Security level estimation and parameter optimization method of fully homomorphic encryption scheme based on LWE problem
By establishing a model of security level estimation and parameter optimization, the efficiency and security compromises of the fully homomorphic encryption scheme based on LWE problems in parameter selection and security level evaluation are solved, and more accurate and automated parameter selection is achieved.
Patent Information
- Application Number
- CN202510103458.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-01-22
AI Technical Summary
The existing fully homomorphic encryption scheme based on LWE problems has a compromise between efficiency and security in parameter selection and security level evaluation, and lacks a unified model for parameter optimization.
A security level estimation and parameter optimization method for a fully homomorphic encryption scheme based on LWE problem is proposed. By establishing models M1 and M2, users can perform security level estimation and parameter optimization based on specified parameters or security levels to improve the target performance of the scheme.
It realizes rapid security level evaluation of LWE problem parameters and optimal selection of parameters, reduces the empirical dependence in solution design, and improves the automation and accuracy of parameter selection.
Smart Images

Figure CN120034312A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a security level estimation and parameter optimization method for a fully homomorphic encryption scheme based on the LWE problem, and belongs to the field of information security. Background Art
[0002] The “availability but invisibility” of data is an effective means of data privacy protection, providing strong guarantees for data circulation and deep mining of data value. Fully homomorphic encryption, as one of the representative technologies, has gradually become an effective way to implement this means. Currently, almost all fully homomorphic encryption schemes are based on the learning with error (LWE) problem, and the main encryption schemes include BGV[4] and BFV[6]. Theoretically, the difficulty of the LWE problem is provable, so the security of fully homomorphic encryption based on the LWE problem is also theoretically guaranteed[1,2]. However, when designing a scheme, it is necessary to select the parameters of the scheme to meet the needs of actual scenarios. This process is usually a process of compromise between efficiency and security. Therefore, correctly analyzing and evaluating the difficulty of the LWE problem under different parameter settings has important guiding significance for the parameter selection and scheme design of lattice cryptographic schemes.
[0003] Secondly, in the process of scheme design, parameter selection is an unavoidable problem. The goal of parameter optimization is to select the optimal parameter settings to maximize the target performance of the scheme while meeting the user-specified security level.
[0004] There have been several studies in academia and industry on the security level estimation problem of schemes based on the LWE problem. In particular, Albrecht and his team comprehensively considered various attack methods against LWE-based encryption schemes and proposed a security level predictor, the Lattice Estimator[3]. However, the calculation process of current security analysis software is relatively complex and not conducive to repeated calls. The parameter optimization problem of the scheme can be regarded as the inverse problem of the security level analysis problem of the scheme. Compared with the security level analysis problem of a single indicator, the parameter selection problem involving different indicators is more difficult and more practical. It can directly provide scheme design guidance from the user's perspective. However, the parameter selection in the current scheme design process is often based on experience and analysis[5]. As fully homomorphic encryption moves from the laboratory to the industry to a greater extent, more accurate, optimized and automated parameter selection is undoubtedly necessary.
[0005] At present, there is no unified model that can describe the parameter optimization problems of all encryption schemes. As the most widely used schemes, BGV and BFV schemes are worthy of study in terms of reducing communication overhead as much as possible.
[0006] [1]Regev O.On lattices,learning with errors,random linear codes,andcryptography[J].Journal of the ACM(JACM),2009,56(6):34.
[0007] [2]Lyubashevsky,V.,Peikert,C.and Regev,O.,On ideal lattices andlearning with errors over rings.In Annual International Conference on theTheory and Applications of Cryptographic Techniques(pp.1-23).Springer,Berlin,Heidelberg,2010.
[0008] [3]Martin R.Albrecht,Rachel Player and Sam Scott.On the concretehardness of Learning with Errors.Journal of Mathematical Cryptology.Volume 9,Issue 3,Pages 169–203,2015
[0009] [4]Zvika Brakerski,Craig Gentry,and Vinod Vaikuntanathan.“(Leveled)Fully Homomorphic Encryption without Bootstrapping”.In:Proceedings of the 3 rd Innovations in Theoretical Computer Science Conference.ITCS’12.Cambridge,Massachusetts:Association for Computing Machinery,2012,pp.309–325.
[0010] [5] M.Albrecht, M.Chase, H.Chen, J.Ding, S.Goldwasser, S.Gorbunov, S.Halevi, J.Hoffstein, K.Laine, K.Lauter, et al. Homomorphic encryption standard. Protecting privacy through homomorphic encryption, pages 31–62, 2021.
[0011] [6]Fan,J.and Vercauteren,F.,2012.Somewhat practical fully homomorphicencryption.Cryptology ePrint Archive.
[0012] [7]Batnini, H., Michel, C. and Rueher, M., 2005, October. Mind the gaps: A newsplitting strategy for consistency techniques. In International Conference on Principles and Practice of Constraint Programming (pp. 77-91). Berlin, Heidelberg: Springer Berlin Heidelberg. Summary of the invention
[0013] In view of this, the present invention provides a security level estimation and parameter optimization method for a fully homomorphic encryption scheme based on the LWE problem, which provides assistance for the evaluation and design of a BGV or BFV scheme based on the LWE problem, wherein the LWE problem is as described in reference [1].
[0014] In order to more clearly describe the method of the present invention, here,
[0015] (1) The security level estimation problem of the fully homomorphic encryption scheme based on the LWE problem with parameters of key length n, modulus q, and noise parameter α is established as a model (M1):
[0016]
[0017] Where C = 5.46, A = 0.296, B = 20.388,
[0018] (2) The parameter optimization model (M2) of the fully homomorphic encryption scheme based on the LWE problem with a specified security level λ and decryption accuracy ρ is established as follows:
[0019]
[0020] Among them, security level is a function of the security level; Erf is the Gaussian error function and k is the variable.
[0021] The application scenario of the present invention involves two parties, a user and a platform, wherein the user sends his or her requirements to the platform, and the platform calculates and gives the results required by the user and returns them to the user.
[0022] For this scenario, the specific steps of the present invention are as follows:
[0023] S1: The user gives instructions and parameters according to the problem to be solved;
[0024] S2: The platform selects the corresponding model (M1) or model (M2) according to the received instruction. If model (M1) is selected, execute step S3; if model (M2) is selected, execute step S4;
[0025] S3: The platform substitutes the parameters specified by the user into the model (M1) and solves the model to obtain the security level corresponding to the parameters, and then executes S5;
[0026] S4: The platform substitutes the numerical value specified by the user into the model (M2) and solves it to obtain the optimal value of the solution parameter, and then executes S5;
[0027] S5: The platform feeds back the calculation results to the user.
[0028] Furthermore, in step S1, the user can select the following instructions: "Perform security level estimation of a fully homomorphic encryption scheme based on the LWE problem" or "Perform parameter optimization of a fully homomorphic encryption scheme based on the LWE problem"; if the former is selected, the user needs to provide the parameter values of the LWE problem corresponding to the scheme, that is, the specific values of n, q, and α; if the latter is selected, the user needs to specify the required security level λ and decryption accuracy ρ.
[0029] Further, for the parameters n, q, α, the specific steps of step S3 are as follows:
[0030] S301: Construct an expression based on the parameters:
[0031]
[0032] Among them, δ 0 is a function of β, β is the variable;
[0033] S302: List the single variable equation Δ=b about β 2 -4ac=0, solve all the roots of the equation, and then round up the largest root to get β m ;
[0034] S303: β = β m Substitute into the expression of a, b, c and find Then round up to get d m .
[0035] S304: (β, d) = (β m ,d m ) is substituted into the objective function f(β,d) in the model (M1), and then the logarithm of the objective function is taken to obtain the security level of the solution.
[0036] Further, with respect to the security level λ and the decryption accuracy ρ, the step S4 is specifically as follows:
[0037] S401: artificially set the value ranges of parameters n, q, α, and k, respectively. Indicates; among them, *respectively represent the upper and lower bounds of the interval of parameter*;
[0038] Preferably, I 1 Take [100,2000],I 2 Take [5000,10 8 ],I 3 Take [10 -20 ,10 -5 ],I 4 Take [11,21].
[0039] S402: If Jump to S405; otherwise, And execute the next step; where ← means assigning the value on the right to the left. Indicates rounding up;
[0040] It is worth noting that it is difficult to directly determine whether there is a feasible solution (n, q, α, k) in model (M2) that satisfies q≤γ. Therefore, it is necessary to establish model (M3) for conversion. Specifically, model (M3) is:
[0041]
[0042] Wherein, the values of λ and ρ are the same as those of model (M2), and the value of γ is shown in S402. If the optimal value of model (M3) is negative, then there exists a feasible solution (n, q, α, k) in model (M2) satisfying q≤γ; otherwise, there does not exist a feasible solution (n, q, α, k) in model (M2) satisfying q≤γ.
[0043] S403: Establish a model (M3) and solve a feasible point where the objective function value is negative;
[0044] S404: If there is a solution x in step S403 * =(n * ,q * ,α * ,k * ), it means that the feasible solution of model (M2) is equivalent to x * And satisfy q * ≤γ, then let And jump to step S402; otherwise, if there is no solution, it means that model (M2) does not have a feasible solution that meets the conditions, so let q ←γ, and jump to step S402;
[0045] S405: When no feasible solution of model (M2) is found, an empty set is output, indicating that there is no parameter setting that meets the user's requirements; otherwise, a feasible solution x of model (M2) is output. * , which is the optimal parameter selection required by the user.
[0046] Furthermore, the solution process described in step S403 is specifically as follows:
[0047] (1) Initialization: Block B = I 1 ×I 2 ×I 3 ×I 4 , initial active queue Q = {B};
[0048] (2) Calculate the optimal value lower bound: For each block B in Q, take p as the point where all coordinate values in B take the lower bound of the value interval, and transform the objective function of model (M3) The value at point p is denoted as η(B); if η(B)>0, then B is removed from Q;
[0049] (3) Block partitioning: Select and take out a block B from Q so that the η(B) value is minimized, and then divide B into two equal-sized sub-blocks B according to the round-robin scheduling strategy. 1 With B 2 , and B 1 With B 2 Join Q;
[0050] The cyclic scheduling strategy is as shown in reference [7], that is, the value interval of the block is divided into two equal parts to obtain sub-blocks, so that after each value interval is divided into two equal parts once, the next cycle is entered, and the sub-blocks are divided into two equal parts according to the value interval.
[0051] (4) Finding a feasible point: For each sub-block B obtained by segmentation i , the feasible point calculation method is used to determine whether there is a feasible point. If not, the block is discarded and the feasible value ω(B i )=+∞; if it exists, a feasible point is calculated and the value of the objective function at this point is recorded as the feasible value ω(B i ); where i = 1, 2;
[0052] (5) Determine the sign of the objective function at the feasible point: If ω * <0, it means that a feasible point x with an objective function value less than 0 is found * , end the solution process and return the feasible point x * , otherwise continue to the next step; where ω * =min{ω(B 1 ),ω(B 2 )};
[0053] (6) Determine whether Q is an empty set. If Q is an empty set, it means that no feasible point with an objective function value less than 0 has been found. The solution process ends and the empty set is returned. If Q is not an empty set, jump to step (2).
[0054] Furthermore, the specific steps of the feasible point calculation method described in step (4) are as follows:
[0055] a) Take block B i The two vertices p 1 and p 2 , where vertex p 1 Correspondence I 1 The lower bound of I 2 ,I 3 ,I 4 The upper bound of the vertex p 2 Correspondence I 1 ,I 2 ,I 3 ,I 4 The upper bound of
[0056] b) Determine p 1 and p 2 Is it a feasible point? If any of them is a feasible point, the feasible point has been obtained and will be returned; otherwise, execute the next step;
[0057] c) Connect p by midpoint bisection 1 and p 2 Find a feasible point on the line segment; if the midpoint is a feasible point, calculate the feasible value ω(B i ); If the midpoint is not a feasible point, repeat this step until the line segment does not contain points where n is an integer, and block B i
[0058] Abandon from Q and let the feasible value ω(B i )=+∞.
[0059] The beneficial effects of the present invention are as follows: the present invention provides a security level estimation and parameter optimization method for a fully homomorphic encryption scheme based on the LWE problem. For an LWE problem with given parameters, the corresponding security level can be quickly calculated. For the BGV and BFV schemes based on LWE, for the security level and decryption accuracy specified by the user, the user can be provided with parameter settings that minimize the communication overhead; it is particularly suitable for assisting users in accurately performing security assessments and adjusting security policies when sampling homomorphic encryption schemes. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] In order to make the purpose and technical solution of the present invention, the present invention provides the following drawings for explanation:
[0061] Figure 1 It is a framework diagram of the method of the present invention;
[0062] Figure 2 A flow chart for solving the model (M2) in the method of the present invention;
[0063] Figure 3 The present invention is a flowchart for solving a feasible point in the model (M3) where the objective function takes a negative value. DETAILED DESCRIPTION
[0064] When analyzing and designing a fully homomorphic encryption scheme based on the LWE problem, it is necessary to evaluate the security level of the scheme and optimize its parameters. In the scenario between users and platforms, users send instructions to the platform based on actual needs. The platform selects model (M1) or model (M2) based on the instructions and solves it, and then feeds the results back to the user. The following is an implementation case for the two user needs of security level evaluation and parameter optimization of the fully homomorphic encryption scheme based on the LWE problem.
[0065] Embodiment 1:
[0066] Assume that user "Zhang San" wants to evaluate the security level of a fully homomorphic encryption scheme based on the LWE problem, and assume that the parameters of the existing scheme are n=128, q=16411, α=0.00180384. The present invention provides a "security level estimation method for a fully homomorphic encryption scheme based on the LWE problem", combined with Figure 1 , the preferred embodiments of the present invention will be described in detail below.
[0067] The specific steps are as follows:
[0068] Step 1: Zhang San gives the security level assessment instruction of the fully homomorphic encryption scheme based on the LWE problem, and provides the parameters n=128, q=16411, α=0.00180384.
[0069] Step 2: The platform selects the (M1) model according to the instruction.
[0070] Step 3: The platform substitutes the parameters n=128, q=16411, α=0.00180384 provided by Zhang San into the model (M1) and solves the model. The specific solution steps are as follows:
[0071] (3-1) Constructing expressions
[0072]
[0073] Among them, a, b, and c are all single-variable expressions about β.
[0074] (3-2) List the single variable equation Δ=b for β 2 -4ac=0, solve all the roots of the equation, and then round up the largest root to get β m =101.
[0075] (3-3) Substitute β = 101 into the expressions of a, b, c and find Then round up to get d m =361.
[0076] (3-4) Substitute (β, d) = (101, 361) into the objective function in model (M1), and then take the logarithm of the value of the objective function to obtain the security level of the solution, which is 58.4.
[0077] Step 4: The platform returns the security level assessment results of the solution to Zhang San.
[0078] Embodiment 2:
[0079] Assume that user "Zhang San" wants to optimize the parameters of a fully homomorphic encryption scheme based on the LWE problem. Further assume that the security level required by Zhang San's scheme is λ=80,ρ=1-2 -100The present invention provides a method for optimizing parameters of a fully homomorphic encryption scheme based on the LWE problem.
[0080] The following is combined with Figure 1 The preferred embodiments of the present invention are described in detail.
[0081] Step 1: Zhang San gives the parameter optimization instructions for the fully homomorphic encryption scheme based on the LWE problem, and provides the parameters λ=80,ρ=1-2 -100 .
[0082] Step 2: Combine Figure 2 , the platform selects the (M2) model according to the instruction:
[0083]
[0084] Step 3: The platform converts the parameters provided by Zhang San into λ=80,ρ=1-2 -100 Substitute into the model (M2) and solve the model. The specific solution steps are as follows:
[0085] (3-1) Artificially set the value range of parameters n, q, α, k:
[0086] I 1 =[100,2000],I 2 =[5000,10 8 ], I 3 =[10 -20 , 10 -5 ], I 4 =[11,21].
[0087] (3-2)Judgement Is it established: Current q =5000, The above inequality does not hold.
[0088] (3-3) Combination Figure 3 , build the model And solve a feasible point where the objective function takes a negative value;
[0089] Further, the specific steps to solve (M3) are:
[0090] (1) Initialization: make B=I 1 ×I 2 ×I 3 ×I 4 . Let the initial active queue Q = {B};
[0091] (2) Calculate the optimal value lower bound: Currently, there is only B in Q. Let p be the point where all coordinate values in B are at the lower bound of the value interval, that is, p = (100, 5000, 10 -2 , 11), and then calculate the value of the objective function of the model (M3) at p, which is -3.1415.
[0092] (3) Block division: Take B from Q. Then divide B into two equal-sized sub-blocks B according to the round-robin scheduling strategy. 1 With B 2 , and B 1 With B 2 Join Q; among them B 1 =I′ 1 ×I 2 ×I 3 ×I 4 and B 2 =I″ 1 ×I 2 ×I 3 ×I 4 , where I′ 1 =[100,1050]andI″ 1 =[1050,2000];
[0093] (4) Finding a feasible point: For each sub-block B obtained by segmentation i , the feasible point calculation method is used to determine whether there is a feasible point. If not, the block is discarded and the feasible value ω(B i )=+∞; if it exists, a feasible point is calculated and the value of the objective function at this point is recorded as the feasible value ω(B i ); where i = 1, 2;
[0094] Furthermore, the specific steps of the feasible point calculation method described in step (4) are as follows:
[0095] a) Take block B i The two vertices p 1 and p 2 , where vertex p 1 Correspondence I 1 The lower bound of I 2 ,I 3 ,I 4 The upper bound of the vertex p 2 Correspondence I 1 ,I 2 ,I 3 ,I 4 The upper bound of
[0096] b) Determine p 1 and p 2Is it a feasible point? If any of them is a feasible point, the feasible point has been obtained and will be returned; otherwise, execute the next step;
[0097] c) Connect p by midpoint bisection 1 and p 2 Find a feasible point on the line segment; if the midpoint is a feasible point, calculate the feasible value ω(B i ); If the midpoint is not a feasible point, repeat this step until the line segment does not contain points where n is an integer, and block B i Abandon from Q and let the feasible value ω(B i )=+∞.
[0098] Using the above method to find B 1 The feasible point in is n=575,q=50002500,α=0.00001,k=21;the value of the objective function at this point is calculated to be 3.98, that is, ω(B 1 )=3.98. For block B 2 Performing the same operation, we get the feasible point n = 1775, q = 50002500, α = 0.00001, k = 21; the value of the objective function at this point is 9.37, that is, ω(B 2 )=9.37.
[0099] d) Determine the sign of the objective function at the feasible point: Let ω * =min{ω(B 1 ),ω(B 2 )}. * >0, so no feasible point is found where the objective function of model (M3) takes a value less than 0.
[0100] e) Determine whether Q is an empty set: Q = {B 1 , B 2} is not an empty set, jump to (2).
[0101] (3-4) Step (3-3) has a solution x * =(575,12650325,7.0084*10 -6 , 21), indicating that the feasible solution of model (M2) is equivalently found. The corresponding q value is 12650325, which is less than γ, so let And jump to step (3-2).
[0102] (3-5) When When , the above loop terminates, and the optimal feasible solution is found to be {n=258,q=44822,α=0.000358360,k=12.0131}, which is the optimal parameter selection required by the user.
[0103] Finally, it should be noted that the above preferred embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail through the above preferred embodiments, those skilled in the art should understand that various changes can be made in form and details without departing from the scope defined by the claims of the present invention.
Claims
1. A method for estimating the security level and optimizing parameters of a fully homomorphic encryption scheme based on the LWE problem, targeting both users and platforms, in which the user sends his or her requirements to the platform, and the platform calculates and returns the results required by the user to the user; characterized in that: The steps include: S1: The user gives instructions and parameters according to the problem to be solved; S2: The platform selects the corresponding model (M1) or model (M2) according to the received instruction; if the model (M1) is selected, the step S3 is executed; if the model (M2) is selected, the step S4 is executed; S3: The platform substitutes the parameters specified by the user into the model (M1) and solves the model to obtain the security level corresponding to the parameters, and then executes S5; S4: The platform substitutes the numerical value specified by the user into the model (M2) and solves it to obtain the optimal value of the solution parameter, and then executes S5; S5: The platform feeds back the calculation results to the user; Among them, the optional instructions of the user in step S1 are: "Perform security level estimation of the fully homomorphic encryption scheme based on the LWE problem" or "Perform parameter optimization of the fully homomorphic encryption scheme based on the LWE problem"; if the former is selected, the user needs to provide the parameter values of the LWE problem corresponding to the scheme, that is, the specific values of the key length n, the modulus q, and the noise parameter α; if the latter is selected, the user needs to specify the required security level λ and the decryption accuracy ρ; The model (M1) for the security level estimation problem of the fully homomorphic encryption scheme based on the LWE problem with parameter values n, q, α is established as follows: Among them, C = 5.46, A = 0.296, B = 20.388, β is a variable; The parameter optimization model (M2) of the fully homomorphic encryption scheme based on the LWE problem with a specified security level λ and decryption accuracy ρ is established as follows: Among them, security level is a function of the security level; Erf is the Gaussian error function and k is the variable.
2. According to the method of claim 1, the security level estimation and parameter optimization method of the fully homomorphic encryption scheme based on the LWE problem is characterized in that: The specific steps of step S3 are as follows: S301: Construct an expression based on the parameters: Among them, δ0 is a function of β, and β is a variable; S302: List the single variable equation Δ=b about β 2 -4ac=0, solve all the roots of the equation, and then round up the largest root to get β m ; S303: β = β m Substitute into the expression of a, b, c and find Then round up to get d m ; S304: (β, d) = (β m ,d m ) is substituted into the objective function f(β,d) in the model (M1), and then the logarithm of the objective function is taken to obtain the security level of the solution.
3. According to the method for security level estimation and parameter optimization of a fully homomorphic encryption scheme based on the LWE problem in claim 1, the step S4 is specifically: S401: artificially set the value ranges of parameters n, q, α, and k, respectively. Indicates; among them, *respectively represent the upper and lower bounds of the interval of parameter*; S402: If Jump to S405; otherwise, And execute the next step; where ← means assigning the value on the right to the left. Indicates rounding up; S403: Establish a model (M3) and solve a feasible point where the objective function value is negative; S404: If there is a solution x in step S403 * =(n * ,q * ,α * ,k * ), it means that the feasible solution of model (M2) is equivalent to x * And satisfy q * ≤γ, then let And jump to step S402; otherwise, if there is no solution, it means that the model (M2) does not have a feasible solution that meets the conditions, then let q←γ, and jump to step S402; S405: When no feasible solution of model (M2) is found, an empty set is output, indicating that there is no parameter setting that meets the user's requirements; otherwise, a feasible solution x of model (M2) is output. * , which is the optimal parameter selection required by the user; The model (M3) is:
4. According to claim 3, a method for estimating the security level and optimizing parameters of a fully homomorphic encryption scheme based on the LWE problem is characterized in that: In step S401, I1 is [100, 2000], and I2 is [5000, 10 8 ], I3 takes [10 -20 ,10 -5 ], I4 takes [11,21].
5. The method for estimating the security level and optimizing the parameters of a fully homomorphic encryption scheme based on the LWE problem according to claim 3, characterized in that: The solution process described in step S403 is specifically as follows: (1) Initialization: Block B = I1 × I2 × I3 × I4, initial active queue Q = {B}; (2) Calculate the optimal value lower bound: For each block B in Q, take p as the point where all coordinate values in B take the lower bound of the value interval, and transform the objective function of model (M3) The value at point p is denoted as η(B); if η(B)>0, then B is removed from Q; (3) Block partitioning: Select and take out a block B from Q so that the value of η(B) is minimized, then divide B into two equal-sized sub-blocks B1 and B2 according to the round-robin scheduling strategy, and add B1 and B2 to Q; (4) Finding a feasible point: For each sub-block B obtained by segmentation i , the feasible point calculation method is used to determine whether there is a feasible point. If not, the block is discarded and the feasible value ω(B i )=+∞; if it exists, a feasible point is calculated and the value of the objective function at this point is recorded as the feasible value ω(B i ); where i = 1, 2; (5) Determine the sign of the objective function at the feasible point: If ω * <0, it means that a feasible point x with an objective function value less than 0 is found * , end the solution process and return the feasible point x * , otherwise continue to the next step; where ω * =min{ω(B1),ω(B2)}; (6) Determine whether Q is an empty set. If Q is an empty set, it means that no feasible point with an objective function value less than 0 has been found. The solution process ends and the empty set is returned. If Q is not an empty set, jump to step (2).
6. The method for estimating the security level and optimizing the parameters of a fully homomorphic encryption scheme based on the LWE problem according to claim 5, characterized in that: The specific steps of the feasible point calculation method described in step (4) are as follows: a) Take block B i There are two vertices p1 and p2, where vertex p1 corresponds to the lower bound of I1 and the upper bounds of I2, I3, and I4; and vertex p2 corresponds to the upper bounds of I1, I2, I3, and I4; b) Determine whether p1 and p2 are feasible points. If either of them is a feasible point, the feasible point has been obtained and returned; Otherwise, proceed to the next step; c) Find a feasible point on the line segment connecting p1 and p2 by midpoint bisection; if the midpoint is a feasible point, calculate the feasible value ω(B i ); If the midpoint is not a feasible point, repeat this step until the line segment does not contain points where n is an integer, and block B i Abandon from Q and let the feasible value ω(B i )=+∞.
Citation Information
Patent Citations
Non-interactive naive Bayesian classification method based on homomorphic encryption
CN114037013A
Multi-key fully homomorphic encryption method on ring surface
CN116707752A
Estimation method for instance calculation amount with error learning problem
CN117081724A
Security evaluation method of password scheme based on LWE problem design
CN117792644A
Precise calculation type homomorphic ciphertext calculation method based on modular lattice
CN118590214A