based on cross-relinearization, characterized in that, Applied to a computational execution method, the method comprising: The homomorphic encryption parameters are negotiated with the data holder, including: polynomial degree n, rank r, approximate scaling factor Δ, maximum number of multiplication layers L, and corresponding ciphertext modulus Q. L ; Obtain the ciphertext ct1, ciphertext ct2, cross-relinearization key, and rank descent key sent by the data holder; wherein, ciphertext ct1 and ciphertext ct2 are based on complex vectors. and complex vectors generate; Calculate the Kronecker product between ciphertext ct1 and ciphertext ct2. Where c0 is the first polynomial in the Kronecker product ct. It is a polynomial vector consisting of r polynomials following polynomial c0. It is a vector The polynomial vector consisting of the following r(r+1) / 2 polynomials; The polynomial vector is based on the cross-relinearization key and the rank descent key. Perform the cross-relinearization operation and the rank descent operation sequentially to obtain the cross-relinearization result. Rank decrease results And for polynomial vector pairs Cross-relinearization results Rank decrease results Perform homomorphic addition; After rescaling the homomorphic addition result ct′, the rescaled result ct″ is transmitted to the data holder, enabling the data holder to obtain a complex vector that the computation execution method cannot obtain based on the rescaled result ct″. and complex vectors The Hadamard product.
2. The method according to claim 1, characterized in that, The ciphertext ct1 and ciphertext ct2 are respectively based on complex vectors. and complex vectors Generation, including: The data holder generates a public / private key pair. The complex vector and the complex vector Encode them as polynomials m1(X) and m2(X) respectively, such that Among them, encoding mapping Where the canonical embedding mapping Map the polynomial m(X) to a complex vector Represents the field of complex numbers. Represents the real number field; The polynomials m1(X) and m2(X) are encrypted using the public key pk, respectively, to obtain ciphertext ct1 and ciphertext ct2.
3. The method according to claim 1, characterized in that, The process of generating the cross-relinearization key includes: Introducing temporary special modulus Define the gadget vector used for cross-relinearization keys. Where K is a positive integer constant, p i Small modules that are coprime, special modules k is a positive integer constant, μ is a small constant, and has and For 0 ≤ j < μ, q i It is the RNS basis that makes up the ciphertext modulus; Introducing temporary rank And generate a temporary private key vector in, ring of polynomials with integer coefficients Regarding the cycloid polynomial X n +1 quotient ring; From matrix space Sampling in a uniform distribution Sample noise vector from noise distribution For 0 ≤ j < μ; Output cross-relinearization key crlk={crlk j } 0≤j<μ ; where the j-th component 4. The method according to claim 3, characterized in that, The process of generating the rank-down key includes: Define the gadget vector used for the rank descent key in α is a small constant, and we have and For 0≤j′ <d; From matrix space Sampling in a uniform distribution Sample noise vector from noise distribution For 0≤j′ <d; Output rank-decreasing key rdk = {rdk j′ } 0≤j′<d ; where the j′-th component 5. The method according to claim 3, characterized in that, The polynomial vector is based on the cross-relinearization key and the rank descent key. Perform the cross-relinearization operation and the rank descent operation sequentially to obtain the cross-relinearization result. Rank decrease results include: For polynomial vectors Performing the inverse number-theoretic transformation yields a polynomial vector. For polynomial vectors Perform gadget decomposition to obtain a polynomial. in For polynomial C μ By performing number theory transformations, we obtain the polynomial. Calculate the cross-relinearization key and the polynomial Formal inner product Formal inner product By performing the inverse transformation of number theory, we obtain the polynomial. For polynomials The modulus descent is used to obtain the polynomial vector. in, It is a polynomial vector The first polynomial in the equation, It is a polynomial vector After A polynomial vector composed of 3 polynomials; Calculate polynomial vectors The NTT transformation from the 0th polynomial to the rth polynomial yields the cross-relinearization result. Calculate polynomials From the (r+1)th to the th Gadget decomposition of a polynomial yields a polynomial Among them, polynomial C d The i-th polynomial in For 0≤i <d; For polynomial C d By performing number theory transformations, we obtain the polynomial. Calculate the rank descent key and the polynomial Formal inner product Formal inner product The inverse transformation of number theory yields a polynomial. For polynomials The modulus descent is calculated to obtain the polynomial. For polynomials Performing number theory transformations, we obtain the rank descent result.
6. The method according to claim 1, characterized in that, The data holder obtains the complex vector based on the rescaling result ct″. and complex vectors The Hadamard product includes: Using private key Decrypt the rescaled result ct″ to obtain the plaintext m′(X); The plaintext m′(X) is decoded based on the approximate scaling factor Δ and the mapping function τ to obtain a complex vector. and complex vectors The approximation of the Hadamard product.
7. The method according to any one of claims 1 to 6, characterized in that, After negotiating the homomorphic encryption parameters with the data holder, it also includes: Obtain the security strength λ corresponding to the homomorphic encryption parameters; Determine whether the security strength λ is greater than a set threshold; If the security strength λ is less than a set threshold, the process returns to negotiating homomorphic encryption parameters with the data holder to negotiate new homomorphic encryption parameters. If the security strength λ is greater than a set threshold, the system will jump to the ciphertext ct1, ciphertext ct2, cross-relinearization key, and rank reduction key sent by the data holder.
8. A privacy protection device based on cross-reproducibility, characterized in that, The device includes: The negotiation module is used to negotiate homomorphic encryption parameters with the data holder. These parameters include: polynomial degree n, rank r, approximate scaling factor Δ, maximum multiplication layer L, and corresponding ciphertext modulus Q. L ; The acquisition module is used to acquire ciphertext ct1, ciphertext ct2, the cross-relinearization key, and the rank descent key sent by the data holder; wherein, ciphertext ct1 and ciphertext ct2 are based on complex vectors. and complex vectors generate; The first calculation module is used to calculate the Kronecker product between ciphertext v1 and ciphertext ct2. Where c0 is the first polynomial in the Kronecker product ct. It is a polynomial vector consisting of r polynomials following polynomial c0. It is a vector The polynomial vector consisting of the following r(r+1) / 2 polynomials; The second computation module is used to calculate the polynomial vector based on the cross-relinearization key and the rank descent key. Perform the cross-relinearization operation and the rank descent operation sequentially to obtain the cross-relinearization result. Rank decrease results And for polynomial vector pairs Cross-relinearization results Rank decrease results Perform homomorphic addition; The third computation module is used to perform a rescaling operation on the homomorphic addition result ct′ and then transmit the rescaled result ct″ to the data holder, so that the data holder can obtain a complex vector that the computation executor cannot obtain based on the rescaled result ct″. and complex vectors The Hadamard product.
9. A privacy protection system based on cross-reproducibility, characterized in that, The system includes a computation executor and at least one data holder; The computation executor is used for: The homomorphic encryption parameters are negotiated with the data holder, including: polynomial degree n, rank r, approximate scaling factor Δ, maximum number of multiplication layers L, and corresponding ciphertext modulus Q. L ; Obtain the ciphertext ct1, ciphertext ct2, cross-relinearization key, and rank descent key sent by the data holder; wherein, ciphertext ct1 and ciphertext ct2 are based on complex vectors. and complex vectors generate; Calculate the Kronecker product between ciphertext ct1 and ciphertext ct2. Where c0 is the first polynomial in the Kronecker product ct. It is a polynomial vector consisting of r polynomials following polynomial c0. It is a vector The polynomial vector consisting of the following r(r+1) / 2 polynomials; The polynomial vector is based on the cross-relinearization key and the rank descent key. Perform the cross-relinearization operation and the rank descent operation sequentially to obtain the cross-relinearization result. Rank decrease results And for polynomial c0, polynomial vector Cross-relinearization results Rank decrease results Perform homomorphic addition; after rescaling the homomorphic addition result ct′, transmit the rescaled result ct″ to the data holder; The data holder is used for: The homomorphic encryption parameters are negotiated with the data holder, including: polynomial degree n (a power of 2), rank r, approximate scaling factor Δ, maximum number of multiplication layers L, and corresponding ciphertext modulus Q. L ; Generate cross-relinearization keys and rank-decreasing keys; Based on complex vectors and complex vectors Generate ciphertext ct1 and ciphertext ct2; Send the ciphertext ct1, ciphertext ct2, cross-relinearization key, and rank reduction key to the computation executor; Based on the rescaling result ct″ returned by the computation executor, a complex vector that cannot be obtained by the computation executor is acquired. and complex vectors The Hadamard product.
10. An electronic device, characterized in that, The electronic device includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the privacy protection method based on cross-reproducibility as described in any one of claims 1 to 7.
Citation Information
Patent Citations
An efficient homomorphic encryption scheme for bilinear forms
CN102822816A
High-dimensional data rapid dimension reduction method based on CKKS homomorphic encryption
CN118233079A