Parameter evaluation method of CKKS type fully homomorphic encryption scheme based on error analysis
By dynamically adjusting the parameters of the CKKS-type fully homomorphic encryption scheme and introducing error analysis technology, the shortcomings of the existing solutions in error analysis and parameter evaluation are solved, and a more efficient and secure encryption scheme is achieved.
Patent Information
- Application Number
- CN202510192428.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-21
AI Technical Summary
The existing CKKS-type all-homomorphic encryption scheme has loose upper error bounds and lacks targeted parameter evaluation methods in error analysis and parameter evaluation, which affects its safety, accuracy and efficiency.
A parameter evaluation method for CKKS-type all-homomorphic encryption scheme based on error analysis is proposed. By dynamically adjusting the polynomial order and other parameters, combined with error analysis technology, the parameters are optimized to meet the requirements of safety, correctness and efficiency.
It realizes a tighter error upper bound and better parameter selection, improving the security, correctness and efficiency of the CKKS-type all-homomorphic encryption solution.
Smart Images

Figure CN120050021A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security technology, and particularly relates to a parameter evaluation method for a CKKS-type fully homomorphic encryption scheme based on error analysis. Background Art
[0002] In recent years, many theoretical and computational advancements have been made in the field of Fully Homomorphic Encryption (FHE), bringing this technology closer to practicality than ever before. For this reason, practitioners from neighboring fields such as machine learning have attempted to understand FHE to provide privacy for their work. Among them, the CKKS-type fully homomorphic encryption algorithm is more favored by practitioners because it can perform encryption operations on floating-point numbers. However, due to this characteristic of the CKKS-type encryption scheme, the noise will become a part of the plaintext after decryption, resulting in errors. If the error term is too large, the decrypted plaintext will be an illegal plaintext. Therefore, performing a tight error analysis on the CKKS-type encryption scheme is particularly important in practical applications. At the same time, due to the impact of the security, correctness, and efficiency of the CKKS-type encryption scheme, under certain conditional constraints, how to select the optimal parameters is also a challenging problem in practical applications.
[0003] In terms of error analysis technology, in 2017, Jung Hee Cheon et al. analyzed the error of the CKKS fully homomorphic encryption scheme while proposing it. This analysis method mainly obtains an evaluation of the noise magnitude by analyzing the infinity norm of each component of the noise term. However, the upper bound obtained in this way is very loose. In 2023, Johannes Mono et al. proposed an error evaluation technology. This technology considers the distribution parameters of the overall error after partial homomorphic operations, and then obtains an evaluation of the noise magnitude through the infinity norm. The upper bound obtained in this way is tighter than the method proposed by Jung Hee Cheon et al., but there is still room for improvement. At the same time, since this analysis theory is proposed based on the BGV fully homomorphic encryption scheme, it is not completely applicable to the CKKS fully homomorphic encryption scheme.
[0004] In terms of parameter evaluation, in 2024, Elena Kirshanova et al. proposed a parameter evaluator for fully homomorphic encryption schemes. This parameter evaluator obtains a set of optimal parameters that meet security requirements by analyzing lattice attacks on the parameters of the FHE scheme. However, this evaluator only considers the security of the fully homomorphic encryption scheme when selecting parameters, without considering the correctness and efficiency of fully homomorphic encryption. Some existing fully homomorphic scheme compilers, such as ALCHEMY, Cingulata, EVA, and SEALion, also provide some parameter evaluation methods. However, most of these parameter evaluation methods only consider the security of the scheme and the required multiplication depth, and there is no specific parameter evaluation method for the CKKS scheme.
[0005] In summary, in the current error evaluation technology of fully homomorphic encryption schemes, the evaluation method for the noise term bound mainly obtains an evaluation of the noise magnitude by analyzing the infinity norm of each component of the noise term. However, the upper bound obtained in this way is very loose. At the same time, there is currently no specific parameter evaluator for CKKS-type fully homomorphic encryption schemes. Summary of the Invention
[0006] To solve the above problems existing in the prior art, the present invention provides a parameter evaluation method for CKKS-type fully homomorphic encryption schemes based on error analysis. The technical problems to be solved by the present invention are realized through the following technical solutions:
[0007] In a first aspect, the present invention provides a parameter evaluation method for CKKS-type fully homomorphic encryption schemes based on error analysis, including:
[0008] S1. Initialize the parameters of the parameter evaluator according to a preset scheme, and determine some parameters of the parameter evaluator according to preset requirements;
[0009] S2. Calculate the polynomial order that meets the preset scheme security according to the determined partial parameters, and calculate the error upper bound; according to the error upper bound, calculate the decryption accuracy corresponding to the determined partial parameters;
[0010] S3. Determine whether the decryption accuracy meets the first preset condition. If not, update the determined partial parameters and continue to execute S2 until the updated decryption accuracy meets the first preset condition to obtain the optimal partial parameters;
[0011] S4. According to the optimal partial parameters, determine whether the preset scheme meets the scheme correctness condition. If not, update the determined partial parameters, continue to execute S2, obtain the updated decryption accuracy, and determine whether the updated decryption accuracy has changed. If it has changed, determine whether the updated decryption accuracy meets the first preset condition. If not, continue to execute S2 - S3 to obtain the updated optimal partial parameters until the preset scheme meets the scheme correctness condition according to the updated optimal partial parameters, and obtain the theoretically optimal partial parameters; if it has not changed, until the preset scheme meets the scheme correctness condition according to the updated optimal partial parameters, and obtain the theoretically optimal partial parameters;
[0012] S5. If the polynomial order corresponding to the theoretically optimal partial parameters meets the second preset condition, set the polynomial order as a fixed value, and re - execute S2 - S4 to obtain the practically optimal partial parameters.
[0013] Advantages of the present invention:
[0014] The parameter evaluation method of the CKKS - type fully homomorphic encryption scheme based on error analysis provided by the present invention has the following advantages:
[0015] First, the present invention introduces error analysis technology. By analyzing the distribution parameters of each part of the error terms, a specific distribution parameter of the final error is obtained, making the upper bound of the final error more compact.
[0016] Second, the present invention introduces dynamic parameter evaluation. By dynamically adjusting the polynomial order N, the bottom - layer ciphertext modulus q 0 , and the scaling factor Δ of the preset scheme, a set of better parameters can be obtained under the preset security level, multiplication depth, and decryption accuracy.
[0017] The following will further elaborate on the present invention in conjunction with the drawings and embodiments. Description of the Drawings
[0018] Figure 1 is a flowchart of the parameter evaluation method of the CKKS - type fully homomorphic encryption scheme based on error analysis provided by the embodiments of the present invention. Detailed Embodiments
[0019] The following further describes the present invention in detail with specific embodiments, but the embodiments of the present invention are not limited thereto.
[0020] Please refer to Figure 1 , Figure 1It is a flowchart of a parameter evaluation method for the CKKS - type fully homomorphic encryption scheme based on error analysis provided by an embodiment of the present invention. The parameter evaluation method for the CKKS - type fully homomorphic encryption scheme based on error analysis provided by the present invention includes:
[0021] S1. According to the preset scheme, initialize the parameters of the parameter evaluator, and determine some parameters of the parameter evaluator according to the preset requirements.
[0022] Specifically, in this embodiment, initializing the parameters of the parameter evaluator according to the preset scheme includes:
[0023] For the secret key s, adopt a uniform ternary key, and initialize the standard deviation σ of the distribution corresponding to the secret key s. s The value can be Initialize the distribution parameter ρ of the random number v, the value can be 0.5, initialize the standard deviation σ of the Gaussian noise e. e The value can be 3.2, initialize the bit - length q of the modulus q of the 0 - th layer of the ciphertext. 0 The bit - length q 0bin The value can be 40, initialize the bit - length Δ of the scaling factor Δ. bin The value can be 20;
[0024] For the secret key s, adopt a sparse ternary key, initialize the parameter h of the distribution corresponding to the secret key s, and calculate the standard deviation of the distribution corresponding to the secret key s. The value, initialize the distribution parameter ρ of the random number v, initialize the standard deviation σ of the Gaussian noise e. e The value, initialize the modulus q of the 0 - th layer of the ciphertext. 0 The bit - length q 0bin The value, initialize the bit - length Δ of the scaling factor Δ. bin The value.
[0025] In this embodiment, the encryption algorithm adopts the standard CKKS scheme, and the user can change the distribution parameter ρ of the random number v according to their own needs.
[0026] In this embodiment, determining some parameters of the parameter evaluator according to the preset requirements includes:
[0027] The user sets the security parameter λ, the multiplication depth L, the preset decryption accuracy prec, the upper bound V of the initial message 0 , the number b of message batches, the number w of homomorphic addition times, and the number r of ciphertext rotation times according to the preset requirements.
[0028] S2. According to the determined some parameters, calculate the polynomial order that meets the security of the preset scheme, and calculate the error upper bound; according to the error upper bound, calculate the decryption accuracy corresponding to the determined some parameters.
[0029] Specifically, in this embodiment, according to the determined partial parameters, the polynomial order N that satisfies the preset scheme security is calculated, including: According to the bit length q
[0030] of the modulus q of the 0th layer of the initialized ciphertext 0 and the bit length Δ 0bin of the initialized scaling factor Δ, the modulus q of the 0th layer of the ciphertext and the scaling factor Δ are calculated, and their expressions are: bin 0 0 L
[0031]
[0032] According to the modulus q of the 0th layer of the ciphertext 0 , the scaling factor Δ, and the multiplication depth L, the modulus q of the Lth layer of the ciphertext is calculated L , q L =Δ L q 0 , and the parameter P = q L ; P and q L are two different parameters. In the theoretical scheme, P and q L are approximately equal. In this embodiment, they are regarded as equal;
[0033] According to the modulus q of the Lth layer of the ciphertext L , the parameter P, the security parameter λ, the standard deviation σ s of the distribution corresponding to the initialized secret key s, and the standard deviation σ e of the initialized Gaussian noise e, the polynomial order N that satisfies the preset scheme security is calculated; where
[0034] For the bounded distance decoding (BDD) attack under the original attack of the learning with errors (LWE) attack method, the expression of the polynomial order N that satisfies the preset scheme security is:
[0035]
[0036] For the unified shortest vector problem (uSVP) attack under the original attack of the learning with errors (LWE) attack method, the expression of the polynomial order N that satisfies the preset scheme security is:
[0037]
[0038] where e represents the base of the natural logarithm, and g represents the non-dominant term.
[0039] In this embodiment, calculating the upper bound of the error includes:
[0040] Calculating the standard deviation of the error distribution of the ciphertext according to the determined partial parameters; optionally, different standard deviations of the error distribution can be obtained according to the operations of the user;
[0041] Calculating the standard deviation σ of the error distribution of the required ciphertext according to the preset requirements and the determined partial parameters e_fin and the upper bound V of the message fin ;
[0042] Calculating the upper bound of the error e according to the standard deviation of the error distribution of the required ciphertext The expression thereof is: fin In this embodiment, calculating the standard deviation of the error distribution of the ciphertext according to the determined partial parameters includes:
[0043]
[0044] For a key that is a uniform ternary key, calculating the standard deviation of the error distribution of the ciphertext decryption structure according to the polynomial order N, the distribution parameter ρ value of the initialized random number v, and the standard deviation σ value of the initialized Gaussian noise e
[0045] The expression thereof is: e Calculating the standard deviation of the rounding error distribution of the ciphertext decryption structure The expression thereof is:
[0046]
[0047] Calculating the standard deviation of the error distribution of the homomorphic multiplication structure according to the standard deviation of the rounding error distribution of the ciphertext decryption structure The expression thereof is:
[0048]
[0049] Wherein, V represents the upper bound of the message after i multiplications and j additions, represents the i-th power of the j-th unit root of the polynomial X
[0050]
[0051] +1, RE represents taking the real part of the imaginary number, ij and respectively represent the standard deviations of the error distributions corresponding to the ciphertexts participating in the homomorphic multiplication or addition, and q N and respectively represent the standard deviations of the error distributions corresponding to the ciphertexts participating in the homomorphic multiplication or addition, and q l represents the modulus of the ciphertext at the l-th layer;
[0052] Standard deviation of the rounding error distribution according to the ciphertext decryption structure Calculate the standard deviation of the error distribution of the rescaling structure Its expression is:
[0053]
[0054] Calculate the standard deviation of the error distribution of the homomorphic addition structure Its expression is:
[0055]
[0056] Standard deviation of the rounding error distribution according to the ciphertext decryption structure Calculate the standard deviation of the error distribution of the homomorphic rotation structure Its expression is:
[0057]
[0058] Among them, q l-1 Represents the modulus of the ciphertext at the (l - 1)-th layer
[0059] In this embodiment, according to the determined partial parameters, calculate the standard deviation of the error distribution of the ciphertext, including:
[0060] For a sparse ternary key, according to the polynomial order N, the distribution parameter ρ of the initialized random number v, the standard deviation σ e Of the value and the parameter h of the distribution corresponding to the initialized key s, calculate the standard deviation of the error distribution of the ciphertext decryption structure Its expression is:
[0061]
[0062] Calculate the standard deviation of the rounding error distribution of the ciphertext decryption structure Its expression is:
[0063]
[0064] Standard deviation of the rounding error distribution according to the ciphertext decryption structure Calculate the standard deviation of the error distribution of the homomorphic multiplication structure Its expression is:
[0065]
[0066] Among them, V ij Represents the upper bound of the message after i multiplications and j additions Represents the polynomial X NThe i-th power of the j-th unit root of +1, where RE represents taking the real part of the imaginary number. and respectively represent the standard deviations of the error distributions corresponding to the ciphertexts participating in homomorphic multiplication or addition, and q l represents the modulus of the ciphertext at the l-th layer;
[0067] According to the standard deviation of the rounding error distribution of the ciphertext decryption structure Calculate the standard deviation of the error distribution of the rescaling structure Its expression is:
[0068]
[0069] Calculate the standard deviation of the error distribution of the homomorphic addition structure Its expression is:
[0070]
[0071] According to the standard deviation of the rounding error distribution of the ciphertext decryption structure Calculate the standard deviation of the error distribution of the homomorphic rotation structure Its expression is:
[0072]
[0073] where q l-1 represents the modulus of the ciphertext at the (l - 1)-th layer.
[0074] S3. Determine whether the decryption accuracy meets the first preset condition. If not, update the determined partial parameters and continue to execute S2 until the updated decryption accuracy meets the first preset condition to obtain the optimal partial parameters.
[0075] In this embodiment, determine whether the decryption accuracy precl meets the first preset condition, and the first preset condition is:
[0076] prec l ≥ prec and prec l-1 < prec;
[0077] where prec l-1 represents the decryption accuracy calculated from the previously determined partial parameters;
[0078] If not, update the determined partial parameters; if prec < prec l , then decrease Δ bin , if prec ≥ prec l , then increase Δ bin , until the updated decryption accuracy meets the first preset condition to obtain the optimal partial parameters Γ = {N, q0 , Δ}。
[0079] S4. According to the optimal partial parameters, determine whether the preset scheme meets the scheme correctness condition. If it does not meet, update the determined partial parameters, continue to execute S2, obtain the updated decryption accuracy, and determine whether the updated decryption accuracy has changed. If it has changed, determine whether the updated decryption accuracy meets the first preset condition. If it does not meet, continue to execute S2 - S3 to obtain the updated optimal partial parameters until the preset scheme meets the scheme correctness condition according to the updated optimal partial parameters, and obtain the theoretically optimal partial parameters; if it has not changed, until the preset scheme meets the scheme correctness condition according to the updated optimal partial parameters, and obtain the theoretically optimal partial parameters.
[0080] In this embodiment, determine whether the preset scheme meets the scheme correctness condition, and the scheme correctness condition is:
[0081] Under the determined partial parameters of the current group, and under the determined partial parameters of the previous group,
[0082] If it does not meet, update the optimal partial parameters; if then decrease q 0bin , if then increase q 0bin 。
[0083] It should be noted that when determining whether the preset scheme meets the scheme correctness condition according to the optimal partial parameters, in the case of non - satisfaction, while updating the determined partial parameters, the decryption accuracy will also be updated. At this time, on the basis that the decryption accuracy meets the first preset condition and the preset scheme meets the correctness condition, the parameters will be determined. Only when both are satisfied can the optimal parameter group be obtained.
[0084] S5. If the polynomial order corresponding to the theoretically optimal partial parameters meets the second preset condition, set this polynomial order as a fixed value, and re - execute S2 - S4 to obtain the actually optimal partial parameters.
[0085] In this embodiment, if the polynomial order corresponding to the theoretically optimal partial parameters meets the second preset condition, the second preset condition is:
[0086] Whether the polynomial order N corresponding to the theoretically optimal partial parameters satisfies 2 i < N ≤ 2 i+1 ;
[0087] If it meets, then set N = 2 i+1, and re-determine the optimal partial parameters, update the optimal partial parameters, and use them as the actually optimal partial parameters.
[0088] It should be noted that the entire process scheme of the present invention is as Figure 1 shown, where sign 0 and sign 1 represent different selection methods, and sign 0 =1 and sign 0 =0 represent two different selections under the same selection method, and sign 1 =1 and sign 1 =0 also represent two different selections under the same selection method.
[0089] In summary, a method for evaluating parameters of a CKKS-type fully homomorphic encryption scheme based on error analysis provided by the present invention has the following beneficial effects:
[0090] First, the present invention introduces error analysis technology. By analyzing the distribution parameters of each part of the error term, a specific distribution parameter of the final error is obtained, making the upper bound of the final error more compact.
[0091] Second, the present invention introduces dynamic parameter evaluation. By dynamically adjusting the polynomial order N of the preset scheme, the modulus q of the bottom-level ciphertext 0 , and the scaling factor Δ, a set of relatively optimal parameters can be obtained under the preset security level, multiplication depth, and decryption accuracy.
[0092] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant is intended to cover non-exclusive inclusion, so that an article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed. Without more limitations, an element defined by the statement "including a..." does not exclude the existence of another identical element in the article or device including the element. "Connection" or "connected" and other similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The orientation or positional relationship indicated by "upper", "lower", "left", "right", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present invention.
[0093] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "examples", "specific examples", or "some examples", etc. mean that the specific features or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.
[0094] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. A parameter evaluation method for a CKKS type fully homomorphic encryption scheme based on error analysis, characterized in that: include: S1. Initialize the parameters of the parameter estimator according to a preset scheme, and determine some parameters of the parameter estimator according to preset requirements; S2. According to the determined partial parameters, the polynomial order that satisfies the preset scheme security is calculated, and the upper bound of the error is calculated; According to the error upper bound, the decryption accuracy corresponding to the determined partial parameters is calculated; S3, determining whether the decryption accuracy satisfies a first preset condition, if not, updating the determined partial parameters, and continuing to execute S2 until the updated decryption accuracy satisfies the first preset condition, and obtaining the optimal partial parameters; S4. According to the optimal partial parameters, determine whether the preset scheme meets the scheme correctness condition. If not, update the determined partial parameters and continue to execute S2 to obtain updated decryption accuracy. Determine whether the updated decryption accuracy has changed. If it has changed, determine whether the updated decryption accuracy meets the first preset condition. If not, continue to execute S2 to S3 to obtain updated optimal partial parameters, until the preset scheme meets the scheme correctness condition according to the updated optimal partial parameters, and obtain the theoretically optimal partial parameters. If no change occurs, until the preset solution meets the solution correctness condition according to the updated optimal partial parameters, the theoretically optimal partial parameters are obtained; S5. If the polynomial order corresponding to the theoretically optimal partial parameters meets the second preset condition, the polynomial order is set to a fixed value, and S2 to S4 are re-executed to obtain the actually optimal partial parameters.
2. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 1 is characterized in that: According to the preset scheme, initialize the parameters of the parameter estimator, including: A uniform ternary key is used for key s, and the standard deviation σ of the distribution corresponding to the initial key s is s The value of the distribution parameter ρ of the initial random number v and the standard deviation σ of the initial Gaussian noise e e The value of initializes the bit length q of the modulus q0 of the ciphertext layer 0 0bin The value of , initializes the bit length Δ of the scaling factor Δ bin The value of For key s, a sparse ternary key is used to initialize the value of the parameter h corresponding to the key s distribution, and the standard deviation of the key s distribution is calculated. The value of the distribution parameter ρ of the initial random number v and the standard deviation σ of the initial Gaussian noise e e The value of initializes the bit length q of the modulus q0 of the ciphertext layer 0 0bin The value of , initializes the bit length Δ of the scaling factor Δ bin The value of .
3. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 2 is characterized in that: According to the preset requirements, some parameters of the parameter estimator are determined, including: According to preset requirements, the user sets the security parameter λ, multiplication depth L, preset decryption precision prec, initial message upper bound V0, number of message batches b, number of homomorphic additions w, and number of ciphertext rotations r.
4. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 3 is characterized in that: According to the determined partial parameters, the polynomial order that satisfies the preset scheme security is calculated, including: According to the bit length q of the initial ciphertext layer 0 modulus q0 0bin The value of and the bit length of the initial scaling factor Δ bin The value of is used to calculate the modulus q0 of the ciphertext layer 0 and the scaling factor Δ, which are expressed as follows: According to the modulus q0 of the ciphertext layer 0, the scaling factor Δ and the multiplication depth L, the modulus q of the ciphertext layer L is calculated. L ,q L =Δ L q0, and set the parameter P = q L ; According to the Lth layer modulus q of the ciphertext L , parameter P, security parameter λ, standard deviation σ of the distribution corresponding to the initialized key s s The value and the standard deviation σ of the initialized Gaussian noise e e The value of is used to calculate the polynomial order N that satisfies the preset scheme security; where, For the bounded distance decoding attack with error-based learning attack as the original attack, the expression of the polynomial order N that satisfies the preset scheme security is: For the unified shortest vector problem attack under the original attack with error learning attack mode, the expression of the polynomial order N that meets the preset scheme security is: Wherein, e represents the base of the natural logarithm and g represents the non-dominant term.
5. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 3 is characterized in that: The upper bound of the error is calculated, including: According to the determined partial parameters, the standard deviation of the error distribution of the ciphertext is calculated; According to the preset requirements and the determined partial parameters, the error distribution standard deviation σ of the required ciphertext is calculated e_fin , and the message upper bound V fin ; According to the required standard deviation of the ciphertext error distribution The upper limit of error is calculated as e fin , whose expression is:
6. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 5 is characterized in that: According to the determined parameters, the standard deviation of the error distribution of the ciphertext is calculated, including: For a uniform ternary key, according to the polynomial order N, the value of the distribution parameter ρ of the initialized random number v and the standard deviation σ of the initialized Gaussian noise e e The value of , calculates the standard deviation of the error distribution of the ciphertext decryption structure Its expression is: Calculate the standard deviation of the rounding error distribution of the ciphertext decryption structure Its expression is: The standard deviation of the rounding error distribution according to the ciphertext decryption structure Calculate the standard deviation of the error distribution of the homomorphic multiplication structure Its expression is: Among them, V ij It represents the upper bound of the message after i multiplications and j additions. Represents the polynomial X N +1 to the i-th power of the j-th root of unity, RE means taking the real part of the imaginary number, and They represent the standard deviation of the error distribution of the ciphertexts involved in homomorphic multiplication or addition, q l The modulus of the ciphertext at the first level l; The standard deviation of the rounding error distribution according to the ciphertext decryption structure Calculate the standard deviation of the error distribution of the rescaled structure Its expression is: Calculate the standard deviation of the error distribution of the homomorphic additive structure Its expression is: The standard deviation of the rounding error distribution according to the ciphertext decryption structure The standard deviation of the error distribution of the homomorphic rotation structure is calculated Its expression is: Among them, q l-1 Represents the modulus of the l-1th layer ciphertext.
7. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 5 is characterized in that: According to the determined parameters, the standard deviation of the error distribution of the ciphertext is calculated, including: For a sparse ternary key, according to the polynomial order N, the value of the distribution parameter ρ of the initialized random number v, and the standard deviation σ of the initialized Gaussian noise e e The value of and the value of the parameter h corresponding to the initialization key s are used to calculate the standard deviation of the error distribution of the ciphertext decryption structure. Its expression is: Calculate the standard deviation of the rounding error distribution of the ciphertext decryption structure Its expression is: The standard deviation of the rounding error distribution according to the ciphertext decryption structure Calculate the standard deviation of the error distribution of the homomorphic multiplication structure Its expression is: Among them, V ij It represents the upper bound of the message after i multiplications and j additions. Represents the polynomial X N +1 to the i-th power of the j-th root of unity, RE means taking the real part of the imaginary number, and They represent the standard deviation of the error distribution of the ciphertexts involved in homomorphic multiplication or addition, q l The modulus of the ciphertext at the first level l; The standard deviation of the rounding error distribution according to the ciphertext decryption structure Calculate the standard deviation of the error distribution of the rescaled structure Its expression is: Calculate the standard deviation of the error distribution of the homomorphic additive structure Its expression is: The standard deviation of the rounding error distribution according to the ciphertext decryption structure The standard deviation of the error distribution of the homomorphic rotation structure is calculated Its expression is: Among them, q l-1 Represents the modulus of the l-1th layer ciphertext.
8. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 1 is characterized in that: Determine whether the decryption accuracy satisfies the first preset condition. If not, update the determined partial parameters and continue to execute S2 until the updated decryption accuracy satisfies the first preset condition to obtain the optimal partial parameters, including: Determine whether the decryption precision precl meets a first preset condition, where the first preset condition is: prec l ≥prec and prec l-1 <prec; Among them, prec l-1 Indicates the decryption accuracy calculated by the previous set of determined partial parameters; If not satisfied, update some of the parameters; if prec <prec l , then reduce Δ bin , if prec ≥ prec l , then increase Δ bin , until the updated decryption accuracy meets the first preset condition, and the optimal partial parameter Γ={N,q0,Δ} is obtained.
9. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 1 is characterized in that: According to the optimal partial parameters, it is judged whether the preset solution meets the solution correctness condition. If not, the determined partial parameters are updated, including: Determine whether the preset solution meets the solution correctness condition, and the solution correctness condition is: Under some parameters determined by the current group, And under the previous set of determined parameters, If it is not satisfied, update the optimal partial parameters; if Then reduce q 0bin ,if Then increase q 0bin .
10. The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis according to claim 1, characterized in that: If the polynomial order corresponding to the theoretically optimal partial parameters meets the second preset condition, the polynomial order is set to a fixed value, and S2 to S4 are executed again to obtain the actual optimal partial parameters, including: If the polynomial order corresponding to the theoretically optimal partial parameters satisfies the second preset condition, the second preset condition is: Does the polynomial order N corresponding to the theoretically optimal partial parameters satisfy 2? i <N≤2 i+1 ; If satisfied, set N = 2 i+1 , and re-determine the optimal partial parameters, and update the optimal partial parameters as the actual optimal partial parameters.
Citation Information
Patent Citations
Improved fully homomorphic encryption method
CN110855421A
Fully homomorphic encryption deep learning reasoning method and system based on FPGA
CN112699384A
Homomorphic encryption calculation method and system
CN115276948A
Security evaluation method of password scheme based on LWE problem design
CN117792644A
Privacy protection contribution evaluation method in horizontal federated learning scene
CN118114296A