Fully homomorphic encryption modular operation method and system based on GPU
By implementing the fully homomorphic encryption modular operation method based on the Barrett and Schup methods on the GPU, the problem of inefficient integer analog computation in the fully homomorphic encryption scheme is solved, and a significant improvement in execution efficiency is achieved.
Patent Information
- Application Number
- CN202510586016.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-05-08
AI Technical Summary
In the existing fully homomorphic encryption scheme, the integer analog operation efficiency is low, resulting in insufficient execution efficiency of the entire scheme.
The fully homomorphic encryption modular operation method based on GPU is adopted, and the modular subtraction and modular multiplication operations are optimized through the Barrett method and the Schupp method, and the modular addition operation is implemented on the GPU to accelerate integer analog operations.
The execution efficiency of the fully homomorphic encryption scheme is significantly improved, and the operation speed is improved by reducing the number of multiplication statements, pre-calculating fixed operands and using simple addition, multiplication and shift operations.
Smart Images

Figure CN120110643A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer and information security algorithms, and relates to a fully homomorphic encryption modular operation method and system based on a GPU. Background Art
[0002] Homomorphic encryption is a cryptographic technique that allows encrypted data to be directly operated on without decrypting the data. The result of homomorphic encryption is also encrypted data, which can only be decrypted by the key holder. Among them, the second-generation homomorphic encryption schemes such as BFV (Brakerski-Fan-Vercauteren) and BGV (Brakerski-Gentry-Vaikuntanathan) are a core type of scheme in the fully homomorphic encryption scheme, which is a type of integer-based homomorphic encryption scheme. The fully homomorphic encryption scheme allows encrypted integers to be added and multiplied in a modular sense, which means that a large number of modular reduction, modular multiplication, and modular addition operations will be generated during the execution of the fully homomorphic encryption scheme. Since the operands in the fully homomorphic encryption scheme are often integers, and the modular operation of integers in actual applications is often complicated and inefficient, accelerating the modular operation of integers can effectively improve the execution efficiency of the entire fully homomorphic encryption scheme.
[0003] CPU and GPU are two different types of processors. The main difference is that CPU is good at processing complex logic control and optimizing the serial execution of programs, while GPU is good at processing simple logical data parallel tasks and optimizing the parallel execution of programs. The modular reduction and modular multiplication operations in the fully homomorphic encryption scheme are simple in logic, single in calculation form, and have a large amount of data, which is very suitable for effective acceleration using GPU computing.
[0004] Barrett's method is a fast modular reduction algorithm, which can quickly complete modular reduction operations using only normal addition, multiplication and shift operations; Shoup's method is a fast modular multiplication algorithm, which can quickly complete modular multiplication operations using only normal addition, multiplication and shift operations when one of the operands remains unchanged. However, in actual applications, the scale of calculations often exceeds the size of the integer data type preset by the programming language, and it is necessary to implement high-precision multiplication including operations such as carry by itself, so that the Barrett method still contains a large number of multiplication and addition operations including carry, and there is still room for improvement in the acceleration effect of modular reduction operations. In addition, these two methods use conditional branching steps to ensure that the calculation results are controlled within the given modulus size range, and executing conditional branch statements on the GPU will cause certain performance losses. Therefore, simply implementing these two algorithms on the GPU cannot achieve a good acceleration effect. Summary of the invention
[0005] Purpose of the invention: The purpose of the present invention is to address the problem of low implementation efficiency of traditional fully homomorphic encryption schemes, and to propose a GPU-based fully homomorphic encryption modular operation method and system, which uses a GPU to accelerate the modular reduction, modular multiplication, and modular addition operations in the fully homomorphic encryption scheme while ensuring the correctness of the calculation results, thereby improving the execution efficiency of the fully homomorphic encryption scheme and enhancing the practicability of the fully homomorphic encryption scheme.
[0006] Technical solution: To achieve the above-mentioned invention object, the present invention adopts the following technical solution: In a first aspect, the present invention provides a fully homomorphic encryption modular operation method based on a GPU, comprising the following steps: Based on GPU implementation, given input parameters a1, q1 and constant mu1 related to q1, calculate the modular reduction result a1 mod q1 of the 2X-bit integers of a1 and q1; where a1 and mu1 are constructed 2X-bit integer data types, q1 is a constructed X-bit integer data type, mu1 is pre-calculated in the initialization step of the fully homomorphic encryption scheme according to the fixed value of q1, and q1 is restricted to ensure that no carry occurs in the multiplication statement in the Barrett method; X is the number of operands; Based on GPU, given the input parameters a2, b2, q2, and the constant mu2 related to b2 and q2, calculate the modular multiplication result of a2 and b2 as X-bit integers ; where a2, b2, q2 and mu2 are all X-bit integer data types, mu2 is pre-calculated in the initialization step of the fully homomorphic encryption scheme through the fixed values of b2 and q2; b2 is a pre-set fixed operand.
[0007] Further, the modular reduction result a1 mod q1 of the 2X-bit integers of a1 and q1 is calculated, including: Calculation results and store it in 64-bit unsigned integer registers; for a1, split it into 64-bit unsigned integers and perform calculations on 64-bit integer data types respectively; Indicates rounding up; calculate ; Calculate res1=res1-2q1; calculate ; Calculate res1=res1-q1; calculate ; Let a1=res1, return a1 as the calculation result of the algorithm, where the calculation result res1 is stored in 64-bit unsigned integer registers.
[0008] Furthermore, by The values of the registers are passed to the corresponding registers storing the low-order data of a1 in sequence, and the value of the register storing the high-order data of a1 is set to 0 to pass the value of res1 to a1 as the final calculation result of the algorithm.
[0009] Further, calculate the modular multiplication result of the X-bit integers of a2 and b2 ,include: Calculation results and store it in 64-bit unsigned integer registers; calculate ; Calculating temporary values and store it in 64-bit unsigned integer registers; Calculate res2 = tmp-res2; Calculate res2 = res2 - q2; calculate ; Returns res2 as the result of the algorithm.
[0010] Furthermore, the method also includes: based on the GPU, given input parameters a3 and b3, or a3, b3 and c3, calculating the modular addition result of the 2X-bit integer a3=a3+b3 or c3=a3+b3; wherein a3, b3 and c3 are all constructed 2X-bit integer data types.
[0011] Further, calculating the modular addition result a3=a3+b3 of the 2X-bit integer includes: calculating a3=a3+b3; returning a3 as the calculation result of the algorithm; calculating the modular addition result c3=a3+b3 of the 2X-bit integer includes: calculating c3=a3+b3; returning c3 as the calculation result of the algorithm.
[0012] Further, according to the Barrett method, the constant mu1= , Indicates rounding down, and the constant mu2 is calculated according to the Shoup method. ; When the fully homomorphic encryption scheme is initialized, all possible values of the constants mu1 and mu2 are precomputed in the CPU and the calculation results are stored in the global memory of the GPU.
[0013] In a second aspect, the present invention provides a fully homomorphic encryption modular operation system based on a GPU, comprising: A fast modular reduction module is used to implement the modular reduction result a1 mod q1 of the 2X-bit integers of a1 and q1 based on GPU given input parameters a1, q1 and a constant mu1 related to q1; Fast modular multiplication module, used to implement the modular multiplication of X-bit integers of a2 and b2 based on GPU given input parameters a2, b2, q2, and constant mu2 related to b2 and q2 ; Furthermore, the system also includes a modular addition module for implementing a modular addition result a3=a3+b3 or c3=a3+b3 of a 2X-bit integer based on a GPU given input parameters a3 and b3, or a3, b3 and c3.
[0014] In a third aspect, the present invention provides a computer program product, comprising a computer program, which, when executed by a processor, implements the steps of a GPU-based fully homomorphic encryption modular operation method.
[0015] Beneficial effect: The present invention utilizes the hardware characteristics of the GPU, uses a fast modular reduction algorithm further optimized based on the Barrett method to accelerate a class of 2X-bit modular reduction operations with the same modulus in the fully homomorphic encryption scheme, uses the fast modular multiplication algorithm in the Shoup method to accelerate a class of X-bit modular multiplication operations with the same operand and the same modulus in the fully homomorphic encryption scheme, and accelerates the 2X-bit modular addition operation in the fully homomorphic encryption scheme, achieving a performance breakthrough for integer modular reduction, modular multiplication and modular addition operations in a homomorphic encryption environment, and enhancing the usability of the fully homomorphic encryption scheme. Compared with the prior art, on the one hand, the fully homomorphic encryption modular operation method implemented by the present invention based on GPU can effectively accelerate the execution efficiency of the fully homomorphic encryption scheme compared with the method based on CPU implementation; on the other hand, the fully homomorphic encryption modular reduction operation method implemented by the present invention reduces the number of multiplication statements at the assembly statement level, and the fully homomorphic encryption modular multiplication operation method pre-calculates one of the fixed operands. These two modular operation methods also use relatively simple addition, multiplication and shift operations to replace the division in the modular operation, thereby quickly realizing modular reduction and modular multiplication, thereby reducing the occupation of hardware resources and improving the operation speed, further accelerating the execution efficiency of the fully homomorphic encryption scheme. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 The flowchart of the 2X-bit fast modular reduction method based on GPU in an embodiment of the present invention.
[0017] Figure 2 The flowchart of the X-bit fast modular multiplication method based on GPU in an embodiment of the present invention is shown in FIG.
[0018] Figure 3 1 is a flow chart of a 2X bit modular addition method based on GPU in an embodiment of the present invention; wherein (a) is a modular addition operation with two input parameters, and (b) is a modular addition operation with three input parameters.
[0019] Figure 4 Schematic diagram of the process of a fully homomorphic encryption modular operation method based on GPU in an embodiment of the present invention. DETAILED DESCRIPTION
[0020] The technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0021] The present embodiment provides a fully homomorphic encryption modular operation method based on GPU, which involves a 2X-bit fast modular reduction operation based on GPU, an X-bit fast modular multiplication operation based on GPU with a fixed operand, and a 2X-bit modular addition operation based on GPU, where X is the number of operands. The main improvements are the fast modular reduction operation and the fast modular multiplication operation. Specifically, the fast modular reduction operation is: based on GPU implementation, given input parameters a1, q1 and a constant mu1 related to q1, calculate the modular reduction result a1 mod q1 of the 2X-bit integers of a1 and q1; wherein a1 and mu1 are constructed 2X-bit integer data types, q1 is a constructed X-bit integer data type, mu1 is pre-calculated in the initialization step of the fully homomorphic encryption scheme according to the fixed value of q1 using the Barrett method, and by restricting q1, it is ensured that no carry occurs in the multiplication statement in the Barrett method. Fast modular multiplication is: based on GPU implementation, given input parameters a2, b2, q2, and constant mu2 related to b2 and q2, calculate the modular multiplication result of a2 and b2 as X-bit integers ; a2, b2, q2 and mu2 are all X-bit integer data types, mu2 is pre-calculated in the initialization step of the fully homomorphic encryption scheme using the Shoup method through the fixed values of b2 and q2; b2 is a pre-set fixed operand. The modular addition operation is: based on the GPU, given the input parameters a3 and b3, or, a3, b3 and c3, calculate the modular addition result of the 2X-bit integer a3=a3+b3 or c3=a3+b3; a3, b3 and c3 are all constructed 2X-bit integer data types.
[0022] Specifically, if Figure 1 As shown, given input parameters a1, q1 and constant mu1, the calculation of the modular reduction result a1 mod q1 of the 2X-bit integer includes the following steps: Step S101: input a1, q1 and mu1, wherein a1 is a 2X-bit integer data type constructed by the system, q1 is an X-bit integer data type constructed by the system, and mu1 is a 2X-bit integer data type constructed by the system.
[0023] Step S102: Calculation results and store it in 64-bit unsigned integer registers. For 2X-bit integer data types present in the input parameters, split them into 64-bit unsigned integers and perform calculations on 64-bit integer data types.
[0024] Step S103: For a1, q1, res1, calculate .
[0025] Step S104: For q1 and res1, calculate res1=res1-2q1.
[0026] Step S105: For q1 and res1, calculate .
[0027] Step S106: For q1 and res1, calculate res1=res1-q1.
[0028] Step S107: For q1 and res1, calculate .
[0029] Step S108: Let a1=res1, return a1 as the calculation result of the algorithm, where the calculation result res1 is stored in 64-bit unsigned integer registers by placing this The values of the registers are passed to the corresponding registers storing the low-order data of a1 in sequence, and the value of the register storing the high-order data of a1 is set to 0 to pass the value of res1 to a1 as the final calculation result of the algorithm.
[0030] like Figure 2 As shown, given the input parameters a2, b2, q2 and the constant mu2, calculate the modular multiplication result of the X-bit integer , including the following steps: Step S201: input a2, b2, q2 and mu2, where a2, b2, q2 and mu2 are all X-bit integer data types constructed by the system, and mu2 is pre-calculated in the initialization step of the fully homomorphic encryption scheme through the fixed values of parameters b2 and q2. Therefore, the value range of the input parameter b2 is pre-set and cannot be selected arbitrarily.
[0031] Step S202: Calculation results and store it in 64-bit unsigned integer registers.
[0032] Step S203: Calculation .
[0033] Step S204: Calculate temporary value and store it in 64-bit unsigned integer registers.
[0034] Step S205: Calculate res2=tmp-res2.
[0035] Step S206: for q2 and res2, calculate res2=res2-q2.
[0036] Step S207: For q2 and res2, calculate ; Step S208: Return res2 as the calculation result of the algorithm.
[0037] like Figure 3 As shown, given input parameters a3, b3, or input parameters a3, b3, c3, calculating the modular addition result of 2X-bit integers a3=a3+b3 or c3=a3+b3, includes the following steps: Solution for calculating a3=a3+b3: Step S301: Input a3 and b3, where a3 and b3 are both 2X-bit integer data types constructed by the system.
[0038] Step S302: Calculate a3=a3+b3.
[0039] Step S303: Return a3 as the calculation result of the algorithm.
[0040] Solution for calculating c3=a3+b3: Step S401: input a3, b3 and c3, wherein a3, b3 and c3 are all 2X-bit integer data types constructed by the system.
[0041] Step S402: Calculate c3=a3+b3.
[0042] Step S403: Return c3 as the calculation result of the algorithm.
[0043] Based on the above-mentioned GPU-based 2X-bit fast modular reduction operation, GPU-based X-bit fast modular multiplication operation with a fixed operand, and GPU-based 2X-bit modular addition operation, when implementing the fully homomorphic encryption scheme, first determine the parameters for the fast modular operation operation, pre-calculate them in the CPU when the fully homomorphic encryption scheme is initialized, and store the results in the GPU global memory; then call the aforementioned GPU-based fast modular reduction, fast modular multiplication or modular addition operation method according to system needs; finally, return the calculation result of the corresponding modular operation method to the system.
[0044] The following embodiment takes the value of X as 64 as an example, and takes the PTX assembly statement as an example to introduce the specific implementation process of the modulo operation method.
[0045] This embodiment provides a fully homomorphic encryption modular operation method based on GPU, which uses the hardware characteristics of GPU and the fast modular reduction algorithm further optimized based on Barrett's method to accelerate a class of 128-bit modular reduction operations with the same modulus in the fully homomorphic encryption scheme for input parameters a1, q1, mu1 (mu1 is a constant related to q1); uses the hardware characteristics of GPU and the fast modular multiplication algorithm in Shoup's method to accelerate a class of 64-bit modular multiplication operations with the same operand and the same modulus in the fully homomorphic encryption scheme for input parameters a2, b2, q2, mu2 (b2 is a constant, mu2 is a constant related to b2 and q2); uses the hardware characteristics of GPU to accelerate the 128-bit modular addition operation in the fully homomorphic encryption scheme for input parameters a3, b3 or a3, b3, c3. Through the above three methods, a performance breakthrough of integer modular reduction, modular multiplication and modular addition operations in a homomorphic encryption environment is achieved, and the availability of the fully homomorphic encryption scheme is enhanced.
[0046] First, the fast modular reduction method is introduced.
[0047] In the Barrett method, since multiplication statements may cause carry, the multiplication-addition statement needs to consider the carry caused by low-order multiplication. This embodiment restricts the modulus q1 so that the value of q1 satisfies q1 2 hi +2q1 2 lo <2 64 ,q1 2 hi Indicates q1 2 The high 64 bits of q1 2 lo Indicates q1 2 The lower 64 bits of the multiplication function are used to ensure that a carry does not occur, thereby omitting the multiplication statements related to the carry in the Barrett method, thereby improving the execution efficiency of the algorithm.
[0048] Fast modular reduction method Mod_Reduce(a1,q1,mu1): input parameters are a1,q1,mu1∈ , 0≤a1 <q1 2 ,mu1= ,in Indicates integers. a1 and mu1 are 128-bit integer data types, and q1 is a 64-bit integer data type. , . The subscript 1 represents the upper 64 bits, and the subscript 0 represents the lower 64 bits. The output result is a1. The specific steps of the algorithm are as follows: Step S501: Set a 64-bit unsigned integer register to store 64-bit integer data res1, calculate , use the high 64-bit integer data of the calculation result as the value of res1. The implementation of this step is as follows: ul.hi.u 64 res1, a1 0 ,mu1 1 .
[0049] Step S502: Calculation , use the high 64-bit integer data of the calculation result as the value of res1. The implementation of this step is as follows: mad.hi.u 64 res1,a1 1 ,mu1 0 ,res1.
[0050] Step S503: Calculation , use the lower 64-bit integer data of the calculation result as the value of res1. The implementation of this step is as follows: mad.lo.u 64 res1,a1 1 ,mu1 1 ,res1.
[0051] Step S504: Calculation , use the lower 64-bit integer data of the calculation result as the value of res1. The implementation of this step is as follows: mul.lo.u 64 res1,res1,q1.
[0052] Step S505: Calculate res1=a1 0 -res1, the implementation of this step is as follows: sub.u 64 res1,a1 0 ,res1.
[0053] Step S506: Calculate res1=res1-2q1.
[0054] Step S507: Calculation .
[0055] Step S508: Calculate res1=res1-q1.
[0056] Step S509: Calculation .
[0057] Step S510: Set the lower 64 bits of the integer data of a1 to the value of res1, and set the upper 64 bits of the integer data to 0.
[0058] Step S511: Output calculation result a1.
[0059] Next, we introduce the fast modular multiplication method.
[0060] Fast modular multiplication method Mod_Mul(a2,b2,q2,mu2): Input parameters are a2,b2,q2,mu2∈ ,0≤a2,b2 <q2,mu2= , where a2, b2, q2, and mu2 are all 64-bit integer data types, and all values of b2 have been determined during precalculation. The output result is a 64-bit integer data res2. The specific steps of the algorithm are as follows: Step S601: Set a 64-bit unsigned integer register to store res2, calculate , use the high 64-bit integer data of the calculation result as the value of res2. The implementation of this step is as follows: mul.hi.u 64 res2,a2,mu2.
[0061] Step S602: Calculation , use the lower 64-bit integer data of the calculation result as the value of res2. The implementation of this step is as follows: mul.lo.u 64 res2,res2,q2.
[0062] Step S603: Calculation And store it in a 64-bit unsigned integer register, use the lower 64-bit integer data of the calculation result as the value of tmp, the implementation method of this step is as follows: mul.lo.u 64 tmp,a2,b2.
[0063] Step S604: Calculate res2=tmp-res2. The implementation of this step is as follows: sub.u 64 res2,tmp,res2.
[0064] Step S605: Calculate res2=res2-q2.
[0065] Step S606: Calculation .
[0066] Step S607: output the calculation result res2.
[0067] Finally, the modular addition method is introduced.
[0068] Mod_Add(a3,b3): Input parameters are a3,b3∈ , where a3 and b3 are both 128-bit integer data types. , The output result is a3. The specific steps are as follows: Step S701: Calculate a3 0 =a3 0 +b3 0And set the condition code to mark the carry information. The implementation method of this step is as follows: add.cc.u 64a3 0 ,a3 0 ,b3 0 .
[0069] Step S702: Calculate a3 using the carry information in S701 1 =a3 1 +b3 1 , the implementation of this step is as follows: addc.u 64a3 1 ,a3 1 ,b3 1 .
[0070] Step S703: Output calculation result a3.
[0071] Mod_Add(a3,b3,c3): Input parameters are a3,b3,c3∈ , where a3, b3, and c3 are all 128-bit integer data types. , , The output result is c3. The specific steps are as follows: Step S801: Calculate c3 0 =a3 0 +b3 0 And set the condition code to mark the carry information. The implementation method of this step is as follows: add.cc.u 64 c3 0 ,a3 0 ,b3 0 .
[0072] Step S802: Calculate c3 using the carry information in S801 1 =a3 1 +b3 1 , the implementation of this step is as follows: addc.u 64 c3 1 ,a3 1 ,b3 1 .
[0073] Step S803: Output calculation result c3.
[0074] The above four algorithms are combined into a GPU-based fully homomorphic encryption modular operation method proposed in this embodiment.
[0075] Based on the same inventive concept, this embodiment provides a fully homomorphic encryption modular operation system based on GPU, which mainly includes: a fast modular reduction module, which is used to implement the modular reduction result a1 mod q1 of the 2X-bit integers of a1 and q1 based on the GPU given input parameters a1, q1 and the constant mu1 related to q1; a fast modular multiplication module, which is used to implement the modular multiplication result of the X-bit integers of a2 and b2 based on the GPU given input parameters a2, b2, q2 and the constant mu2 related to b2 and q2 The invention also includes a modular addition module, which is used to implement the given input parameters a3 and b3, or a3, b3 and c3 based on the GPU, and calculate the modular addition result a3=a3+b3 or c3=a3+b3 of the 2X-bit integer.
[0076] Combined with the above method, the specific implementation plan of the fully homomorphic encryption modular operation system based on GPU is described, such as Figure 4 As shown, the process is as follows: First, initialize the parameters mu1 and mu2. In the fully homomorphic encryption scheme, the optional values of the candidate moduli of q1 and q2 have been determined when the scheme is initialized. Therefore, according to the formula mu1= And the formula mu2= in Shoup's method , all possible values of mu1,mu2 can be precomputed in the CPU when the fully homomorphic encryption scheme is initialized and the calculation results can be stored in the global memory of the GPU.
[0077] During the execution process, the GPU-based fully homomorphic encryption scheme receives input data from the GPU global memory and calls the kernel function to accelerate the calculation. In the kernel function, calls to the modular reduction method Mod_Reduce, the modular multiplication method Mod_Mul, and the modular addition method Mod_Add are generated. For the Mod_Reduce algorithm, the system first prepares the parameters a1, q1, and mu1, and then uses them as input parameters to call the fast modular reduction method Mod_Reduce for modular reduction operations, and finally returns the parameter a1 as the calculation result; for the Mod_Mul algorithm, the system first prepares the parameters a2, b2, q2, and mu2, and then uses them as input parameters to call the fast modular multiplication method Mod_Mul for modular multiplication operations, and finally returns the parameter res2 as the calculation result; for the Mod_Add algorithm, the system first prepares the parameters a3, b3 or a3, b3, c3, and then uses them as input parameters to call the modular addition method Mod_Mul for modular addition operations, and finally returns the parameters a3 or c3 as the calculation result according to the different input parameters.
[0078] This embodiment also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the aforementioned GPU-based fully homomorphic encryption modular operation method.
[0079] In summary, the GPU-based fully homomorphic encryption modular operation method and system proposed in the present invention improves the computational efficiency of the underlying operators of modular operation in the fully homomorphic encryption system by optimizing modular reduction, modular multiplication and modular addition operations, thereby accelerating the calculation process of the kernel function performing modular operation in the GPU-based fully homomorphic encryption system, which plays an important role in improving the execution efficiency of the fully homomorphic encryption scheme.
[0080] In addition to being applicable to the CUDA (Compute Unified Device Architecture) platform architecture, the present invention can also be applied to other multi-core computing structures with parallel computing characteristics.
[0081] The above is only an embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention shall be included in the protection scope of the present invention. For example, in the above specific embodiment, the value of X is 64. In other cases where X takes other values, if the addition, multiplication, shift and storage statements in the algorithm need to be modified in a simple manner due to the limitation of the register size without further optimization, then these modifications shall be regarded as equivalent transformations or substitutions made based on the technical solution of the present invention, and shall also fall within the scope of protection of the claims of the present invention.
Claims
1. A fully homomorphic encryption modular operation method based on GPU, characterized in that: The following steps are involved: Based on GPU implementation, given input parameters a1, q1 and constant mu1 related to q1, calculate the modular reduction result a1 mod q1 of the 2X-bit integers of a1 and q1; where a1 and mu1 are constructed 2X-bit integer data types, q1 is a constructed X-bit integer data type, mu1 is pre-calculated in the initialization step of the fully homomorphic encryption scheme using the Barrett method according to the fixed value of q1, and by restricting q1, it is ensured that no carry occurs in the multiplication statement in the Barrett method; X is the number of operands; Based on GPU, given the input parameters a2, b2, q2, and the constant mu2 related to b2 and q2, calculate the modular multiplication result of a2 and b2 as X-bit integers ; a2, b2, q2 and mu2 are all X-bit integer data types, mu2 is pre-calculated in the initialization step of the fully homomorphic encryption scheme using the Shoup method through the fixed values of b2 and q2; b2 is a pre-set fixed operand.
2. According to a GPU-based fully homomorphic encryption modular operation method according to claim 1, it is characterized in that: Calculate the modular reduction result a1 mod q1 of the 2X-bit integers a1 and q1, including: Calculation results and store it in 64-bit unsigned integer registers; for a1, split it into 64-bit unsigned integers and perform calculations on 64-bit integer data types respectively; Indicates rounding up; calculate ; Calculate res1=res1-2q1; calculate ; Calculate res1=res1-q1; calculate ; Let a1=res1, return a1 as the calculation result of the algorithm, where the calculation result res1 is stored in 64-bit unsigned integer registers.
3. According to a GPU-based fully homomorphic encryption modular operation method according to claim 2, it is characterized in that: By The values of the registers are passed to the corresponding registers storing the low-order data of a1 in sequence, and the value of the register storing the high-order data of a1 is set to 0 to pass the value of res1 to a1 as the final calculation result of the algorithm.
4. According to a GPU-based fully homomorphic encryption modular operation method according to claim 1, it is characterized in that: Calculates the modular multiplication of a2 and b2 as X-bit integers ,include: Calculation results and store it in 64-bit unsigned integer registers, Indicates rounding up; calculate ; Calculating temporary values and store it in 64-bit unsigned integer registers; Calculate res2 = tmp-res2; Calculate res2 = res2 - q2; calculate ; Returns res2 as the result of the algorithm.
5. According to a GPU-based fully homomorphic encryption modular operation method according to claim 1, it is characterized in that: Also includes: Based on GPU implementation, given input parameters a3 and b3, or a3, b3 and c3, calculate the modular addition result of 2X-bit integers a3=a3+b3 or c3=a3+b3; Where a3, b3 and c3 are all constructed 2X-bit integer data types.
6. According to claim 5, a fully homomorphic encryption modular operation method based on GPU is characterized in that: Calculating the modular addition result a3=a3+b3 of the 2X-bit integers, including: calculating a3=a3+b3; returning a3 as the calculation result of the algorithm; calculating the modular addition result c3=a3+b3 of the 2X-bit integers, including: calculating c3=a3+b3; returning c3 as the calculation result of the algorithm.
7. The GPU-based fully homomorphic encryption modular operation method according to claim 1, characterized in that: According to Barrett's method, the constant mu1= , Indicates rounding down, and the constant mu2 is calculated according to the Shoup method. ; When the fully homomorphic encryption scheme is initialized, all possible values of the constants mu1 and mu2 are pre-calculated in the CPU and the calculation results are stored in the global memory of the GPU.
8. A fully homomorphic encryption modular operation system based on GPU, characterized in that: include: A fast modular reduction module is used to implement the modular reduction result a1 mod q1 of the 2X-bit integers of a1 and q1 based on GPU given input parameters a1, q1 and a constant mu1 related to q1; where a1 and mu1 are constructed 2X-bit integer data types, q1 is a constructed X-bit integer data type, mu1 is pre-calculated in the initialization step of the fully homomorphic encryption scheme according to the fixed value of q1, and q1 is restricted to ensure that no carry occurs in the multiplication statement in the Barrett method; X is the number of operands; Fast modular multiplication module, used to implement the modular multiplication of X-bit integers of a2 and b2 based on GPU given input parameters a2, b2, q2, and constant mu2 related to b2 and q2 ; where a2, b2, q2 and mu2 are all X-bit integer data types, mu2 is pre-calculated in the initialization step of the fully homomorphic encryption scheme through the fixed values of b2 and q2; b2 is a pre-set fixed operand.
9. The GPU-based fully homomorphic encryption modular operation system according to claim 8, characterized in that: It also includes a modular addition module, which is used to implement the given input parameters a3 and b3, or a3, b3 and c3 based on the GPU, and calculate the modular addition result a3=a3+b3 or c3=a3+b3 of the 2X-bit integer; Where a3, b3 and c3 are all constructed 2X-bit integer data types.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of a GPU-based fully homomorphic encryption modular operation method according to any one of claims 1-7 are implemented.
Citation Information
Patent Citations
Self-adaptive large integer modular multiplication operation method and device based on homomorphic encryption
CN115374458A
GPU acceleration method for fully homomorphic multiplication
CN118466898A
Method and apparatus for performing efficient side-channel attack resistant reduction
US20100332578A1