Method for performing operation in cryptographic application

By determining variable representation parameters based on noise source model and input attributes in encryption applications, the problem of large overhead of polynomial multiplication in FHE is solved, and more efficient calculations and lower implementation costs are achieved.

CN119998784APending Publication Date: 2025-05-13KATHOLIEKE UNIV LEUVEN
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380070581.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-08-26
Filing Date
2023-08-23
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In encryption applications, especially in total homomorphic encryption (FHE), the computational overhead of polynomial multiplication is high, resulting in slower calculation speed, and it is difficult for the prior art to quickly find variable representation parameters that meet specific constraints.

Method used

By performing operations in an encryption application, the representation parameters of the variable are determined based on the noise source model and input properties of the subtask, so that they satisfy predefined constraints, and these parameters are applied to optimize the implementation of the operation.

Benefits of technology

This method allows quick scanning of the search space of parameter values, significantly reducing the time to find the best representation parameter, improving the computing efficiency of encryption applications, and reducing implementation costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119998784A_ABST
    Figure CN119998784A_ABST
Patent Text Reader

Abstract

A method for performing an operation in a cryptographic application, the present invention relates to a method for deriving one or more parameters for determining a representation of a variable used in performing an operation on an input operand in a cryptographic application, where an output resulting from performing the operation satisfies one or more predefined constraints, the operation includes one or more sub-tasks, where a sub-task of the operation outputs the variable as an input for a subsequent sub-task or as an output of the operation, and where at least one of the sub-tasks receives the input operand. The method comprises:-determining one or more attributes of said variable output by one of said sub-tasks based on a model of a noise source originating from said sub-task and / or based on at least one attribute of an input of said one sub-task, the one or more attributes of the variable are characterized by one or more parameters,-determining a representation of the variable by fixing at least one of the parameters to a value such that the one or more attributes satisfy one or more predefined constraints, applying the representation of the variable in the implementation of the operation in the cryptographic application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates generally to the field of encryption. More particularly, the present invention relates to a method and apparatus for performing operations in encryption applications. Background Art

[0002] In the context of cloud computing, for example, users face certain risks when uploading raw data to untrusted cloud servers. Therefore, adequate security is required to protect user data. A promising new technology has emerged in the field of data security: fully homomorphic encryption (FHE). It allows homomorphic computations to be performed on encrypted data (ciphertext) without requiring additional information about the data itself. In other words, there's no need to first decrypt the data. Over the years, methods for implementing FHE have been refined to the point where they are practically feasible.

[0003] FHE algorithms are typically executed on cloud computing servers. However, the computation is slow. The ciphertext data on which computations are performed in an FHE scheme is a large polynomial (of length N) from a certain polynomial ring related to the scheme. Typical operations on these polynomials include addition and multiplication. While addition is linear in the length of the polynomial (O(N) operations), multiplication has a quadratic cost (O(N)) when using common direct techniques (also known as textbook multiplication). 2 ) operation).

[0004] One of the main challenges facing practical applications of FHE is its computational overhead. Since polynomial multiplication is one of the most expensive operations in FHE schemes, speeding up multiplication can be very helpful in reducing this computational overhead. This can be achieved by exploiting specific properties of polynomials. Various well-studied algorithms can be used to accelerate this multiplication, including number theoretic transformations (NTT), Toom-Cook multiplication, and Karatsuba multiplication. Multiplication using NTT is generally the most efficient of these algorithms, but it also imposes the most stringent conditions on the polynomial ring used. Therefore, it cannot be used in every FHE scheme.

[0005] When the underlying ring structure allows NTT, FHE schemes typically use NTT for fast polynomial multiplication. Two notable exceptions where NTT is not applied are the FHEW scheme disclosed in the paper “FHEW: Bootstrapping homomorphic encryption in less than a second” (L. Ducas et al., Eurocrypt, pp. 617-640, 2015) and the TFHE scheme described in “TFHE: Fast Fully Homomorphic Encryption Over the Torus” (I. Chillotti et al., J. Cryptol. 33, 34-91, 2020). The ring structure of both of them prohibits the use of NTT. Instead, these schemes can use Toom-Cook multiplication, Karatsuba multiplication, or fast Fourier transform (FFT) for fast polynomial multiplication, where the typical FFT is the fastest option. The FFT transform is similar to the NTT transform, but the polynomial ring requirements for the FFT transform are not as strict. Both FHEW and TFHE support the use of homomorphic Boolean algebra, such as NAND logic gates, XOR logic gates, and XNOR logic gates.

[0006] Each FHE operation introduces a certain amount of noise into the ciphertext, which is essential for security. FHE can tolerate this noise as long as it does not exceed a certain threshold noise level. Therefore, FHE schemes must periodically invoke bootstrapping operations to reduce the amount of noise in the ciphertext, keeping it below the threshold noise level. TFHE and FHEW differ from previous FHE schemes in that they invoke a bootstrapping operation after each homomorphic Boolean gate. In TFHE schemes, bootstrapping operations are preferably kept short.

[0007] To represent numbers in a computer architecture, one must choose a representation type (e.g., fixed-point, floating-point, or integer) and a set of parameters (e.g., mantissa size, exponent size, etc.). Precision and dynamic range are measures of how accurately a number can be represented. Precision defines how many bits are used to represent a number. Dynamic range defines the minimum or maximum value that a number can represent.

[0008] Real numbers can be represented with finite precision in a variety of ways. On a CPU, the typical approach is to use single-precision floating point numbers or double-precision floating point numbers. The precision is limited by the size of the mantissa, and the dynamic range is limited by the size of the exponent. This approach is effective due to the integration of floating point units (FPUs) in CPUs, and is therefore the typical representation of choice for software designers. Implementations of the TFHE and FHEW schemes mentioned above have been limited to double-precision floating point FFTs, as single-precision FFTs were found to introduce too much noise. Double-precision floating point FFTs have been found to keep the amount of noise introduced at a sufficiently small level. Fixed-point representation is determined by the number of bits in the representation and the scaling factor. In a fixed-point representation, the mantissa has a fixed number of bits.

[0009] The paper "MATCHA: A Fast and Energy-Efficient Accelerator for FullyHomomorphic Encryption over the Torus" (L. Jiang et al., 59th Annual Design Automation Conference, July 2022, pre-published online on February 17, 2022) also addresses the aforementioned TFHE scheme. A hardware accelerator for processing TFHE gates is presented, which outperforms accelerators that frequently invoke expensive double-precision floating-point FFT and IFFT kernels in terms of efficiency. To fully exploit TFHE's error tolerance, polynomial multiplication is accelerated using approximate multiplication-free integer FFTs and IFFTs that require only additions and binary shifts. While the approximate FFTs and IFFTs introduce errors in each ciphertext, the errors can be rounded off along with the noise during decryption, allowing the ciphertext to be correctly decrypted. The integer representation can be viewed as a scaled version of the fixed-point representation to remove the decimal point.

[0010] When determining the error caused by the finite accuracy of the digital representation in FFT and IFFT, this error is observed for a given digital representation (e.g., floating point, fixed point) or a given precision (e.g., 32 bits). If the bit width or any other encryption parameter changes, all error calculations need to be re-performed. Therefore, it would be beneficial to have a technique that can pre-calculate the effect of changing parameters on the resulting error.

[0011] Therefore, a method is needed in which the representation of the data can be adjusted in a flexible manner each time a new error calculation is performed after a change in encryption parameters. This applies not only to FFT-based multiplications, but generally to any operation performed on operands in encryption applications. Summary of the Invention

[0012] An object of embodiments of the present invention is to provide a method for determining parameter values ​​of variables when performing an operation on input operands in a cryptographic application, and for imposing one or more constraints on the output of the operation.

[0013] The above objects are achieved by the solution according to the invention.

[0014] In a first aspect, the present invention relates to a method for deriving, by means of an apparatus comprising processing means, one or more parameters determining a representation of a variable used in performing an operation on an input operand in a cryptographic application, wherein an output obtained by performing the operation satisfies one or more predefined constraints. The operation comprises one or more subtasks, wherein a subtask of the operation outputs a variable as input for a subsequent subtask or as output of the operation, and wherein at least one of the subtasks receives the input operand, the method comprising:

[0015] - determining one or more properties of a variable output by one of said subtasks based on a model of noise sources originating from said one subtask and / or based on at least one property of an input to said one subtask, said one or more properties of said variable being characterized by said one or more parameters,

[0016] - determining said representation of said variable by fixing at least one of the parameters to a value such that said one or more properties satisfy one or more predefined constraints,

[0017] - using said representation of variables in the implementation of operations in cryptographic applications.

[0018] The proposed method presents a procedure for pre-deriving one or more parameter values ​​representing variables used when executing an operation. The proposed solution effectively allows obtaining a representation of a variable with optimal or near-optimal values, given the constraints imposed on the output of the operation. The variable is either an intermediate variable obtained as a result of a subtask of the operation and used as input for a subsequent subtask, or a variable that is the output of the operation. In a preferred embodiment, the method steps are repeated for all variables that play a role in the operation under consideration, as will be described below.

[0019] In the first step of the method, determine one or more attributes of the variable obtained at the subtask output, i.e., the relevant parameters of the attribute of the variable. One or more attributes are relevant to the assessment predefined constraints. In some embodiments, this is completed based on at least one attribute of the (one or more) variable at the input of the subtask. In other embodiments, the determination of the attribute is based on a model of the noise source of the subtask under consideration. In another other embodiment, two options are combined together, i.e., one or more attributes of the noise model and the input of the subtask are used to find one or more relevant attributes (parameters) for the variable under consideration. In the next step, by fixing the parameter value so as to meet the constraints imposed on the output of the operation, determine one or more parameters representing the variable. In a preferred embodiment, this is achieved by solving an optimization problem. Then, as will be fixed in the previous method step, the representation of the variable with one or more parameters is applied in the actual implementation of the operation in the encryption application of the computer.

[0020] The present invention offers several advantages over prior art solutions. When determining suitable representations for variables that satisfy one or more imposed constraints, it allows the search space of possible parameter values ​​to be scanned much faster than with conventional solutions. In practice, the prior art requires an iterative approach, where a different parameter value is tested at each iteration. In contrast, the present invention employs a one-shot approach to obtaining values ​​for a parameter. The proposed method also allows for faster finding of optimal values ​​for a parameter, or at least good approximations of such optimal values. The method of the present invention is suitable for rapid prototyping.

[0021] In a preferred embodiment, the variable is characterized by means of one or more parameters from a set of parameters including {bit width, dynamic range, size of the integer part, size of the fractional part, position of the decimal point, i.e., the interval between the integer part and the fractional part}.

[0022] Preferably, one or more subtasks of the operation are multiplication and / or addition.

[0023] Advantageously, the method comprises the step of determining the total error introduced by one or more subtasks.

[0024] In some embodiments, one source of noise comes from removing bits on the least significant bit side of a subtask's input. In other embodiments, one source of noise may come from discarding bits on the most significant bit side of a subtask's input. Note that the input of a subtask can also be considered the output of the previous subtask.

[0025] Advantageously, the operation is a multiplication or a multiply-accumulate operation performed by means of a Fast Fourier Transform, and the input operands are a set of polynomials.

[0026] In another embodiment, determining the representation of a variable output by one of the subtasks may include finding a maximum value represented by the variable.

[0027] In one embodiment, some of the parameters are grouped together into a set of parameters. This is particularly advantageous when there are a large number of parameters. Grouping may then help reduce the number of parameters in the model.

[0028] In a preferred embodiment, the method as described is applied in a fully homomorphic encryption scheme.

[0029] In another preferred embodiment, the operation is performed on a reconfigurable hardware device.

[0030] Another aspect of the invention relates to a program executable on a programmable device, the program comprising instructions which, when executed, carry out the method as described above.

[0031] Yet another aspect of the present invention relates to a device arranged to perform an operation on an input operand in a cryptographic application, wherein an output obtained by performing the operation satisfies one or more predefined constraints, the operation comprising one or more subtasks, wherein a subtask of the operation outputs a variable as input for a subsequent subtask or as output of the operation, and wherein at least one of the subtasks receives the input operand, the device comprising a processing device for: determining one or more properties of the variable output by the one subtask based on a model of a noise source originating from one of the subtasks and / or based on at least one property of the input of the one subtask, the one or more properties of the variable being characterized by the one or more parameters; and determining the representation of the variable by fixing at least one of the parameters to a value such that the one or more properties satisfy the one or more predefined constraints; and applying the representation of the variable when performing the linear operation in the cryptographic application.

[0032] In a preferred embodiment, the device is implemented as a hardware accelerated computing system.

[0033] For the purpose of summarizing the present invention and its advantages over the prior art, certain objects and advantages of the present invention have been described above. Of course, it will be understood that not all such objects or advantages may be achieved according to any particular embodiment of the present invention. Thus, for example, those skilled in the art will recognize that the present invention may be implemented or carried out in a manner that achieves or optimizes one advantage or group of advantages as taught herein without necessarily achieving other objects or advantages as taught or suggested herein.

[0034] The above and other aspects of the invention will be apparent from and elucidated with reference to one or more embodiments described hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] The present invention will now be further described, by way of example, with reference to the accompanying drawings, in which like reference numerals refer to like elements throughout the various views.

[0036] Figure 1 A block diagram for performing the linear operation ax+by+c is shown.

[0037] Figure 2 Shown Figure 1 The intermediate variables and output variables in the scheme.

[0038] Figure 3 Shows the introduction of additional building blocks into Figure 2 in the plan.

[0039] Figure 4 The decomposition scheme used for calculation at the nodes in Example 2 is shown.

[0040] Figure 5 The butterfly structure commonly used in FFT implementation is shown.

[0041] Figure 6 The decomposition into subtasks and the addition of building blocks for intermediate variables in the third example are shown.

[0042] Figure 7 A scheme for polynomial multiplication using FFT is shown. DETAILED DESCRIPTION

[0043] The present invention will be described with respect to particular embodiments and with reference to certain drawings but the invention is not limited thereto but only by the claims.

[0044] Furthermore, the terms "first," "second," and the like in the specification and claims are used to distinguish similar elements and are not necessarily used to describe a temporal, spatial, sequential, or any other order. It should be understood that the terms so used are interchangeable under appropriate circumstances, and that the embodiments of the invention described herein are capable of operation in an order other than that described or illustrated herein.

[0045] It should be noted that the term "comprising" used in the claims should not be interpreted as being limited to the means listed thereafter; it does not exclude other elements or steps. It should therefore be interpreted as specifying the presence of the features, integers, steps, or components mentioned, but not excluding the presence or addition of one or more other features, integers, steps, or components, or groups thereof. Thus, the scope of the expression "a device comprising means A and means B" should not be limited to devices comprising only components A and B. This means that, for the purposes of the present invention, the only relevant components of the device are A and B.

[0046] Throughout this specification, references to "one embodiment" or "an embodiment" mean that a particular feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment of the present invention. Thus, throughout this specification, the phrases "in one embodiment" or "in an embodiment" do not necessarily refer to the same embodiment, but may refer to the same embodiment. Furthermore, as will be apparent to one of ordinary skill in the art from this disclosure, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0047] Similarly, it should be understood that in the description of exemplary embodiments of the present invention, in order to streamline the disclosure and aid in understanding one or more different inventive aspects, various features of the present invention are sometimes grouped together in a single embodiment, figure, or description thereof. However, this method of disclosure should not be interpreted as reflecting an intention that the claimed invention requires more features than those explicitly recited in each claim. On the contrary, as reflected in the appended claims, inventive aspects lie in fewer than all the features of the aforementioned single disclosed embodiment. Therefore, the claims appended to the detailed description are hereby expressly incorporated into this detailed description, with each claim itself serving as a separate embodiment of the present invention.

[0048] Furthermore, although some embodiments described herein include additional features not included in other embodiments, combinations of features from different embodiments are intended to be within the scope of the present invention and to form different embodiments, as will be understood by those skilled in the art. For example, in the appended claims, any of the claimed embodiments may be used in any combination.

[0049] It should be noted that the use of a particular term in describing certain features or aspects of the present invention should not be understood as implying that the term is redefined herein to include only any specific characteristics of the feature or aspect of the invention with which the term is associated.

[0050] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the present invention may be practiced without these specific details. In other cases, well-known methods, structures, and techniques are not shown in detail in order not to obscure the understanding of this description.

[0051] The present invention discloses a novel method for deriving parameters that determine how to represent variables when performing an operation (e.g., FFT) in a cryptographic application (e.g., a fully homomorphic encryption scheme), or for deriving parameters that determine how to represent output variables obtained as a result of the operation.

[0052] While searching for ways to efficiently implement FFT operations in cryptographic applications, the inventors of the present invention made the following observations:

[0053] - Certain classes of cryptographic applications require computations that contain the "noise" of deterministic mathematics. Therefore, these applications can also tolerate approximate computations that contain the noise of deterministic algorithms.

[0054] - Encryption works using uniformly distributed random values, which limits the dynamic range of the coefficients on which the calculations are based. This makes it easier to predict the necessary bit representation range (i.e. word length) required to represent the coefficients.

[0055] - The noise tolerance of the FFT in encryption applications depends on the (freely chosen) encryption parameter set, not on the application constraints. The encryption parameter set can be chosen to be more or less noise tolerant.

[0056] These insights provide the opportunity to perform the FFT operation in such a way that the intermediate variables used in performing the operation have an optimized representation. In other words, they form the trigger for the invention as presented here.

[0057] More specifically, the present invention presents a method for establishing one or more parameters that determine how to represent variables used when performing operations on input operands in cryptographic applications. While mathematical descriptions of algorithms that perform such operations typically assume infinite precision for variables, hardware and software implementations must decide on the specific representation type for the variables, such as fixed-point, floating-point, or block floating-point, as well as the precision of the chosen representation. This choice can impact the cost and accuracy of the implementation.

[0058] Once the representation type for each variable has been chosen, the exact parameters of the representation must still be determined. For example, for fixed-point representation, the least significant bit (LSB) and most significant bit (MSB) of the representation need to be determined. Floating-point representation is parameterized by the minimum and maximum possible values ​​of both the mantissa and the exponent (and therefore the bit size (word length)). For example, the MSB value is characterized by whether overflow is likely to occur. In the present invention, a method is presented to determine the valid values ​​of one or more of these parameters for the representation, for use in the implementation of cryptographic applications.

[0059] By way of example, the parameterization of the MSB and LSB is as follows. Assume that the value a has 8 integer bits and 16 fractional bits, and the value b has 4 integer bits and 8 fractional bits. The full-precision result c = a × b then has 8 + 4 = 12 integer bits and 16 + 8 = 24 fractional bits. In this case, it can be said that the MSB of c is at position 12 and the LSB is at position -24. In an implementation, the parameterization is performed for the variable c: MSBc and LSBc. By truncating the bits at the MSB, i.e. performing a rescaling, (e.g., choosing MSBc = 11), a certain overflow probability P is allowed. overflow This value depends on the distribution of the values ​​a and b, and in practice all MSBs are set so that, for example, P overflow <2 -64 By truncating bits on the LSB side, some noise due to quantization is introduced, which increases the output noise. Note that any form of rounding can be considered instead of truncation.

[0060] Importantly, the representation of the variables has an impact on the cost of the implementation, as a larger range of possible values ​​results in higher computational costs, but also in higher accuracy implementations. For a typical implementation, there will be design constraints on the accuracy of the output variables. These constraints are known in advance and can be, for example, the maximum noise variance introduced or the maximum probability of having a variable overflow (e.g., 2 -20 or 2 -40 The goal is to determine parameters that allow an efficient implementation while satisfying the design constraints.

[0061] A general overview of the proposed method is now provided, which is applied to a specific algorithm to be implemented (e.g., FFT) that performs operations on input operands in cryptographic applications. The input operands include one or more variables, depending on the operation being considered. For example, when a subtask performs multiplication on two variables fed to the subtask, the two variables can form the input operands. One or more constraints are imposed on certain properties of the resulting output of the operation (e.g., the maximum value of the variance of the introduced noise). The goal is to determine effective parameters for the representation of the output variable and the intermediate variables in the implementation. At a high level, the method includes three main steps. First, a model of one or more noise sources that affect one or more constraints on the properties of the output is constructed based on the parameters of the (one or more) representations to be determined. In the next step, specific values ​​for each parameter of the representation are determined so that all constraints are satisfied. Preferably, the values ​​for these parameters are determined in an optimal manner, that is, according to an appropriate optimization function. These parameter values ​​are then used to implement the operation on a programmable (hardware) device.

[0062] In some embodiments, the operation is a linear operation, that is, the following operation f satisfies f(x+y)=f(x)+f(y) and f(cx)=cf(x) for all x and y, where c is a constant.

[0063] Performing an operation involves executing one or more subtasks of the operation (e.g., addition, multiplication), where at least one of the subtasks receives the input operands of the operation at its input. One of the subtasks outputs a variable, which is the resulting output of the operation. Any subtask that does not generate an output of the operation under consideration generates a variable, which is referred to in this description as an intermediate variable. Any intermediate variable is then used as an input to one or more subsequent subtasks.

[0064] Building the model can be performed as follows. The algorithm that performs the operation is decomposed into various subtasks, and intermediate variables are identified. For each subtask, the input-output behavior of the properties relative to the constraints is determined (e.g., the noise introduced, the scaling factor from input to output, ...). For each of these variables, the type of representation is selected (i.e., fixed point, floating point, ...). The parameters of this representation (e.g., the highest representable value, the lowest representable value, ...) are still undetermined and are initially left as symbolic variables, i.e., variables that do not yet have a specific value.

[0065] To analyze the execution of an algorithm, we use an additional building block that is introduced at the location of each intermediate variable in the scheme of operations. This building block represents the effects of the finite precision of the representation of the variables, but has no effect on the algorithm itself. To achieve this, the additional building block has an input-output behavior that relates symbolic parameters to the imposed constraints.

[0066] The algorithm is then performed step by step from input to output, and a model is constructed for each constraint. To this end, one or more relevant properties (e.g., noise variance, input variance, maximum possible value, etc.) are determined at the input of the subtask or at the input of the input operand, and these properties are then propagated to the output. For each subtask, the input properties are converted into corresponding output properties using input-output behavior. As a result, for each constraint, a model of the properties is obtained, on which the constraints are imposed based on symbolic parameters.

[0067] In the next step of the method, the value of each of the symbolic parameters is determined so that the constraints are met. Preferably, these values ​​are selected so that the implementation cost is as low as possible. One way to achieve this is to select a cost function for each symbolic parameter that models the implementation cost for a given value of that parameter. A solution can then be found by solving an optimization problem, wherein a value is determined that reduces and preferably minimizes the total cost function while complying with all constraints.

[0068] Finally, the selected values ​​for the parameters are applied to instantiate the design of an algorithm for performing linear operations in cryptographic applications.

[0069] First example

[0070] In a first example, consider a simple algorithm that computes the value of the expression ax+by+c for input operands comprising x-values ​​and y-values, where intermediate variables are represented as fixed-point numbers and a, b, and c represent constants. Figure 1 The exact sequence of subtasks for this linear operation is given in . The goal is to select a value for the least significant bit (LSB) position of each intermediate variable. The constraint is the maximum noise variance σ for the output variable 2 maxnoise For simplicity, in this example it is assumed that the input variance has a distribution with a given variance and mean zero, and that when the precision of the variable is reduced, this reduction is performed using rounding operations.

[0071] As mentioned above, a model is first developed that allows the constraints to be evaluated. Figure 1As shown in , the computation is decomposed into subtasks and intermediate variables are identified. For each subtask, the input-output behavior with respect to the attributes associated with one or more imposed constraints needs to be determined. In this example, the least significant bit (LSB) and variance of the noise and signal are considered as relevant attributes. For the subtask, f(x, y) = x + y is a LSB with in1 and σ 2 noise,in1 The first input x has the LSB in2 and σ 2 noise,in2 The addition of the second input y has an input-output behavior

[0072] LSB out =min(LSB in1 ,LSB in2 )

[0073] and noise

[0074] σ 2 noise,out =σ 2 noise,in1 +σ 2 noise,in2 .

[0075] For the multiplication of two inputs f(x, y) = x*y, it has the input-output behavior

[0076] LSB out =LSB in1 ++LSB in2

[0077] and

[0078] σ 2 noise,out =σ 2 noise,in1 *σ 2 in2 +σ 2 in1 *σ 2 noise,in2 +σ 2 x oise,in1 *σ 2 noise,in2

[0079] (Assume that the input has zero mean. For simplicity, this is the only assumption here.) For each intermediate variable v (see Figure 2 , where intermediate variables have been given subscripts to indicate which operations they are generated by), which requires the introduction of a sign parameter, namely the least significant bit LSB vSymbolic parameters are displayed in bold to distinguish them from other parameters or properties.

[0080] Next, intermediate variables are introduced into the scheme as additional building blocks, e.g. Figure 3 These blocks model the inaccuracies due to the limited range of the representation. A model is constructed that is the noise introduced by truncating the least significant bits to be uniformly distributed—that is, the truncated LSB bits are independently uniformly distributed. For each additional building block, the following input-output behavior is achieved:

[0081] LSB out =LSB v and

[0082] σ 2 noise,out =σ 2 noiSe,in +ramp(2 2LSBv -2 2LSBin ) / 12,

[0083] The input has the least significant bit LSB in and noise variance σ 2 noise,in , and the noise variance σ 2 noise,in Indicates the increased noise level due to reduced precision. The ramp() function returns 0 for negative input values ​​and returns the input value for positive input values. This function is used because additional noise only occurs when the relevant bits are discarded. If the LSB v <LSB in This is what happens.

[0084] Once the input-output behavior is described, the model can be examined from beginning to end to determine the properties associated with the constraints in terms of symbolic parameters. The intermediate calculations at the nodes can then be written down. For example, after multiplying a and x, we can get

[0085] LSB=LSB a +LSB ×

[0086] σ 2 =σ 2 a +σ 2 x

[0087] σ 2 noise =0

[0088] Considering additional building blocks and intermediate variablesV The inaccuracy of the representation of ax can be concluded

[0089] LSB=LSB ax

[0090] σ 2 =σ 2 a +σ 2 ×

[0091] σ 2 noise =ramp(2 2LSBax -2 2(LSBa+LSBx) / 12

[0092] A similar expression can be written for the other branch, where b and y are multiplied. After adding by to ax, we can write

[0093] LSB=min(LSB ax , LSB by )

[0094] σ 2 =σ 2 a *σ 2 × +σ 2 b *σ 2 y

[0095] σ 2 noise =ramp(2 2LSBax -2 2(LSBa+LSBx) ) / 12+ramp(2 2LSBby -2 2(LSBb+LSBy) ) / 12 and taking into account the intermediate variables V The inaccurate representation of ax+by can be obtained

[0096] LSB=LSB ax+by

[0097] σ 2 =σ 2 a *σ 2 x +σ 2 b *σ 2 y

[0098] σ 2 noise =ramp(2 2LsBax -22(LSBa+LSBx) ) / 12+ramp(2 2LSBby -2 2(LSBb+LSBy) ) / 12+ramp(2 2LSBax +by -2 2min(LSBax,LSBby) ) / 12 This process finally generates the LSB according to the sign parameter ax , LSB by , LSB ax+by , and LSB out σ 2 noise,out Remember that this value is constrained to be less than or equal to the maximum noise variance σ at the output 2 maxnoise .

[0099] In the next step of the method, the values ​​of the symbolic parameters are determined. The constraint function σ was derived in the previous step. 2 noise,out (LSB ax , LSB by , LSB ax+by , LSB out )≤σ 2 maxnoise Now the parameters should each be fixed to a value such that this constraint is satisfied. One way to achieve this is to construct a cost function, e.g. a function where all parameters are equally costed according to their bit width, which would result in a cost function: LSB ax +LSB by +LSB ax+by +LSB out An optimizer that optimizes the cost function under given constraints can then be used to find efficient parameter values. In some embodiments of the method, the cost function can of course be changed to a function that more closely represents the cost of implementation.

[0100] A different cost function that one might look for is, for example, an implementation on an FPGA, where the multiplication is performed in a dedicated DSP block. In this case, each DSP block has 18 bits of multiplication available, which can be extended to more bits at the expense of using multiple of these DSP blocks. If the bit width (MSB-LSB) is between 1 and 18, the cost of the multiplication is 1, and if the bit width is between 19 and 36, the cost of the multiplication is 3.

[0101] In embodiments where there is a risk of the number of noise sources exploding, noise sources with (approximately) similar properties can be bundled together. This results in a smaller number of variables to consider.

[0102] Second example

[0103] Consider the same algorithm as in the first example to calculate ax+by+c, but now with the added constraint that no variables overflow, and the addition of the most significant bit NSB v As the symbolic parameter that needs to be determined, the additional steps required to take this additional constraint into account in the method are discussed below.

[0104] Added input-output behavior related to overflow constraints. Two additional properties are kept track of: the maximum absolute value (MAV) of a variable and a list of all previous overflow conditions. One such list is made for each intermediate variable, and it represents the conditions on that variable that need to be met to avoid overflow. The input-output behavior with respect to these properties is then as follows. For addition, the MAV out =MAV op1 +MAV op2 , and the input overflow condition lists are combined into a new overflow condition combination list. For multiplication, MAV out =MAV op1 *MAV op2 , and as before, the lists of input overflow conditions are combined into a new list with overflow conditions.

[0105] Next we must add the input-output behavior of the intermediate variable building block. Here we have MAV out =MAV in And the condition MSB v ≥log2(MAV in ) is added to the list of overflow conditions.

[0106] Figure 4 Shows the calculation of some properties. After multiplying a and x, we can get

[0107] MAV=MAV a *MAV x

[0108] List = []

[0109] Includes additional building blocks V ax After that, it becomes:

[0110] MAV=MAV a *MAV x

[0111] List=[MSB ax ≥log2(MAV a *MAV x )]

[0112] Similarly, a similar expression can be written for the branch that performs the multiplication of b and y.

[0113] Once the sum a.x+by has been found, the following expression is obtained

[0114] MAV=MAV a *MAV x +MAV b *MAV y

[0115] List=[MSB ax ≥log2(MAV a *MAV x ),MSB by ≥log2(MAV b *MAV y )]

[0116] After the additional block for Vax+by:

[0117] MAV=MAV a *MAV x +MAV b *MAV y

[0118] List=[MSB ax ≥log2(MAV a *MAV x ),MSB by ≥log2(MAV b *MAV y )]

[0119] LSB ax+by ≥log2(MAV a *MAV x +MAV b *MAV y )].

[0120] Next, the values ​​for the symbol parameters are also determined. This can be done by constructing a cost function, as discussed above.

[0121] The method described above can be extended to other constraints, input distributions, or situations. For example, other constraints can be considered, such as the maximum overflow probability P at each variable. overflow,max . For this constraint, we then keep track of the distribution of variables throughout the algorithm and add the condition P[v>2 MSBv ] <P overflow,max A simplified version of this condition may be to keep track of only the variance of the variable (and possibly its mean) and make assumptions about its distribution, typically a Gaussian distribution due to the central limit theorem.

[0122] Third example

[0123] One notable application area of ​​the method of the present invention is the implementation of polynomial multiplications by means of the Fast Fourier Transform (FFT). The use of an FFT scheme allows the implementation of polynomial multiplications in an accelerated manner. FFT-based multiplication is itself a well-known technique and relies on the convolution theorem:

[0124] c = a × b = FFT -1 (FFT(a).FFT(b))

[0125] Where c, a, and b represent polynomials. FFT-based multiplication has also recently been used in its own way in cryptographic applications, for example, in fully homomorphic encryption (FHE). FFT-based multiplication works by converting the input polynomial into another representation using the FFT. In this domain, the multiplication operation can be performed point by point (N operations). Afterwards, an inverse FFT (IFFT) is needed to convert the result back to the original representation. The FFT and IFFT conversion operations are typically the most expensive operations in FFT-based multiplication, requiring O(N.log(N)) operations, where N is the number of coefficients in the polynomial. The number of coefficients determines the depth and width of the FFT, among other parameters.

[0126] FFT-based multiplication operates on complex numbers, where both the real and imaginary parts are real numbers, while other multiplication algorithms use integers. When finite precision is used to represent real numbers, the multiplication calculation is not always exact and may be noisy, i.e., a small error δ may be introduced:

[0127] FFT -1 (FFT(a)).FFT(b))=c+δ

[0128] Due to the special properties of FHE, a certain degree of noise introduced by the FFT can be tolerated. In FHE, the (mathematical) noise required for security is already present in the formulas. FHE is inherently tolerant to a certain degree of this mathematical noise, and the additional noise introduced by the use of the FFT can also be tolerated up to a certain point. This means that the size of the noise δ must be carefully considered. FHE implementations impose strict limits on the noise introduced. If excessive noise is introduced by the FFT in the polynomial multiplication, the calculation will fail and return incorrect results.

[0129] NTT is an exact variant of FFT, where δ=0, but, as already mentioned, imposes restrictions on the parameters of the encryption scheme.

[0130] The important part of FFT transformation is butterfly operation, such as Figure 5The butterfly operation, with its two inputs and two outputs, is well known in the implementation of FFT algorithms and recursively decomposes the discrete Fourier transform of composite size n = rm into r smaller transforms of size m, where r is the basis of the transform. These smaller DFTs are then combined via a butterfly of size r, which itself is a DFT of size r (performed m times on the corresponding outputs of the sub-transforms), pre-multiplied by roots of unity called twiddle factors.

[0131] The variables in the Fast Fourier Transform are complex numbers, and therefore the variables in the butterfly operation are also complex numbers. However, it is typically assumed that the distribution and properties of the real and imaginary parts are the same. In this case, one can only focus on the properties of the real part in the analysis.

[0132] In the example considered here, a maximum noise variance constraint is imposed on the butterfly structure (just as in the first example). Again, the algorithm is divided into subtasks first. Next, the intermediate variable v at 、v c 、v d Additional building blocks are added to the solution, such as Figure 6 As described in .

[0133] The multiplication subtask can be simplified by exploiting the knowledge of the rotational input properties. Any real and the imaginary part t imag An interesting property of the twiddle factor t is that real 2 +t imag 2 = 1. Given a number x whose real and imaginary parts have the same variance, multiplying x by the rotation factor t does not change the variance, i.e. var(xt) = var(x). This can be easily deduced as follows:

[0134]

[0135] For multiplication, the input-output behavior can thus be described as LSB at =LSB a +LSB t and σ 2 noise,out =σ 2 noise,x +σ 2 x σ 2 noise,t (Again, assuming the inputs have zero mean.) Note that the input-output behavior of the addition block for adding variables in1 and in2 remains unchanged from before, namely:

[0136] LSB out(min(LSB in1 , LSB in2 ) and σ 2 noise,out =σ 2 noise,in1 +σ 2 noise,in2 .

[0137] The model can then be computed starting from the rotated input, with reduced accuracy due to the finite representation (except for rotations of 1 and –1).

[0138] LSB=LSB t

[0139] σ 2 =1

[0140] σ 2 noise =2 2LSBt / 12

[0141] For the intermediate variable v at After the additional building blocks, we get the real part of the product:

[0142] LSB=LSB at

[0143] σ 2 =σ 2 a

[0144] σ 2 noise =σ 2 noise,a +2 2LSBt / 12*σ 2 a +ramp(2 2LSBat -2 2(LSBa) ) / 12, and for the imaginary part, the expression results are similar.

[0145] For the intermediate variable v c After the additional building blocks, one can write:

[0146] LSB out =LSB c

[0147] σ 2 c =σ 2 a +σ 2 b

[0148] σ 2 noise,out =σ2 noise,c =σ 2 noise,a +2 2LSBt / 12*σ 2 a +σ 2 noise,b +ramp(2 2LSBat -2 2(LSBa) ) / 12+ramp(2 2LSBc -2 2min(LSBat,LSBb) / 12.

[0149] Fourth Example

[0150] In a fourth example, consider polynomial multiplication using FFT, specifically for a fully homomorphic encryption scheme. The goal of this operation is to compute the inner product between the input (a vector of polynomials) and the bootstrap key (also a vector of polynomials). To handle this multiplication efficiently, a three-step procedure can be used: FFT, coefficient multiplication and accumulation, and inverse FFT. Figure 7 This procedure is depicted in . Note that, in contrast to typical FFT-based multiplications, the second multiplication term in the figure (i.e., the bootstrap key) does not undergo an explicit FFT operation. This is because the input is known in advance and the FFT can therefore be pre-computed with very high accuracy, implying that this particular FFT does not need to be considered in this method.

[0151] First consider the product-accumulation operation. This operation is performed in a coefficient manner, and therefore can be modeled using similar multiplication and addition operations discussed in Examples 1 and 2. FFT operations and inverse FFT operations mainly include multilayer butterfly operations. Therefore, the analysis of Example 3 is applied to these butterfly operations to generate a model of FFT operations and IFFT operations. In some embodiments of polynomial multiplication, different types of butterfly operations (radix 2, radix 4, ...) can be used, but the analysis of these butterfly operations can be carried out in a manner similar to the analysis in Example 3. By combining the building blocks previously discussed, a noise model based on the polynomial multiplication of the full FFT can be constructed.

[0152] One challenge is that a large number of operations need to be determined, and therefore a large number of parameters need to be determined. In order to reduce the number of parameters in the model, similar parameters can be grouped together. In this example, there is a high degree of parallelism and structure that can be used to achieve this. For example, similar parameters of variables in the same "layer" of the FFT (i.e., variables that have undergone the same number of butterfly operations) or variables after the multiplication operation in the product-accumulation can be grouped together. This will reduce the number of parameters from approximately O((V+1) N / 2log2(N / 2)) (where V is the vector length and N is the number of coefficients in the polynomial) to about O(2log2(N / 2)), as this is approximately the number of layers in the proposed algorithm.

[0153] Furthermore, it will be noted that typical cryptographic applications such as FHE require performing negative circular convolutions, rather than traditional circular convolutions. In circular convolutions (with N coefficients), coefficients that are out of bounds (at positions i>N) are cycled around to the first coefficient (at positions iN). In contrast, in negative circular convolutions, these coefficients are not only cycled back, but also negated. To achieve this, many implementations of cryptographic algorithms perform so-called twist and fold steps at the beginning and end of the algorithm, which explains the negative circular behavior. This twist and fold step involves additional packing of the inputs and multiplication with complex numbers. Packing takes two integers a and b and combines them into a complex number a+bi. This operation typically does not generate any noise. The additional multiplication operation can be modeled using the methods of Examples 1 and 2.

[0154] As already mentioned, the type of representation for the variables must be selected. In FFT schemes, for example, for performing polynomial multiplications, a fixed-point representation is advantageously chosen. The method set forth above can then be applied to determine the parameters of the fixed-point representation of the variables that appear when performing the operation, while satisfying the imposed constraints.

[0155] Given the optimal parameters obtained using the method according to the present invention, a hardware circuit can be constructed using fixed-point arithmetic for these parameters. In fact, it may be advantageous to have a library of parameterized hardware circuit implementations where the fixed-point bit width is a common parameter. A circuit can be selected to match the input type, and these parameters can be set at "circuit synthesis time" to match the desired output noise delta.

[0156] Given the optimal parameters, the hardware circuit can be simulated using this parameter set. The output noise δ is measured and compared to a floating-point reference implementation. It is verified that the output noise meets the noise bounds determined above (e.g., a standard deviation of 2). An FPGA bitstream can be created for the circuit with the optimal fixed-point parameter set determined in the method presented above. The FPGA bitstream allows for the acceleration of the FHE bootstrap procedure, which involves many (thousands) of iterations of polynomial vector multiplications.

[0157] Although the present invention has been illustrated and described in detail in the drawings and the foregoing description, such illustration and description should be regarded as illustrative or exemplary rather than restrictive. The foregoing description details certain embodiments of the present invention. However, it will be understood that no matter how much detail is shown in the foregoing text, the present invention can be practiced in many ways. The present invention is not limited to the disclosed embodiments.

[0158] Those skilled in the art can understand and implement other variations to the disclosed embodiments when practicing the claimed invention based on a study of the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other elements or steps, and the indefinite article "a" or "an" does not exclude a plurality. A single processor or other unit can implement the functions of multiple items recited in the claims. The fact that specific measures are recited in mutually different dependent claims does not in itself indicate that a combination of these measures cannot be advantageously utilized. The computer program may be stored / distributed on a suitable medium, such as an optical storage medium or solid-state medium provided with or as part of other hardware, but may also be distributed in other forms, such as via the Internet or other wired or wireless telecommunications systems. Any figure marks in the claims should not be interpreted as limiting the scope.

Claims

1. A method of deriving, by means of an apparatus comprising processing means, one or more parameters determining the representation of a variable used in performing an operation on an input operand in a cryptographic application, wherein: The output obtained by performing the operation satisfies one or more predefined constraints, the operation includes one or more subtasks, wherein the subtasks of the operation use the variable output as input for subsequent subtasks or as output of the operation, and wherein at least one of the subtasks receives the input operand, and the method includes: - determining one or more properties of the variable output by one of the subtasks based on a model of noise sources originating from said one of the subtasks and / or based on at least one property of an input to said one subtask, said one or more properties of the variable being characterized by said one or more parameters, - determining said representation of said variable by fixing at least one of said parameters to a value such that said one or more properties satisfy said one or more predefined constraints, - applying said representation of said variable in the implementation of said operation in said cryptographic application.

2. The method for determining according to claim 1, wherein: The variable is characterized by means of one or more parameters from a set of parameters including {bit width, dynamic range, size of integer part, size of fractional part, position of decimal point}.

3. The method for determining according to claim 1 or 2, wherein: The one or more subtasks include one or more of the group of subtasks including {multiplication, addition}.

4. A method for determining according to any one of claims 1 to 3, comprising determining a total error introduced by one or more of the subtasks included in the operation.

5. The method for determining according to any one of the preceding claims, wherein: One source of noise comes from removing bits on the least significant bit side of the input of the one subtask.

6. The method for determining according to any one of the preceding claims, wherein: One source of noise comes from discarding bits on the most significant bit side of the input of the one subtask.

7. The method for determining according to any one of the preceding claims, wherein: The operation is a multiplication or a product-accumulate operation performed with the aid of a Fast Fourier Transform, and wherein the input operands are a set of polynomials.

8. The method for determining according to any one of the preceding claims, wherein: Determining the representation of the variable output by one of the subtasks includes finding a maximum value represented by the variable.

9. The method for determining according to any one of the preceding claims, wherein: Some of the parameters are grouped together as a group of parameters.

10. The method for determining according to any one of the preceding claims, which is applied in a fully homomorphic encryption scheme.

11. The method for determining according to any one of the preceding claims, wherein: The operations are performed on a reconfigurable hardware device.

12. A program executable on a programmable device, the program comprising instructions, which when executed, perform the method according to any one of claims 1 to 11.

13. A device arranged to perform an operation on an input operand in a cryptographic application, wherein: The output obtained by performing the operation satisfies one or more predefined constraints, the operation includes one or more subtasks, wherein the subtask output variables of the operation are used as inputs for subsequent subtasks or as outputs of the operation, and wherein at least one of the subtasks receives the input operands, and the apparatus includes processing means, the processing means being used to: determine one or more properties of the variable output by the one subtask based on a model of a noise source originating from one of the subtasks and / or based on at least one property of an input to the one subtask, the one or more properties of the variable being characterized by the one or more parameters; and Determining a representation of the variable by fixing at least one of the parameters to a value such that the one or more properties satisfy the one or more predefined constraints; and applying the representation of the variable when performing the operation in the cryptographic application.

14. The device of claim 13, implemented as a hardware accelerated computing system.