CKKS bootstrap method and system realized based on blind rotation
By introducing a blind rotation algorithm based on NTRU into the CKKS bootstrap method, the problems of low computing efficiency and increased key scale in the prior art are solved, and a more efficient and high-precision bootstrap process is realized, supporting smaller N-value parameter selection and ensuring security.
Patent Information
- Application Number
- CN202510257338.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-05
AI Technical Summary
When the existing CKKS bootloader method handles high noise ciphertexts, the operation efficiency is low and the key scale increases, resulting in excessive consumption of layers and affecting the number of homomorphic operations.
The blind rotation algorithm based on NTRU is adopted to improve the computing efficiency of the blind rotation step, and the ciphertext scale is controlled through the characteristics of NTRU encryption to achieve a more efficient bootstrap process.
The calculation efficiency and accuracy of the CKKS bootstrap method are significantly improved, and the number of layers consumes only one-tenth of the traditional bootstrap solution. At the same time, it supports smaller N-value parameter selection, ensuring security and computing efficiency.
Smart Images

Figure CN119995830A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of fully homomorphic encryption, and in particular to a CKKS bootstrapping method and system based on blind rotation. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] Fully homomorphic encryption is one of the core breakthroughs in modern data privacy protection technology. Its core idea is to achieve "available but invisible" data, allowing any calculation on encrypted data without decryption. The CKKS scheme is a fully homomorphic encryption scheme that supports floating-point operations, homomorphic addition and homomorphic multiplication operations. The security of the CKKS scheme is based on the RLWE problem, and its ciphertext contains noise components. The ciphertext after encrypting the plaintext contains only a small amount of noise, which has no effect on decryption. At this time, it is a low-noise ciphertext. However, in the actual operation process, homomorphic operations, especially homomorphic multiplication operations, will multiply the noise, causing it to increase rapidly, and when the noise exceeds a certain threshold, it will lead to the inability to correctly decrypt. Therefore, the ciphertext that is about to reach the critical value is called high-noise ciphertext. High-noise ciphertext will only support a few homomorphic operations, otherwise it will not be correctly decrypted. At this time, it is necessary to use the bootstrap technology to restore it to low-noise ciphertext to support more homomorphic operations on the premise of being able to correctly decrypt. The purpose of bootstrapping is to increase the number of layers corresponding to the ciphertext. The essence of bootstrapping is to homomorphically calculate the decryption function of the CKKS homomorphic encryption scheme. Modulo operation is a nonlinear operation that cannot be directly calculated by combining homomorphic addition and homomorphic multiplication. It is the most difficult and computationally expensive step in the bootstrapping operation.
[0004] In the initial CKKS scheme and many subsequent optimization schemes, the decryption function in the encrypted state is approximated with a smaller error by finding a better approximation polynomial. However, the inherent error introduced by the polynomial approximation will cause a significant loss of accuracy in the bootstrap. In order to achieve high-precision bootstrapping, this also requires that the CKKS scheme must use larger parameters. For the polynomial ring, the value of N is usually not less than 2. 16 The increase in the degree of the polynomial means an increase in the computational cost, and the number of layers consumed by the bootstrap step will also increase, resulting in a decrease in the number of homomorphic operations that can be performed on the ciphertext from the time of this bootstrap until the next bootstrap is needed, resulting in more frequent bootstrap operations.
[0005] The existing scheme calculates the decryption function through a blind rotation algorithm, which does not rely on polynomial approximation, reduces the error, and supports smaller values of N, such as 2 13, and security can be guaranteed under this value. However, the blind rotation in this scheme is still inefficient, and the key size increases because the scheme expands the rotation key. Summary of the invention
[0006] In order to overcome the shortcomings of the above-mentioned prior art, the present invention provides a CKKS bootstrapping method and system based on blind rotation. By introducing advanced NTRU-based blind rotation, the computational efficiency of the blind rotation step is improved, and the characteristics of NTRU encryption are used to control the ciphertext scale, thereby improving the overall computational efficiency of the scheme.
[0007] To achieve the above objectives, one or more embodiments of the present invention provide the following technical solutions:
[0008] The first aspect of the present invention provides a CKKS bootstrapping method based on blind rotation;
[0009] A CKKS bootstrapping method based on blind rotation, comprising:
[0010] Obtain a high-noise CKKS ciphertext, and perform a preprocessing operation and a homomorphic linear operation on the high-noise CKKS ciphertext to generate a first ciphertext and a second ciphertext;
[0011] Performing modulus lifting on the first ciphertext to generate a third ciphertext;
[0012] Bootstrapping the second ciphertext based on the NTRU blind rotation algorithm to obtain a fourth ciphertext;
[0013] The third ciphertext and the fourth ciphertext are added based on homomorphic addition to obtain the final required low-noise ciphertext.
[0014] As a further technical solution, the preprocessing operation is to perform modulus decomposition on the high-noise ciphertext to obtain the first ciphertext; specifically,
[0015] For high noise ciphertext
[0016] In the formula, (c0, c1) is the encrypted ciphertext, m is the plaintext polynomial; s and e are The polynomial on yes The residual class ring of is a polynomial quotient ring, where q is the modulus, which represents the power of 2;
[0017] Then the decryption of the high-noise ciphertext ct is:
[0018] [<ct,s> ] q =c1·s+c0=m+e(mod q),
[0019] In the formula,<ct,sk> represents the outer product of ct and sk, where sk is the private key; [·] q represents the modulo q operation; m+e(mod q) is expressed as m+e+q·v, where mod q is the modulo q operation on the coefficients of the polynomial obtained by adding m+e; let q′=q / p, where p, q, q′ are all moduli, which are powers of 2, and the first ciphertext ct′ is calculated:
[0020] Its decryption can be expressed as m+e+q′·u.
[0021] As a further technical solution, the process of performing modulus enhancement on the first ciphertext to generate the third ciphertext is: enhancing the modulus of the first ciphertext ct′ from q′ to Q, where Q>>q′, to obtain the third ciphertext; specifically,
[0022] The first ciphertext ct′=RLWE q′,s After decryption, (m+e) is m+e(mod q′). According to the basic operation rules of modular operation, m+e(mod q′) is converted to m+e+q′·u, where u is The third ciphertext is obtained by using the above polynomial
[0023] As a further technical solution, the NTRU-based blind rotation algorithm bootstraps the second ciphertext to obtain the fourth ciphertext in the following process:
[0024] Extracting the second ciphertext into n LWE ciphertexts, and preprocessing the LWE ciphertexts;
[0025] Obtain the computation key and automorphic key of the preprocessed LWE ciphertext; obtain the NTRU ciphertext based on the blind rotation algorithm, and convert the NTRU ciphertext into the fourth ciphertext that complies with the CKKS encoding through the repackaging algorithm.
[0026] As a further technical solution, it also includes initialization settings, which include parameter initialization and encoding of message vectors.
[0027] As a further technical solution, the parameter initialization includes defining a polynomial ring and setting security parameters.
[0028] The second aspect of the present invention provides a CKKS bootstrap system based on blind rotation.
[0029] A CKKS bootstrap system based on blind rotation, comprising:
[0030] A preprocessing module is configured to: obtain a high-noise ciphertext, perform a preprocessing operation on the high-noise ciphertext, and generate a first ciphertext;
[0031] A homomorphic linear operation module is configured to: perform a homomorphic linear operation on the high-noise ciphertext to generate a second ciphertext;
[0032] A modulus enhancement module is configured to: perform modulus enhancement on the first ciphertext to generate a third ciphertext;
[0033] A bootstrapping module is configured to: bootstrap the second ciphertext based on the NTRU blind rotation algorithm to obtain a fourth ciphertext;
[0034] The low-noise ciphertext acquisition module is configured to: add the third ciphertext and the fourth ciphertext based on homomorphic addition to obtain the final required low-noise ciphertext.
[0035] As a further technical solution, the bootstrapping system further includes an initialization setting module, and the initialization setting includes parameter initialization and encoding of a message vector.
[0036] The third aspect of the present invention provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the steps in a CKKS bootstrapping method based on blind rotation as described in the first aspect of the present invention.
[0037] The fourth aspect of the present invention provides an electronic device, including a memory, a processor, and a program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps in the CKKS bootstrapping method based on blind rotation as described in the first aspect of the present invention are implemented.
[0038] One or more of the above technical solutions have the following beneficial effects:
[0039] The present invention aims at the problem that the CKKS bootstrap scheme does not support a smaller N value, consumes too many layers, and there is always an inherent error between the approximate polynomial and the decryption function that affects the bootstrap accuracy. By applying the blind rotation algorithm to the homomorphic calculation decryption function and introducing blind rotation based on the NTRU problem, the bootstrap of CKKS is realized, the computational efficiency of the blind rotation step is improved, and at the same time, it has higher accuracy, and the number of layers consumed is only one tenth of that of the traditional bootstrap scheme.
[0040] Advantages of additional aspects of the present invention will be given in part in the following description, and in part will become obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The accompanying drawings in the specification, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0042] Figure 1This is a flow chart of the method of the first embodiment.
[0043] Figure 2 It is a schematic diagram of the comparison result between the self-bootstrapping scheme adopted by the present invention and the existing self-bootstrapping scheme in the first embodiment.
[0044] Figure 3 It is a system structure diagram of the second embodiment. DETAILED DESCRIPTION
[0045] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.
[0046] It should be noted that the terms used herein are for describing specific embodiments only and are not intended to be limiting of exemplary embodiments according to the present invention.
[0047] In the absence of conflict, the embodiments of the present invention and the features of the embodiments may be combined with each other.
[0048] Embodiment 1
[0049] This embodiment discloses a CKKS bootstrapping method based on blind rotation implementation;
[0050] like Figure 1 As shown, a CKKS bootstrapping method based on blind rotation implementation includes the following steps:
[0051] Step S1, obtaining a high-noise CKKS ciphertext, performing a preprocessing operation and a homomorphic linear operation on the high-noise CKKS ciphertext, respectively, to generate a first ciphertext and a second ciphertext;
[0052] Step S2, performing modulus lifting on the first ciphertext to generate a third ciphertext;
[0053] Step S3, bootstrapping the second ciphertext based on the blind rotation algorithm of NTRU to obtain a fourth ciphertext;
[0054] Step S4: Add the third ciphertext and the fourth ciphertext based on homomorphic addition to obtain the final required low-noise ciphertext.
[0055] In step S1, the high-noise ciphertext ct is the ciphertext encrypted under the CKKS homomorphic encryption scheme. The CKKS scheme is proposed based on the RLWE problem, so the ciphertext can be expressed in RLWE form. In the formula, (c0, c1) is the encrypted ciphertext, m is the plaintext polynomial; s and e are The polynomial on yes The residual class ring of is a polynomial quotient ring, q is the modulus. s, m, e, c0, c1 are Polynomial on RLWE q,s (m+e) represents the RLWE encryption of the plaintext polynomial m. is a polynomial ring with integer coefficients, is an integer ring; N is the polynomial degree, then the decryption of the high-noise ciphertext ct is:
[0056] [<ct,sk> ] q =c1·s+c0=m+e(mod q);
[0057] In the formula,<ct,sk> represents the outer product of ct and sk, where sk is the private key; [·] q Represents modulo q operation. m+e(mod q) can be expressed as m+e+q·v, where mod q is the modulo q operation on the coefficients of the polynomial obtained by adding the two polynomials m+e; let q′=q / p, where p, q, q′ are all moduli, which are powers of 2 and whose values meet the following requirements: q′|q, p|q, p|N. The first ciphertext ct′ is calculated as:
[0058] Its decryption can be expressed as m+e+q′·u.
[0059] Based on the obtained high-noise ciphertexts ct and ct′, a homomorphic linear operation is performed to obtain the second ciphertext ct″, as shown in the following formula:
[0060] ct″=(ct-ct′) / q′;
[0061] ct″ can essentially be regarded as RLWE ciphertext
[0062] Furthermore, in step S2, the modulus of the first ciphertext ct′ is increased from q′ to Q, where Q>>q′. ct′=RLWE q′,s (m+e) is decrypted to m+e(modq′). According to the basic operation rules of modular operation, m+e(modq′)=m+e+q′·u, where u is In the above polynomial, since Q>>q, the coefficients of the polynomial obtained by m+e+q′·u are all less than Q, so m+e+q′·u(modQ)=m+e+q′·u, which can be regarded as The third ciphertext is obtained
[0063] Further, in step S3, the bootstrap of the high-noise ciphertext ct is converted to the second ciphertext ct″″=RLWE p,s(-u) bootstrap. Bootstrapping keeps the decrypted plaintext unchanged and achieves modulus improvement, which is equivalent to increasing the number of layers in the CKKS scheme. After bootstrapping, the fourth ciphertext is obtained e1 is the new noise generated during the bootstrap process. Specifically,
[0064] S31, since the RLWE ciphertext consists of two ring polynomials and cannot be blindly rotated, it is necessary to extract the RLWE ciphertext into LWE ciphertext. Input the second ciphertext Output Vector (u0,u1,…,u n-1 ) is the coefficient vector of -u. The decryption is essentially r(X)s(X)+t(X), assuming that the coefficient vector corresponding to -u is (u0,u1,…,u n-1 ), similarly, the coefficient vector corresponding to r is (r0,r1,…,r n-1 ), the coefficient vector corresponding to s is (s0,s1,…,s n-1 ), the coefficient vector corresponding to t is (t0, t1, …, t n-1 ).
[0065] According to polynomial multiplication, it is easy to infer:
[0066]
[0067] and
[0068] S32, discuss one of the LWE ciphertexts and set this ciphertext to Generate a compute key and automorphic keys 1:1≤i≤p-1, where N is the degree of the polynomial ring and f is the private key of NTRU.
[0069] Due to its automorphic structure, it is necessary to i Perform preprocessing to ensure w i is relatively prime to 2N so that the property can be maintained for subsequent operations. Ask for w i The inverse under the module p is output as w′, and w′ n Set to 1. Among them, r i For vector The i-th element of i The inverse modulo p can be found by extending the Euclidean algorithm.
[0070] S33, input The fourth ciphertext is obtained based on the blind rotation algorithm of NTRU
[0071] (1) The blind rotation algorithm first initializes the homomorphic accumulator ACC to an NTRU ciphertext Using automorphism Convert the input ciphertext from an encryption of u(X) to an encryption of encryption.
[0072] Specifically, isomorphism Exists in There is an automorphism mapping NTRU is also So we have Since the key has also changed accordingly, the key exchange algorithm is implemented once. After n cycles, the new ciphertext is obtained
[0073] (2) Make up for the redundant items caused by ciphertext processing.
[0074] The formula to make up for the redundant items caused by ciphertext processing is as follows:
[0075] in To calculate the secret key. The operation can be transformed into The calculation is:
[0076]
[0077] Substituting the above formula into Verifiable:
[0078]
[0079] Then, the processed ciphertext is obtained
[0080] (3) Extract and repack the processed ciphertext and verify the obtained fourth ciphertext. Specifically, after blind rotation, the output ACC is NTRU ciphertext, and the NTRU ciphertext is converted into the fourth ciphertext that complies with CKKS encoding through the repacking algorithm.
[0081] Specifically, since the NTRU ciphertext is a polynomial, the polynomial coefficient vector is The n LWE ciphertexts extracted by RLWE are subjected to blind rotation and NTRU extraction steps to obtain n vectors
[0082] Repack the obtained vector into RLWE ciphertext through linear operation and output the fourth ciphertext Among them, n vectors As the i-th row of the matrix M. Set the repackaging key to The CKKS encryption of the NTRU key using the key s is calculated with the vector encoding as input. Get the fourth ciphertext Its essence is matrix and vector multiplication.
[0083] Further, in step S4, the third ciphertext With the fourth ciphertext Add together to obtain the final required low-noise RLWE ciphertext RLWE Q,s (m+e+e1). This ciphertext is still an encryption of the initial plaintext, and has a higher modulus, that is, a higher number of layers, to support subsequent homomorphic computation.
[0084] In addition, the CKKS bootstrapping process also includes initialization settings, where the initialization settings include parameter initialization and encoding the message vector.
[0085] Parameter initialization involves defining the polynomial ring Its business cycle is Both q and N are powers of 2; given a base p and an integer L, let q l =p l , where l = 1, ..., L, L can be understood as the number of layers; set the scaling factor Δ, the value of the scaling factor is similar;
[0086] Set security parameters λ, standard deviation σ and scaling factor Δ; generate private key sk, randomly select noise polynomial e from Gaussian distribution with standard deviation σ, and select random noise polynomial e from distribution with Hamming weight h. A polynomial s is randomly selected from .
[0087] During the encoding process, rounding operations may destroy some numbers in the message, so the message vector is multiplied by a scaling factor Δ before rounding to maintain its accuracy.
[0088] In addition, combined Figure 2 The scheme of the present invention is verified by experiments. Under the optimal parameter selection, the bootstrapping efficiency of CKKS ciphertext will be increased by 32.67% compared with the best scheme of the same type. Compared with the CKKS bootstrapping scheme implemented by the polynomial approximation scheme, the present invention only consumes 1-2 levels in the bootstrapping process, providing more times of redundancy for subsequent homomorphic operations.
[0089] The present invention supports N=2 13The parameters are selected, and under these parameters, it has IND-CPA (indistinguishable under chosen plaintext attacks) security.
[0090] Solution supports N=2 12 The parameter selection is improved and the bootstrap accuracy under this parameter is improved.
[0091] By comparing with the existing CKKS ciphertext bootstrapping scheme, the experimental results are as follows Figure 2 As shown, when N = 2 12 The computational efficiency of this solution is about 15.7% higher than that of the best solution of the same type. 13 The computational efficiency of this scheme is about 30.4% higher than that of the best scheme of the same type.
[0092] Due to the existence of rotating key pairs in the existing scheme, the size of blind rotating keys increases, especially when N=2 13 The scale of the blind rotation key of the present invention is only half of that of the existing scheme.
[0093] Embodiment 2
[0094] This embodiment discloses a CKKS bootstrap system based on blind rotation implementation;
[0095] like Figure 3 As shown, a CKKS bootstrap system based on blind rotation implementation includes:
[0096] A preprocessing module is configured to: obtain a high-noise ciphertext, perform a preprocessing operation on the high-noise ciphertext, and generate a first ciphertext;
[0097] A homomorphic linear operation module is configured to: perform a homomorphic linear operation on the high-noise ciphertext to generate a second ciphertext;
[0098] A modulus enhancement module is configured to: perform modulus enhancement on the first ciphertext to generate a third ciphertext;
[0099] A bootstrapping module is configured to: bootstrap the second ciphertext based on the NTRU blind rotation algorithm to obtain a fourth ciphertext;
[0100] The low-noise ciphertext acquisition module is configured to: add the third ciphertext and the fourth ciphertext based on homomorphic addition to obtain the final required low-noise ciphertext.
[0101] Furthermore, the bootstrapping system further comprises an initialization setting module, wherein the initialization setting comprises parameter initialization and encoding of a message vector.
[0102] Embodiment 3
[0103] The purpose of this embodiment is to provide a computer-readable storage medium.
[0104] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in a CKKS bootstrapping method based on blind rotation as described in Example 1.
[0105] Embodiment 4
[0106] The purpose of this embodiment is to provide an electronic device.
[0107] An electronic device comprises a memory, a processor and a program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps in a CKKS bootstrapping method based on blind rotation as described in Example 1 are implemented.
[0108] The steps involved in the apparatuses of the above embodiments 2, 3 and 4 correspond to the method embodiment 1, and the specific implementation methods can refer to the relevant description part of embodiment 1. The term "computer-readable storage medium" should be understood as a single medium or multiple media including one or more instruction sets; it should also be understood to include any medium that can store, encode or carry an instruction set for execution by a processor and enable the processor to execute any method in the present invention.
[0109] Those skilled in the art should understand that the modules or steps of the present invention described above can be implemented by a general-purpose computer device, or alternatively, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. The present invention is not limited to any specific combination of hardware and software.
[0110] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without creative work are still within the scope of protection of the present invention.
Claims
1. A CKKS bootstrapping method based on blind rotation, characterized in that: include: Obtain a high-noise CKKS ciphertext, and perform a preprocessing operation and a homomorphic linear operation on the high-noise CKKS ciphertext to generate a first ciphertext and a second ciphertext; Performing modulus lifting on the first ciphertext to generate a third ciphertext; Bootstrapping the second ciphertext based on the NTRU blind rotation algorithm to obtain a fourth ciphertext; The third ciphertext and the fourth ciphertext are added based on homomorphic addition to obtain the final required low-noise ciphertext.
2. A CKKS bootstrapping method based on blind rotation as claimed in claim 1, characterized in that: The preprocessing operation is to perform modulus decomposition on the high-noise ciphertext to obtain the first ciphertext; specifically, For high noise ciphertext In the formula, (c0, c1) is the encrypted ciphertext, m is the plaintext polynomial; s and e are The polynomial on yes The residual class ring of is a polynomial quotient ring, where q is the modulus, which represents the power of 2; Then the decryption of the high-noise ciphertext ct is: [<ct,s>] q =c1·s+c0=m+e(mod q), In the formula,<ct,sk> represents the outer product of ct and sk, where sk is the private key; [·] q represents the modulo q operation; m+e(mod q) is represented by m+e+q·v, where mod q is the modulo q operation performed on the coefficients of the polynomial obtained by adding m+e; Let q′=q / p, where p, q, q′ are all moduli, which are powers of 2, and the first ciphertext ct′ is calculated as: Its decryption can be expressed as m+e+q′·u.
3. A CKKS bootstrapping method based on blind rotation as claimed in claim 1, characterized in that: The process of performing modulus enhancement on the first ciphertext to generate the third ciphertext is: enhancing the modulus of the first ciphertext ct′ from q′ to Q, where Q>>q′, to obtain the third ciphertext; specifically, The first ciphertext ct′=RLWE q′,s After decryption, (m+e) is m+e(modq′). According to the basic operation rules of modular operation, m+e(modq′) is converted to m+e+q′·u, where u is The third ciphertext is obtained by using the above polynomial 4. A CKKS bootstrapping method based on blind rotation as claimed in claim 1, characterized in that: The process of bootstrapping the second ciphertext by the NTRU-based blind rotation algorithm to obtain the fourth ciphertext is as follows: Extracting the second ciphertext into n LWE ciphertexts, and preprocessing the LWE ciphertexts; Obtain the computation key and automorphic key of the preprocessed LWE ciphertext; obtain the NTRU ciphertext based on the blind rotation algorithm, and convert the NTRU ciphertext into the fourth ciphertext that complies with the CKKS encoding through the repackaging algorithm.
5. A CKKS bootstrapping method based on blind rotation as claimed in claim 1, characterized in that: It also includes initialization settings, which include parameter initialization and encoding the message vector.
6. A CKKS bootstrapping method based on blind rotation as claimed in claim 5, characterized in that: The parameter initialization includes defining a polynomial ring and setting security parameters.
7. A CKKS bootstrap system based on blind rotation, characterized in that: include: A preprocessing module is configured to: obtain a high-noise ciphertext, perform a preprocessing operation on the high-noise ciphertext, and generate a first ciphertext; A homomorphic linear operation module is configured to: perform a homomorphic linear operation on the high-noise ciphertext to generate a second ciphertext; A modulus enhancement module is configured to: perform modulus enhancement on the first ciphertext to generate a third ciphertext; A bootstrapping module is configured to: bootstrap the second ciphertext based on the NTRU blind rotation algorithm to obtain a fourth ciphertext; The low-noise ciphertext acquisition module is configured to: add the third ciphertext and the fourth ciphertext based on homomorphic addition to obtain the final required low-noise ciphertext.
8. A CKKS bootstrap system based on blind rotation as claimed in claim 7, characterized in that: The bootstrapping system further comprises an initialization setting module, wherein the initialization setting module comprises parameter initialization and encoding of a message vector.
9. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the steps in a CKKS bootstrapping method based on blind rotation as described in any one of claims 1 to 6 are implemented.
10. An electronic device comprising a memory, a processor, and a program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the steps in the CKKS bootstrapping method based on blind rotation as described in any one of claims 1-6.
Citation Information
Patent Citations
Privacy computing heterogeneous acceleration method and device based on fully homomorphic encryption
CN115622684A
Homomorphic decryption method and device, nonvolatile storage medium and computer equipment
CN116192361A
Universal privacy calculation method and device based on fully homomorphic encryption, equipment and medium
CN116846535A
Key packaging lightweight method and system based on number-theory transformation, medium and equipment
CN117714054A
Fully homomorphic encryption and decryption method and computing device
CN119449260A