Method for carrying out rotation accumulation on homomorphic ciphertext and computing equipment
By mod-raising the second ciphertext instead of the mod-down of the first ciphertext, the calculation efficiency problems caused by mode increase and mode drop in the rotation accumulation operation in the CKKS scheme are solved, and a more efficient rotation accumulation operation is achieved.
Patent Information
- Application Number
- CN202510359457.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-20
AI Technical Summary
In the CKKS scheme, the mode increase and mode drop need to be frequently performed in the rotational accumulation operation, resulting in low calculation efficiency.
By replacing the modular reduction of the first ciphertext in the prior art, the calculation amount of the rotation accumulation operation is reduced, and the calculation speed is accelerated without adding additional memory access overhead.
The calculation amount of rotation accumulation operation is significantly reduced and the calculation speed is increased. The specific experimental results show that when 8 rounds of rotation accumulation operation are performed, the speed is increased by 38%.
Smart Images

Figure CN120185791A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification belong to the technical field of data processing, and particularly relate to a method and a computing device for performing rotation accumulation on homomorphic ciphertexts. Background Art
[0002] The fully homomorphic encryption (FHE) scheme allows performing computational operations such as addition and multiplication on ciphertexts without decrypting the data. Thus, using the FHE scheme, tasks such as model training and private information retrieval can be completed while keeping the data confidential.
[0003] The CKKS scheme is a class of FHE algorithms for approximate real number calculations. After encoding the plaintext vector into a plaintext polynomial, the plaintext polynomial is encrypted with a key to obtain a ciphertext, and then the required computational operations are performed on the ciphertext.
[0004] In the CKKS scheme, the rotation accumulation operation is a relatively basic computational operation. For example, in the sub-step of bootstrapping - homomorphic decoding (CoeffToSlot), multiple rounds of rotation accumulation operations are required. Generally, one round of rotation accumulation operation includes rotating the current ciphertext and adding the rotated current ciphertext to the ciphertext to be added to obtain an updated current ciphertext. To ensure the accuracy of the calculation, during the rotation of the current ciphertext, the current ciphertext needs to be Modup to increase the number of moduli of the current ciphertext. However, when performing ciphertext addition, it is required that the number of moduli of each ciphertext is the same. Therefore, when adding the current ciphertext to the ciphertext to be added, it is also necessary to perform Moddown on the current ciphertext after Modup. The operation process of Moddown is relatively complex, which greatly affects the computational efficiency of the rotation accumulation operation. Summary of the Invention
[0005] The objective of the present invention is to provide a method and a computing device for performing rotation accumulation on homomorphic ciphertexts, including:
[0006] The first aspect of this specification provides a method for performing rotation accumulation on homomorphic ciphertexts. The method is executed for each ciphertext to be encrypted. Each ciphertext to be encrypted includes a zero component and a one component. The number of moduli of each zero component and each one component is p. The zero component is determined according to the public key, the noise polynomial, and the plaintext polynomial. The one component is determined according to the public key and the noise polynomial. The method includes:
[0007] In each ciphertext to be encrypted, determine a first ciphertext and a second ciphertext;
[0008] Rotate the first ciphertext to obtain a rotated first ciphertext, where the number of moduli of the zero components of the rotated first ciphertext is p + q;
[0009] Perform modular increment on the zero components of the second ciphertext to obtain an updated second ciphertext, where the number of moduli of the zero components of the updated second ciphertext is p + q;
[0010] Obtain an intermediate accumulation result based on the updated second ciphertext and the rotated first ciphertext.
[0011] A second aspect of this specification provides a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method described in the first aspect is implemented.
[0012] An embodiment of this specification provides a method and a computing device for rotating and accumulating homomorphic ciphertexts. By replacing the modular reduction of the first ciphertext in the prior art with modular elevation of the second ciphertext, the computational complexity of the rotation and accumulation operation is reduced, and the computational speed of the rotation and accumulation operation is accelerated without increasing additional memory access overhead. Description of the Drawings
[0013] To more clearly illustrate the technical solutions of the embodiments of this specification, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0014] Figure 1 is a schematic diagram of a method for rotating and accumulating homomorphic ciphertexts in the prior art;
[0015] Figure 2 is a flowchart of a method for rotating and accumulating homomorphic ciphertexts in an embodiment of this specification;
[0016] Figure 3 is a comparison schematic diagram of a method for rotating and accumulating homomorphic ciphertexts in an embodiment of this specification and the prior art;
[0017] Figure 4 is a flowchart of a method for continuing to rotate and accumulate homomorphic ciphertexts on the intermediate accumulation result in an embodiment of this specification. Detailed Embodiments
[0018] To enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the scope of protection of this specification.
[0019] The following will first explain the professional terms involved in this specification.
[0020] Ring Learning With Errors (RLWE): For the plaintext vector m, the plaintext vector m is encoded into a plaintext polynomial p represented in the polynomial space in. m , according to the private key sk randomly sampled from R k and the noise vector, the corresponding public key a = (a0, a1) can be generated. Using the public key a to encrypt the plaintext polynomial p m results in the ciphertext ct. The ciphertext is also in the polynomial space R k . Using the ciphertext ct, homomorphic encryption operations can be performed. After the homomorphic encryption operations are completed, use the private key held by the user to decrypt the result ct' of the homomorphic operation and decode the decrypted result to obtain the plaintext calculation result. Among them, for the polynomial space R k , x N + 1 indicates that the degree of the polynomial in this polynomial space is not greater than N. The polynomials in this polynomial space are usually represented in the form of vectors, and the elements in the vector are the results of taking the modulus of the coefficients of each term in the polynomial with respect to the modulus k.
[0021] Ciphertext: The ciphertext is usually represented as For example, in the Cheon-Kim-Kim-Song (CKKS) encryption scheme, c1 = u * a1 + e1, c0 = u * a0 + e0 + p m , where represents a polynomial space where the highest degree of the polynomial is N and the coefficients follow a Gaussian distribution with a standard deviation of σ. u, e0, and e1 are all noise vectors randomly drawn from this polynomial space, and p m is the plaintext. Generally, c1 is called the first component of the ciphertext ct, and c0 is called the zero component of the ciphertext ct.
[0022] Modulus: In actual homomorphic encryption schemes, several different moduli are usually used
[0023] k1, k2, ……, kp ∈ K are used to represent the ciphertext ct. That is, the ciphertext ct can be represented by p vectors. The i-th vector consists of the results of taking the modulus of the coefficients of each term in the polynomial with respect to the modulus ki. k1, k2, ……, kp are the p moduli of the ciphertext ct. Among them, the larger p is, the larger the coefficients in the polynomial of the ciphertext ct that can be represented. Correspondingly, when performing homomorphic encryption calculations on the ciphertext ct, more noise can be tolerated.
[0024] Modulus increase (modup): Increase the modulus of the ciphertext, that is, use more moduli to represent the ciphertext. Generally, when performing more complex homomorphic encryption calculations, the ciphertext needs to have a higher modulus to prevent noise overflow and affect the accuracy of the results. Specifically, the process of modulus increase can be referred to the following formula:
[0025]
[0026] where ki represents the initial moduli of the ciphertext x, ki [x] is the vector representation of the ciphertext x under the modulus ki, bj is a newly added modulus,
[0027] and is the vector representation of the ciphertext x under the newly added modulus bj. It should also be noted that when using the CKKS encryption scheme, generally, to achieve more efficient ciphertext multiplication, the ciphertext polynomial is usually in point-value representation. Before performing modulus increase on the ciphertext, it is necessary to perform an inverse Number Theoretic Transform (iNTT) on the ciphertext in point-value representation to convert the ciphertext in point-value representation to coefficient representation, perform the operations of the above formula in coefficient representation, and after completing the operations of the above formula, perform a Number Theoretic Transform (NTT) on the ciphertext in coefficient representation to convert the ciphertext back to point-value representation.
[0028] Modulus decrease (moddown): Decrease the modulus of the ciphertext, that is, use fewer moduli to represent the ciphertext. Generally, when performing ciphertext addition, to ensure the accuracy of homomorphic operations, it is required that the moduli of the added ciphertexts are the same. Therefore, if any ciphertext has been previously modulus increased, it is necessary to perform modulus decrease on the modulus-increased ciphertext before ciphertext addition. Specifically, the process of modulus decrease can be referred to the following formula:
[0029]
[0030] where, ki represents the ciphertext each modulus to be retained after modulus decrease, is the ciphertext to be modulus decreased, and bj represents the ciphertext Each modulus to be discarded after modulus reduction, where q is the number of moduli to be discarded. is the ciphertext before modulus reduction The vector representation of under the modulus ki, B·B -1 ≡1 (mod ki), where x is the ciphertext after modulus reduction. is the vector representation of the ciphertext x after modulus reduction under the modulus ki.
[0031] Similar to modulus lifting, before and after modulus reduction of the ciphertext, the above-mentioned inverse fast number-theoretic transform and fast number-theoretic transform need to be performed, and the timing of the operation can also refer to the process of modulus lifting.
[0032] Ciphertext rotation: Taking the plaintext vector corresponding to the ciphertext (m1, m2, m3, m4, m5) as an example, rotating the ciphertext can correspondingly change the arrangement order of the plaintext vector. For example, the plaintext vector corresponding to the rotated ciphertext can be transformed into (m5, m1, m2, m3, m4). Of course, due to the existence of the encoding step and the encryption step in the process of transforming the plaintext into the ciphertext, to achieve the effect of changing the positions of the elements in the plaintext vector in the encrypted state, relatively complex homomorphic encryption operations are required. Specifically, ciphertext rotation can include an automorphism step and a key conversion step. The automorphism can be performed on the ciphertext to change the arrangement order of the plaintext corresponding to the ciphertext. However, referring to the introduction of the ciphertext structure in the previous text, the public key corresponding to the ciphertext after automorphism also changes, and an additional step - key conversion - is required to convert the ciphertext after automorphism into the original key to ensure that the ciphertext after automorphism can be correctly decrypted.
[0033] In the current FHE schemes, RLWE has been widely used. FHE schemes such as the CKKS encryption scheme and the Brakerski-Fan-Vercauteren (BFV) encryption scheme are all implemented based on RLWE. In various homomorphic encryption schemes based on RLWE, when calculating the ciphertext polynomial, the rotation accumulation operation can accumulate ciphertexts corresponding to different plaintext arrangement orders together, which is a basic operation with a relatively high frequency of use. For example, when performing homomorphic decoding, a sub-step of the ciphertext bootstrap, a homomorphic encryption discrete Fourier transform needs to be performed on the ciphertext, and this process is achieved through multiple rounds of rotation accumulation operations.
[0034] The following briefly introduces the implementation method of the rotation accumulation operation in the existing scheme.
[0035] Figure 1 is a schematic diagram of the method for rotating and accumulating homomorphic ciphertexts in the prior art.
[0036] As Figure 1As shown in the figure, ctA in the figure represents the ciphertext A to be phase-encrypted, [0] represents the zero component, and ctA[0] represents the zero component of the ciphertext A to be phase-encrypted. The representation meanings of ctB and [1] can be deduced by analogy, and will not be elaborated here. It should also be noted that the number of initial moduli of each ciphertext to be phase-encrypted is p, and the initial moduli of each ciphertext to be phase-encrypted are the same. As shown in the figure, in the prior art, when performing the rotation accumulation operation on each ciphertext to be phase-encrypted, first rotate the ciphertext A to be phase-encrypted to obtain the zero component and the first component of the rotated ciphertext A to be phase-encrypted, both of which have the number of moduli p. Subsequently, directly add the ciphertext B to the rotated ciphertext A to complete one round of rotation accumulation operation and obtain the intermediate calculation result. Among them, the rotation operation is a relatively complex homomorphic encryption calculation. During the rotation operation, it is necessary to perform modulus elevation on the ciphertext A to be phase-encrypted. However, for the subsequent accumulation calculation, it is also necessary to perform modulus reduction on the ciphertext A after modulus elevation.
[0037] If it is necessary to perform the next round of rotation accumulation operation, use the intermediate calculation result as the ciphertext A to be phase-encrypted again, and re-determine the ciphertext B to be phase-encrypted, and continue to execute as Figure 1 shown in the figure; if there is no ciphertext to be phase-encrypted that has not been calculated, the intermediate calculation result can be used as the final rotation accumulation result.
[0038] Specifically, in the prior art, rotating the ciphertext A to be phase-encrypted is achieved through automorphism and key conversion. Among them, the automorphism step is performed on both the zero component and the first component of the ciphertext A to be phase-encrypted. The key conversion step is to perform modulus elevation on the first component after automorphism (it should be noted that performing modulus elevation on the ciphertext A in the key conversion step only equivalently achieves the effect of raising the modulus of the first component of the ciphertext A to p + q. Its actual operation process is different from the introduction of modulus elevation in professional terms and will not be elaborated here). Take the inner product of the modulus-elevated first component and the pre-prepared key conversion key. The calculation result of the inner product is two sub-components corresponding to the zero component and the first component of the ciphertext A to be phase-encrypted respectively (here, the sub-component corresponding to the zero component is denoted as sub-component x, and the sub-component corresponding to the first component is sub-component y). Since modulus elevation is performed on the first component before the inner product, the number of moduli of each sub-component is also p + q. To ensure that the number of moduli of each ciphertext is the same when adding ciphertexts, it is necessary to perform modulus reduction on the two sub-components respectively, and then add the modulus-reduced sub-component x to the zero component after automorphism. Thus, the key conversion of the ciphertext A to be phase-encrypted is completed.
[0039] From Figure 1 it can be seen that the modulus elevation operation and the modulus reduction operation performed in the process of each rotation accumulation operation in the prior art specifically include one modulus elevation on the first component of the ciphertext A to be phase-encrypted, and modulus reduction on the conversion component x and the conversion component y respectively, for a total of one modulus elevation and two modulus reductions.
[0040] Figure 2 This is a schematic flowchart of a method for rotating and accumulating homomorphic ciphertexts in an embodiment of this specification. This method can be executed by a computing device for performing rotation and accumulation operations. This method is executed for each ciphertext to be encrypted. Each ciphertext to be encrypted can be stored in the memory of the computing device or other communicable storage devices. Each ciphertext to be encrypted includes a zero component and a one component. The number of moduli of each zero component and each one component is p. The zero component is determined according to the public key, the noise polynomial, and the plaintext polynomial. The one component is determined according to the public key and the noise polynomial, and includes:
[0041] Step S201: In each ciphertext to be encrypted, determine a first ciphertext and a second ciphertext.
[0042] Among them, for the specific form of each ciphertext to be encrypted, reference can be made to the introduction of ciphertext in the aforementioned professional terms; each ciphertext to be encrypted is encrypted using the same encryption algorithm; further, each ciphertext to be encrypted has the same modulus.
[0043] Specifically, the computing device can determine the first ciphertext from the ciphertexts to be encrypted stored in its own memory, or the computing device can receive the first ciphertext transmitted from other storage devices. This specification does not limit this here.
[0044] Similarly, the computing device can determine the second ciphertext from the ciphertexts to be encrypted stored in its own memory, or the computing device can receive the second ciphertext transmitted from other storage devices. This specification does not limit this here.
[0045] It should be noted that the second ciphertext needs to have the same arrangement order as the plaintext corresponding to the rotated first ciphertext.
[0046] In some implementation manners, when performing the sub-step of ciphertext bootstrapping - homomorphic decoding, a raw ciphertext can be rotated to obtain respective rotation results with the same corresponding raw plaintext but different arrangement orders of the elements in the plaintext. The raw ciphertext and the rotation results are used as the ciphertexts to be encrypted.
[0047] Step S203: Rotate the first ciphertext to obtain a rotated first ciphertext. The number of moduli of the zero component of the rotated first ciphertext is p + q.
[0048] After determining the first ciphertext, the computing device rotates the first ciphertext.
[0049] As can be seen from the introduction of ciphertext rotation in the foregoing technical terms, rotating the ciphertext will cause a change in the arrangement order of the plaintext corresponding to the rotated ciphertext. Generally, when performing ciphertext addition, the calculator hopes that the ciphertext addition is equivalent to adding the original plaintexts corresponding to the respective ciphertexts. Therefore, to ensure that the ciphertexts to be encrypted can be added normally in subsequent steps, the plaintext corresponding to the first ciphertext needs to be rotated to the same arrangement order as the plaintext corresponding to the second ciphertext.
[0050] Specifically, the process of rotating the first ciphertext can refer to Figure 1 the method shown in Figure 1 Different from the method shown in
[0051] in the process of rotating the first ciphertext in step S203, there is no need to perform modulus reduction on the rotated first ciphertext, so the number of moduli of the zero component of the rotated first ciphertext is p + q.
[0052] Step S205: Perform modulus increment on the zero component of the second ciphertext to obtain an updated second ciphertext, and the number of moduli of the zero component of the updated second ciphertext is p + q.
[0053] Different from the method shown in Figure 1 after determining the second ciphertext in step S205, the computing device performs modulus increment on the zero component of the second ciphertext to increase the number of moduli of the zero component of the second ciphertext to p + q. The process of performing modulus increment on the second ciphertext can refer to the introduction of modulus increment in the foregoing technical terms.
[0054] In some implementation manners, to correspond to the modulus reduction step (the input ciphertext of the modulus reduction step is and the output ciphertext is x,
[0055] ) and improve the computing efficiency, when performing modulus increment on the zero component of the second ciphertext, the modulus increment step can be improved as:
[0056]
[0057] where x is the ciphertext before modulus increase, [x] ki is the vector representation of the ciphertext x under the modulus ki, is the ciphertext after modulus increase, ki represents the initial moduli of the ciphertext x, in this embodiment, the ciphertext x before modulus increase has p moduli k1, k2,..., kp ∈ K, and bj represents the newly added moduli of the ciphertext after modulus increase, in this embodiment, the ciphertext adds q newly added moduli b1, b2,..., bq ∈ B in total,
[0058] It should be noted that, different from the method shown in formula (1), after modulus lifting using the methods shown in formula (4) and formula (5), (after modulus lifting using the method shown in formula (1), ) Since Therefore, for each newly added modulus bj, it can be obtained without calculation On the other hand, referring to the introduction of modulus reduction in the aforementioned professional terms, for perform modulus reduction, and x can be directly obtained without additional calculation after modulus reduction.
[0059] It can be seen that when modulus lifting the zero component of the second ciphertext using formula (4) and formula (5), only one multiplication needs to be performed for each of the initial p moduli of the zero component of the second ciphertext; while when modulus lifting the zero component of the second ciphertext using formula (1), 2p multiplications and p additions need to be performed for each of the newly added q moduli. Thus, it is easy to know that using the modulus lifting method such as formula (4) and formula (5) can further reduce the computational complexity of the modulus lifting step.
[0060] It should be noted that the q moduli added to the zero component of the second ciphertext need to be the same as the q moduli added to the zero component of the rotated first ciphertext.
[0061] Thus, the zero component in the updated second ciphertext has the same p + q moduli as the zero component of the rotated first ciphertext, and the one component of the second ciphertext has the same p moduli as the one component of the rotated first ciphertext.
[0062] Step S207: Obtain an intermediate accumulation result according to the updated second ciphertext and the rotated first ciphertext.
[0063] On the one hand, through modulus increment of the second ciphertext, the updated second ciphertext and the rotated first ciphertext have the same modulus; on the other hand, by rotating the first ciphertext, the rotated first ciphertext and the plaintext corresponding to the second ciphertext have the same arrangement order, and the computing device can directly add the updated second ciphertext and the rotated first ciphertext to achieve the calculation effect of homomorphic addition, and thus the intermediate accumulation result can be obtained.
[0064] After obtaining the intermediate accumulation result, use the method such as Figure 2 shown to process the intermediate accumulation result as the first ciphertext, and continuously re - determine the second ciphertext in the uncalculated ciphertexts to be encrypted pairwise, then the rotation accumulation of each pair of ciphertexts to be encrypted can be completed.
[0065] According to the introduction of modulus increase and modulus decrease in the foregoing technical terms, when performing modulus increase operation from p moduli to p + q moduli and modulus decrease operation from p + q moduli to p moduli, on the one hand, the calculation amount of formula (1) in the modulus increase operation is similar to that of formula (2) in the modulus decrease operation, and the modulus decrease operation also requires an additional operation of formula (3); on the other hand, after the modulus increase operation, when performing NTT operation on the ciphertext in the coefficient state, the elements in the point value representation corresponding to the original p moduli can be retained, and only the elements corresponding to the newly added q moduli in the point value representation need to be re-determined. However, after the modulus decrease operation, when performing NTT operation on the ciphertext in the coefficient state, the elements corresponding to the p moduli in the point value representation need to be re-determined. Considering both aspects, the calculation amount of one modulus decrease operation is several times that of the modulus increase operation.
[0066] As Figure 2 shown, a method for rotating and accumulating homomorphic ciphertexts replaces the modulus decrease of the first ciphertext in the prior art with modulus increase of the second ciphertext, reducing the calculation amount of the rotation and accumulation operation and accelerating the calculation speed of the rotation and accumulation operation without increasing additional memory access overhead.
[0067] In some implementation manners, in step S203 as Figure 2 shown, an automorphism is performed on the first ciphertext to obtain a first isomorphic ciphertext, a key conversion is performed on one component of the first isomorphic ciphertext to obtain a first conversion component and a second conversion component, and based on the first conversion component, the second conversion component, and the zero component of the first isomorphic ciphertext, the zero component and one component of the rotated first ciphertext are obtained.
[0068] Before performing the key conversion, the key required to decrypt the ciphertext is called the private key s. Since in relatively complex homomorphic operations such as ciphertext rotation and homomorphic multiplication on the ciphertext, a change in the ciphertext structure will cause the ciphertext after the operation to be unable to be correctly decrypted using the private key s. To ensure that the ciphertext can be correctly decrypted, it is necessary to perform a key conversion on the ciphertext during the foregoing operations (operations such as ciphertext rotation and homomorphic multiplication). After the key conversion, the plaintext corresponding to the ciphertext remains unchanged, while the key required to decrypt the ciphertext becomes the private key s'.
[0069] Specifically, in some implementation manners, a key switching key (KSK) can be pre-configured (different types of homomorphic operations correspond to different key switching keys), and the key conversion is implemented by processing the first isomorphic ciphertext using the key switching key:
[0070] ct s =(ct s [0], ct s [1]), KSK s-s′ =(a, b), (6)
[0071] ct ′ [1]=modup(ct s [1]), (7)
[0072] (U, V)=<ct ′ [1], KSK>, (U = a·ct ′ [1], V = b·ct ′ [1])(8)
[0073] ct s′ [0]=modup(ct s [0])+U, ct s′ [1]=moddown(V). (9)
[0074] Wherein, s is the private key corresponding to the first isomorphic ciphertext before automorphism, and KSK s-s′ is the key conversion key corresponding to the automorphism operation, and KSK s-s′ includes two components of the same length and both lengths are adapted to the extended component-(a, b).
[0075] Figure 3 This is a comparison schematic diagram of the method for implementing the rotation accumulation operation in an embodiment of this specification and the prior art. Figure 3 The left side is the method corresponding to the prior art, which will not be elaborated here. Figure 3 The upper right part is the specific steps of the first round of rotation accumulation operation in the method corresponding to an embodiment of this specification. Figure 3 The lower right part is the specific steps of each round of rotation accumulation operation after the first round in the method corresponding to an embodiment of this specification.
[0076] Refer to the method shown in Figure 3 the upper right part. After automorphizing the first ciphertext ct1, the first isomorphic ciphertext ct s is obtained. Subsequently, the key conversion steps shown in the above formulas (6)-(9) can be performed.
[0077] Specifically, the key conversion steps include: performing modulo up on a component ct s [1] of the first isomorphic ciphertext to obtain the extended component ct ′ [1], taking the inner product of the extended component and the key conversion key KSK s-s′ to obtain the first conversion component U and the second conversion component V, adding the modulo-up of the zero component ct s [0] of the first isomorphic ciphertext to the first conversion component U to obtain the zero component ct s′ [0] of the rotated first ciphertext, and performing modulo down on the second conversion component V to obtain the one component ct of the rotated first ciphertexts′ [1]. Thus, the key conversion of the first isomorphic ciphertext can be completed, and at the same time, the rotation of the first ciphertext can be completed.
[0078] It should be noted that after the rotation of the first ciphertext is completed, further adding the second ciphertext after modulus increase to the rotated first ciphertext can complete one round of rotation accumulation operation.
[0079] In some implementation manners, in step S203 as shown in Figure 2 , a component of the first isomorphic ciphertext is segmented to obtain a number of sub-components. The total number of moduli of each sub-component is p. Each sub-component is modulus-increased and combined to obtain an extended component with the number of moduli of p + q. Multiply the extended component by a pre-determined key conversion key.
[0080] It should be noted that in the key conversion process, in the step as shown in formula (7), the method as shown in formula (1) is not directly used to modulus-increase a component of the first isomorphic ciphertext, but only equivalently achieves the effect of modulus-increasing a component of the first isomorphic ciphertext to p + q moduli.
[0081] Specifically, the key conversion process includes: segmenting a component of the first isomorphic ciphertext represented by p moduli to obtain n sub-components. Each sub-component contains the representation of the component of the first isomorphic ciphertext under p / n moduli. Each sub-component is respectively modulus-increased so that each modulus-increased sub-component altogether contains the representation of the component of the first isomorphic ciphertext under p + q moduli. Combining each modulus-increased sub-component can obtain an extended component with the number of moduli of p + q. Subsequently, determine the inner product of the extended component and a pre-determined key conversion key.
[0082] In some implementation manners, in step S203 as shown in Figure 2 , the zero component of the first isomorphic ciphertext is modulus-increased to obtain an updated zero component of the first isomorphic ciphertext with the number of moduli of p + q. Add the updated zero component to the first conversion component to obtain the zero component of the rotated first ciphertext.
[0083] Referring to Figure 1 , in the prior art, to achieve the rotation of the ciphertext A to be encrypted, the conversion component x (corresponding to the first conversion component in an embodiment of this specification) is modulus-reduced. Subsequently, the conversion component x with the number of moduli of p and the zero component after the automorphism of the ciphertext A to be encrypted (corresponding to the zero component of the first isomorphic ciphertext in an embodiment of this specification) are added to obtain the zero component of the rotated ciphertext A to be encrypted with the number of moduli of p.
[0084] However, in an embodiment of the present specification, the first conversion component is not modulo-reduced, but instead, modulo-increment is selected for the zero component of the first isomorphic ciphertext (the specific steps of modulo-increment can refer to the aforementioned formula (1), formula (4), and formula (5)), so as to unify the number of moduli of the first conversion component and the zero component of the first isomorphic ciphertext. As described above, under the condition corresponding to the number of moduli, the computational amount of modulo-increment is much smaller than that of modulo-reduction, and this step reduces a large amount of computational overhead.
[0085] In some implementation manners, in step S203 as shown in Figure 2 a one-component with a modulus of p of the rotated first ciphertext is obtained by modulo-reducing the second conversion component.
[0086] For the specific implementation manner, reference can be made to the introduction of Figure 1 which is not elaborated herein in this specification.
[0087] In some implementation manners, in step S207 as shown in Figure 2 the zero component of the updated second ciphertext is added to the zero component of the rotated first ciphertext to obtain the zero component of the intermediate accumulation result, and the one-component of the updated second ciphertext is added to the one-component of the rotated first ciphertext to obtain the one-component of the intermediate accumulation result.
[0088] As a result, the zero component of this intermediate accumulation result has p + q moduli, and the one-component of this intermediate accumulation result has p moduli. According to the characteristics of the ciphertext rotation operation (the specific steps can refer to the introduction of rotating the ciphertext to be encrypted in Figure 1 ), the zero component does not need to have the same modulus as the one-component, which does not affect the subsequent steps of continuing the rotation accumulation operation based on this intermediate accumulation result.
[0089] In some implementation manners, after step S207, it further includes continuing the rotation accumulation operation on the intermediate accumulation result.
[0090] Figure 4 FIG. is a schematic flowchart of continuing the rotation accumulation operation on the intermediate accumulation result in this specification, including:
[0091] Step S401: Automorph the intermediate accumulation result to obtain an intermediate isomorphic ciphertext.
[0092] Specifically, reference can be made to step S203.
[0093] It should be noted that according to the introduction of the automorphism operation in the foregoing text, the automorphism operation is performed separately on the zero component and the one component of the intermediate accumulation result, and the modulus difference between the zero component and the one component does not affect the progress of the automorphism operation. On the other hand, the overhead required for performing the automorphism operation and the ciphertext addition operation on the zero component with modulus p + q is much smaller (several orders of magnitude difference) than the modulus reduction operation of reducing the number of moduli from p + q to p.
[0094] Step S403: Perform key conversion on the one component of the intermediate isomorphic ciphertext to obtain a first intermediate component and a second intermediate component both with the number of moduli p + q.
[0095] Specifically, reference can be made to step S203. However, since the number of moduli of the zero component of the intermediate accumulated ciphertext is already p + q, there is no need to perform modulus increment on the zero component of the intermediate isomorphic ciphertext in step S403.
[0096] Step S405: Add the first intermediate component and the zero component of the intermediate isomorphic ciphertext to obtain the zero component of the rotated intermediate accumulation result, and perform modulus reduction on the second intermediate component to obtain the one component of the rotated intermediate accumulation result with the number of moduli p.
[0097] Specifically, reference can be made to step S203.
[0098] Step S407: Among the ciphertexts to be encrypted that have not undergone the rotation accumulation operation, determine the third ciphertext, and update the intermediate accumulation result according to the rotated intermediate accumulation result and the third ciphertext.
[0099] Specifically, reference can be made to steps S205 and S207.
[0100] In some implementation manners, after step S207, if there is no ciphertext to be encrypted that has not been calculated, perform modulus reduction on the zero component of the current intermediate accumulation result to obtain the zero component of the rotated accumulation result with the number of moduli p, and use the one component of the current intermediate accumulation result as the one component of the rotated accumulation result.
[0101] It should be noted that since the initial number of moduli of each ciphertext to be encrypted is p, and the number of moduli of the zero component of the intermediate accumulation result is the same as that of the second ciphertext after modulus increment - p + q, to ensure that the rotated accumulation results of each ciphertext to be encrypted can continue to be used for other homomorphic encryption operations, after completing the rotation accumulation operation on each ciphertext to be encrypted, modulus reduction can be performed on the zero component of the current intermediate accumulation result to obtain the final rotated accumulation result.
[0102] Reference Figure 3It can be seen that during the first-round rotation accumulation operation, the modulo increase operation and the modulo decrease operation performed in an embodiment of this specification specifically include one modulo increase on one component of the first ciphertext, one modulo increase on the zero component of the first ciphertext, one modulo increase on the zero component of the second ciphertext, and one modulo decrease on the second conversion component, for a total of three modulo increases and one modulo decrease. During the rotation accumulation operations in each round after the first round, the modulo increase operation and the modulo decrease operation performed in an embodiment of this specification specifically include one modulo increase on one component of the intermediate isomorphic ciphertext, one modulo decrease on the second intermediate component, and one modulo increase on the zero component of the third ciphertext, for a total of two modulo increases and one modulo decrease. Additionally, after completing the rotation accumulation of all ciphertexts to be encrypted pairwise, an embodiment of this specification may further include one modulo decrease on the current intermediate accumulation result.
[0103] When a total of n rounds of rotation accumulation operations are performed, as can be seen from the foregoing, the prior art requires n modulo increases and 2n modulo decreases. In contrast, an embodiment of this specification requires 2n + 1 modulo increases and n + 1 modulo decreases. Since the computational cost of modulo decrease is several times that of modulo increase, when n is greater than 1, the method provided in this specification can significantly improve the computational efficiency of the rotation accumulation operation. According to the experimental results, when n = 8, the speed of the rotation accumulation operation in an embodiment of this specification can be increased by 38% compared to the prior art.
[0104] In some implementation manners, each ciphertext to be encrypted pairwise is a CKKS ciphertext.
[0105] In the 1990s, it was possible to clearly distinguish whether an improvement to a technology was a hardware improvement (e.g., improvement to circuit structures such as diodes, transistors, switches, etc.) or a software improvement (improvement to method flows). However, with the development of technology, many method flow improvements today can be regarded as direct improvements to hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented using a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is an integrated circuit whose logic function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system onto a single PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not just one type of HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow using the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.
[0106] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.
[0107] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a server system. Of course, this application does not exclude that with the development of future computer technologies, the computers for implementing the functions of the above embodiments can be, for example, personal computers, laptop computers, in-vehicle human-machine interaction devices, cellular phones, camera phones, smart phones, personal digital assistants, media players, navigation devices, email devices, game consoles, tablet computers, wearable devices, or any combination of these devices.
[0108] Although one or more embodiments of this specification provide method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way among many orders of step execution and does not represent the only execution order. When the actual device or terminal product is executed, it may be executed in the order of the method shown in the embodiments or the drawings or executed in parallel (for example, in an environment of parallel processors or multi-threaded processing, or even in a distributed data processing environment). The terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, product or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, product or device. Without further limitation, it does not exclude the existence of additional identical or equivalent elements in the process, method, product or device including the said elements. For example, if terms such as first and second are used to denote names, they do not denote any particular order.
[0109] For convenience of description, when describing the above device, it is divided into various modules according to functions and described separately. Of course, when implementing one or more of this specification, the functions of each module may be implemented in the same or multiple software and / or hardware, or the modules implementing the same function may be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other may be through some interfaces, and the indirect coupling or communication connection of the device or unit may be in electrical, mechanical or other forms.
[0110] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate a device for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0111] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction means that implements the functions specified in one or more of the processes and / or blocks Figure 1 in the process or processes and / or blocks Figure 1 specified in the block or blocks.
[0112] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the processes and / or blocks Figure 1 in the process or processes and / or blocks Figure 1 specified in the block or blocks.
[0113] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0114] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.
[0115] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage, graphene storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0116] Those skilled in the art should understand that one or more embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0117] One or more embodiments of this specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of this specification can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0118] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments. In the description of this specification, the description of reference terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0119] The above description is only for the embodiments of one or more embodiments of this specification and is not intended to limit one or more embodiments of this specification. For those skilled in the art, one or more embodiments of this specification can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims.
Claims
1. A method for performing rotational accumulation on homomorphic ciphertexts, wherein the method is performed on each ciphertext to be encrypted, each ciphertext to be encrypted includes a zero component and a one component, the number of moduli of each zero component and each one component is p, the zero component is determined according to a public key, a noise polynomial and a plaintext polynomial, and the one component is determined according to a public key and a noise polynomial, and the method includes: In each of the ciphertexts to be encrypted, determine the first ciphertext and the second ciphertext; Rotate the first ciphertext to obtain a rotated first ciphertext, wherein the number of moduli of zero components of the rotated first ciphertext is p+q; Performing a modulus increase on the zero component of the second ciphertext to obtain an updated second ciphertext, wherein the number of moduli of the zero component of the updated second ciphertext is p+q; An intermediate accumulation result is obtained according to the updated second ciphertext and the rotated first ciphertext.
2. The method according to claim 1, wherein rotating the first ciphertext to obtain the rotated first ciphertext comprises: Performing automorphism on the first ciphertext to obtain a first isomorphic ciphertext; Performing key conversion on a component of the first isomorphic ciphertext to obtain a first converted component and a second converted component; A zero component and a one component of the rotated first ciphertext are obtained according to the first conversion component, the second conversion component and the zero component of the first isomorphic ciphertext.
3. The method according to claim 2, performing key conversion on a component of the first isomorphic ciphertext, specifically comprising: Splitting a component of the first isomorphic ciphertext to obtain a plurality of subcomponents, wherein the total number of moduli of the subcomponents is p; Perform modular multiplication on each subcomponent and combine them to obtain an extended component whose number of extended moduli is p+q; The extended component is multiplied with a predetermined key conversion key.
4. The method according to claim 2, obtaining the zero component of the rotated first ciphertext according to the first transformed component, the second transformed component and the zero component of the first isomorphic ciphertext, specifically comprising: Performing modular increase on the zero components of the first isomorphic ciphertext to obtain updated zero components whose modulus number is p+q; The updated zero component is added to the first converted component to obtain the zero component of the rotated first ciphertext.
5. The method according to claim 2, obtaining a component of the rotated first ciphertext according to the first transformed component, the second transformed component and the zero component of the first isomorphic ciphertext, specifically comprising: Modulus reduction is performed on the second transformed component to obtain a component whose modulus number of the rotated first ciphertext is p.
6. The method according to claim 1, obtaining an intermediate accumulation result according to the updated second ciphertext and the rotated first ciphertext, specifically comprising: The zero component of the updated second ciphertext is added to the zero component of the rotated first ciphertext to obtain the zero component of the intermediate cumulative result, and a component of the updated second ciphertext is added to a component of the rotated first ciphertext to obtain a component of the intermediate cumulative result.
7. The method according to claim 4, after obtaining the intermediate accumulation result, further comprising: Performing automorphism on the intermediate accumulation result to obtain an intermediate isomorphic ciphertext; Performing key conversion on a component of the intermediate isomorphic ciphertext to obtain a first intermediate component and a second intermediate component, both of which have a modulus of p+q; Adding the first intermediate component to the zero component of the intermediate isomorphic ciphertext to obtain the zero component of the rotated intermediate accumulation result, and performing modular reduction on the second intermediate component to obtain a component whose modulus number is p of the rotated intermediate accumulation result; A third ciphertext is determined in each of the encrypted texts that have not been subjected to the rotation and accumulation operation, and the intermediate accumulation result is updated according to the intermediate accumulation result after the rotation and the third ciphertext.
8. The method according to claim 5, after obtaining the intermediate accumulation result, further comprising: If there is no uncalculated encrypted text, the zero component of the current intermediate cumulative result is reduced modulo, the modulus of the obtained rotation cumulative result is the zero component of p, and a component of the current intermediate cumulative result is used as a component of the rotation cumulative result.
9. The method according to claim 1, wherein the encrypted text is a CKKS ciphertext.
10. A computing device comprising a memory and a processor, wherein the memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 1 to 9 is implemented.