Parameter evaluation method for ckks type fully homomorphic encryption scheme based on error analysis
By optimizing the parameters of the CKKS-type fully homomorphic encryption scheme through error analysis and dynamic parameter adjustment, the problem of lenient noise term evaluation was solved, thereby improving security and decryption accuracy.
Patent Information
- Application Number
- CN202510192428.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-02-21
AI Technical Summary
Existing CKKS-type fully homomorphic encryption schemes have overly lenient bounds on noise term evaluation and lack dedicated parameter evaluation methods, which affect their security, correctness, and efficiency.
By using a parameter evaluation method based on error analysis, the polynomial order N, the lowest-level ciphertext modulus q0, and the scaling factor Δ are dynamically adjusted, and combined with error distribution parameters, the parameters are optimized to meet the requirements of security, correctness, and decryption accuracy.
It achieves a tighter upper bound on the error and a better combination of parameters, improving the security and decryption accuracy of the CKKS-type fully homomorphic encryption scheme.
Smart Images

Figure CN120050021B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of network security, and particularly relates to a parameter evaluation method of a CKKS type fully homomorphic encryption scheme based on error analysis. BACKGROUND
[0002] In recent years, the field of fully homomorphic encryption (FHE) has made many theoretical and computational advances, making the technology more practical than ever. For this reason, practitioners from neighboring fields such as machine learning are trying to understand FHE in order to provide privacy for their work. Among them, the CKKS type fully homomorphic encryption algorithm is favored by the majority of practitioners because it can encrypt floating-point numbers for encryption operations. However, due to the characteristics of the CKKS type encryption scheme, the noise after decryption will become part of the plaintext, resulting in errors. If the error term is too large, the decrypted plaintext will be an illegal plaintext. Therefore, compact error analysis of the CKKS type encryption scheme is particularly important in practical applications. At the same time, due to the influence of the security, correctness and efficiency of the CKKS type encryption scheme, under certain conditions, how to select the optimal parameters in practical applications is also a challenging problem.
[0003] In the aspect of error analysis technology, in 2017, Jung Hee Cheon et al. proposed the CKKS fully homomorphic encryption scheme and analyzed the error of the scheme. This analysis method mainly obtains an evaluation of the noise magnitude by analyzing the infinite norm of each component of the noise term. However, the upper bound obtained by this method is very loose. In 2023, Johannes Mono et al. proposed an error evaluation technology. This technology considers the distribution parameters of the overall error after the partially homomorphic operation, and then obtains an evaluation of the noise magnitude through the infinite norm. The upper bound obtained by this method is more compact than the method proposed by Jung Hee Cheon et al. However, there is still room for improvement. At the same time, since this analysis theory is based on the BGV fully homomorphic encryption scheme, it is not completely applicable to the CKKS fully homomorphic encryption scheme.
[0004] In terms of parameter evaluation, Elena Kirshanova et al. proposed a parameter evaluator for fully homomorphic encryption schemes in 2024, which obtained a set of optimal parameters that satisfy security by analyzing lattice attacks on FHE scheme parameters, but the evaluator only considers the security of the fully homomorphic encryption scheme to select parameters, without considering the correctness and efficiency of the fully homomorphic encryption. Some existing fully homomorphic scheme compilers such as ALCHEMY, Cingulata, EVA and SEALion also provide some parameter evaluation methods, but these parameter evaluation methods mostly only consider scheme security and required multiplication depth, and there is no parameter evaluation method specifically for the CKKS scheme.
[0005] In summary, the current fully homomorphic encryption scheme error evaluation techniques mainly evaluate the noise term limit by analyzing the infinity norm of each component of the noise term to obtain an evaluation of the noise magnitude, but the upper bound obtained by this method is very loose. At present, there is no parameter evaluator specifically for CKKS type fully homomorphic encryption scheme. SUMMARY
[0006] In order to solve the above problems existing in the prior art, the present application provides a parameter evaluation method for CKKS type fully homomorphic encryption scheme based on error analysis. The technical problem to be solved by the present application is solved by the following technical scheme:
[0007] In a first aspect, the present application provides a parameter evaluation method for CKKS type fully homomorphic encryption scheme based on error analysis, comprising:
[0008] S1, according to the preset scheme, initialize the parameters of the parameter evaluator, and according to the preset requirements, determine part of the parameters of the parameter evaluator;
[0009] S2, according to the determined part of the parameters, calculate the polynomial order that satisfies the security of the preset scheme, and calculate the error upper bound; according to the error upper bound, calculate the decryption precision corresponding to the determined part of the parameters;
[0010] S3, judge whether the decryption precision satisfies the first preset condition, if not, update the determined part of the parameters, continue to execute S2, until the updated decryption precision satisfies the first preset condition, and obtain the optimal part of the parameters;
[0011] S4, judging whether the preset scheme meets the scheme correctness condition according to the optimal partial parameter, if not, updating the determined partial parameter, continuing to execute S2 to obtain the updated decryption precision, judging whether the updated decryption precision changes, if it changes, judging whether the updated decryption precision meets the first preset condition, if not, continuing to execute S2-S3 to obtain the updated optimal partial parameter, until the preset scheme meets the scheme correctness condition according to the updated optimal partial parameter, obtaining the theoretically optimal partial parameter; if it does not change, until the preset scheme meets the scheme correctness condition according to the updated optimal partial parameter, obtaining the theoretically optimal partial parameter;
[0012] S5, if the polynomial order corresponding to the theoretically optimal partial parameter meets the second preset condition, setting the polynomial order as a fixed value, and re-executing S2-S4 to obtain the practically optimal partial parameter.
[0013] The beneficial effects of the present application are as follows:
[0014] The parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis provided by the present application has the following beneficial effects:
[0015] Firstly, the present application introduces error analysis technology, obtains a specific distribution parameter of the final error by analyzing the distribution parameters of each partial error term, so that the upper bound of the final error is more compact.
[0016] Secondly, the present application introduces dynamic parameter evaluation, adjusts the polynomial order N, the bottom layer ciphertext module q0 and the scaling factor Δ of the preset scheme dynamically, so that a group of optimal parameters meeting the preset security level, the multiplication depth and the decryption precision can be obtained.
[0017] The present application will be further described in detail below in combination with the drawings and embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 is a flow chart of the parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis provided by the embodiment of the present application. DETAILED DESCRIPTION
[0019] The present application will be further described in detail below in combination with the drawings and embodiments.
[0020] Please refer to Figure 1 , Figure 1 is a flow chart of the parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis provided by the embodiment of the present application, and the parameter evaluation method of the CKKS type fully homomorphic encryption scheme based on error analysis provided by the present application comprises:
[0021] S1. According to the preset scheme, initialize the parameters of the parameter evaluator, and determine some parameters of the parameter evaluator according to the preset requirements.
[0022] Specifically, in this embodiment, the parameters of the parameter evaluator are initialized according to a preset scheme, including:
[0023] A uniform ternary key is used for key s, and the standard deviation σ of the distribution corresponding to key s is initialized. s The value can be: Initialize the distribution parameter ρ of the random number v to a value of 0.5, and initialize the standard deviation σ of the Gaussian noise e. e The value can be 3.2, which initializes the bit length q of the ciphertext's level 0 modulus q0. 0bin The value can be 40, and the bit length Δ is used to initialize the scaling factor Δ. bin The value can be 20;
[0024] A sparse ternary key is used for key s. The parameter h of the distribution corresponding to key s is initialized, and the standard deviation of the distribution corresponding to key s is calculated. The value of ρ, the initial distribution parameter of the random number v, and the standard deviation σ of the Gaussian noise e. e The value of q is used to initialize the bit length q of the ciphertext's 0th layer modulus q0. 0bin The value of the initial scaling factor Δ, and the bit length Δ. bin The value of .
[0025] In this embodiment, the encryption algorithm adopts the standard CKKS scheme. Users can change the distribution parameters ρ of the random number v according to their own needs.
[0026] In this embodiment, some parameters of the parameter estimator are determined according to preset requirements, including:
[0027] Users can set the security parameters λ, multiplication depth L, preset decryption precision prec, initial message upper bound V0, number of message batches b, number of homomorphic additions w, and number of ciphertext rotations r according to preset requirements.
[0028] S2. Based on the determined partial parameters, calculate the polynomial order that satisfies the preset security scheme, and calculate the upper bound of the error; based on the upper bound of the error, calculate the decryption accuracy corresponding to the determined partial parameters.
[0029] Specifically, in this embodiment, based on certain parameters, a ring that satisfies the preset security requirements is calculated. The polynomial order N includes:
[0030] Based on the bit length q of the initial ciphertext's level 0 modulus q0. 0bin The value and the bit length Δ of the initial scaling factor Δ bin The value of is used to calculate the modulus q0 of the ciphertext at level 0 and the scaling factor Δ, which are expressed as follows:
[0031]
[0032] The Lth-th layer modulus q0 of the ciphertext is calculated based on the 0th layer modulus q0, the scaling factor Δ, and the multiplication depth L. L q L =Δ L q0, and set parameter P = q L P and q L For two different parameters, in the theoretical scheme, P and q L They are approximately equal; in this embodiment, they are considered to be equal.
[0033] Based on the Lth layer modulus q of the ciphertext L Parameter P, security parameter λ, and the standard deviation σ of the distribution corresponding to the initial key s s The value and the standard deviation σ of the initialized Gaussian noise e e The value of is used to calculate the polynomial order N that satisfies the preset security of the scheme; where,
[0034] For the Leaving-Learning-Wrong (LWE) attack, which is a bounded distance decoding (BDD) attack under the original attack, the expression for the polynomial order N that satisfies the preset security of the scheme is:
[0035]
[0036] For the Unified Shortest Vector Problem (uSVP) attack, which is a simple LWE attack, the expression for the polynomial order N that satisfies the pre-defined security of the scheme is:
[0037]
[0038] Where e represents the base of the natural logarithm, and g represents the non-dominant term.
[0039] In this embodiment, the upper bound of the error is calculated, including:
[0040] Based on the determined parameters, the standard deviation of the error distribution of the ciphertext is calculated; optionally, different standard deviations of the error distribution can be obtained depending on the user's operation.
[0041] According to the preset requirement and the determined partial parameter, a required ciphertext error distribution standard deviation σ is calculated e_fin , and a message upper bound V fin ;
[0042] According to the required ciphertext error distribution standard deviation σ , an error upper bound e fin is calculated, and the expression is
[0043]
[0044] In the embodiment, the ciphertext error distribution standard deviation σ is calculated according to the determined partial parameter, including
[0045] For the uniform ternary key, according to the polynomial order N, the value of the distribution parameter ρ of the initialized random number v and the standard deviation σ e of the initialized Gaussian noise e, a ciphertext decryption structure error distribution standard deviation σ is calculated, and the expression is
[0046]
[0047] A ciphertext decryption structure rounding error distribution standard deviation σ is calculated, and the expression is
[0048]
[0049] According to the ciphertext decryption structure rounding error distribution standard deviation σ , a homomorphic multiplication structure error distribution standard deviation σ is calculated , and the expression is
[0050]
[0051] , wherein V ij represents a message upper bound after i times of multiplication and j times of addition, represents the i-th power of the j-th unit root of the polynomial X N +1, RE represents the real part of a complex number, and respectively represent the standard deviation of the error distribution corresponding to the ciphertext participating in the homomorphic multiplication or addition, q l represents the modulus of the l-th layer ciphertext;
[0052] According to the ciphertext decryption structure rounding error distribution standard deviation σ , a re-scaling structure error distribution standard deviation σ is calculated , and the expression is
[0053]
[0054] The error distribution standard deviation of the homomorphic addition structure is calculated The expression is:
[0055]
[0056] The error distribution standard deviation of the rounding error of the ciphertext decryption structure is calculated The error distribution standard deviation of the homomorphic rotation structure is calculated The expression is:
[0057]
[0058] Wherein, q l-1 Indicates the modulus of the (l-1) th ciphertext.
[0059] In this embodiment, the error distribution standard deviation of the ciphertext is calculated according to the determined part of the parameter, including:
[0060] For the sparse ternary key, according to the polynomial order N, the value of the distribution parameter p of the initialized random number v, the value of the standard deviation s of the initialized Gaussian noise e e And the value of the parameter h corresponding to the initialized key s, the error distribution standard deviation of the ciphertext decryption structure is calculated The expression is:
[0061]
[0062] The error distribution standard deviation of the rounding error of the ciphertext decryption structure is calculated The expression is:
[0063]
[0064] The error distribution standard deviation of the rounding error of the ciphertext decryption structure is calculated The error distribution standard deviation of the homomorphic multiplication structure is calculated The expression is:
[0065]
[0066] Wherein, V ij Indicates the upper bound of the message after i times of multiplication and j times of addition, Indicates the i power of the j th unit root of the polynomial X N +1, RE indicates the real part of the imaginary number, And Indicate the standard deviation of the error distribution corresponding to the ciphertext participating in the homomorphic multiplication or addition, q l Indicates the modulus of the l th ciphertext;
[0067] The standard deviation of the rounding error distribution according to the ciphertext decryption structure The standard deviation of the rounding error distribution according to the re-scaling structure The expression is:
[0068]
[0069] The standard deviation of the rounding error distribution according to the homomorphic addition structure The expression is:
[0070]
[0071] The standard deviation of the rounding error distribution according to the ciphertext decryption structure The standard deviation of the rounding error distribution according to the homomorphic rotation structure The expression is:
[0072]
[0073] Wherein, q l-1 Indicates the modulus of the (l-1) th ciphertext.
[0074] S3, judge whether the decryption precision meets the first preset condition, if not, update the determined partial parameter, continue to execute S2, until the updated decryption precision meets the first preset condition, and the optimal partial parameter is obtained.
[0075] In this embodiment, it is judged whether the decryption precision precl meets the first preset condition, and the first preset condition is:
[0076] prec l ≥ prec and prec l-1 < prec;
[0077] Wherein, prec l-1 Indicates the decryption precision calculated by the last group of determined partial parameters;
[0078] If not, update the determined partial parameter; if prec < prec l , reduce Δ bin , if prec ≥ prec l , increase Δ bin , until the updated decryption precision meets the first preset condition, and the optimal partial parameter Γ = {N, q0, Δ} is obtained.
[0079] S4, judging whether the preset scheme satisfies the scheme correctness condition according to the optimal partial parameter, if not, updating the determined partial parameter, continuing to execute S2 to obtain the updated decryption precision, judging whether the updated decryption precision is changed, if changed, judging whether the updated decryption precision satisfies the first preset condition, if not, continuing to execute S2-S3 to obtain the updated optimal partial parameter, until the preset scheme satisfies the scheme correctness condition according to the updated optimal partial parameter, obtaining the theoretically optimal partial parameter; if not changed, until the preset scheme satisfies the scheme correctness condition according to the updated optimal partial parameter, obtaining the theoretically optimal partial parameter.
[0080] In the embodiment, judging whether the preset scheme satisfies the scheme correctness condition, the scheme correctness condition is:
[0081] Under the current group determined partial parameter, and under the last group determined partial parameter,
[0082] If not, updating the optimal partial parameter; if then reducing q 0bin , if then increasing q 0bin .
[0083] It should be noted that when judging whether the preset scheme satisfies the scheme correctness condition according to the optimal partial parameter, the decryption precision is also updated when not satisfying, at this time, the preset scheme satisfies the correctness condition on the basis of the decryption precision satisfying the first preset condition, the parameter is determined, both satisfy, and the optimal parameter group is obtained.
[0084] S5, if the polynomial order corresponding to the theoretically optimal partial parameter satisfies the second preset condition, setting the polynomial order as a fixed value, and re-executing S2-S4 to obtain the practically optimal partial parameter.
[0085] In the embodiment, if the polynomial order corresponding to the theoretically optimal partial parameter satisfies the second preset condition, the second preset condition is:
[0086] Whether the polynomial order N corresponding to the theoretically optimal partial parameter satisfies 2 i <N≤2 i+1 ;
[0087] If satisfied, setting N=2 i+1 , and re-determining the optimal partial parameter, updating the optimal partial parameter as the practically optimal partial parameter.
[0088] It should be noted that the whole flow scheme of the present application is as shown in Figure 1 Wherein sign0 and sign1 represent different selection modes, sign0=1 and sign0=0 represent two different selections under the same selection mode, and sign1=1 and sign1=0 also represent two different selections under the same selection mode.
[0089] In summary, the present application provides a CKKS type homomorphic encryption scheme based on error analysis Parameter evaluation method, has the following beneficial effects:
[0090] First, the present application introduces error analysis technology, through analyzing the distribution parameters of each part of the error term to get a specific distribution parameter of the final error, so that the upper bound of the final error is more compact.
[0091] Second, the present application introduces dynamic parameter evaluation, by dynamically adjusting the polynomial order N, the bottom layer of the ciphertext module q0 and the scaling factor Delta of the preset scheme, a set of optimal parameters can be obtained to meet the preset security level, multiplication depth and decryption accuracy.
[0092] It should be noted that in this paper, such as the first and second relationship terms are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the term "includes", "contains" or any other variant is intended to cover non-exclusive inclusion, so that the article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed. Without more limitation, the element defined by the sentence "including a" does not exclude the presence of other identical elements in the article or device including the element. "Connection" or "connected" and similar words are not limited to physical or mechanical connection, but can include electrical connection, whether direct or indirect. "Up", "down", "left", "right" and other indicative orientation or position relationship are based on the orientation or position relationship shown in the drawings, only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, so it cannot be understood as a limitation on the present application.
[0093] In the description of the specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" and the like means that the specific feature or characteristic described in connection with the embodiment or example is included in at least one embodiment or example of the present application. In the specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in any suitable manner in one or more embodiments or examples. In addition, those skilled in the art can combine and combine different embodiments or examples described in the specification.
[0094] The above is a further detailed description of the present application in combination with specific preferred embodiments, and cannot be considered as limiting the specific implementation of the present application to these descriptions. For those skilled in the art, without departing from the concept of the present application, a number of simple deductions or substitutions can be made, which should be considered as falling within the protection scope of the present application.
Claims
1.A method for parameter evaluation of a CKKS-type fully homomorphic encryption scheme based on error analysis, characterized by, Comprise: S1, according to the preset scheme, initialize the parameter evaluator parameters, and determine part of the parameters of the parameter evaluator according to the preset requirements; S2, according to the determined part of the parameter, the polynomial order that satisfies the preset scheme security is calculated, and the error upper bound is calculated; According to the error upper bound, the decryption accuracy corresponding to the determined part of the parameter is calculated; Wherein, the error upper bound is calculated, comprising: According to the determined part of the parameter, the error distribution standard deviation of the ciphertext is calculated; According to the preset requirement and the determined part parameter, a standard deviation of error distribution of the required ciphertext is calculated , and a message upper bound According to the error distribution standard deviation of the required ciphertext , the error upper bound is calculated, and the expression is ; wherein, denotes a polynomial order satisfying a pre-set scheme security, denotes a scaling factor; S3, judging whether the decryption accuracy satisfies a first preset condition, if not, updating the determined partial parameter, continuing to execute S2 until the updated decryption accuracy satisfies the first preset condition, obtaining the optimal partial parameter; comprising: judging whether the decryption accuracy satisfies the first preset condition , the first preset condition is: , and ; wherein, the decryption accuracy calculated by the last group of determined partial parameters; if not, updating the determined partial parameter; if , then reducing , , wherein, the bit length of the scaling factor , if , then increasing , until the updated decryption accuracy satisfies the first preset condition, obtaining the optimal partial parameter , , wherein, the 0th layer modulus of the ciphertext S4, according to the optimal part of the parameter, judge whether the preset scheme satisfies the scheme correctness condition, if not, update the determined part of the parameter, continue to execute S2, get the updated decryption accuracy, judge whether the updated decryption accuracy changes, if it changes, judge whether the updated decryption accuracy satisfies the first preset condition, if not, continue to execute S2-S3, get the updated optimal part of the parameter, until according to the updated optimal part of the parameter, the preset scheme satisfies the scheme correctness condition, get the theoretically optimal part of the parameter; If it does not change, until according to the updated optimal part of the parameter, the preset scheme satisfies the scheme correctness condition, get the theoretically optimal part of the parameter; Including: judge whether the preset scheme satisfies the scheme correctness condition, the scheme correctness condition is: Under the part parameters determined by the current group, , and under the part parameters determined by the previous group, ; represents the number of message batch processing; If not satisfied, update the optimal partial parameters; if , reduce , if , increase ; represents the bit length of the ciphertext 0th layer modulus ; S5, if the polynomial order corresponding to the theoretically optimal part of the parameter satisfies the second preset condition, set the polynomial order as a fixed value, and execute S2-S4 again to get the actually optimal part of the parameter; Including: if the polynomial order corresponding to the theoretically optimal part of the parameter satisfies the second preset condition, the second preset condition is: the corresponding polynomial order in the theoretically optimal partial parameters whether the condition is satisfied ; If satisfied, set and re-determine the optimal partial parameters, update the optimal partial parameters as actually optimal partial parameters, denotes the th multiplication. 2.The parameter evaluation method of an error analysis-based CKKS-type fully homomorphic encryption scheme according to claim 1, characterized in that, According to the preset scheme, initialize the parameter evaluator parameters, comprising: For the key With a uniform ternary key, initialize the key With a value of the standard deviation of the corresponding distribution, initialize the random number With a value of the distribution parameter, initialize the Gaussian noise With a value of the standard deviation, initialize the ciphertext 0th layer modulus With a value of the bit length, initialize the scaling factor With a value of the bit length, initialize the scaling factor With a value of the bit length, initialize the scaling factor With a value of the bit length, initialize the scaling factor With a value of the bit length, initialize the scaling factor With a value of the bit length, initialize the scaling factor With a value of the bit length, initialize the scaling factor For the key Use a sparse ternary key to initialize the key. Parameters of the corresponding distribution The value of and calculate the key. Standard deviation of corresponding distribution The value of the initial random number. Distribution parameters The value of the initial Gaussian noise. Standard deviation The value of the initialization ciphertext level 0 modulus. bit length The value of the initial scaling factor. bit length The value of . 3.The parameter evaluation method of an error analysis-based CKKS-type fully homomorphic encryption scheme according to claim 2, characterized in that, According to the preset requirements, determine part of the parameters of the parameter evaluator, comprising: The user sets the security parameters according to preset requirements , multiplication depth , preset decryption precision , initial message upper bound , message batch processing number , homomorphic addition number , and ciphertext rotation number . 4.The parameter evaluation method of an error analysis-based CKKS-type fully homomorphic encryption scheme according to claim 3, characterized in that, According to the determined part of the parameter, the polynomial order that satisfies the preset scheme security is calculated, comprising: The ciphertext 0th layer modulus is calculated according to the initialized ciphertext 0th layer modulus, the bit length of the value of the initialized modulus, the value of the initialized modulus, the bit length of the value of the initialized scaling factor, and the value of the initialized scaling factor. The ciphertext 0th layer modulus is calculated according to the initialized ciphertext 0th layer modulus, the bit length of the value of the initialized modulus, the value of the initialized modulus, the bit length of the value of the initialized scaling factor, and the value of the initialized scaling factor. < ; According to the ciphertext 0th layer modulus , a scaling factor , and a multiplication depth , the ciphertext 1st layer modulus is calculated , , and the parameter is set According to the ciphertext Layer modulus , parameter , security parameter , initialized key The standard deviation of the corresponding distribution The value of the initialized Gaussian noise The standard deviation The value of the initialized Gaussian noise ; wherein, The expression of the polynomial order satisfying the preset scheme security for a bounded distance decoding attack under an original attack with a wrong learning attack mode is: The expression is: ; The expression of the polynomial order satisfying the preset scheme security for the unified shortest vector problem attack under the original attack with the wrong learning attack mode is: The expression is: ; wherein represents the base of the natural logarithm, represents the non-dominant term. 5.The parameter evaluation method of an error analysis-based CKKS-type fully homomorphic encryption scheme according to claim 4, characterized in that, According to the determined part of the parameter, the error distribution standard deviation of the ciphertext is calculated, comprising: For a uniform ternary key, based on the polynomial order Initialized random numbers Distribution parameters The value and the initial Gaussian noise Standard deviation The value is used to calculate the standard deviation of the error distribution of the ciphertext decryption structure. Its expression is: ; The standard deviation of the rounding error distribution of the ciphertext decryption structure is calculated The expression is: ; The standard deviation of the rounding error distribution according to the ciphertext decryption structure The standard deviation of the error distribution of the homomorphic multiplication structure The expression is: ; wherein, denotes that the message upper bound after times of multiplication, denotes the th root of unity of the polynomial denotes taking the real part of a complex number, and denote the standard deviation of the ciphertext corresponding error distribution participating in homomorphic multiplication or addition, respectively, denotes the modulus of the layer ciphertext; The standard deviation of the rounding error distribution of the ciphertext decryption structure is calculated The standard deviation of the error distribution of the re-scaling structure is calculated The expression is: ; The standard deviation of the error distribution of the homomorphic addition structure is calculated whose expression is: ; The standard deviation of the rounding error distribution according to the ciphertext decryption structure The standard deviation of the error distribution of the homomorphic rotation structure is calculated The expression is: ; wherein, represents the modulus of the layer ciphertext. layer ciphertext. 6.The parameter evaluation method of an error analysis-based CKKS-type fully homomorphic encryption scheme according to claim 5, characterized in that, According to the determined part of the parameter, the error distribution standard deviation of the ciphertext is calculated, comprising: For a sparse ternary key, based on the polynomial order Initialized random numbers Distribution parameters Values, initialized Gaussian noise Standard deviation The value and the initialization key Parameters of the corresponding distribution The value is used to calculate the standard deviation of the error distribution of the ciphertext decryption structure. Its expression is: ; The standard deviation of the rounding error distribution of the ciphertext decryption structure is calculated The expression is: ; The standard deviation of the rounding error distribution according to the ciphertext decryption structure The standard deviation of the error distribution of the homomorphic multiplication structure The expression is: ; in, Indicated that it has been carried out Multiplication by a factor of two, The upper bound of the message after the second addition Representing a polynomial The One unit root Power of 1 means taking the real part of the imaginary number, and Let represent the standard deviations of the error distributions corresponding to the ciphertexts involved in the homomorphic multiplication or addition, respectively. Indicates the first The modulus of the ciphertext; The standard deviation of the rounding error distribution of the ciphertext decryption structure is calculated The standard deviation of the error distribution of the re-scaling structure is calculated The expression is: ; The standard deviation of the error distribution of the homomorphic addition structure is calculated whose expression is: ; The standard deviation of the rounding error distribution according to the ciphertext decryption structure The standard deviation of the error distribution of the homomorphic rotation structure is calculated The expression is: ; wherein, represents the modulus of the layer ciphertext. the modulus of the layer ciphertext.
Citation Information
Patent Citations
Improved fully homomorphic encryption method
CN110855421A
Fully homomorphic encryption deep learning reasoning method and system based on FPGA
CN112699384A