Secret key with special digits
By using keys with common digits and/or digits with predetermined values in the key set, the shortcomings of existing TFHE encryption computing technology in terms of computing efficiency, storage requirements and flexibility in cryptographic parameters are solved, and more efficient and flexible encryption computing is achieved.
Patent Information
- Application Number
- CN202380067890.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-08-18
- Filing Date
- 2023-08-17
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2043-08-17
AI Technical Summary
The existing TFHE-based encryption computing technology has shortcomings in terms of computing efficiency, storage requirements of key materials, and flexibility of cryptographic parameters.
By changing the way the keys forming the key sets, a key with common digits and/or a key with a predetermined value is used to improve the efficiency of key-related operations, reduce the storage requirements of key materials, and improve the flexibility of cryptographic parameters.
It realizes more efficient cryptographic calculations, reduces the storage requirements of key materials, and provides greater flexibility in the selection of cryptographic parameters.
Smart Images

Figure CN119948802A_ABST
Abstract
Description
Technical Field
[0001] The subject matter of the present disclosure relates to a cryptographic method for performing cryptographic calculations, to a corresponding cryptographic device, and to a computer-readable medium. Background Art
[0002] Homomorphic cryptography allows encrypted computations to be performed on encrypted data by a party without that party being able to decrypt it: a computation, such as evaluating a circuit, can receive input data and return computation results in encrypted form. Intermediate data (e.g., the internal state of a computation) can also be in encrypted form.
[0003] Even if the result of a computation is returned in encrypted form, when decrypted, the expected output is the same or very close to it as if the operation was performed on the unencrypted data. Homomorphic encryption can be used to outsource storage and computation with privacy preservation. This allows data to be encrypted and outsourced to a cloud environment for processing and / or storage, all while being encrypted.
[0004] For example, homomorphic cryptography can be applied in fields such as healthcare, where privacy regulations make it difficult to share plaintext data, but allow computations on encrypted medical data. For example, a medical model developed to, for example, classify medical data can be configured to receive medical data in encrypted form from a third party (e.g., a hospital). The medical model can, for example, classify medical data as normal or abnormal, or as having a specific medical syndrome, disease, or other disorder. Using homomorphic encryption, the medical model can be applied to medical data received in encrypted form. This means that the party providing the medical model cannot obtain the plaintext medical data corresponding to the encrypted medical data. Users of the service are able to decrypt the results of the application of the medical model.
[0005] Specifically, existing homomorphic cryptography techniques can, at least in principle, be used to compute any function on encrypted data. This technique is called "fully homomorphic encryption" (FHE).
[0006] For security reasons, known implementations of FHE use noisy ciphertexts. For example, encryption of a data item may include mapping the data item to a point in a key-dependent lattice, where noise is added to the point. In particular, many known implementations of FHE use LWE-type ciphertexts, the security of which depends on the cryptographic difficulty of the fault-tolerant learning problem or one of its variants, such as ring fault-tolerant learning (RLWE) or generalized fault-tolerant learning (GLWE). Such an LWE-type ciphertext may be an LWE ciphertext that includes one or more mask values (e.g., values modulo a particular modulus q, or torus elements) plus a body value, the body value being derived from the mask value and from the plaintext using an encryption key, and the body value containing noise. A generalization of such a ciphertext is a GLWE ciphertext, which uses a polynomial instead of a scalar value for encryption. An RLWE ciphertext is another type of GLWE ciphertext. Other known implementations of FHE use NTRU-type ciphertexts, to which the same considerations generally apply.
[0007] When a data item is just encrypted, the noise is low and the encryption is recent. For example, the amount of noise is very low so that if the data item is to be decrypted, the noise can be removed at some point in the decryption process (e.g., by rounding). On the other hand, the noise should be high enough to make it difficult to attack the system. For example, many homomorphic encryption schemes are attacked by linear algebra or other efficient algorithms (e.g., lattice reduction algorithms) under the assumption that there is no noise. When the data item is encrypted, the noise is added so that the attack is difficult while still being able to perform homomorphic operations and still being able to decrypt.
[0008] Most homomorphic operations increase the noise inherent in the homomorphically encrypted data items. When such operations are performed many times, the noise may reach a level that cannot be uniquely decrypted. In general, it is known to reduce the noise of homomorphically encrypted values using a technique called bootstrapping. Bootstrapping can use a public key called a bootstrap key. By using bootstrapping to reduce the noise when needed, it is in principle possible to compute any desired number of homomorphic operations.
[0009] A specific type of fully homomorphic encryption scheme is the TFHE-like homomorphic encryption scheme. This scheme is described in "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks" by I. Chillotti et al., Cyber Security Cryptography and Machine Learning (CSCML 2021), Volume 12716 of Lecture Notes in Computer Science, pages 1 to 19, Springer, 2021 (incorporated herein by reference). The TFHE-like scheme differs from other FHE schemes in that it supports a relatively very efficient bootstrapping technique; in addition, it simultaneously implements the evaluation of functions during the bootstrapping operation (called programmable bootstrapping). Conventional bootstrapping corresponds to programmable bootstrapping with an identity function. Interestingly, the amount of noise possessed by the output of the programmable bootstrapping is independent of the noise in the input ciphertext. Therefore, by performing programmable bootstrapping, the function can be applied to the input ciphertext while reducing the noise in the input ciphertext to a fixed amount. By performing an appropriate number of programmable bootstrappings, encryption calculations of infinite multiplication complexity can be performed.
[0010] Typically, cryptographic computations using TFHE-like homomorphic encryption schemes involve values and polynomials that are encrypted according to a set of keys (e.g., a set of LWE and / or GLWE keys, or a set of NTRU keys). For example, blind rotations can be used that act on encrypted values and can output encrypted polynomials. As another embodiment, key switching can be used that switches between encryptions according to different keys.
[0011] The keys used in cryptographic calculations are typically randomly generated according to a probability distribution. For example, the keys for the inputs to a blind rotation can be independently randomly generated, and similarly, the keys for the inputs and outputs of a key switch.
[0012] The manner in which the key is randomly generated depends on the type of key. Various types of keys are known, for example, whose digits can be generated according to independent probability distributions (e.g., uniform binary or Gaussian), or according to an overall probability distribution (e.g., with a fixed overall Hamming weight). The type of key used can affect many aspects of the cryptographic calculation, including the manner in which the cryptographic operation is implemented, the resulting computational complexity and noise growth, and the level of security. Summary of the invention
[0013] Although existing TFHE-based cryptographic computing techniques are capable of performing a variety of operations on encrypted values, there is still a need to improve their computational efficiency, storage requirements for key materials used to perform cryptographic computations, and / or the flexibility of the cryptographic parameter values used. The present invention aims to address at least some of the above problems.
[0014] According to one aspect of the invention, there is provided a cryptographic method for performing cryptographic calculations as defined in the claims. According to another aspect, there is provided an apparatus corresponding to the computer-implemented method as defined in the claims. According to a further aspect, there is provided a computer-readable medium as defined in the claims.
[0015] The cryptographic computation may involve a value and a polynomial encrypted according to one or more cryptographic keys. The cryptographic key that encrypts the value is also referred to herein as a "value key". The cryptographic key that encrypts the polynomial is also referred to herein as a "polynomial key". These keys may together form a key set. The keys in the key set may support programmable bootstrap operations, in other words, the cryptographic computation may be in a "TFHE-like" setting. Specifically, the keys may be defined according to lattice-based encryption, for example, the value key may be an LWE key, and the polynomial key may be a GLWE key.
[0016] The cryptographic calculation may involve a variety of "key-related" operations that convert between different types of encryption and / or encryption based on different keys. Specifically, the cryptographic calculation may include a blind rotation operation, in which an input value encrypted based on a blind rotation input key of a key set is converted into a rotation polynomial encrypted based on a blind rotation output key of the key set. Blind rotation can evaluate the homomorphic decryption of the encrypted input value in the exponent of the polynomial. For example, the rotation polynomial obtained can represent the application of a lookup table to the input value. Such blind rotation is often applied as a step in programmable bootstrapping, see "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks".
[0017] The encryption calculation may also include a sample extraction operation and / or a key switching operation, wherein in the sample extraction operation, a polynomial encrypted according to a sample extraction input key of a key set can be converted into an encryption of the coefficients of the polynomial, wherein in the key switching operation, a value or polynomial encrypted according to a key switching input key of a key set can be converted into a key switching output encrypted according to a key switching output key of the key set (e.g., different from the key switching input key).
[0018] When using prior art techniques, corresponding keys of a key set for cryptographic computations are typically independently randomly generated, where the digits of the key are defined, for example, as iid (independent and identically distributed) random variables, or based on a joint probability distribution that allows multiple possible values for the digits. The term "digit" may generally refer to a scalar value that forms a key, such as a value that forms an LWE key or a coefficient of a polynomial that forms a GLWE key.
[0019] Interestingly, the inventors have realized that by changing the manner in which the keys of a key set are formed, the efficiency of various key-related operations can be improved, the storage requirements for key material used in cryptographic calculations can be reduced, and the flexibility of cryptographic calculations with respect to cryptographic parameters can be improved. That is, the inventors contemplate the use of a key set in which the assumption that the keys are independently and randomly generated is relaxed; specifically, by using keys having one or more common digits and / or by using keys having one or more digits with predetermined values.
[0020] By using this special type of key in the key set of encryption calculation, multiple operations can be implemented in a better way. Specifically, by using a key with a common digit and / or using a key with a digit with a predetermined value, the storage requirement of the key material can be reduced. That is, the blind rotation operation and the key switching operation typically use a bootstrap key and a key switching key respectively, which includes encryption based on the value of the input key. By using a key with a common digit, encryption can be shared between different bootstrap keys and key switching keys. By using a key with a digit with a predetermined value, the corresponding encryption can be eliminated, thereby making the required encryption less, and then making the key material smaller. Using the predetermined value digit and the common digit also produces fewer encryption operations, thereby making the operation more efficient in calculation and less noise in the output.
[0021] In the same way, for sample extraction, having an input key with a predetermined value makes the operation more efficient, while using an input key that has bits in common with other keys in the encryption calculation for sample extraction can make subsequent key switches less expensive, or even allow them to be eliminated entirely.
[0022] The provided techniques can effectively provide a party performing cryptographic calculations with some controllable knowledge of the keys being used, thereby allowing cryptographic calculations to be performed in an improved manner. This provides greater flexibility in the cryptographic parameters that can be used. Specifically, the prior art in many cases relies on polynomial rings modulo polynomials of degree N, where N is a power of 2. This means that when N is increased to improve security, N needs to be doubled, thereby doubling the key size and the computational cost of various operations. For example, in the case of an encryption polynomial, After taking the modulus by N and performing LWE-type sample extraction, the LWE ciphertext is obtained. Thus, its size effectively doubles as N increases. However, when sampling is performed using a key having bits with predetermined values, sampling of these bits can be skipped, allowing the number of elements of the generated LWE ciphertext to be efficiently and flexibly set to a value that is not equal to the value k·N+1 specified by the parameters of the GLWE encryption.
[0023] It is also possible to use both keys having bits in common with other keys and keys having bits with predetermined values. Surprisingly, this combination has been found to work particularly well; in particular, it allows a particularly efficient implementation of programmable bootstrapping of cryptographic calculations, wherein key switching (producing encryption according to a key switching output key, wherein the key switching output key has bits in common with a key for subsequent operations and bits with predetermined values) can be applied before sample extraction, instead of first performing sample extraction and then performing key switching in currently known PBS implementations.
[0024] It should be noted that the sample-extracted output key (which is the same as the input key, but reinterpreted as a set of numbers rather than a set of polynomials) should not be considered as a separate key from the sample-extracted input key in the key set. Specifically, keys from the key set that have common digits and / or predetermined values can be the input key and output key of the blind rotation and / or key switching as well as the sample-extracted input key.
[0025] Thus, using the provided techniques provides more options in cryptographic parameters and allows a smaller amount of public key material to be used in a given use case. In addition, improved efficiency and less noise growth can be obtained for a variety of cryptographic operations. Thus, for example, more efficient computation of Boolean circuits, arithmetic circuits, neural network reasoning, or functional circuits can be obtained.
[0026] Often, in many cryptographic computations, for performance reasons, it is beneficial to use a key set having multiple keys for plaintext encryption and / or multiple keys for polynomial encryption, and to switch between encryptions according to the corresponding keys throughout the computation. This allows, for example, different sets of parameters to be used for corresponding blind rotations depending on the desired precision or accuracy of the corresponding results of the corresponding blind rotations. In this case, the provided techniques are particularly advantageous by providing improved efficiency and reducing the size of the required public key (e.g., key switching key and / or bootstrap key) material.
[0027] In one embodiment, sample extraction may be applied based on an encryption rotation polynomial (e.g., an encryption rotation polynomial representing application of a lookup table to an input value). The sample extraction input key may have one or more digits with predetermined values. In general, sample extraction may determine the resulting encryption of coefficients of the encryption input polynomial by determining corresponding elements of the resulting encryption corresponding to corresponding digits of the sample extraction input key. If the sample extraction input key has digits with predetermined values, the corresponding elements in the encryption result may be eliminated, resulting in faster sample extraction and a smaller encryption result.
[0028] However, when sample extraction is not applied to the output of blind rotation, the advantages discussed herein also apply. For example, a polynomial encrypted according to a sample extraction input key can be used to pack multiple values. The sample extraction input key can be a partial key having one or more digits with predetermined values. By applying the corresponding sample extraction to the encryption polynomial, encryption of the corresponding packed value can be obtained. In this case, due to the use of a partial key, the encryption result will be smaller. As an illustrative embodiment, 1024 messages can be packed into an encryption polynomial with a partial key (e.g., an RLWE key), wherein all coefficients except the first 600 coefficients are filled with zeros. This ciphertext can be unpacked into, for example, 1024 corresponding encryptions. Advantageously, the resulting ciphertext will be smaller, for example, in this embodiment, the size is 601 instead of 1025.
[0029] In one embodiment, the sample extraction input key may be the same as the blind rotation output key, for example, sample extraction may be applied to the encrypted rotation polynomial output of the blind rotation. In this way, a more efficient programmable bootstrap operation may be obtained. That is, the programmable bootstrap operation may include a modulus switch; followed by a blind rotation; followed by sample extraction; optionally, followed by a key switch. Improved sample extraction may make such programmable bootstrapping more efficient.
[0030] In one embodiment, the sample extraction input key may also have one or more common digits with the blind rotation input key. Specifically, programmable bootstrapping may be applied to encryption based on the blind rotation input key, and may produce an encrypted output based on the same blind rotation input key. By using a sample extraction input key that has a common digit with the blind rotation input key, this output encryption may be determined particularly efficiently. Specifically, key switching may be performed to obtain an encrypted output, which can be performed more efficiently due to the common digits. Specifically, the sample extraction input key may be defined such that its set of digits consists only of the digits of the blind rotation input key and a set of digits with predetermined values. In this case, sample extraction may directly produce the desired output encryption, and may even completely eliminate key switching, making this option particularly efficient in terms of computation and storage.
[0031] In one embodiment, programmable bootstrapping can be performed by performing blind rotations; applying key switching based on a polynomial obtained by the blind rotations; and applying sample extraction based on the output of the key switching. The sample extraction results in encryption according to a desired key (e.g., the key according to which the blind rotated input value was encrypted or another desired key). To this end, the key switching output key can be defined such that it includes one or more digits with predetermined values and also includes digits of the desired key.
[0032] Thus, compared to the known programmable bootstrapping in which a blind rotation is followed by a sample extraction and then a key switch, the order of the key switch and the sample extraction can be swapped. Furthermore, the key switch can be a key switch acting on an encryption polynomial rather than a key switch acting on an encryption value. Interestingly, this improves efficiency because a key switch of an encryption polynomial can be implemented more efficiently than a key switch of an encryption value. In particular, a polynomial key switch can be implemented particularly efficiently using a Fast Fourier Transform (FFT), also referred to in this context as a Number Theoretic Transform (NTT). Furthermore, because a key switch of a polynomial is used rather than a key switch of a value, the key switch key will be smaller. This effect will be particularly strong if the encryption is an RLWE encryption.
[0033] In one embodiment, programmable bootstrapping can be improved to produce outputs with different expected keys by combining blind rotation with key switching with different key switching output keys. For example, another blind rotation can be applied based on the same blind rotation input key and output key, and its output can be used for another key switch and subsequent another sample extraction. For example, one expected key can be a blind rotation input key, and another expected key can be a different key (e.g., a key formed by a subset or superset of the digits of the blind rotation input key). This allows bootstrapping with different input keys to be effectively combined in homomorphic computation, effectively using polynomial key switching to switch between keys. Similarly, in this case, because the polynomial key switching has a small key switching key (specifically, if RLWE key switching is used), a particularly small amount of key material can be used to perform cryptographic calculations. It is particularly advantageous for situations where the expected keys have common digits or even subsets of each other, because this allows the size of the bootstrapping key to be reduced, as described herein.
[0034] In one embodiment, a key switch can be performed when the key switch input key has one or more common digits with the output key. This allows key switching to be performed particularly effectively. Specifically, a key switch can generally include a corresponding key switch contribution combination of the corresponding key element of the key switch input key, which is calculated based on the corresponding component of the key switch key. When the input key has a common digit with the output key, it is not necessary to determine these components, and alternatively, elements from the input ciphertext can be used. In addition, digits that appear in the key switch output key but do not appear in the key switch input key can be effectively processed, such as by adding zeros corresponding to additional digits. Therefore, generally, key switching can be more effectively processed using a smaller key switch key, and the noise is smaller.
[0035] In one embodiment, key switching can be applied to one or more values encrypted according to a common key switching input key to obtain an encrypted key switching output polynomial based on the one or more values. Specifically, the key switching can be a so-called packing key switching that combines the value ciphertext into the polynomial ciphertext. In addition, this key switching from value to polynomial can be improved by using the common digits described herein.
[0036] Specifically, the digits of the key switch input key may be a subset of the digits of the key switch output key. In this case, the key switch may set to zero the ciphertext elements in the key switch output corresponding to the digits in the key switch output key that do not appear in the key switch input key. Therefore, this key switch has very low computational cost, does not use the key switch key, and does not add noise.
[0037] Similarly, the digits of the key switch input key may be a superset of the digits of the key switch output key. In this case, the key switch may include key switching only the ciphertext elements in the encrypted input value or encryption polynomial that correspond to the digits in the key switch input key that do not appear in the key switch output key. Thus, in this case, the key switch has fewer key switch keys, is faster to compute, and generates less noise.
[0038] In one embodiment, a sequence of at least three keys may be used in which the digits of one key are a subset of the digits of a subsequent key. For example, the digits of a first key may be a subset of the digits of a second key, and the digits of the second key may be a subset of the digits of a third key, and so on. This arrangement allows for efficient key switching between different keys based on key switching between subsequent keys, as described herein. In this way, cryptographic calculations may be performed in which corresponding portions are performed with the smallest possible key that provides a desired level of accuracy, thereby achieving more efficient cryptographic calculations.
[0039] In one embodiment, multiple blind rotations may be performed using corresponding blind rotation input keys and output keys having one or more common digits. Similar to the key switching key, the blind rotation key may include encryption of the corresponding digits of the blind rotation input key. When using common digits for the input key, common encryption of the digits may also be used. Specifically, the digits of the first blind rotation input key may be a subset of the digits of the second blind rotation input key. For compatibility, encryption may use the same polynomial order N; the blind rotation output keys may be the same, and the bases may be compatible, they are the same or one base is a power of another base (e.g., base 8=2^3 has 6 levels, base 64=2^6 has 3 levels). In this case, the bootstrap key for the first input key and output key may be included in the bootstrap key for the second input key and output key. Therefore, encryption calculations may use less key material.
[0040] The provided techniques for improving the computation of encrypted data can be applied to a wide range of practical applications. Such practical applications include the evaluation of software programs for encryption without access to the plaintext data. For example, medical data on medical diagnostic software can be evaluated without actual access to the medical data. The medical data may include medical images. The medical images may include, for example, multi-dimensional image data, for example, two-dimensional (2D), three-dimensional (3D) or four-dimensional (4D) images, acquired through a variety of acquisition modes, such as, but not limited to: standard X-ray imaging, computed tomography (CT), magnetic resonance imaging (MRI), ultrasound (US), positron emission tomography (PET), single photon emission computed tomography (SPECT), and nuclear medicine (NM).
[0041] In one embodiment, the provided techniques can be used to evaluate a neural network of encrypted inputs. The party evaluating the neural network may or may not have plaintext access to the neural network training parameters (e.g., weights and biases). In general, the techniques provided herein increase the efficiency of evaluating the neural network and / or reduce the storage and transmission requirements of the ciphertext or key material used.
[0042] An embodiment of the method may be implemented on a computer as a computer-implemented method, or implemented in dedicated hardware, or implemented in a combination of the two. Executable code of an embodiment of the method may be stored on a computer program product. Examples of computer program products include memory devices, optical storage devices, integrated circuits, servers, online software, etc. Preferably, the computer program product includes non-transitory program code stored on a computer-readable medium, and when the program product is executed on a computer, the non-transitory program code is used to perform the embodiment of the method.
[0043] In one embodiment, the computer program comprises computer program code, which is suitable for performing all or part of the steps of the embodiment of the method when the computer program is run on a computer. Preferably, the computer program is implemented on a computer readable medium. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Further details, aspects and embodiments will be described by way of example only with reference to the accompanying drawings. The elements in the drawings are illustrated for simplicity and clarity and are not necessarily drawn to scale. In the drawings, elements corresponding to elements already described may have the same reference numerals. In the drawings,
[0045] FIG. 1 a schematically illustrates an example of an embodiment of a cryptographic device;
[0046] FIG. 1 b schematically illustrates an example of an implementation of an encryption computing system;
[0047] Figure 2 An embodiment of a key having a digit of a predetermined value is shown;
[0048] Figure 3 An embodiment of a key having a common digit is shown;
[0049] 4a to 4e show an embodiment of programmable bootstrap;
[0050] Figures 5a to 5e illustrate switching between encryptions with different keys;
[0051] Figure 6 An example of an implementation of a cryptographic method for performing cryptographic calculations is schematically illustrated;
[0052] Figure 7 schematically illustrates a computer readable medium having a writable portion according to one embodiment;
[0053] Figure 8 A representation of a processor system according to one embodiment is schematically shown. DETAILED DESCRIPTION
[0054] While the subject matter of the present disclosure is susceptible of embodiment in many different forms, one or more specific embodiments are shown in the drawings and will be described in detail herein, it being understood that the present disclosure is to be considered as an example of the principles of the subject matter of the present disclosure and is not intended to be limited to the specific embodiments shown and described.
[0055] In the following, for ease of understanding, various elements of the embodiments are described in operation. However, it will be appreciated that the corresponding elements are arranged to perform the functions described by them.
[0056] Furthermore, the subject matter of the disclosure is not restricted to these embodiments but also comprises every other combination of the features described herein or recited in mutually different dependent claims.
[0057] First, some general information and notation applicable to several embodiments is provided. Throughout this specification, the parameter q represents the modulus used to encrypt a value, for example a positive integer. Indicator ring The parameter N represents the size of the multiple polynomials used and is typically a power of 2. Indicator ring and Indicator ring Where p(X) is a cyclotomic polynomial, for example if N is a power of 2, then p(X) = (XN+1). σ indicates a Gaussian distribution whose mean is set to zero and whose standard deviation is set to σ. The symbol || indicates concatenation.
[0058] Multiple embodiments use LWE-type encryption. This encryption can be based on the cryptographic difficulty of the LWE problem family (such as learning to erroneous (LWE) or ring learning to erroneous (RLWE), or the more general generalized learning to erroneous (GLWE) that covers LWE and RLWE). Typically, an LWE ciphertext may include one or more mask values and a body value, which is derived from the mask value and the plaintext value. These values are typically integers modulo a given modulus q. Multiple embodiments also use GLWE (generalized learning to erroneous) type ciphertexts. GLWE ciphertexts may include one or more mask polynomials and a body polynomial, which is derived from the mask polynomial and the plaintext polynomial. GLWE ciphertexts can be limited to modulo q and a quotient polynomial p(X). LWE ciphertexts can be viewed as a specific GLWE ciphertext in which the quotient polynomial is of first order. GLWE ciphertexts other than LWE ciphertexts (e.g., GLWE ciphertexts using polynomials that do not have a constant order) are also referred to as polynomial ciphertexts. Another special ciphertext is the RLWE (Ring Tolerant Learning with Errors) ciphertext, where the number of masking polynomials is 1.
[0059] Specifically, according to the key information The GLWE ciphertext can be defined as follows:
[0060]
[0061] Here, is a GLWE key, where the coefficients are sampled from, for example, a uniform bivariate distribution, a uniform ternary distribution, or a Gaussian distribution. The key elements may be indicated as The polynomial coefficient s of the corresponding polynomial of the key i,jThe number of bits is called the key. In the specific case of LWE, the polynomial is a 0th order polynomial, ie the constant term (as a value itself) is the only bit.
[0062] also, This can be an appropriate scaling of the input message. Mask elements yes The polynomial in which the coefficients are, for example, The uniform distribution in is sampled, B is also called the main element. E is The noise (error) polynomial in , so that its coefficients are from the Gaussian distribution χ σ The parameter k is a positive integer and represents the number of polynomials in the GLWE key.
[0063] To simplify the notation, the notation S is sometimes used. k+1 = -1. However, this value or polynomial S k+1 shall not be considered as part of the GLWE key. The GLWE key may only include the corresponding mask element A i Instead of the corresponding secret element S of the main element B i Therefore, the digits of the GLWE key may include only the digits of these secret elements (values or polynomials) that correspond to the principal elements (values or polynomials).
[0064] In this embodiment, the LWE ciphertext is the GLWE ciphertext with N = 1. In this case, the parameter n = k can be considered for the size of the LWE key, and both the ciphertext and the key can be indicated by lowercase letters, such as ct q and s. The RLWE ciphertext in this embodiment is a GLWE ciphertext with k=1 and N>1 (eg, a power of 2).
[0065] Although an integer q is used throughout this specification to indicate a ciphertext modulus, it should be noted that multiple ciphertext moduli may be used in cryptographic multiplications, for example, modulus switching may be used to align ciphertexts according to the same q when necessary.
[0066] However, in principle, it is not necessary to use LWE type ciphertexts. In addition, for other types of ciphertexts (e.g., NTRU-based ciphertexts), the keys can be limited to having common digits and / or digits with predetermined values, and the various advantages described herein also apply to this setting.
[0067] The above embodiments describe secret key, symmetric encryption variants. The techniques provided herein are equally applicable to public key variants known per se. In the latter case, for example, the above secret key may be used as a private key, where the public key comprises one or more encryptions of zeros, e.g., see R. Rothblum, "Homomorphic encryption: From private-key to public-key", Theory of Cryptography (TCC 2011), Volume 6597 of Lecture Notes in Computer Science, pages 219-234, Springer, 2011 (incorporated herein by reference).
[0068] The provided techniques can also be used in cryptographic computations based on multi-key fully homomorphic encryption. In such a setup, multiple counterparts may have multiple corresponding keys (e.g., generated as conventional FHE keys), and cryptographic computations may be performed on ciphertexts encrypted under the corresponding keys. In particular, multi-key FHE may be based on a transformation operation, where a ciphertext encrypted under one of the corresponding keys is transformed into a (typically larger) ciphertext that encrypts the same message under a combination of the keys. For example, given a corresponding key and The concatenation key can be defined as According to the corresponding key (for example, ) can be converted to a ciphertext based on the concatenated key The techniques described herein can be used to perform cryptographic calculations on ciphertext encrypted under a combined key.
[0069] Several embodiments operate in a TFHE setting, which means using ciphertexts that support programmable self-bootstrapping (PBS). A programmable bootstrapping can take a ciphertext as input and output a ciphertext of the same message, or a function of the message (in other words, a lookup table applied to the message), with noise that is independent of the input. The PBS can include blind rotations for evaluating homomorphic decryption of the input ciphertext in a polynomial exponent.
[0070] Specifically, the programmable bootstrap may take as input: a ciphertext for encrypting a message m; a bootstrap key; and an encryption of a lookup table L. The programmable bootstrap may output an encryption of the message L[m] encrypted at a fixed noise level. Such programmable bootstrapping using blind rotations is known, for example, from I. Chillotti et al., “TFHE: fastfully homomorphic encryption over the torus”, J. Cryptol, 33(1): 34-91, 2020, or L. Ducas et al., “FHEW: bootstrapping homomorphic encryption in less than asecond”, proceedings EUROCRYPT 2015. Blind rotations are also known as updates to accumulators, see, for example, D. Micciancio et al., “Bootstrapping in FHEW-like Cryptosystems”, https: / / eprint.iacr.org / 2020 / 086 (incorporated herein by reference).
[0071] Programmable bootstrapping in the art is typically implemented by performing the following steps: modulus switching; followed by blind rotation; followed by converting the blind rotation result into a value ciphertext, for example by means of an optional key switch after performing a sample extraction. Sample extraction is also known as extraction from an accumulator. Such an implementation is described, for example, in "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks" and in the LWE setting in "Bootstrapping in FHEW-like Cryptosystems". Programmable bootstrapping in the NTRU setting is known from "FINAL: Faster FHE instantiated with NTRU and LWE" and "NTRU-v-um: Secure Fully Homomorphic Encryption from NTRU with Small Modulus".
[0072] Modulus switching essentially scales the programmable bootstrapped encrypted input to produce a scaled input that is encrypted under the same key as the original input. Since blind rotation is typically followed by application of modulus switching, and modulus switching does not change the key under which the value was encrypted, mode switching is sometimes implicit in this specification. Blind rotation can evaluate the homomorphic decryption of the encrypted input value in the exponent of the polynomial, for example by computing X -μ′ +V, where μ' is a scaling of the encrypted input value and v is a polynomial encoding the lookup table. Blind rotations can also be applied in contexts other than programmable bootstrapping. For example, blind rotations without using a lookup v are also known as monomial lifts.
[0073] Programmable bootstrapping typically utilizes gadget ciphertexts. Specifically, programmable bootstrapping may be based on computing the outer product of an encryption polynomial with such a gadget ciphertext. In general, a gadget ciphertext may be defined as a ciphertext comprising a plurality of component ciphertexts that encrypt corresponding values defined based on the plaintext and based on the gadget matrix. For LWE / GLWE, the gadget ciphertext may be a GGSW ciphertext, known, for example, from "Programmable bootstrapping enables ..." (incorporated herein by reference for the purpose of describing GGSW). In the NTRU setting, the gadget encryption may be, for example, the NGS encryption of C. Bonte et al., “FINAL: Faster FHE instantiated with NTRU and LWE”, https: / / ia.cr / 2022 / 074 (incorporated herein by reference for purposes of defining NGS); or the gadget NTRU encryption of K. Kluczniak, “NTRU-v-um: Secure Fully Homomorphic Encryption from NTRU with Small Modulus”, https: / / ia.cr / 2022 / 089 (incorporated herein by reference for purposes of defining gadget NTRU). As known per se, NTRU bootstrapping may be applied to LWE encrypted values, for example, cryptographic calculations may be performed on LWE encrypted values using NTRU bootstrapping. This is described, for example, in C. Bonte et al., “FINAL: Faster FHE instantiated with NTRU and LWE”, https: / / ia.cr / 2022 / 074. In general, a secure set of cryptographic parameters can be chosen in TFHE-class schemes to minimize computational cost while satisfying the required accuracy. Interestingly, these parameters can be chosen independently of the amount of homomorphic operations and the depth of the circuit to be evaluated.
[0074] The keys used in this specification may be sparse keys. Hamming weight A sparse binary (or ternary) key of can be defined as a key whose polynomial coefficients are in {0,1} (or {-1,0,1}) and contain exactly h non-zero coefficients. When such a key is used, the dimension k, the polynomial ring (including the polynomial order N), the distribution (binary or ternary), and the Hamming weight h may all be known. Sparse keys may be useful for homomorphic computation, see, for example, JH Cheon et al., "Homomorphic encryption for arithmetic of approximate numbers", proceedings ASIACRYPT 201 (incorporated herein by reference).
[0075] More generally, various types of keys may be used, where the corresponding parameters are known, for example, to the party performing the cryptographic computation. Such parameters typically include the size of the key (e.g., the dimension k and the polynomial ring of the key elements), and the ring used for the cryptographic computation. For example, the following types of keys may be used, where public knowledge is indicated:
[0076]
[0077] Throughout this specification, plain text may refer to modulo integer. Equivalently, these values can be viewed as coming from the torus of real numbers The discretized values of , as in several references mentioned above. That is, positive numbers modulo a given modulus and discrete torus elements can be used interchangeably, specifically, and There is isomorphism between them, as also mentioned in the literature, for example, see C. Boura et al., “CHIMERA: Combining Ring-LWE-based FullyHomomorphic Encryption Schemes”, J. Math. Cryptol, 14(1): 316-338, 2020.
[0078] The programmable bootstrapping operations in TFHE-like schemes make them an attractive choice for a wide range of applications. Because bootstrapping is relatively efficient compared to many other FHE schemes, it is more feasible when performing relatively complex computations (e.g., with a multiplication depth of at least 10, at least 50, or at least 100). Specifically, the cryptographic parameters of TFHE-like schemes can be selected based on the desired accuracy and the computational cost incurred, independent of the amount of homomorphic operations and their circuit depth. In contrast, in other FHE schemes, bootstrapping can be so inefficient that in practice these schemes are typically applied in a hierarchical manner, meaning that their parameters are selected depending on a given computation so that it can be performed without bootstrapping. However, this hierarchical approach is not feasible for more complex computations, so TFHE-like schemes are particularly beneficial in such cases.
[0079] Specifically, in the LWE setting, the security of the GLWE-based ciphertext is based on the distribution of the key and on three main parameters: n = kN, where N is the order of the quotient polynomial, k is the number of random mask polynomials of the ciphertext, and n is the length of the key; q, the modulus; σ, a statistical parameter of the noise, such as the standard deviation of the noise. Given these parameters, it is known per se how to evaluate the level of security provided, see, for example, M. Albrecht et al., "On the concrete hardness of Learning with Errors", Journal of Mathematical Cryptology, 9(3): 169-203, 2015 (incorporated herein by reference).
[0080] In embodiments herein, the parameters of the TFHE-like ciphertexts used may be selected based on the desired security level and based on the desired precision of operations (such as linear combinations of ciphertexts and / or application programmable bootstrapping) (in other words, the noise level generated by applying these operations). Interestingly, in the TFHE setting, the security parameters may be selected independently of the computational complexity, e.g., independently of the multiplication depth of the computation. This is different from non-TFHE-like schemes, where the security parameters are typically selected to limit or eliminate bootstrapping.
[0081] Specifically, the LWE-based ciphertext and / or GLWE-based ciphertext used in the TFHE setting of this article may use a relatively small modulus, such as at most 32 bits, at most 64 bits, or at most 128 bits. This modulus is typically selected independently of the computation to be performed, for example, it is selected based on the desired accuracy and / or efficiency. The parameters N, k, and / or σ may be selected to achieve the desired security level, which is also typically independent of the computation to be performed. For example, N may be set to at least 512 and / or at most 2048 or 4096 (e.g., set to 1024). For example, in one embodiment, the RLWE used has N of at least 512 and / or at most 2048 or 4096 (e.g., 1024), and k=1. Such a value of N is typically not used in non-TFHE-type encryption schemes because such a value would severely limit the computation that can be performed; instead, in non-TFHE-type schemes, q and N are typically both selected based on the desired security level, so that q can be much larger.
[0082] Fig. 1a schematically shows an embodiment of a cryptographic computing device 110. The device 110 may be used to perform cryptographic computing.
[0083] Device 110 may include a processor system 130, a memory 140, and a communication interface 150. Memory 140 may include local memory, such as a local hard drive or electronic memory. Memory 140 may include non-local memory, such as cloud storage. In the latter case, memory 140 may include a storage interface connected to the non-local memory. For example, memory 40 may be used to store values and polynomials encrypted according to one or more encryption keys. The keys form a key set. Device 110 typically cannot access the keys in the key set in plain text. Memory 140 may store additional data, such as a bootstrap key or a key switching key, as discussed elsewhere.
[0084] The device 110 can communicate internally with other devices, external memory, input devices, output devices, and / or one or more sensors via a computer network. The computer network can be the Internet, an intranet, a LAN, a WLAN, etc. The computer network can be the Internet. The device optionally includes a connection interface 150, which is arranged to communicate with other devices as needed. For example, the connection interface may include a connector, such as a wired connector (e.g., an Ethernet connector, a fiber optic connector, etc.) or a wireless connector (e.g., an antenna (e.g., a Wi-Fi, 4G or 5G antenna)). Communications (e.g., internal communications) can use other communication protocols or media, such as an internal data bus.
[0085] In device 110, communication interface 150 may be used to send or receive digital data. For example, device 110 may be configured to receive or send data representing one or more encryption values and / or encryption polynomials (e.g., representing inputs and / or outputs of encryption calculations). As another example, communication interface 150 may be used to receive data representing one or more bootstrapping keys and / or one or more key switching keys.
[0086] The execution of device 110 may be implemented in a processor system 130 (e.g., one or more processor circuits, such as microprocessors, embodiments of which are shown herein). Device 110 may include multiple processors, which may be distributed at different locations. For example, device 110 may use cloud computing.
[0087] The processor subsystem 130 may be configured to apply a blind rotation to an input value encrypted according to a blind rotated input key of a key set, thereby obtaining a rotation polynomial encrypted according to a blind rotated output key of the key set. The rotation polynomial may, for example, represent applying a lookup table to the input value.
[0088] The processor subsystem 130 may also be configured to perform sample extraction and / or key switching. The processor subsystem 130 may be configured to apply sample extraction to a polynomial encrypted according to a sample extraction input key of a key set, thereby obtaining encrypted coefficients of the polynomial. Alternatively or additionally, the processor subsystem 130 may be configured to apply key switching to a value or polynomial encrypted according to a key switching input key of a key set, thereby obtaining a key switching output encrypted according to a key switching output key of the key set.
[0089] The first key and the second key of the key set may have one or more common digits, and / or at least one key of the key set may have one or more digits with predetermined values. Although the device 110 typically does not know the keys themselves, the device 110 may know information about which digits are common digits or predetermined digits, so that the device 110 may be configured to perform cryptographic calculations using this information about the common digits and predetermined digits, which allows the calculations to be performed in the improved manner described herein.
[0090] The processor subsystem 130 may be configured to obtain one or more inputs to the cryptographic calculation (e.g., one or more cryptographic input values and / or one or more cryptographic input polynomials). The processor subsystem 130 may be configured to output one or more outputs of the cryptographic calculation (e.g., including one or more cryptographic output values and / or including one or more cryptographic output polynomials). For example, the processor subsystem 130 may obtain inputs from the memory 140 and / or from another party via the communication interface 150, and / or output the outputs to the memory 140 and / or to another party.
[0091] The functional units shown in some of the figures may be functional units of a processor system. For example, the figures may be used as blueprints of possible functional organizations of a processor system. In most of the figures, the processor circuitry is not shown separately from the units. For example, Figure 2 The functional units illustrated through FIG5 (see below) may be implemented in whole or in part in the form of computer instructions stored at a device such as device 110, e.g., in an electronic memory of device 110, and executable by a microprocessor of device 110. In a hybrid embodiment, the functional units are implemented partly in hardware (e.g., as a coprocessor (e.g., an arithmetic and / or cryptographic coprocessor)) and partly in software (the software being stored on and executed on device 110).
[0092] For example, device 110 can be a device for performing cryptographic calculations. Cryptographic calculations can use homomorphic encryption ciphers. For example, device 110 can be used to perform cryptographic calculations, for example, even if data is received in encrypted form from, for example, a data provider, and even if device 110 cannot decrypt the data, the device can still perform the calculations. The calculations may involve blind rotations, key switching, and / or sample extraction as described herein. The calculations may include a variety of other homomorphic encryption operations, such as linear operations (e.g., addition, subtraction, and / or scalar multiplication; multiplication; unary function evaluation; etc.).
[0093] For example, memory 140 may store encrypted data items, such as those received from one or more data providers, or generated as intermediate or final results (e.g., outputs) of computations. Typically, most or all of the data items (on which computations of device 110 are performed) are encrypted by a key (or keys) unknown to device 110, i.e., device 110 may be configured not to obtain plaintext data items corresponding to encrypted data items, such as plaintext data items stored in memory 140. The decryption key in plaintext form is a secret to device 110, although the encryption key / decryption key may be available in encrypted form.
[0094] Figure lb schematically illustrates an example of one implementation of a cryptographic computing system 100. The system 100 is configured to perform cryptographic computing using homomorphic encryption (eg, fully homomorphic encryption).
[0095] In this embodiment, system 100 includes key generation device 111, data provider device 113 and cryptography device 112. Key generation device 111 can be combined with data provider device 113 in a single device. Device 112 can be configured to receive encrypted data items from data provider device 113. At least one or more data items can be received in encrypted form. One or more other data items can be received in plain text format. Device 112 can be configured to receive key material for performing cryptographic calculations from key generation device 111, such as a bootstrap key and / or a key switching key.
[0096] Device 112 may perform the computations described herein on the received data items and possibly also on the stored data items. Interestingly, the device may perform computations on the encrypted data without decrypting the data, e.g., without converting the encrypted data items to data in plain text format.
[0097] In this embodiment, the device 112 may be based on the device 110 of Figure 1a, for example, it may include the processor system 130, memory 140 and / or communication interface 150 of Figure 1a. Each of the devices 111, 112, and 113 is generally based on the hardware configuration of the device 110 of Figure 1a, for example, each may include a processor system, memory and / or communication interface as shown in Figure 1a.
[0098] Although not shown in this figure, the cryptographic computing system 100 may include multiple cryptographic devices, such as two, three, or more cryptographic devices. The cryptographic calculations may be distributed among multiple cryptographic devices. The cryptographic devices may exchange intermediate calculation results (typically encrypted) between each other. Each cryptographic device may be implemented like the cryptographic device 112 and may perform cryptographic operations as described herein.
[0099] Homomorphic encryption schemes can be applied in a variety of settings. For example, the encryption cryptography device 112 can be operated by a cloud provider. The cloud provider can provide computing and storage services to its clients. By adopting homomorphic encryption, the data provider device 113 (for example, the client of the cloud provider) can send their data in encrypted form. The cloud provider can still perform the required calculations and / or the required storage, but cannot know the correspondence with the plaintext data. For example, the data provider device 113 can use an encryption key of a type corresponding to the specific homomorphic encryption system that encrypts the data item. When the data provider 113 receives the calculation results from the encryption computing device 112, the corresponding decryption key can be used to decrypt the encrypted data item. The encryption key and the decryption key can be the same, and typically are.
[0100] For example, the cryptographic computing system 100 can be configured to train a machine learning model (e.g., an image classifier, such as a medical model) without having the cryptographic computing device access the plaintext data items. For example, linear regression can be performed on the input data, possibly even without bootstrapping. For example, back propagation can be performed on the input data, possibly with bootstrapping. The generated model parameters can be returned to the entity that owns the decryption key. This enables multiple providers of medical data to aggregate their data by sending the data to a cloud provider. The cloud provider then returns the model parameters without having access to the plaintext data. The encryption key can be equal to the decryption key.
[0101] After the model is trained, the cryptographic computing system 100 can be used to provide the model, such as for use with medical data. This can be accomplished using plaintext model parameters or encrypted model parameters, in both cases using encrypted data (e.g., encrypted inputs), intermediate data, and output data. Using plaintext model parameters is generally more efficient. In both cases, the system acts to perform calculations (such as image classification, such as medical image classification) without the computer knowing the plaintext data items. For example, a breast X-ray image can be evaluated for cancer, where the image is never in plaintext at the cryptographic device 112, and any cryptographic device 112 or combination of these devices will not know the results of the cancer assessment. From a privacy perspective, it is acceptable to run a plaintext model on encrypted privacy-sensitive data, but it is unacceptable to run a plaintext model on plaintext privacy-sensitive data.
[0102] Other applications involve database services (e.g., looking up encrypted data in an encrypted database); for example, the calculation can be a comparison between an input item and a database item. For example, multiple calculations can be combined to produce a database index that matches the index. For example, the database can be a genomic database, and the input is a gene sequence. For example, the system 100 can be used for protected control of equipment. For example, a device (even a large device such as a power plant) can send a sensor value to a cryptographic device 112 and receive an encrypted control signal in return. The control signal is calculated from the sensor signal. An attacker of the system may be able to determine the content of data to and from one or more cryptographic devices 112, or even access intermediate data of these devices, but he will not get any help from this because the data is encrypted. Even if all cryptographic devices 112 of the system 100 are completely cracked, the data will not be leaked because the devices do not know the decryption key. The calculation of the control signal may involve mathematical operations such as linear algebra, averaging, matrix multiplication, polynomial evaluation, etc., all of which can be performed using homomorphic encryption operations.
[0103] For example, a pool of encrypted data items may be maintained in an encrypted computing system; a subset of the encrypted data items may be received, and another subset of the encrypted data items may be the result of the encrypted computing (e.g., an intermediate result). For example, the cryptographic device 112 may be configured to apply homomorphic encryption operations to one, two or more encrypted data items in a pool (e.g., a series of input values and / or intermediate values and / or output values). The result may be a new encrypted data item that may be stored in the pool. The pool may be stored in a memory of the encrypted computing system. This may be a local memory or a distributed memory. In the latter case, it may happen that one or more encrypted data items are represented multiple times in the pool. If, for example, the value of an encrypted data item is needed elsewhere, the encrypted data item may be sent from one computing device to another computing device. The pool may be implemented in a variety of ways, such as register files, arrays, a variety of data structures, etc.
[0104] Encrypted data items may represent all kinds of data. For example, an encrypted data item may represent a number that needs to be averaged or used for linear regression, etc. For example, an encrypted data item may represent an image. For example, each pixel of an image may correspond to one or more encrypted data items. For example, a grayscale pixel may be represented by a grayscale level, which in turn may be represented by a single encrypted data item. For example, 256 grayscale levels may be encoded as a single encrypted data item. For example, a color pixel may be represented by multiple color levels (e.g., RGB levels), which in turn may be represented by a tuple of encrypted data items. For example, three 256 levels of color may be encoded as corresponding encrypted values.
[0105] A set of homomorphic encryption operations can be defined for use in a computation. For example, a computation network or circuit can be established from the homomorphic encryption operations to jointly implement the computation, for example, by a compiler device as described in FIG. 1b or by the cryptographic device itself. For example, the computation may include Boolean operations. The manner in which the homomorphic encryption operations are combined (e.g., which operation is applied to which operation object in the pool) determines which computation is being performed. For example, a computation may be represented as a list of homomorphic encryption operations to be performed together with an indication of which encrypted data item these homomorphic encryption operations are to be performed on. The network or circuit may indicate to the cryptographic device 112 when blind rotations, sample extractions, and / or key switching are performed. For example, the network or circuit may indicate whether the digits of the key used in the corresponding operation are common digits or digits with predetermined values so that the cryptographic device can perform encryption computations suitable for the key shape used.
[0106] Figure 2A detailed but non-limiting embodiment of a key having one or more digits with predetermined values is shown. A key with digits with predetermined values is also referred to herein as a partial key, specifically a partial GLWE key, a partial LWE key, a partial NTRU key, etc. This is in contrast to the keys known in the prior art, in which each digit typically has at least two possible values, which obtain a non-zero probability when generating the key.
[0107] Specifically, the figure illustrates a partial key 200 (eg, a GLWE key) comprising two polynomials, wherein the coefficients of the polynomials are flattened into a coefficient array for the purpose of illustration. The key 200 is defined as follows:
[0108] in and Among them, the digit s of the first polynomial 1,0 ,…,s 1,N-1 ,210 and the subset of the digits of the second polynomial is random, for example, selected from a uniform binary distribution; and the remaining digits is set to a predetermined value, for example, to zero.
[0109] More generally, in a partial key, only a publicly predetermined portion of the bits of the partial key may be from a probability distribution (e.g., a joint distribution or The remaining digits may be filled with publicly predetermined elements. The positions of these predetermined elements and the position of each random element from a distribution may be known.
[0110] Mathematically, a partial key can be defined as a key parameterized by:
[0111] Public vector of exponents Represents the portion of the key that is filled with random elements, such as
[0112] ·and Common vector of associated distributions
[0113] Public vector of exponents Represents the portion of the key that is filled with predetermined elements, such as
[0114] ·and A common vector of associated values For example
[0115] In this mathematical description, the partial key satisfies and (e.g., there is at least one digit with a predetermined value); as well as
[0116] For example, consider a partial key 200. This key includes 2 polynomials, where the second polynomial includes a first half 221 filled with random coefficients and a second part 222 (predetermined part) filled with zeros. Based on the above mathematical description, this key can be expressed as: in in in as well as in
[0117] Figure 3 A detailed but non-limiting embodiment of a key with one or more public digits is shown. Such a key is also referred to herein as a shared randomness key. In other words, such a key has public knowledge about a shared coefficient.
[0118] This embodiment is illustrated in the figure, where three different keys are shown, for example, the GLWE key: 311; 312; and 313.
[0119] Specifically, as illustrated in this figure, keys 311 to 313 may be LWE keys, for example, N1=N2=N3=1. As illustrated in the figure, the keys in this embodiment are 313 includes All coefficients of 312 (in this case, as the key 313 leading coefficient); and 312 includes All coefficients of 311 (in this case, in the key 312 in the leading coefficient).
[0120] Mathematically, a set of multiple keys with common digits can be defined as a shared randomness key structure SRSK, including:
[0121] List of keys as well as
[0122] A collection of shared relationships between keys
[0123] For dimension k x and the polynomial size is Nx Key The digits (coefficients) of the key can be indicated as: Equivalently, in
[0124] The set of shared relations can be restricted to the form A non-empty set of elements where: v i ∈{1,…,k x}×{0,…,N x -1}, This element means: In particular, f can be, and in many cases is, the identity function.
[0125] Specifically, the embodiment illustrated in this figure can be mathematically described as a list Where N = 1, gather can be defined as follows:
[0126]
[0127] in, express 311 and The sharing coefficient between 312, and express 312 and The sharing coefficient between 313.
[0128] Specifically, by using a shared randomness key, key switching between a key switching input key and a key switching output key can be implemented more efficiently. Figure 3 An LWE-type key of the key shown (e.g., an LWE key for encrypting a value, and / or a GLWE key for encrypting a polynomial).
[0129] Specifically, the shared randomness key (e.g. 311 and 312), where the bit set of one key is a subset of the bit set of another key. Specifically, as illustrated in the figure, the key may be a LWE secret key, such as N=1. For the purpose of the following discussion, the key 311 may be indicated as and key 312 may be indicated as where n1<n2 and
[0130] As a first embodiment, a key switch may be performed from a smaller key 311 to a larger key 312. The bits of the key switch input key 311 may be a subset of the bits of the key switch output key 312. In this case, the key switch may be performed by setting to zero the ciphertext elements in the key switch output corresponding to the bits of the key switch output key 312 that do not appear in the key switch input key 311.
[0131] Specifically, according to the key 311 ciphertext The key can be switched to the key by adding zeros at the end of the ciphertext 312, thus outputting
[0132] This improves computational efficiency, since regular key switching for ciphertexts of size n1 can be avoided, and reduces noise, since adding linear combinations of noise can be avoided.
[0133] As a second embodiment, a key switch from a larger key 312 to a smaller key 311 may be performed. The digits of the key switch input key 312 may be a superset of the digits of the key switch output key 311. This key switch is also referred to as a "block key switch." In this case, the key switch may include key switching only for ciphertext elements in the encrypted value or encryption polynomial that correspond to digits in the key switch input key 312 that do not appear in the key switch output key 311.
[0134] Specifically, consider the key 312 ciphertext Key Switch to Key 311 can be improved because of shared randomness as follows. The b′ part can be reassembled into a temporary ciphertext: Some of them can be key-switched, for example, using conventional key-switching procedures. You can switch keys from key to key by key Key Switch to 311. The result can be added to ct″ to obtain the result.
[0135] In this embodiment, the key switching key can be smaller, for example proportional to n2-n1 instead of proportional to n2; the calculation can be faster, for example corresponding to a conventional key switch for a ciphertext of size n2-n1+1 instead of a conventional key switch for a ciphertext of size n2+1; the noise in the output may be smaller, for example because the algorithm involves smaller linear combinations.
[0136] In the same manner as described above, packed key switching (e.g., key switching that switches from one or more value ciphertexts to a polynomial ciphertext) can also be improved. In this case, the key switch can be applied to one or more values encrypted according to the key switch input key, thereby obtaining an encrypted key switch output polynomial based on the one or more values. Similarly, the above techniques are also applicable when the key switch input key and the key switch output key have common digits, but one of the keys is not a subset of the other key. Also in this case, the key switch operation for the common digits can be avoided (as discussed above), making the key switch key smaller, more efficient, and less noisy.
[0137] Combination Figure 2 and Figure 3 In an embodiment of the present invention, the key may also include both digits with predetermined values and digits with common digits with another key. This combination is called a shared randomness partial key. Specifically, the shared randomness partial key may be defined as follows: Figure 2 A partial list of keys described, with Figure 3 Such a key can be obtained by, for example, Figure 3 The structure in question is defined as SRSK, where the key is as Figure 2 The limited part of the key.
[0138] Figure 4a shows a detailed but non-limiting embodiment of a Programmable Self Bootstrapping (PBS).This embodiment illustrates a PBS in a LWE setting as known in the art.
[0139] It is known that PBS includes three operations: MS (modular switching), BR (blind rotation) and SE (sample extraction). This figure illustrates the input of LWE key according to blind rotation. The encrypted ciphertext 410 enters the MS+BR step 420 to output the RLWE key according to the blind rotation. The encrypted RLWE ciphertext 430 is then output by SE 440 according to the LWE key The encrypted LWE ciphertext is then encrypted 450, and finally an LWE key switch 460 is performed to return to the original blindly rotated input LWE key
[0140] In this case, the programmable bootstrap is used to return to the original LWE key It should be noted that this is usually not required. In addition, although this figure uses RLWE ciphertext as an example, another type of GLWE ciphertext can also be used.
[0141] Figure 4b shows a detailed but non-limiting embodiment of a programmable bootstrapping. This programmable bootstrapping is based on the embodiment of Figure 4a, but uses samples with one or more bits with predetermined values to extract the input key.
[0142] In more detail, modulus switching and blind rotation 421 may be applied to an input value 410 encrypted according to a blind rotation input key 421, thereby obtaining a rotation polynomial encrypted according to a blind rotation output key 431. The rotation polynomial may represent the application of a lookup table to the input value. Sample extraction 441 may be applied to the encrypted rotation polynomial, thereby obtaining an encrypted coefficient of the polynomial, which represents the output of the lookup table, wherein the sample extraction input key 431 in this embodiment is the same as the blind rotation output key. In addition, key switching 461 may be applied to the encrypted coefficient, thereby obtaining a key switching output. In this embodiment, the key switching returns to the key 410 based on which the input value is encrypted. Therefore, it is possible to obtain an encryption of the result of applying a lookup table to the input value, wherein the amount of noise of the resulting encryption is independent of the noise of the input value.
[0143] As illustrated, in this case, the output key 431 of the blind rotation (which is equal to the input key of the sample extraction) is a partial key. That is, it contains digits 432 that do not have a predetermined value and digits 433 that have a predetermined value.
[0144] As a result of using this partial key, the LWE ciphertext output by sample extraction 441 can be smaller than that in FIG. 4a because it is based on a smaller LWE key. 451 is encrypted with the LWE key 451 corresponds to the partial RLWE key As a result, the computational cost of key switching 461, the noise growth, and the storage requirements of the key switching key are reduced. In addition, the noise growth during blind rotation 421 is also smaller because the key polynomial includes zeros.
[0145] The illustrated embodiment can be generalized in several ways. Typically, one or more operations (e.g., linear homomorphic operations) may be applied to the ciphertext before applying sample extraction 441 and / or before applying key switching 461. As shown in FIG. 4a, key switching 461 may also be omitted or delayed.
[0146] Predetermined values other than zero may also be used. For example, the predetermined value may be all zeros or all ones, or may be a combination of zeros and ones, for example the predetermined value may be a hash of a preimage. In general, ciphertext may be efficiently converted between keys that differ only in the predetermined value, for example by computing ct′=(a1, a2, a3, a4, b-a3-a4), based on the partial key The ciphertext ct = (a1, a2, a3, a4, b) can be converted into The ciphertext of the same message encrypted.
[0147] Figure 4c shows a detailed but non-limiting embodiment of programmable bootstrapping. This embodiment is also based on the embodiment of Figure 4a. Similar to Figure 4b, it involves applying sample extraction using a sample extraction input key having one or more digits with predetermined values.
[0148] In this embodiment, the order of key switching and sample extraction is opposite to that in Figures 4a and 4b. That is, key switching is performed before sample extraction rather than after sample extraction.
[0149] Specifically, in this figure, modulus switching and blind rotation 420 are applied to an input encrypted according to an input key 410, thereby generating an encrypted rotation polynomial. The rotation polynomial can be encrypted according to a key 430 that is independent of the input key. A key switch 470 (in this embodiment, RLWE key switch) is applied based on the encrypted rotation polynomial to obtain a key switch output, which is encrypted according to a key switch output key 480.
[0150] Interestingly, the key switching output key 480 can be selected so that the subsequent sample extraction 490 produces an encryption according to the desired key. To this end, as illustrated, the key switching output key 480 (in this embodiment, the same as the sample extraction input key) can include one or more digits 482 with predetermined values, and can also include digits 481 of the desired key. In this way, the sample extraction 490 can indeed give the expected output, see Figure 4b.
[0151] For example, as also illustrated in the figure, the desired key may be the same key 410 as the key used to encrypt the input, that is, the blindly rotated input key of blind rotation 420. In this way, the encryption calculation may continue to be performed according to this key after the blind rotation. However, it may also be possible to switch to a different LWE key as desired.
[0152] By using sample extraction 490 with a shared randomness partial key in this manner, faster programmable bootstrapping with key switching is achieved. By performing key switching 470 prior to sample extraction, key switching 470 (in this embodiment, RLWE key switching) can be used on an encrypted polynomial rather than on an encrypted value. This is particularly advantageous because polynomial key switching can utilize FFT / NTT to speed up computations, thereby improving efficiency. Additionally, the size of the key material can also be reduced compared to value key switching.
[0153] As with FIG. 4 b , additional operations (e.g., linear homomorphic operations) may be performed, as desired, typically prior to key switching 470 or prior to sample extraction 490. Multiple programmable bootstrappings may also be performed that use the same blind rotations 420 but different key switches 470; thus, the proposed programmable bootstrapping may be used to obtain the resulting encryptions according to multiple corresponding output keys.
[0154] Figure 4d shows a detailed but non-limiting embodiment of programmable bootstrapping. This embodiment is also based on the embodiment of Figure 4a. As in Figures 4b and 4c, sample extraction 490 is used, where the sample extraction input key has one or more digits with predetermined values.
[0155] As shown in the embodiment, analog-to-digital conversion and blind rotation 422 may be performed on the input ciphertext. In this embodiment, interestingly, the blind rotation is performed so that the blind rotated output key 480 (also the sample extraction input key) includes one or more digits 482 with predetermined values and digits 481 of the desired output key. Thus, as discussed with respect to FIG. 4 c, applying sample extraction 490 results in encryption according to the desired output key. For example, as illustrated, the desired output key may be the same key 410 as the key under which the input ciphertext was encrypted (that is, the blind rotated input key), or any other desired key.
[0156] In other words, a partial key that shares randomness with the input key can be used so that the analog-to-digital conversion, blind rotation 422, and sample extraction 490 directly have the same key as input and output. Interestingly, in this embodiment, no key switch needs to be calculated to return to the input key, making this programmable bootstrapping particularly efficient and also eliminating the need for a key switch key in this embodiment.
[0157] FIG. 4 e shows a detailed but non-limiting embodiment of programmable bootstrapping.
[0158] This embodiment is similar to the embodiment of Figure 4d in that analog-to-digital conversion and blind rotation 423 are used, where the blind rotation has an output key 435, the output key 43 including a digit 436 of the desired output key and a digit 438 with a predetermined value. Also in this embodiment, sample extraction 442 is used, where the sample extraction input key is equal to the blind rotation output key 435. For example, sample extraction can be applied directly to the output of the blind rotation, or there can be one or more operations in between.
[0159] However, the blind rotation input key in this case includes not only the digit 436 of the desired output key and the digit 438 with a predetermined value, but also one or more additional digits 437. Therefore, the output of the sample extraction 442 can also be encrypted according to the key 455, which includes the digit 436 of the desired output key and the additional digit 437.
[0160] Thus, key switching 461 can be used to convert the output of sample extraction to an encryption based on a desired output key 436. As illustrated, this output key can be the same as the blindly rotated input key 410 used to encrypt the input encryption based on, but this is not required. Interestingly, the key switching in FIG. 4e is from an input key whose set of bits 436, 437 include the bits 436 of the output key. Thus, key switching 461 can be effectively implemented as a block key switching, see Figure 3 .
[0161] More generally, it is also advantageous if the sample extracted output key 455 has one or more bits in common with the desired output key, as this allows a more efficient implementation of the key switch 461 as described herein compared to a general key switch such as in FIG. 4a .
[0162] Specifically, a polynomial partial key 435 may be used that shares randomness with the input key 410 and also adds additional randomness 437 and a digit 438 with a known value. In this way, the efficiency of the key switching 461 is improved.
[0163] FIG5a shows a detailed but non-limiting example conversion between keys. In general, a cryptographic calculation or a portion of a cryptographic calculation may be based on a value key s,511 (e.g., an LWE key) and an associated polynomial key 521 (eg, GLWE key). The key material associated with this portion of the cryptographic calculation may be referred to herein as a key set.
[0164] As illustrated in the figure, this part of the encryption calculation may include one or more programmable bootstraps 520 from the value key 511 to the polynomial key 521. For example, as shown in Figure 4a, the programmable bootstrap may include modulus switching, blind rotation, and sample extraction. The programmable bootstrap, such as the blind rotation of the programmable bootstrap, may use the bootstrap key 529.
[0165] Additionally, the portion of the cryptographic calculation may include one or more key switches 560 from the polynomial key 521 to the value key 511. The key switches may use a key switch key 569.
[0166] The portion of the calculation may include other operations performed on the ciphertext encrypted according to the key 511, 521, for example linear operations such as addition between ciphertexts, or multiplication between ciphertexts and known integers.
[0167] Thus, the set of keys associated with this portion of the cryptographic calculation may include: value key 511; polynomial key 521; bootstrap key 529; and key switching key 569. It should be noted that the party performing the cryptographic calculation only uses bootstrap key 529 and key switching key 569, and typically does not have access to value key 511 and polynomial key 521.
[0168] Specifically, a key set can be defined as a set including the following keys: value key 511; polynomial key 521, wherein for the purpose of key switching 560, the polynomial key 521 can also be interpreted as a value key From the value key 511 to polynomial key 521's bootstrap key BSK, 529; and, from the polynomial key 521 (interpreted as value key) to value key Key switching key KSK of 511, 569.
[0169] It should be noted that the polynomial key and its interpretation as a value key are considered to be the same key and are not considered to be separate keys in a key set.
[0170] Typically, the number of digits in polynomial key 521 is greater than the number of digits in value key 511, for example, at least 2 times, at least 4 times, or at least 8 times. Therefore, polynomial key 521 is sometimes referred to as the "big key" in the key set, and value key 511 is sometimes referred to as the "small key" in the key set.
[0171] By using a key set as illustrated, cryptographic calculations with any number of operations may be performed, eg, there is no restriction on the number of applicable operations (eg, additions or multiplications).
[0172] Typically, the overall key set for homomorphic encryption may include multiple key sets as described with respect to this figure, such as multiple value keys and associated polynomial keys. Interestingly, by using keys 511, 521 with common digits and / or digits with predetermined values in this overall key set, there may be a smaller amount of public material, such as for key switching keys 569 and / or bootstrap keys 529, and improved computational efficiency. Multiple embodiments are presented herein.
[0173] FIG. 5 b shows a detailed but non-limiting example of conversion between keys.
[0174] As also discussed with respect to FIG. 5a, generally, the overall key set used in the cryptographic multiplication may include multiple key sets as defined with respect to FIG. 5a. Specifically, the overall key set may include multiple value keys (e.g., LWE keys) and associated polynomial keys (e.g., GLWE keys). By using different keys, typically with different parameters (e.g., N, k), for different parts of the cryptographic calculation, the cryptographic calculation can efficiently handle different precision requirements for different parts.
[0175] For example, a cryptographic calculation may involve at least two key sets of associated value keys and polynomial keys; at least three key sets; or at least five key sets. A cryptographic calculation may include one or more operations from one key set to another key set. The key material used by these operations may be referred to as a bridge key set.
[0176] For example, the figure illustrates the encryption calculation of three key sets, with corresponding value keys s (1) ,511;s (2) ,512; and s (3) ,513. The six arrows represent key switches between value keys. In this case, the bridging key set may include six corresponding key switch keys for the six corresponding key switches. More generally, the key set may include a key switch key for performing a key switch from each value key to each other value key.
[0177] Interestingly, the provided techniques allow for the use of a smaller set of bridge keys and / or the use of more efficient transformations.A number of embodiments are presented herein.
[0178] FIG. 5 c shows a detailed but non-limiting example of conversion between keys.
[0179] This embodiment shows how, by using keys with a common number of bits, one can have a smaller set of bridge keys and more efficient conversion between encryptions based on corresponding keys (specifically, LWE / GLWE keys). This embodiment shows key switching for value keys used in cryptographic calculations (thus not polynomial keys used in, for example, programmable bootstrapping).
[0180] That is, the figure shows a key switch between a first key 511, a second key 512, and a third key 513, wherein the digits of the first key 511 are a subset of the digits of the second key 512, and the digits of the second key 512 are a subset of the digits of the third key 513. The dotted arrows represent a key switch from a smaller key to a larger key. The solid arrows represent a key switch from a larger key to a smaller key. Three keys are shown in the figure, but this embodiment can also be extended to more than three keys, for example, at least five keys.
[0181] In this embodiment, because of the overlapping sets of digits, a key switch from a smaller key to a subsequently larger key (e.g., from key 511 to key 512, or from key 512 to key 513), or a key switch from a larger key to a subsequently smaller key (e.g., from key 513 to key 512, or from key 512 to key 511) can be efficiently performed, as described with respect to Figure 3 A key switch from one key to another non-subsequent key may be performed by performing a corresponding key switch between the subsequent keys (e.g., from key 511 to key 512, then from key 512 to key 513; or from key 513 to key 512, then from key 512 to key 511).
[0182] Specifically, for LWE-type keys, data may be converted from key set (1), 511 to either of the other two key sets 512, 513 by padding the ciphertext with zeros. Converting data from key set (2), 512 to key set (1), 511 may include computing a smaller key switch only for the portion of the ciphertext that does not correspond to key 511. This type of key switch is also referred to herein as a block key switch. In a similar manner, data conversion from key set (3), 513 to key set (1), 511 may be performed by first converting to key set (2), 512 by performing a key switch on the portion of key 513 that is not included in key 512, and then converting to key set (1), 511, as described above.
[0183] Therefore, the bridge key set in this case can be formed only by key switching from subsequent larger keys to smaller keys (e.g., from key 513 to key 512, and from key 512 to key 511). In other words, using shared randomness keys 511 to 513 will enable factoring of several key switching keys so that the key switching keys require a smaller total amount of data. It can also generate lower noise and achieve a more efficient key switching ciphertext procedure, as described.
[0184] FIG. 5 d shows a detailed but non-limiting example of conversion between keys.
[0185] In this embodiment, as shown in Figure 5c, three value keys 511, 512, 513 (e.g., LWE keys) are shown, where the bits of value key 511 are a subset of the bits of value key 512, and the bits of value key 512 are a subset of the bits of value key 513.
[0186] As described with respect to Figure 5a, typically, the encryption calculation typically involves a polynomial key (e.g., a GLWE key) corresponding to the corresponding value key. Specifically, the encryption calculation may involve a first polynomial key, a second polynomial key, and a third polynomial key corresponding to the first value key, the second value key, and the third value key.
[0187] Interestingly, in this embodiment, the polynomial key is also a shared randomness key. Specifically, the digits of the third value key 513 are a subset of the digits of the first polynomial key 521; the digits of the first polynomial key 521 are a subset of the digits of the second polynomial key 522; the digits of the second polynomial key 522 are a subset of the digits of the third polynomial key 523. As shown in Figure 5c, this embodiment can be generalized to a different number of value / polynomial key sets other than three, such as at least five such key sets.
[0188] This arrangement is beneficial because it provides an efficient method of transmitting data between key sets using small amounts of key material.
[0189] Specifically, as discussed with respect to FIG. 5 a, the encryption calculation may include key switches from a polynomial key of a key set to a corresponding value key (e.g., from key 521 to key 511; from key 522 to key 512; and / or from key 523 to key 513). In this embodiment, these key switches are from one key to another key that includes the key as a subset, so that they can be efficiently implemented, as discussed with respect to FIG. Figure 3 In addition, by implementing these key switches as key switches between subsequent keys 511, 512, 513, 521, 522, 523 (e.g., a key switch from key 521 to key 513; a key switch from key 513 to key 512; and a key switch from key 512 to key 511), the total amount of key material used for key switching keys can be greatly reduced.
[0190] Specifically, in this embodiment, the key switching key (whether from the key set or the bridge key set) can be factored into a list of block key switching keys because the digits of the keys in the key sequence formed by the value key and the polynomial key 511 to 523 are subsets of each other. For example, in this embodiment, the key switching key used for encryption calculations can be stored by storing the following keys:
[0191] ·from 523 to 522 block key switching key;
[0192] ·from 522 to 521 block key switching key;
[0193] ·from 521 to 513 block key switching key;
[0194] ·from 513 to 512 block key switching key;
[0195] ·from 512 to 511 block key switching key.
[0196] Compared to storing the randomness from arrive from arrive and from arrive The key material required for the key switching key can be much smaller.
[0197] Another advantage of using a value key and a polynomial key with shared randomness is that it allows for smaller bootstrap keys. Specifically, a first blind rotation can be applied by a first blind rotation input key 511 and an output key 521, and a second blind rotation can be applied by a second blind rotation input key 512 and the same blind rotation output key 521. If the blind rotation input keys 511, 512 have common digits (e.g., the digits of key 511 are a subset of the digits of key 512), the blind rotation keys can be stored more efficiently because they contain a common encryption. Similarly, the blind rotation keys from keys 511-513 to key 522 and from keys 511-513 to key 523 can be stored more efficiently using a common encryption.
[0198] Thus, by using a shared randomness key, several bootstrap keys may be factored together. Specifically, the bootstrap key may include multiple gadget ciphertexts that encrypt corresponding key digits of blindly rotated input keys 511-513. If one input key 511 is included in another key 512, the bootstrap key of the larger input key 512 may include the bootstrap key of the smaller input key 511. The gadget encryption may use the same polynomial size and the same base, or one base may be divided by the other base.
[0199] FIG. 5e shows a detailed but non-limiting example of conversion between keys.
[0200] This embodiment is based on the embodiment of Fig. 4c. That is, programmable bootstrapping from a value key 512 (e.g., a LWE key) to the same key can be implemented by performing modulus switching and blind rotation 520, thereby obtaining encryption according to a polynomial key 532 (e.g., a GLWE key); performing a key switching 572 (in this embodiment: a RLWE key switching; but this is not necessary), thereby obtaining an encryption polynomial according to a key 580, wherein the key 580 includes the digits of the key 512 and the digits 582 with predetermined values; applying sample extraction 592 according to the key 580.
[0201] This embodiment shows how such programmable bootstrapping can be used in cryptographic calculations that use multiple different key sets of associated value keys and polynomial keys. That is, as illustrated in the figure, a programmable bootstrapping can be effectively performed, wherein the programmable bootstrapping takes as input a value encrypted according to one key and takes as output a value encrypted according to another key. To this end, instead of performing a key switch 572 to a key that includes digits 512 of the value input key, a key switch 571, 537 can be performed to a key that includes digits of another expected value key. Subsequently, corresponding sample extraction 591, 593 can be applied to obtain an encrypted value according to the expected key.
[0202] Specifically, in this arrangement, the value key 512 and the polynomial key 532 may be independent of each other. The key switches 571-573 may be polynomial key switches, resulting in a partial and shared randomness key 572 to enable subsequent sample extractions 591 to 593. This will result in a different set of bridge keys than that shown in FIG5d. Interestingly, the key switches 571, 572, 573 may be polynomial key switches, specifically RLWE key switches, thereby allowing for small key switch keys (e.g., the RLWE key switch key may only include the same number of RLWE ciphertexts as the level), and may allow for efficient implementation using FFT.
[0203] In order to convert between value encryptions based on different keys, the value keys 512 may be defined so that their bits are subsets of each other, as discussed with respect to FIG. 5c. As explained, this enables efficient conversion, especially in an LWE setting. However, this is not required in this embodiment, for example because conversion between value encryptions may be performed via programmable bootstrapping, as described herein.
[0204] Similar to FIG. 5d , the blind rotation keys may also be factorized by having corresponding input keys of the blind rotation 520 be subsets of each other and have the same output key, which further reduces the size of the key material.
[0205] Figure 6 An example of one implementation of a cryptographic method 600 for performing cryptographic calculations is schematically illustrated. The method 600 may be computationally implemented.
[0206] The method 600 may include storing 610 a value and a polynomial encrypted according to one or more encryption keys. The keys may form a key set. A first key and a second key of the key set may have one or more common digits. Alternatively or additionally, at least one key of the key set may have one or more digits with predetermined values.
[0207] The method 600 may include applying 620 a blind rotation to an input value encrypted according to a blind rotated input key of the key set, thereby obtaining a rotation polynomial encrypted according to a blind rotated output key of the key set.
[0208] The method 600 may include applying 630 sample extraction to a polynomial encrypted according to a sample extraction input key of the key set, thereby obtaining encrypted coefficients of the polynomial. Alternatively or additionally, the method 600 may also include applying 640 key switching to a value or polynomial encrypted according to a key switching input key of the key set, thereby obtaining a key switching output encrypted according to a key switching output key of the key set.
[0209] Many different ways of performing method 600 are possible, as will be apparent to one of ordinary skill in the art. For example, the order of the steps may be performed in the order shown, but the order of the steps may be changed, or some steps may be performed in parallel. In addition, other method steps may be inserted between the steps. The inserted steps may represent improvements to the methods described herein, or may be unrelated to the present method. For example, some steps may be performed at least partially in parallel. In addition, a given step may not be completely completed before the next step begins.
[0210] The embodiment of the method can be performed using software, and the software includes instructions for making the processor system perform method 600. The software may only include those steps taken by the specific sub-entity of the system. The software can be stored in a suitable storage medium (such as, hard disk, floppy disk, memory, CD-ROM, etc.). The software can be sent as a signal by wired or wireless or using a data network (for example, the Internet). The software can be on a server for downloading and / or remote use. The embodiment of the method can be performed using a bit stream, and the bit stream is arranged to be used to configure a programmable logic (for example, a field programmable gate array (FPGA)), so as to perform the method.
[0211] It will be understood that the subject matter of the present disclosure is also extended to a computer program suitable for putting the subject matter of the present disclosure into practice, specifically a computer program on or in a carrier. The program can be in the form of source code, object code, code intermediate source, and object code such as partially compiled form, or any other form suitable for implementing the embodiment of the present method. The embodiment related to the computer program product includes computer executable instructions corresponding to each processing step of at least one method stated. These instructions can be subdivided into subroutines and / or stored in one or more files that can be statically or dynamically linked. Another embodiment related to the computer program product includes computer executable instructions corresponding to each device, unit and / or part of at least one system and / or product stated.
[0212] Typically, the devices described herein (e.g., the devices in Figures 1a to 1b) include one or more microprocessors for executing appropriate software stored in the system; for example, the software may have been downloaded and / or stored in a corresponding memory, for example, a volatile memory such as RAM or a non-volatile memory such as Flash. Alternatively, the system may be implemented in whole or in part with programmable logic (e.g., as a field programmable gate array (FPGA)). The system may be implemented in whole or in part as a so-called application-specific integrated circuit (ASIC), for example, an integrated circuit (IC) customized for their specific use. For example, the circuit can be implemented in CMOS, for example using a hardware description language such as Verilog, VHDL, etc. Specifically, the system may include a circuit for evaluating cryptographic primitives.
[0213] The processor circuit may be implemented in a distributed manner (e.g., as multiple sub-processor circuits). The memory may be distributed across multiple distributed sub-memories. Some or all of the memory may be electronic memory, magnetic memory, etc. For example, the memory may have a volatile portion and a non-volatile portion. A portion of the memory may be read-only.
[0214] Figure 7 A computer readable medium 1000 is shown having a writable portion 1010. The computer readable medium 1000 is shown in the form of an optically readable medium. The computer readable medium 1000 may store data 1020, where the data may indicate instructions that, when executed by a processor system, cause the processor system to perform an embodiment of a method of performing cryptographic calculations according to one embodiment.
[0215] Alternatively or additionally, data 1020 may represent one or more key switching keys and / or one or more bootstrap keys used to perform cryptographic calculations on values encrypted according to one or more encryption keys and polynomials, as described herein. The keys may form a key set. A first key and a second key of the key set may have one or more common digits, and / or at least one key of the key set may have one or more digits with predetermined values.
[0216] The data 1020 may be implemented on the computer readable medium 1000 as a physical mark or by magnetization of the computer readable medium 1000. However, any other suitable implementation is also conceivable. In addition, it will be understood that although the computer readable medium 1000 is shown as an optical disk, the computer readable medium 1000 may be any suitable computer readable medium, such as a hard disk, solid state memory, flash memory, etc., and may be non-recordable or recordable.
[0217] Figure 8 A schematic representation of a processor system 1140 according to one embodiment of a device for performing cryptographic calculations is shown. The processor system includes one or more integrated circuits 1110. The architecture of one or more integrated circuits 1110 is schematically shown in the figure. The circuit 1110 includes a processing unit 1120 (e.g., a CPU) for running a computer program component to perform a method according to one embodiment and / or implement its modules or units. The circuit 1110 includes a memory 1122 for storing programming code, data, etc. A portion of the memory 1122 may be read-only. The circuit 1110 may include a communication element 1126, such as an antenna, a connector, or both. The circuit 1110 may include an application-specific integrated circuit 1124 for performing some or all of the processing defined in the method. The processor 1120, the memory 1122, the application-specific integrated circuit 1124, and the communication element 1126 may be connected to each other via an interconnect 1130 (e.g., a bus). The processor system 1110 may be arranged for contact and / or contactless communication, using an antenna and / or a connector, respectively.
[0218] For example, in one embodiment, the processor system 1140 (e.g., a device for performing cryptographic calculations) may include a processor circuit and a memory circuit, wherein the processor is arranged to execute software stored in the memory circuit. For example, the processor circuit may be an Intel Core i7 processor, an ARM Cortex-R8, etc. In one embodiment, the processor circuit may be an ARM Cortex M0. The memory circuit may be a ROM circuit, or a non-volatile memory (e.g., flash memory). The memory circuit may be a volatile memory (e.g., SRAM memory). In the latter case, the device may include a non-volatile software interface (e.g., a hard disk, a network interface, etc.) arranged to provide software.
[0219] The following clauses include advantageous embodiments.
[0220] Clause 1. A cryptographic method for performing a cryptographic computation, comprising:
[0221] - storing a value and a polynomial encrypted according to one or more encryption keys, wherein the one or more encryption keys form a key set;
[0222] - applying blind rotation to an input value encrypted according to a blind rotated input key of said key set, thereby obtaining a rotation polynomial encrypted according to a blind rotated output key of said key set; and
[0223] - applying sample extraction to a polynomial encrypted according to a sample extraction input key of the key set, thereby obtaining encrypted coefficients of the polynomial, and / or applying key switching to a value or polynomial encrypted according to a key switching input key of the key set, thereby obtaining a key switching output encrypted according to a key switching output key of the key set;
[0224] The first key and the second key of the key set have one or more common digits, and / or at least one key implementing the key set has one or more digits with predetermined values.
[0225] Clause 2. The method of clause 1, comprising applying sample extraction based on a cryptographic rotation polynomial, wherein the sample extraction input key has one or more digits with predetermined values.
[0226] Clause 3. The method of clause 2, wherein the sample extraction input key is a blind rotation output key.
[0227] Clause 4. The method of clause 2 or 3, wherein the sample extraction input key also has one or more digits in common with the blind rotation input key.
[0228] Clause 5. The method of clause 4, wherein the set of digits of the sample-extracted input key consists only of the digits of the blindly rotated input key and the set of digits with predetermined values.
[0229] Clause 6. The method according to clause 2, comprising:
[0230] - Apply blind rotation to obtain the encrypted rotation polynomial;
[0231] - applying the key switching based on the encryption rotation polynomial to obtain a key switching output encrypted according to the key switching output key, and
[0232] - applying said sample extraction based on said key switching output so as to obtain encryption according to a desired key,
[0233] The key switching output key includes digits with predetermined values and also includes digits of the desired key.
[0234] Clause 7. The method of clause 6, wherein the desired key is the blindly rotated input key.
[0235] Clause 8. The method according to Clause 6 or 7 also includes: applying another blind rotation based on the same blind rotation input key and blind rotation output key; applying another key switch based on the another blind rotation and according to another key switch output key; and applying another sample extraction based on the another key switch to obtain another encryption based on another expected key.
[0236] Clause 9. A method according to any preceding clause, comprising applying the key switch, wherein the key switch input key and the key switch output key have one or more digits in common.
[0237] Clause 10. The method of clause 9, comprising applying the key switching to one or more values encrypted according to the key switching input key, thereby obtaining an encrypted key switching output polynomial based on the one or more values.
[0238] Clause 11. The method according to clause 9 or 10, wherein:
[0239] - the bits of the key switch input key are a subset of the bits of the key switch output key, and the key switch comprises setting to zero ciphertext elements in the key switch output corresponding to bits in the key switch output key that do not appear in the key switch input key, and / or
[0240] -The digits of the key switch input key are a superset of the digits of the key switch output key, and the key switch includes key switching only for ciphertext elements in the encrypted value or encryption polynomial that correspond to digits in the key switch input key that do not appear in the key switch output key.
[0241] Clause 12. A method according to clause 11, wherein the digits of the first key are a subset of the digits of the second key, and the digits of the second key are a subset of the digits of the third key, wherein the method includes applying a key switch between the first key and the second key, and applying a key switch between the second key and the third key.
[0242] Clause 13. A method according to any preceding clause, comprising applying blind rotation with the first blind rotation input key and the second blind rotation input key respectively, wherein the first blind rotation input key and the second blind rotation input key have one or more common digits.
[0243] Clause 14. A cryptographic device (110) for performing cryptographic calculations, comprising:
[0244] - a memory (140) for storing values and polynomials encrypted according to one or more encryption keys, wherein the one or more encryption keys form a key set;
[0245] - a processor subsystem (130), configured to:
[0246] - applying blind rotation to an input value encrypted according to a blind rotated input key of said key set, thereby obtaining a rotation polynomial encrypted according to a blind rotated output key of said key set; and
[0247] - applying sample extraction to a polynomial encrypted according to a sample extraction input key of the key set, thereby obtaining encrypted coefficients of the polynomial, and / or applying key switching to a value or polynomial encrypted according to a key switching input key of the key set, thereby obtaining a key switching output encrypted according to a key switching output key of the key set;
[0248] The first key and the second key of the key set have one or more common digits, and / or at least one key of the key set has one or more digits with predetermined values.
[0249] Clause 15. A transitory or non-transitory computer-readable medium (1000) comprising data (1020) representing:
[0250] - instructions which, when executed by a processor system, cause the processor system to perform a method according to any of clauses 1 to 13; and / or
[0251] - one or more key switching keys and / or bootstrap keys for performing cryptographic calculations on values and polynomials encrypted according to one or more encryption keys, wherein the one or more encryption keys form a key set, wherein a first key of the key set has one or more common digits with a second key, and / or at least one key of the key set has one or more digits with predetermined values.
[0252] Although device 1110 is shown as including one of each described component, multiple components may be repeated in multiple embodiments. For example, processor 1120 may include multiple microprocessors configured to independently perform the methods described herein, or configured to perform the steps or subroutines of the methods described herein so that multiple processors cooperate to implement the functions described herein. In addition, in the case where device 1110 is implemented in a cloud computing system, multiple hardware components may belong to separate physical systems. For example, processor 1120 may include a first processor in a first server and a second processor in a second server.
[0253] It should be noted that the above-mentioned embodiments illustrate rather than limit the disclosed subject matter, and that those skilled in the art will be able to design many alternative embodiments.
[0254] In the claims, any reference numerals placed in brackets shall not be interpreted as limiting the claims. The use of the verb 'comprise' and its variants does not exclude the presence of elements or steps other than those stated in the claims. The article 'a' or 'an' in front of an element does not exclude the presence of multiple such elements. When an expression such as "at least one" is placed before a list of elements, it means selecting all elements or any subset thereof from the list. For example, the expression "at least one of A, B, and C" should be understood to include only A, only B, only C, both A and B, both A and C, both B and C, or all of A, B, and C. The subject matter of the present disclosure can be implemented by hardware including several different elements, and by a suitably programmed computer. In a device claim that lists several parts, several of these parts can be implemented by the same hardware item. The mere fact that certain measures are recorded in mutually different dependent claims does not indicate that the combination of these measures cannot be used to advantage.
[0255] In the claims, reference numerals in parentheses refer to reference numerals in the drawings illustrating the embodiments or formulas of the embodiments, thereby improving the intelligibility of the claims. These reference numerals should not be construed as limiting the claims.
Claims
1. A cryptographic method (600) for performing cryptographic computations in fully homomorphic encryption [FHE] supporting programmable bootstrapping, comprising: - storing (610) a value and a polynomial encrypted according to one or more encryption keys, the one or more encryption keys forming a key set, the encryption key having a plurality of digits; - applying (620) a blind rotation to an input value encrypted according to a blind rotated input key of said key set, thereby obtaining a rotation polynomial encrypted according to a blind rotated output key of said key set; as well as - applying (630) sample extraction to a polynomial encrypted according to a sample extraction input key of the key set, thereby obtaining encrypted coefficients of the polynomial, and / or applying (640) key switching to a value or polynomial encrypted according to a key switching input key of the key set, thereby obtaining a key switching output encrypted according to a key switching output key of the key set; The digits of the first key are a subset of the digits of the second key of the key set, and / or at least one key of the key set has one or more digits with predetermined values.
2. The method (600) of claim 1, comprising applying sample extraction based on a cryptographic rotation polynomial, wherein the sample extraction input key has one or more digits with predetermined values.
3. The method (600) of claim 2, wherein the sample extraction input key is the blind rotation output key.
4. The method (600) of claim 2 or 3, wherein the sample extraction input key also has one or more digits in common with the blind rotation input key.
5. The method (600) of claim 4, wherein the set of digits of the sample-extracted input key consists only of the digits of the blindly rotated input key and the set of digits with predetermined values.
6. The method (600) of claim 2, comprising: - Applying the blind rotation to obtain an encrypted rotation polynomial; - applying the key switching based on the encryption rotation polynomial to obtain a key switching output encrypted according to the key switching output key, and - applying said sample extraction based on said key switching output so as to obtain encryption according to a desired key, The key switching output key includes one or more digits with predetermined values and also includes the digits of the expected key.
7. The method (600) of claim 6, wherein the desired key is the blindly rotated input key.
8. The method (600) according to claim 6 or 7, further comprising: applying another blind rotation based on the same blind rotation input key and blind rotation output key; Another key switch is applied based on the another blind rotation and according to another key switch output key; and another sample extraction is applied based on the another key switch, thereby obtaining another encryption according to another desired key.
9. The method (600) of any preceding claim, comprising applying the key switching, wherein the key switch input key has one or more digits in common with the key switch output key.
10. The method (600) of claim 9, comprising applying the key switching to one or more values encrypted according to the key switching input key, thereby obtaining an encrypted key switching output polynomial based on the one or more values.
11. The method (600) according to claim 9 or 10, wherein: - the bits of the key switch input key are a subset of the bits of the key switch output key, and the key switch comprises setting to zero ciphertext elements in the key switch output corresponding to bits in the key switch output key that do not appear in the key switch input key, and / or -The digits of the key switch input key are a superset of the digits of the key switch output key, and the key switch includes key switching only for ciphertext elements in the encrypted value or encryption polynomial that correspond to digits in the key switch input key that do not appear in the key switch output key.
12. A method according to claim 11, wherein the digits of the first key are a subset of the digits of the second key, and wherein the digits of the second key are a subset of the digits of the third key, wherein the method includes applying key switching between the first key and the second key, and applying key switching between the second key and the third key.
13. The method (600) according to any preceding claim, comprising applying blind rotation with a first blind rotation input key and a second blind rotation input key, respectively, wherein the first blind rotation input key and the second blind rotation input key have one or more common digits.
14. The method (600) of any preceding claim, wherein the first key comprises a digital The second key where n1<n2, and where for 1≤i≤n1, 15. The method (600) of any preceding claim, wherein the second key has at least 2 times, at least 4 times, or at least 8 times the number of digits of the first key.
16. A method (600) according to any preceding claim, wherein the digits comprise scalar values forming a cryptographic key, for example values forming a LWE key, or coefficients of a polynomial forming a GLWE key.
17. The method (600) of any preceding claim, wherein the first key comprises a digital And the second key includes a digital And among them for And among them and Indicates common digits between the first key and the second key.
18. A cryptographic device (110) for performing cryptographic computations in fully homomorphic encryption [FHE] supporting programmable bootstrapping, comprising: - a memory (140) for storing values and polynomials encrypted according to one or more encryption keys, wherein the one or more encryption keys form a key set, the encryption key having a plurality of digits; - a processor subsystem (130), configured to: - applying blind rotation to an input value encrypted according to a blind rotated input key of said key set, thereby obtaining a rotation polynomial encrypted according to a blind rotated output key of said key set; as well as - applying sample extraction to a polynomial encrypted according to a sample extraction input key of the key set, thereby obtaining encrypted coefficients of the polynomial, and / or applying key switching to a value or polynomial encrypted according to a key switching input key of the key set, thereby obtaining a key switching output encrypted according to a key switching output key of the key set; The digits of the first key are a subset of the digits of the second key of the key set, and / or at least one key of the key set has one or more digits with predetermined values.
19. A transitory or non-transitory computer-readable storage medium (1000) comprising data (1020), wherein the data represents: - instructions which, when executed by a processor system, cause the processor system to perform a method according to any one of claims 1 to 17; and / or - one or more key switching keys and / or blind rotation keys for performing cryptographic calculations on values and polynomials encrypted according to one or more encryption keys, wherein the one or more encryption keys form a key set, wherein a first key and a second key of the key set have one or more common digits, and / or at least one key of the key set has one or more digits with predetermined values.
Citation Information
Patent Citations
Enabling constant plaintext space in bootstrapping in fully homomorphic encryption
CN112075050A
Quantum homomorphic encryption and decryption method based on multi-valued single quantum state
CN113922944A
Electronic device for using homomorphic encryption and method for processing encrypted data thereof
CN113972978A
System and Method For Cryptographic Keys Security in the Cloud
US20200250318A1