Method for carrying out coding form conversion on homomorphic ciphertext and computing equipment

By rotating and multiplying homomorphic ciphertexts on the calculation chip, combining the method of accumulating zero components and transmitting one component, the problem of ciphertext noise accumulation is solved, and efficient ciphertext bootstrap and encoding form conversion is achieved.

CN120223284APending Publication Date: 2025-06-27ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510371382.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In a fully homomorphic encryption scheme based on the assumption of error learning on the ring, more complex homomorphic operations will introduce noise, resulting in the ciphertext being unable to be decrypted correctly, and the ciphertext needs to be frequently booted to refresh the ciphertext.

Method used

By performing a method on the computing chip, the method includes obtaining the original ciphertext and evaluating the key, rotating the ciphertext, and multiplying it with a pre-stored plaintext transformation matrix to obtain a multiplication result sequence. Then, the zero component fragments of the multiplication result sequence are accumulated, one of its components is transmitted to the off-chip memory, and the conversion ciphertext is determined based on the accumulated zero component and one component.

Benefits of technology

While maintaining the low memory capacity requirement of computing chips, the amount of data transmitted between the computing chip and off-chip memory is reduced, and the speed of homomorphic ciphertext encoding conversion is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223284A_ABST
    Figure CN120223284A_ABST
Patent Text Reader

Abstract

The method comprises the following steps: acquiring an original ciphertext and a first evaluation key, rotating the original ciphertext by using the first evaluation key to obtain a plurality of rotating ciphertexts, taking the original ciphertext and the plurality of rotating ciphertexts as to-be-converted ciphertexts, and performing encoding form conversion on the to-be-converted ciphertexts to obtain a to-be-converted ciphertext; multiplying each to-be-converted ciphertext by a pre-stored plaintext conversion matrix to obtain a plurality of multiplication result sequences, and for any multiplication result sequence, accumulating each first sub-result in a first sub-sequence of the multiplication result sequence to obtain an accumulated zero component fragment corresponding to the multiplication result sequence, according to the method and the device, the original ciphertext is multiplied by the intermediate ciphertext, the second sub-sequence of the multiplied result sequence is transmitted to the off-chip memory, and the converted ciphertext corresponding to the original ciphertext is determined according to the accumulated zero component and one component of each intermediate ciphertext, so that the data volume transmitted by the computing chip and the off-chip memory can be reduced on the premise of keeping a relatively low memory capacity requirement of the computing chip, and the computing efficiency is improved. And the coding form conversion speed of the homomorphic ciphertext is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification belong to the field of data processing technology, and in particular, relate to a method and computing device for converting the encoding form of homomorphic ciphertext. Background Art

[0002] In the fully homomorphic encryption scheme based on the Ring Learning With Errors (RLWE) hypothesis, more complex homomorphic operations (such as homomorphic multiplication) will introduce noise into the ciphertext. After performing the above-mentioned more complex homomorphic operations a certain number of times, the accumulation of noise will make the ciphertext unable to be correctly decrypted. Therefore, it is necessary to continuously bootstrap the ciphertext during the homomorphic operation to refresh the ciphertext so that the ciphertext can continue to support more homomorphic operations.

[0003] The bootstrapping of ciphertext includes four steps: modulus lifting, homomorphic decoding, homomorphic evaluation, and homomorphic encoding. Among them, both the homomorphic decoding step and the homomorphic encoding step will convert the ciphertext into a coded form, and in the process of bootstrapping the ciphertext, converting the ciphertext into a coded form is the most critical and most computationally resource-consuming step. It should be noted that the homomorphic encoding step can be implemented by a homomorphic discrete Fourier transform (H-DFT), and the homomorphic decoding step can be implemented by a homomorphic inverse discrete Fourier transform (H-IDFT), and the homomorphic encoding step and the homomorphic decoding step are the same except that the plaintext transformation matrix used when performing H-DFT or H-IDFT is different.

[0004] Taking the homomorphic encoding step as an example, when performing H-DFT on the ciphertext represented by the slot, we first enter the small-step stage to rotate the ciphertext to obtain several rotated ciphertexts with different rotation numbers; then we enter the large-step stage to multiply each rotated ciphertext with the pre-prepared plaintext matrix bit by bit, and finally rotate and accumulate the multiplication results to obtain the ciphertext converted from the slot representation to the coefficient representation.

[0005] When using a computing chip to perform the H-DFT step, since the ciphertext and the evaluation key required for ciphertext rotation both require a large amount of memory, if the rotated ciphertexts and key conversion keys are stored on the chip, a very high on-chip storage space is required (usually 256MB-512MB); and if the rotated ciphertexts and key conversion keys are stored off the chip, the computing speed will be greatly reduced due to the time required for data transmission. Summary of the invention

[0006] The object of the present invention is to provide a method and a computing device for converting the encoding form of homomorphic ciphertexts, including:

[0007] The first aspect of this specification provides a method for converting the encoding form of homomorphic ciphertexts. The method is executed using a computing chip. Each ciphertext includes a zero component and a one component. The zero component is determined according to a public key, a noise polynomial, and a plaintext polynomial. The one component is determined according to the public key and the noise polynomial. The method includes:

[0008] Obtain an original ciphertext and a first evaluation key;

[0009] Rotate the original ciphertext using the first evaluation key to obtain a plurality of rotated ciphertexts;

[0010] Use the original ciphertext and the plurality of rotated ciphertexts as ciphertexts to be converted, and multiply each ciphertext to be converted by a pre-stored plaintext conversion matrix to obtain a plurality of multiplication result sequences. Each multiplication result sequence consists of a first subsequence corresponding to the zero component and a second subsequence corresponding to the one component;

[0011] For any multiplication result sequence, accumulate each first sub-result in the first subsequence of the multiplication result sequence to obtain an accumulated zero component shard corresponding to the multiplication result sequence, and transmit the second subsequence of the multiplication result sequence to an off-chip memory;

[0012] Determine the converted ciphertext corresponding to the original ciphertext according to the accumulated zero component and the one component of each intermediate ciphertext, where the accumulated zero component is obtained by splicing each accumulated zero component shard, and the one component of each intermediate ciphertext is obtained by splicing each second subsequence.

[0013] The second aspect of this specification provides a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method described in the first aspect is implemented.

[0014] The embodiments of this specification provide a method and a computing device for converting the encoding form of homomorphic ciphertexts, which can reduce the data volume transmitted between the computing chip and the off-chip memory in the overall computing process and improve the speed of converting the encoding form of homomorphic ciphertexts on the premise of maintaining a low memory capacity requirement of the computing chip. Description of the Drawings

[0015] To more clearly illustrate the technical solutions of the embodiments of this specification, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0016] Figure 1 It is a schematic diagram of the method of multiplying a ciphertext by a plaintext conversion matrix;

[0017] Figure 2 It is a schematic flowchart of a method for converting the encoding form of a homomorphic ciphertext in an embodiment of this specification;

[0018] Figure 3 It is a schematic flowchart of the process of multiplying a ciphertext to be converted by a plaintext conversion matrix;

[0019] Figure 4 It is a schematic flowchart of the rotation accumulation operation;

[0020] Figure 5 It is a schematic flowchart of the process of multiplying a ciphertext shard by a plaintext conversion matrix in an embodiment of this specification;

[0021] Figure 6 It is a schematic flowchart of the key conversion step in an embodiment of this specification. Detailed implementation manners

[0022] In order to enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification with reference to the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.

[0023] The following will first explain the professional terms involved in this specification.

[0024] Ring Learning With Errors (RLWE): For a plaintext vector m, the plaintext vector m is encoded as a plaintext polynomial p represented in a polynomial space in m , according to the private key sk randomly sampled from R k and a noise vector, a corresponding public key a = (a0, a1) can be generated. Using the public key a to encrypt the plaintext polynomial p m results in a ciphertext ct, which is also in the polynomial space R k . Homomorphic encryption operations can be performed using the ciphertext ct. After the homomorphic encryption operation is completed, the private key held by the user is used to decrypt the result ct' of the homomorphic operation, and the decrypted result is decoded to obtain the plaintext calculation result. Among them, for the polynomial space R k , x N+1 indicates that the degree of the polynomial in this polynomial space is no greater than N. The polynomials in this polynomial space are usually represented in the form of vectors, and each element in the vector is the result of taking the modulus of the coefficients of each term in the polynomial with respect to the modulus k.

[0025] Ciphertext: Ciphertext is usually represented as For example, in the Cheon-Kim-Kim-Song (CKKS) encryption scheme, c1 = u * a1 + e1, c0 = u * a0 + e0 + p m , where represents a polynomial space where the highest degree of the polynomial is N and each coefficient follows a Gaussian distribution with a standard deviation of σ. u, e0, and e1 are all noise vectors randomly selected from this polynomial space, and p m is the plaintext. Usually, c1 is called the first component of the ciphertext ct, and c0 is called the zero component of the ciphertext ct.

[0026] Ciphertext rotation: Taking the plaintext vector corresponding to the ciphertext as (m1, m2, m3, m4, m5) as an example, rotating the ciphertext can correspondingly change the arrangement order of the plaintext vector. For example, the plaintext vector corresponding to the rotated ciphertext can be transformed into (m5, m1, m2, m3, m4). Of course, due to the existence of the encoding step and the encryption step during the conversion of the plaintext to the ciphertext, to achieve the effect of changing the positions of the elements in the plaintext vector in the encrypted state, relatively complex homomorphic encryption operations are required. Specifically, ciphertext rotation can include an automorphism step and a key conversion step. The automorphism can be performed on the ciphertext to change the arrangement order of the plaintext corresponding to the ciphertext. However, referring to the previous introduction to the ciphertext structure, the public key corresponding to the ciphertext after automorphism also changes, and an additional step - key conversion - is required to convert the ciphertext after automorphism into the original key to ensure that the ciphertext after automorphism can be correctly decrypted. Among them, the automorphism step is performed on the zero component and the first component of the ciphertext respectively; the key conversion is obtained by multiplying the first component of the ciphertext after automorphism by the corresponding evaluation key. After multiplication, the first conversion component corresponding to the zero component and the second conversion component corresponding to the first component are obtained. Adding the zero component after automorphism to the first conversion component gives the zero component of the rotated ciphertext, and the first component of the rotated ciphertext is obtained according to the first component after automorphism.

[0027] Bootstrapping: In RLWE-based homomorphic encryption schemes, noise is introduced as interference to ensure the security of ciphertexts during homomorphic operations. When multiple rounds of homomorphic operations are performed, the magnitude of the noise accumulated in the ciphertext will also increase. When it exceeds the preset magnitude, the ciphertext cannot be decrypted. Therefore, it is necessary to "refresh" the ciphertext during the homomorphic operation process to remove the accumulated noise so that the ciphertext can continue to accept more homomorphic operations. This operation of "refreshing" the ciphertext is called bootstrapping. In different homomorphic encryption schemes, the bootstrapping schemes are not exactly the same. For example, in the Cheon-Kim-Kim-Song (CKKS) encryption scheme, the bootstrapping of the ciphertext is achieved by performing modulus elevation on the ciphertext and then performing homomorphic evaluation (also known as homomorphic modulo) on the modulus-elevated ciphertext. Since homomorphic evaluation of the ciphertext requires the ciphertext to be in the slot representation state, it is also necessary to perform homomorphic decryption on the ciphertext before homomorphic evaluation to convert the ciphertext into the slot representation, and perform homomorphic encryption on the ciphertext after homomorphic evaluation to convert the ciphertext back to the coefficient representation that can perform regular homomorphic operations.

[0028] Encoding and Decoding: In the CKKS encryption scheme, the initial representation form of the plaintext is a vector, and each element in the vector can store a piece of data, while the representation form of the ciphertext is a polynomial, and the coefficients of each term in the polynomial store the encrypted information. Before encrypting the ciphertext, it is first necessary to encode the plaintext vector into a plaintext polynomial. This encoding process presets a set of unit roots X (x1, x2,..., xn ∈ X), regards each element in the plaintext vector as the function values of the corresponding X of the plaintext polynomial, and thus solves for the coefficients of each term of the plaintext polynomial. The decoding process is the opposite of the encoding process. Substituting this set of independent variables into the plaintext polynomial, the plaintext vector can be determined according to the function values of the polynomial. The above encoding process can be achieved by multiplying the arranged plaintext vector by an IDFT (Inverse Discrete Fourier Transform) matrix. Correspondingly, the decoding process can be achieved by multiplying the coefficients of the arranged plaintext polynomial by a DFT (Discrete Fourier Transform) matrix. The above IDFT matrix and DFT matrix are collectively referred to as the plaintext conversion matrix in this specification.

[0029] It should be noted that during the homomorphic encoding process, the ciphertext vector is directly encoded without decrypting it, so it is called homomorphic encoding. Correspondingly, during the homomorphic decoding process, the ciphertext polynomial is decoded, so it is called homomorphic decoding.

[0030] Baby-Step Giant-Step (BGSG): Since the multiplication operation supported by the ciphertext based on RLWE only includes vector multiplication (multiplying the vector A of length n and the vector B bit by bit to obtain the vector C of length n), when performing H-DFT or H-IDFT, multiplying the ciphertext by the plaintext transformation matrix requires matrix multiplication (multiplying the matrix A and the matrix B to obtain the matrix C, where the element in the i-th row and j-th column of the matrix C ). Since the operation of accumulating a ik b kj in matrix multiplication is difficult to directly implement in ciphertext operations, in order to implement matrix multiplication in the ciphertext state and reduce the computational complexity, the Baby-Step Giant-Step (BGSG) method is usually used to optimize the calculation process of H-DFT or H-IDFT. First, in the baby-step stage, the ciphertext is rotated. Correspondingly, the DFT sub-matrices corresponding to each rotated ciphertext are extracted from the complete DFT matrix in advance; then in the giant-step stage, each rotated ciphertext is multiplied by the corresponding DFT sub-matrix, and the rotated sum of each multiplication result can be used to obtain the ciphertext after the representation conversion.

[0031] Briefly, the method of multiplying the ciphertext by the plaintext transformation matrix can be referred to Figure 1 . In the figure, A is the plaintext transformation matrix, B is the ciphertext vector, and the expected result of matrix multiplication is C. In the expected result C, it can be observed that the elements in the i-th row of the plaintext transformation matrix A are located in the i-th position of the expected result C after accumulation, and the elements in the j-th column of the plaintext transformation matrix A need to be multiplied by b j in the ciphertext vector B. Thus, the plaintext transformation matrix A can be arranged to obtain N vectors Referring to the elements in the plaintext transformation matrix A, is the main diagonal vector of the plaintext transformation matrix A, is the (i + 1)-th diagonal vector of the plaintext transformation matrix A. Correspondingly, the ciphertext vector B is rotated to obtain N vectors After multiplying and bit by bit and adding the multiplication results bit by bit, the expected result C can be obtained. Thus, matrix multiplication can be realized through the operations supported in the ciphertext state (vector multiplication and bit-by-bit addition between vectors).

[0032] In this process, the ciphertext vector B needs to be rotated N - 1 times (the original ciphertext vector does not need to be rotated and is which can be used for subsequent multiplication with (Multiplication). Since the arrangement of the plaintext transformation matrix A can be completed in advance before operating on the ciphertext vector B, the rotation of the plaintext transformation matrix A does not consume computational effort in subsequent methods such as Figure 2 as shown. On this basis, using the large-step small-step method, the matrix multiplication process of the ciphertext vector B and the plaintext transformation matrix A is split into a small-step stage of rotating the ciphertext vector and a large-step stage of rotating the multiplication result, which can further reduce the number of rotations of the ciphertext vector:

[0033] N1·N2 = N (1)

[0034]

[0035] Among them, a formula in the form of Rot(X, y) represents rotating the vector X to the right by y bits. After expanding the above formula (2), the same expected result C can be obtained, where Thus, using the large-step small-step method, the number of rotations of the ciphertext can be reduced to N1 - 1 + N2 - 1 times ((N1 - 1 + N2 - 1) < N - 1 according to formula (1)). Specifically, it includes N2 - 1 rotations of the ciphertext vector B (each rotation has a bit number of i·r, or it can also be said that the step size of each rotation is i·r), and N1 - 1 rotations of the multiplication result (each rotation has a bit number of j·N2·r). Among them, N2 can be called the number of steps in the small-step stage, and N1 can be called the number of steps in the large-step stage.

[0036] It should be noted that generally, in formula (2), r = 1, that is, the number of bits for rotating the ciphertext each time in the small-step stage is i, and the corresponding plaintext transformation matrix is arranged according to r = 1. However, when the parameter scale of the plaintext transformation matrix is large, the plaintext transformation matrix can be further divided into r parts. Correspondingly, the number of bits for rotating the ciphertext each time is i·r.

[0037] Currently, the calculation of ciphertext under the fully homomorphic encryption algorithm is usually carried out on a computing chip, and this computing chip can be, for example, an Application Specific Integrated Circuit (ASIC). Currently, researchers have proposed two types of methods for converting the encoding form of homomorphic ciphertext. The first type of method is to increase the memory of the computing chip and store the key required for rotating the ciphertext and all intermediate products during the operation process in the memory of the computing chip. Thus, the entire calculation process is completed on-chip. The second type of method is to transmit all intermediate products during the operation process to an off-chip memory, and in subsequent steps, receive all intermediate products transmitted by the off-chip memory in real time according to the calculation requirements.

[0038] Obviously, more memory space also means a larger chip area and a higher chip cost. Usually, the first method requires the memory of the computing chip to reach 256MB - 512MB. On the one hand, this method has extremely high costs. On the other hand, due to the large chip area, it is difficult to be commercially used. While adopting the second method means that data needs to be frequently transferred between on-chip and off-chip during the operation process. In such a scheme, the time required for transmission is much higher than the calculation time, greatly extending the overall calculation time.

[0039] Figure 2 FIG. 4 is a flowchart of a method for converting the encoding form of a homomorphic ciphertext in an embodiment of this specification. This method can be executed by a computing device that performs rotation accumulation operations. This method is executed for the original ciphertext, and the original ciphertext can be pre-stored in the memory of the computing chip or a communicable off-chip memory. Each ciphertext includes a zero component and a one component. The zero component is determined according to the public key, the noise polynomial, and the plaintext polynomial. The one component is determined according to the public key and the noise polynomial. This method includes:

[0040] S201: Obtain the original ciphertext and the first evaluation key.

[0041] It should be noted that the conversion of the encoding form of the homomorphic ciphertext can include homomorphic decoding that converts the homomorphic ciphertext from coefficient representation to slot representation, and homomorphic encoding that converts the homomorphic ciphertext from slot representation to coefficient representation. Among them, during the process of homomorphic encoding or homomorphic decoding, except for the different plaintext conversion matrices used, other steps are the same. Hereinafter, only homomorphic encoding is taken as an example to introduce Figure 2 the method shown.

[0042] Among them, the original ciphertext can be the ciphertext that needs to be converted in encoding form. When applying Figure 1 the method shown to perform homomorphic encoding on the original ciphertext, the original ciphertext can be the ciphertext after homomorphic evaluation during the bootstrapping process; the first evaluation key can be used to rotate the original ciphertext. It should be noted that when the rotation bits for rotating different ciphertexts under the same encryption algorithm are the same, the same evaluation key can be used.

[0043] According to the process required for executing the complete bootstrapping operation on the computing chip, at least part of the original ciphertext and the first evaluation key can be pre-stored in the memory of the computing chip, and the remaining part that is not stored in the memory is received from the off-chip memory by the computing chip when executing step S201; or the complete original ciphertext and the first evaluation key can be received from the off-chip memory by the computing chip when executing step S201. This specification does not limit this here.

[0044] S203: Rotate the original ciphertext using the first evaluation key to obtain a number of rotated ciphertexts.

[0045] Specifically, for the rotation process, reference can be made to the descriptions of rotation and the large-step small-step method in the previous glossary.

[0046] It should be noted that, referring to the description of the large-step small-step method in the previous glossary, before performing the method as Figure 2 shown, the number of ciphertexts to be converted can be determined in advance according to the number of steps N2 = n in the preset small-step stage, and then the number of rotated ciphertexts required in step S203 can be determined - n - 1.

[0047] On the other hand, each of the rotated ciphertexts obtained in step S203 and the original ciphertext can be all transmitted by the computing chip to the off-chip memory, so that no rotated ciphertext or original ciphertext is retained in the memory of the computing chip; or according to the memory size of the computing chip, the computing chip can retain some of the rotated ciphertexts or the original ciphertext, and transmit the rotated ciphertexts and the original ciphertext not retained in the memory of the computing chip to the off-chip memory, and this specification does not make any restrictions here.

[0048] Thus, the computing chip does not need to retain all the ciphertexts to be rotated, which can reduce the requirement for the memory capacity of the computing chip.

[0049] In some implementation manners, after completing step S203, the first evaluation key stored in the memory of the computing chip can also be deleted to make room for the calculation of subsequent steps, further reducing the requirement for the memory size of the computing chip.

[0050] S205: Use the original ciphertext and the number of rotated ciphertexts as the ciphertexts to be converted, multiply each ciphertext to be converted by the pre-stored plaintext conversion matrix to obtain a number of multiplication result sequences, and each multiplication result sequence is composed of a first subsequence corresponding to the zero component and a second subsequence corresponding to the one component.

[0051] After obtaining each ciphertext to be converted, the first sub-stage of the large-step stage can be entered - multiplying each ciphertext to be converted by the plaintext conversion matrix.

[0052] According to the description in step S203, after obtaining each ciphertext to be converted, the computing chip can transmit at least part of the ciphertexts to be converted to the off-chip storage to reduce the requirement for the memory capacity of the computing chip. Correspondingly, in step S205, the computing chip can receive the ciphertexts to be converted transmitted by the off-chip memory and complete the multiplication with the plaintext conversion matrix using the received ciphertexts to be converted and the ciphertexts to be converted stored in the memory of the computing chip.

[0053] It should also be noted that the plaintext conversion matrix can be pre-stored in the memory of the computing chip at any time before step S205 is executed.

[0054] Among them, referring to formula (2) in the previous term introduction, the original ciphertext is represented as B, and each ciphertext to be converted can be Rot(B, i·r), (0 ≤ i < n); the plaintext conversion matrix is represented as A, and the arrangement method of the plaintext conversion matrix can be referred to It is determined according to the preset number of steps N2 = n in the small-step stage and the number of steps N1 = m in the large-step stage; multiplying the ciphertext to be converted by the pre-stored plaintext conversion matrix can be referred to formula (2) in the previous term introduction to determine the multiplication object of each ciphertext to be converted.

[0055] In some implementation manners, the plaintext conversion matrix can be arranged into n sequences of plaintext conversion sub-matrices corresponding to the number of ciphertexts to be converted. Each sequence of plaintext conversion sub-matrices corresponds to a different ciphertext to be converted, and each sequence of plaintext conversion sub-matrices includes m plaintext conversion sub-matrices.

[0056] Continuing to refer to formula (2), for the ciphertext to be converted Rot(B, i·r), the sequence of plaintext conversion sub-matrices corresponding to this ciphertext to be converted can be The multiplication result sequence can be obtained according to After multiplying each ciphertext to be converted by the corresponding sequence of plaintext conversion sub-matrices respectively, and accumulating them.

[0057] Specifically, Figure 3 shows the process of multiplying the ciphertext to be converted by the plaintext conversion matrix in the prior art under the conditions of n = 3 and m = 4. Among them, n = 3 also represents a total of 3 ciphertexts to be converted, and m = 4 also represents a total of 4 plaintext conversion sub-matrices in the sequence of plaintext conversion sub-matrices. In the figure, cti, (1 ≤ i ≤ 3) represents each ciphertext to be converted, ptji, (1 ≤ i ≤ 3, 1 ≤ j ≤ 4) represents each plaintext conversion sub-matrix, (pt1i,..., pt4i) represents the sequence of plaintext conversion sub-matrices corresponding to the ciphertext to be converted cti. Multiplying the ciphertext to be converted cti by the corresponding sequence of plaintext conversion sub-matrices can obtain the ciphertext (ct′1i,..., ct′4i). Adding the ciphertexts 9ct ′ 1i,..., ct ′ 4i), (1 ≤ i ≤ 3) bitwise can obtain the multiplication result sequence (ct′1,..., ct′4) composed of each intermediate ciphertext ct ′ j, (ct′j = ∑ 1≤i≤3 ct′ji, (1 ≤ j ≤ 4)).

[0058] It can be noted that in such as Figure 3In the process shown, the complete ciphertext to be converted is multiplied by the plaintext conversion matrix, and at the same time, only one multiplication result sequence is obtained. Since when performing step S205 using the method shown in Figure 3 , it is necessary to store n complete ciphertexts to be converted in the memory of the computing chip, and this calculation method still has relatively high requirements for the memory capacity of the computing chip. The method provided in this specification is further improved based on Figure 3 .

[0059] In some implementation manners, the same fragmentation method can be used to fragment each ciphertext to be converted, so that each ciphertext to be converted is fragmented into a number of ciphertext fragments with the same quantity, and the shapes of the ciphertext fragments corresponding to each ciphertext to be converted are the same. Specifically, when the ciphertext matrix X to be converted is expressed as , the ciphertext matrix to be converted is fragmented into two ciphertext fragments, and the fragmentation result can be, for example, the ciphertext fragment and the ciphertext fragment Using the same fragmentation method for the ciphertext matrix to be converted , the fragmentation result is the ciphertext fragment and the ciphertext fragment

[0060] Furthermore, when multiplying the ciphertext to be converted by the plaintext conversion matrix, the multiplication of the complete ciphertext to be converted by the plaintext conversion matrix is realized through multiple rounds of multiplication of the ciphertext fragments by the plaintext conversion matrix. Thus, the multiplications of the ciphertext fragments by the plaintext conversion matrix in each round succeed each other without affecting or overlapping each other. During the multiplication process of each round, only the ciphertext fragments required for the multiplication of this round need to be stored in the memory of the computing chip, instead of storing the complete ciphertexts to be converted, which can greatly reduce the requirements for the memory capacity of the computing chip. For example, if each ciphertext to be converted is fragmented into 4 ciphertext fragments, then 4 rounds of multiplication of the ciphertext fragments by the plaintext conversion matrix are required. During the multiplication process of one round, the memory consumed for storing each ciphertext fragment is only 1 / 4 of that for storing all the complete ciphertexts to be converted.

[0061] Correspondingly, each multiplication result sequence obtained in step S205 is the multiplication result sequence corresponding to each round of calculation. Thus, if a ciphertext to be converted is fragmented into p ciphertext fragments, then each ciphertext to be converted corresponds to p rounds and a total of p multiplication result sequences.

[0062] It should also be noted that each ciphertext includes a zero component and a one component. Correspondingly, each ciphertext to be converted also includes a zero component and a one component. Multiplying any ciphertext to be converted by the plaintext conversion matrix can determine the plaintext conversion sub-matrix sequence corresponding to the ciphertext to be converted, and multiplying the zero component and the one component of the ciphertext to be converted by the plaintext conversion sub-matrix sequence corresponding to the ciphertext to be converted respectively. Correspondingly, each multiplication result sequence is composed of a first subsequence corresponding to the zero component and a second subsequence corresponding to the one component.

[0063] S207: For any multiplication result sequence, accumulate each first sub-result in the first subsequence of the multiplication result sequence to obtain the accumulated zero component slice corresponding to the multiplication result sequence, and transmit the second subsequence of the multiplication result sequence to the off-chip memory.

[0064] After obtaining each multiplication result sequence, the second sub-stage of the large-step stage can be carried out.

[0065] Referring to Formula (2), in the second sub-stage of the large-step stage in the prior art, the intermediate ciphertexts in the multiplication result sequence are directly rotated and accumulated (it can be known from Figure 3 that the method of slicing the ciphertext to be converted is not adopted in the prior art, so a unique multiplication result sequence will be obtained, and this multiplication result sequence is directly composed of intermediate ciphertexts).

[0066] The following gives a simple introduction to rotation and accumulation. When adding two arbitrary ciphertexts, for example, ct1 and ct2, by rotation, first rotate one of the ciphertexts, for example, ct1, so that the ciphertext ct1 is rotated to the same plaintext arrangement order as the other ciphertext ct2, and then add ct1 and ct2 to obtain an intermediate accumulation result. Then, continue to add the intermediate accumulation result to other ciphertexts by rotation according to the foregoing method to achieve rotation and accumulation.

[0067] Among them, the process of rotating ct1 can refer to the introduction of ciphertext rotation in the previous term introduction. Thus, the process of rotating and accumulating ciphertext can be split into an operation cycle of rotation - addition - rotation - addition -.... And the rotation process includes an automorphism step and a key conversion step. As described above, in the process of key rotation, it is necessary to update the zero component of the current ciphertext using the one component of the current ciphertext. Therefore, the rotation and accumulation operation in the prior art needs to process both the zero component and the one component simultaneously.

[0068] Specifically, the process of performing rotation and accumulation operation in the prior art is as Figure 4As shown. As shown in the figure, first, the zero component ctA[0] and the one component ctA[1] of the ciphertext ctA are respectively automorphized. Subsequently, the automorphized ctA[1] is subjected to key conversion (the key conversion includes two steps: modulus elevation and multiplying the modulus-elevated ctA[1] by the evaluation key) to obtain a first component and a second component (not shown in the figure). Next, the first component after modulus reduction is added to ctA[0] (the addition operation of ciphertexts requires that the moduli of each ciphertext be the same, which will not be elaborated here), that is, the rotated ctA[0] is obtained. On the other hand, the second component after modulus reduction is the rotated ctA[1]. At this time, the rotated ctA and ctB correspond to the same plaintext arrangement order and can be directly added. Further, using the process as Figure 4 shown, the result after adding the ciphertext ctA and the ciphertext ctB is substituted back into ctA, and ctB is re-determined, so as to realize the rotational accumulation of several ciphertexts.

[0069] Note that in the process of performing rotational accumulation operations, the zero component does not affect the one component. Therefore, even if the zero component is deformed, it does not affect the calculations required for the one component. Further, according to the introduction of ciphertext rotation, ciphertext rotation consists of an automorphism step and a key conversion step. In the automorphism step, the operations of the zero component and the one component do not affect each other. In the key conversion step, the zero component needs to receive the first conversion component obtained by multiplying the one component by the evaluation key.

[0070] In some implementation manners, the method provided in this specification splits the key conversion step and the automorphism step in the complete rotational accumulation operation. For any sequence of multiplication results, the automorphism is performed on each first sub-result in the sequence of multiplication results, and each first sub-result is rotated to the same plaintext arrangement order. The automorphized first sub-results are accumulated to obtain the accumulated zero-component shard corresponding to the sequence of multiplication results. And each round of key conversion required for this accumulated zero-component shard is split into subsequent step S209 for execution.

[0071] If after obtaining any sequence of multiplication results, the first sub-results are not accumulated and the sequence of multiplication results is not stored outside the chip, the memory capacity of the second sub-stage calculation chip in the large-step stage needs to support storing an evaluation key and p sequences of multiplication results. Among them, the p sequences of multiplication results are also equivalent to m complete intermediate ciphertexts (the number of intermediate ciphertexts is determined according to the number of steps in the pre-set large-step stage). This is also the reason why the first type of method in the prior art described above has extremely high requirements for the memory capacity of the calculation chip.

[0072] Generally, when the memory of the computing chip is not sufficient to store all the sequences of multiplication results, it is necessary to transfer each sequence of multiplication results outside the chip, and splice each sequence of multiplication results outside the chip into each intermediate ciphertext (each intermediate ciphertext includes a zero component and a one component). According to the introduction of the rotation accumulation operation in the previous text, during the rotation accumulation operation, only two intermediate ciphertexts (or one intermediate ciphertext and one intermediate accumulation result) and one evaluation key need to be stored in the memory of the computing chip. Thus, the computing chip receives each intermediate ciphertext transmitted from outside the chip in batches, and can complete the rotation accumulation of each intermediate ciphertext under the condition of consuming a small memory capacity. However, if all the sequences of multiplication results are transferred outside the chip, the computing chip needs to receive the complete intermediate ciphertext (including the zero component and the one component) during the rotation accumulation operation, and thus the transmission process and the calculation process are difficult to overlap with each other, which is also the reason why the overall calculation time of the second method in the prior art described above is relatively long.

[0073] By using the method provided in this specification, after obtaining each sequence of multiplication results, the rotation accumulation is performed on each first sub-result in each first sub-sequence to obtain the accumulated zero component shard corresponding to each sequence of multiplication results. The content capacity required to store this accumulated zero component shard is only equivalent to storing one first sub-result, which can greatly reduce the requirement for the memory capacity of the computing chip. Thus, the accumulated zero component shard can be directly stored in the memory of the computing chip, and only each second sub-sequence is transferred to the off-chip memory.

[0074] Thus, on the one hand, in step S207, only each second sub-sequence needs to be transferred to the off-chip memory; on the other hand, in the subsequent step S209, the computing chip only needs to receive the one component of each intermediate ciphertext transmitted from the off-chip memory, which can further reduce the time consumed in the data transmission process.

[0075] To more clearly illustrate the relationship between the sequence of multiplication results, the accumulated zero component shard, and the intermediate ciphertext, this specification provides Figure 5 . Figure 5 shows the process of multiplying the ciphertext to be converted by the plaintext transformation matrix under the condition that n = 3, m = 4, and each ciphertext to be converted is split into two ciphertext shards in an embodiment of this specification. As Figure 5 can be seen, each ciphertext to be converted includes 2 ciphertext shards - cti(1), cti(2) (1 ≤ i ≤ 3). Correspondingly, ptji(1) (1 ≤ i ≤ 3, 1 ≤ j ≤ 4) represents the part of the plaintext transformation sub-matrix sequence pti that multiplies with cti(1), and ptji(2) (1 ≤ i ≤ 3, 1 ≤ j ≤ 4) represents the part of the plaintext transformation sub-matrix sequence pti that multiplies with cti(2). The intermediate result sequence ct ′ ji(1) (1 ≤ i ≤ 3, 1 ≤ j ≤ 4)) is obtained by multiplying ptji(1) with cti(1), and the intermediate result sequence ct′ ji(2) (1 ≤ j ≤ 3, 1 ≤ j ≤ 4) is obtained by multiplying ptji(2) and cti(2), and the multiplication result sequence is ct ′ j(1)

[0076] ∑ 1≤i≤3 ct ′ ji(1), (1 ≤ i ≤ 3, 1 ≤ j ≤ 4), and the multiplication result sequence is ct ′ j(2) = ∑ 1≤i≤3 ct ′ ji(2), (1 ≤ i ≤ 3). Each multiplication result sequence consists of a first subsequence corresponding to the zero component and a second subsequence corresponding to the one component. The first subsequence is represented by {0} shown in the figure for the corresponding zero component, and the second subsequence is represented by {1} for the corresponding one component. The first subsequence includes m = 4 first sub-results. Correspondingly, the second subsequence includes m = 4 second sub-results.

[0077] When performing step S207, first obtain each cti91), and obtain the corresponding multiplication result sequence ct according to each cti(1) ′ j(1). By accumulating each first sub-result in the first subsequence of the multiplication result sequence, the accumulated zero-component shards corresponding to each cti(1) can be obtained. On the other hand, the second subsequences corresponding to each cti(1) are transmitted to the off-chip memory to complete the multiplication of each cti(1) and the plaintext conversion matrix. Then continue to obtain each cti(2), and in the same way, obtain the accumulated zero-component shards corresponding to each cti(2), and splice them with the accumulated zero-component shards corresponding to each cti(1) to obtain the accumulated zero component. On the other hand, the second subsequences corresponding to each cti(2) are transmitted to the off-chip memory and spliced with the second subsequences corresponding to each cti(1) to obtain the one component of each intermediate ciphertext. It should be noted that the method of splicing each second subsequence is to splice each second sub-result in each second subsequence bit by bit. For example, for the multiplication result sequences ct ′ j(1) and ct ′ j(2), the second sub-results in ct ′ 1(1) are spliced with the second sub-results in ct ′ 1(2) to obtain the first one component of the intermediate ciphertext, and so on. Thus, the one components of each intermediate ciphertext also maintain the same sorting relationship as the multiplication result sequence.

[0078] S209: Determine the conversion ciphertext corresponding to the original ciphertext according to the accumulated zero component and the one components of each intermediate ciphertext, where the accumulated zero component is obtained by splicing each accumulated zero-component shard, and the one components of each intermediate ciphertext are obtained by splicing each second subsequence.

[0079] According to the method of splitting each ciphertext to be converted, each second subsequence can be concatenated to obtain one component of each intermediate ciphertext; similarly, each accumulated zero-component shard can be concatenated to obtain the accumulated zero component.

[0080] As described above, the accumulated zero component has completed the automorphism step and the accumulation step of the zero component. It is also necessary to perform key conversion on the accumulated zero component according to one component of each intermediate ciphertext; on the other hand, for one component of each intermediate ciphertext, since obtaining the accumulated zero component in advance does not affect the operation process of one component in the rotation accumulation operation, the rotation accumulation of one component of each intermediate ciphertext can be completed according to the method in the prior art.

[0081] Thus, according to the accumulated zero component after key conversion and one component of each intermediate ciphertext after rotation accumulation, the conversion ciphertext corresponding to the original ciphertext can be determined.

[0082] Such as Figure 2 shown in a method for converting the encoding form of a homomorphic ciphertext, which can reduce the data volume transmitted between the computing chip and the off-chip memory in the overall computing process and improve the speed of converting the encoding form of the homomorphic ciphertext while maintaining a low memory capacity requirement for the computing chip.

[0083] In some implementation manners, in step S207 as shown in Figure 2 determine a first target and a second target in each first sub-result of the multiplication result sequence. According to the difference in the plaintext arrangement order corresponding to the second target and the first target, perform automorphism on the second target, add the first target and the automorphized second target to obtain an intermediate accumulation result, and determine the accumulated zero-component shard corresponding to the multiplication result sequence according to the intermediate accumulation result and each first sub-result.

[0084] Specifically, referring to formula (2), performing automorphism on each first sub-result in the multiplication result sequence corresponds to the calculation step of Rot(, j·N2·r. Thus, the difference in the number of bits of the plaintext arrangement order corresponding to two adjacent first sub-results in the multiplication result sequence - n·r (in this embodiment, the number of steps N2 in the small-step stage = n) can be determined, and then the difference in the number of bits between the first target and the second target can be determined. By performing automorphism on the second target according to this difference in the number of bits, the plaintext arrangement order corresponding to the first target and the second target can be unified.

[0085] After obtaining the intermediate accumulation result, continuously determine an updated second target in each first sub-result of the multiplication result sequence that has not been accumulated, and use the aforementioned method to accumulate the intermediate accumulation result as the first target and the updated second target, so as to determine the accumulated zero component corresponding to the multiplication result sequence.

[0086] In some implementations, when accumulating each first sub-result in each multiplication result sequence, the same accumulation order can be adopted, so that the plaintext arrangement orders corresponding to each accumulated zero component slice are the same. Thus, each accumulated zero component slice can be directly concatenated to obtain the accumulated zero component.

[0087] In some implementations, in step S209 as shown Figure 2 obtain a first component to be accumulated, a second component to be accumulated, and a second evaluation key. Both the first component to be accumulated and the second component to be accumulated are components of the intermediate ciphertext. Using the second evaluation key, rotate the first component to be accumulated to obtain a first transformed component and a second transformed component corresponding to the first component to be accumulated. Update the accumulated zero component according to the first transformed component, and obtain the accumulated first component according to the second transformed component. Update the accumulated first component according to the second component to be accumulated. Update the current accumulated zero component according to the updated accumulated first component and the second evaluation key, and re-determine the second component to be accumulated among the components of each intermediate ciphertext. Update the current accumulated first component according to the updated second component to be accumulated and the second evaluation key until the rotation accumulation of all intermediate ciphertexts is completed. Determine the transformed ciphertext corresponding to the original ciphertext according to the current accumulated zero component and the current accumulated first component.

[0088] As described above, the accumulation of zero components has been completed in step S207, and subsequent key conversion steps need to be continued in step S209. Specifically, this key conversion step can consist of m - 1 rounds of conversion processes. Figure 6 shows the conversion process of the first round. Among them, acc[0] represents the accumulated zero component, ct ′ 1[1] represents the first component to be accumulated, ct ′ 2[1] represents the second component to be accumulated. First, perform an automorphism on ct ′ 1[1]. Subsequently, perform a key conversion on the automorphized ct ′ 1[1] (the key conversion includes two steps: modulus increase and multiplying the modulus-increased ct ′ 1[1] by the second evaluation key) to obtain a first transformed component and a second transformed component. On the other hand, perform a modulus increase on acc[0], and perform an automorphism on the modulus-increased acc[0], so that the automorphized acc[0], the automorphized ct ′ 1[1], and ct ′ 2[1] correspond to the same plaintext arrangement order. Next, add the first transformed component to the automorphized acc[0] to obtain the updated acc[0], and add the modulus-decreased second transformed component to ct ′ 2[1] to obtain the accumulated first component.

[0089] Further, using the method as Figure 6 shown, re-determine ct ′ 2[1], take the accumulated first component as ct ′ 1[1] and substitute it, and substitute the updated acc[0], then the rotation accumulation of all intermediate ciphertexts can be completed. After the rotation accumulation of all intermediate ciphertexts is completed, the current accumulated first component is the first component of the converted ciphertext. And since the modulus of the current accumulated zero component is the modulus after modulus increase, perform modulus reduction on the current accumulated zero component to obtain the zero component of the converted ciphertext. It should be noted that after the first round of conversion process, since acc[0] already has the same modulus as ct ′ 1[1] after modulus increase, there is no need to perform modulus increase on acc[0] in the subsequent rounds of conversion process.

[0090] Among them, at any moment before executing step S207, the computing chip can receive the second evaluation key transmitted from the off-chip memory and store it in the memory of the computing chip under the condition of sufficient memory capacity. This specification does not limit it here.

[0091] In some implementation manners, represent the sorting of the first component to be accumulated among the first components of the intermediate ciphertexts as t, determine the first component with the sorting of t + 1 among the first components of the intermediate ciphertexts as the second component to be accumulated. After completing the accumulation of the first component to be accumulated and the second component to be accumulated, continue to obtain the first component with the sorting of t + 2 as the updated second component to be accumulated. Thus, the differences in the plaintext sorting orders corresponding to (the first component to be accumulated, the second component to be accumulated), (the accumulated first component, the updated second component to be accumulated) are all the same, and this difference corresponds to "the number of bits difference in the plaintext arrangement order corresponding to two adjacent first sub-results - n·r" in the foregoing text. Therefore, the key conversion of the accumulated first component in each round can be completed through a unified second evaluation key.

[0092] In some implementation manners, in step S209 as Figure 2 shown, according to the modulus difference between the first conversion component and the accumulated zero component, perform modulus increase on the accumulated zero component to obtain the accumulated zero component after modulus increase. According to the difference in the plaintext arrangement order between the accumulated zero component after modulus increase and the first conversion component, perform automorphism on the accumulated zero component after modulus increase to obtain the automorphized accumulated zero component. Add the automorphized accumulated zero component and the first conversion component to obtain the updated accumulated zero component.

[0093] Specifically, reference can be made to the description of Figure 6 before.

[0094] It should be noted that Figure 6The automorphism step performed on the accumulated zero component in the steps shown can be omitted under certain conditions. Among them, according to the description corresponding to step S207, when accumulating each first sub-result, an automorphism needs to be performed on each first sub-result to unify the plaintext arrangement order corresponding to each first sub-result. Thus, the accumulated zero component as the accumulation result must have the same plaintext arrangement order as a group of first sub-results. Also, each first sub-result in the multiplication result sequence has a second sub-result with the same corresponding plaintext arrangement order. Thus, when the second component to be accumulated is obtained by splicing the second sub-results corresponding to this group of first sub-results, there is no need to perform an automorphism on the accumulated zero component.

[0095] In some implementation manners, in step S203 as shown in Figure 2 the original ciphertext is rotated using the first evaluation key to obtain a plurality of rotated ciphertexts, and according to the memory size of the computing chip, the original ciphertext and each rotated ciphertext that cannot be stored are transmitted to an off-chip memory.

[0096] Thus, after rotating the original ciphertext, it is not necessary to store all the ciphertexts to be converted in the memory of the computing chip, which can reduce the requirement for the memory capacity of the computing chip.

[0097] It should be noted that in step S205, if the ciphertext to be converted required for multiplying with the plaintext conversion matrix is not stored in the memory of the computing chip, the computing chip can receive the ciphertext to be converted transmitted from the off-chip memory.

[0098] In some implementation manners, each ciphertext to be converted includes p ciphertext shards. In step S205 as shown in Figure 2 p rounds of multiplication operations are performed using the ciphertext shards of each ciphertext to be converted and a pre-stored plaintext conversion matrix. The steps of the i-th round of multiplication operation are as follows: Obtain the i-th ciphertext shard of each ciphertext to be converted as each shard to be converted, and multiply each shard to be converted with the sub-matrix at the corresponding position in the pre-stored plaintext conversion matrix to obtain the multiplication result sequence corresponding to the i-th round.

[0099] Specifically, multiplying each shard to be converted with the plaintext conversion matrix can refer to the previous description of Figure 3 and Figure 5 .

[0100] It should be noted that each round of multiplication operation is carried out in succession. After obtaining the multiplication result sequence corresponding to the i-th round, it can be judged according to the memory capacity of the computing chip. If the current computing chip's memory does not support storing the multiplication result sequence corresponding to the i + 1-th round, the multiplication result sequence corresponding to the i-th round can be transmitted to the off-chip memory.

[0101] In addition, after completing the multiplication operation in the i-th round, each shard to be converted corresponding to the i-th round can be deleted from the memory of the computing chip, further releasing the memory space of the computing chip.

[0102] In some implementation manners, in step S205 as Figure 2 shown, before obtaining the multiplication result sequence corresponding to the i-th round, for any ciphertext to be converted that is not stored in the memory of the computing chip, the (i + 1)-th ciphertext shard of the ciphertext to be converted is received.

[0103] When using a computing chip for calculation, the two main factors affecting the calculation efficiency are data calculation and data reading / writing. For a computing chip, simply performing data reading / writing does not affect the efficiency of data calculation. However, in multi-round calculations, if the data for the next round has not been transferred to the memory of the computing chip after the data calculation for the current round is completed, it will cause the calculation to stagnate, thereby affecting the overall calculation efficiency.

[0104] It should be noted that in the prior art, since the ciphertext is not sharded before the multiplication operation, on the one hand, receiving the complete ciphertext to be converted takes too much time, and on the other hand, it is impossible to achieve the mutual coverage of data reading / writing and data calculation. Therefore, this multiplication operation takes a relatively long time.

[0105] As described above, the multiplication operations in each round of this embodiment are carried out in succession. Therefore, during the process of performing the multiplication operation in the i-th round, the computing chip can simultaneously receive the ciphertext shards required for the (i + 1)-th round, thereby achieving the mutual coverage of the data reading / writing process and the data calculation process and improving the calculation efficiency of the computing chip.

[0106] In some implementation manners, in step S207 as Figure 2 shown, for any shard to be converted, the shard to be converted is multiplied by the i-th part of each plaintext conversion sub-matrix in the plaintext conversion sub-matrix sequence corresponding to the shard to be converted to obtain the intermediate result sequence corresponding to the shard to be converted. The intermediate result sequences corresponding to each shard to be converted are added to obtain the multiplication result sequence corresponding to the i-th round. The multiplication result sequence is composed of m first sub-results and m second sub-results.

[0107] Specifically, reference can be made to the description of Figure 5 .

[0108] It should be noted that the multiplication supported in the ciphertext state is vector multiplication (i.e., the corresponding elements of the vectors are multiplied pairwise). Thus, for the ciphertext B split into p ciphertext shards, when the plaintext conversion sub-matrix corresponding to the ciphertext B is the matrix A, the matrix A is split into p parts according to the method of splitting the ciphertext B, and the p-th ciphertext shard of the ciphertext B is multiplied with the corresponding parts in the matrix A and then spliced, and the result is equivalent to directly multiplying the ciphertext B with the matrix A.

[0109] In some implementation manners, in step S203 as shown in Figure 2 using the original ciphertext as the ciphertext to be rotated, rotating the ciphertext to be rotated by using the first evaluation key to obtain the rotated ciphertext corresponding to the ciphertext to be rotated, using the rotated ciphertext as the ciphertext to be rotated again, and rotating the updated ciphertext to be rotated by using the first evaluation key to obtain the updated rotated ciphertext until n - 1 rotated ciphertexts are obtained.

[0110] Thus, after obtaining a rotated ciphertext, the original ciphertext or other rotated ciphertexts obtained in history can be transmitted to off-chip storage according to the memory capacity of the computing chip, so as to achieve the mutual coverage of the data reading and writing process and the data calculation process, and improve the calculation efficiency of the computing chip.

[0111] In the 1990s, it was obvious to distinguish whether an improvement in a technology was an improvement in hardware (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or an improvement in software (improvement in method processes). However, with the development of technology, many improvements in method processes today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structure by programming the improved method process into the hardware circuit. Therefore, it cannot be said that an improvement in a method process cannot be implemented with a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. The designer can program by himself to "integrate" a digital system on a piece of PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called Hardware Description Language (HDL), and there is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. Currently, the most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that as long as the method process is slightly logically programmed with the above-mentioned several hardware description languages and programmed into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method process.

[0112] The controller may be implemented in any suitable manner. For example, the controller may take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller may also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller may be considered a hardware component, and the devices included therein for implementing various functions may also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions may be regarded as either software modules for implementing the method or the structures within the hardware component.

[0113] The systems, devices, modules, or units illustrated in the above embodiments may be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a server system. Of course, this application does not exclude that with the development of future computer technologies, the computers for implementing the functions of the above embodiments may be, for example, personal computers, laptop computers, in-vehicle human-machine interaction devices, cellular phones, camera phones, smart phones, personal digital assistants, media players, navigation devices, email devices, game consoles, tablet computers, wearable devices, or any combination of these devices.

[0114] Although one or more embodiments of this specification provide method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way among many orders of step execution and does not represent the only execution order. When actually executed by a device or terminal product, it may be executed in the order of the method shown in the embodiments or the drawings or executed in parallel (for example, in an environment of parallel processors or multi-threaded processing, or even in a distributed data processing environment). The term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, product or device comprising a series of elements not only includes those elements but also includes other elements not explicitly listed, or also includes elements inherent to such a process, method, product or device. Without further limitation, it does not exclude the existence of additional identical or equivalent elements in the process, method, product or device comprising the said elements. For example, if terms such as first and second are used to denote names, they do not denote any specific order.

[0115] For convenience of description, when describing the above device, it is divided into various modules according to functions and described separately. Of course, when implementing one or more of this specification, the functions of each module can be implemented in the same or multiple software and / or hardware, or the modules implementing the same function can be realized by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.

[0116] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate a device for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0117] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device that implements the functions specified in one or more of the acts Figure 1 and / or boxes of one or more of the acts Figure 1 specified in one or more of the boxes.

[0118] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing steps for implementing the functions specified in one or more of the acts Figure 1 and / or boxes of one or more of the acts Figure 1 specified in one or more of the boxes.

[0119] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0120] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.

[0121] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technologies, compact disc read only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage, graphene storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0122] Those skilled in the art should understand that one or more embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0123] One or more embodiments of this specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of this specification can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0124] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the method embodiments for the relevant content. In the description of this specification, the description of reference terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0125] The above description is only for the embodiments of one or more embodiments of this specification and is not intended to limit one or more embodiments of this specification. For those skilled in the art, one or more embodiments of this specification can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims.

Claims

1. A method for converting the encoding form of homomorphic ciphertext, the method being executed by a computing chip, each ciphertext comprising a zero component and a one component, the zero component being determined according to a public key, a noise polynomial and a plaintext polynomial, the one component being determined according to a public key and a noise polynomial, the method comprising: Obtaining the original ciphertext and the first evaluation key; Using the first evaluation key to rotate the original ciphertext to obtain a plurality of rotated ciphertexts; The original ciphertext and the plurality of rotated ciphertexts are used as ciphertexts to be converted, and each ciphertext to be converted is multiplied by a pre-stored plaintext conversion matrix to obtain a plurality of multiplication result sequences, each of which is composed of a first subsequence corresponding to a zero component and a second subsequence corresponding to a one component; For any multiplication result sequence, each first sub-result in a first sub-sequence of the multiplication result sequence is accumulated to obtain an accumulated zero component slice corresponding to the multiplication result sequence, and a second sub-sequence of the multiplication result sequence is transmitted to an off-chip memory; The converted ciphertext corresponding to the original ciphertext is determined according to the accumulated zero component and a component of each intermediate ciphertext, wherein the accumulated zero component is obtained by splicing the accumulated zero component fragments, and the component of each intermediate ciphertext is obtained by splicing the second subsequences.

2. The method according to claim 1, accumulating each first sub-result in the first sub-sequence of the multiplication result sequence to obtain an accumulated zero component slice corresponding to the multiplication result sequence, specifically comprising: Determining a first target and a second target in each first sub-result of the multiplication result sequence; According to the difference between the plaintext arrangement order corresponding to the second target and the first target, the second target is subjected to automorphism; Add the first goal to the second goal after the automorphism to obtain the intermediate cumulative result; The accumulated zero component slice corresponding to the multiplication result sequence is determined according to the intermediate accumulated result and the first sub-results.

3. The method according to claim 1, determining the converted ciphertext corresponding to the original ciphertext according to the accumulated zero component and a component of each intermediate ciphertext, specifically comprises: Obtaining a first component to be accumulated, a second component to be accumulated, and a second evaluation key, wherein the first component to be accumulated and the second component to be accumulated are both components of the intermediate ciphertext; Using the second evaluation key, rotating the first component to be accumulated to obtain a first converted component and a second converted component corresponding to the first component to be accumulated; According to the first conversion component, the accumulated zero component is updated, and according to the second conversion component, an accumulated one component is obtained; updating the accumulated component according to the second component to be accumulated; The current accumulated zero component is updated according to the updated accumulated one component and the second evaluation key, and the second one component to be accumulated is re-determined in the one component of each intermediate ciphertext, and the current accumulated one component is updated according to the updated second one component to be accumulated and the second evaluation key, until the rotation accumulation of all intermediate ciphertexts is completed; The converted ciphertext corresponding to the original ciphertext is determined according to the current accumulated zero component and the current accumulated one component.

4. The method according to claim 3, updating the accumulated zero component according to the first conversion component, specifically comprising: According to the modulus difference between the first conversion component and the accumulated zero component, performing modulus up-conversion on the accumulated zero component to obtain a modulus up-converted accumulated zero component; According to the difference between the order of plain text arrangement corresponding to the accumulated zero component after modular upgrading and the first conversion component, the accumulated zero component after modular upgrading is subjected to automorphism to obtain an automorphic accumulated zero component; The automorphism accumulated zero component is added to the first conversion component to obtain an updated accumulated zero component.

5. The method according to claim 1, wherein the original ciphertext is rotated using the first evaluation key to obtain a plurality of rotated ciphertexts, specifically comprising: The original ciphertext is rotated using the first evaluation key to obtain a plurality of rotated ciphertexts, and the original ciphertext and the rotated ciphertexts that cannot be stored are transmitted to an off-chip memory according to the memory size of the computing chip.

6. The method as claimed in claim 5, wherein each ciphertext to be converted comprises p ciphertext fragments; Multiply each ciphertext to be converted with the pre-stored plaintext conversion matrix to obtain a number of multiplication result sequences, including: The ciphertext segments of each ciphertext to be converted are used to perform p rounds of multiplication operations with the pre-stored plaintext conversion matrix, where the steps of the i-th round of multiplication operations are as follows: Obtain the i-th ciphertext fragment of each ciphertext to be converted as each fragment to be converted; Each of the to-be-converted segments is multiplied by a submatrix at a corresponding position in a pre-stored plaintext conversion matrix to obtain a multiplication result sequence corresponding to the i-th round.

7. The method according to claim 6, before obtaining the multiplication result sequence corresponding to the i-th round, further comprising: For any ciphertext to be converted that is not stored in the memory of the computing chip, an i+1th ciphertext fragment of the ciphertext to be converted is received.

8. The method according to claim 6, wherein the plaintext conversion matrix specifically comprises: n plaintext conversion submatrix sequences corresponding to the number of ciphertexts to be converted, each plaintext conversion submatrix sequence corresponds to a different ciphertext to be converted, each plaintext conversion submatrix sequence includes m plaintext conversion submatrices, and each plaintext conversion submatrix includes p parts; Multiplying each of the to-be-converted segments with a submatrix at a corresponding position in a pre-stored plaintext conversion matrix to obtain a multiplication result sequence corresponding to the i-th round, specifically including: For any slice to be converted, multiply the slice to be converted by the i-th part of each plaintext conversion submatrix in the plaintext conversion submatrix sequence corresponding to the slice to be converted, to obtain an intermediate result sequence corresponding to the slice to be converted; The intermediate result sequences corresponding to the slices to be converted are added together to obtain a multiplication result sequence corresponding to the i-th round, wherein the multiplication result sequence consists of m first sub-results and m second sub-results.

9. The method according to claim 5, wherein the first evaluation key is used to rotate the original ciphertext to obtain a plurality of rotated ciphertexts, specifically comprising: Taking the original ciphertext as the ciphertext to be rotated, and rotating the ciphertext to be rotated using the first evaluation key to obtain a rotated ciphertext corresponding to the ciphertext to be rotated; The rotated ciphertext is used again as the ciphertext to be rotated, and the updated ciphertext to be rotated is rotated using the first evaluation key to obtain an updated rotated ciphertext, until n-1 rotated ciphertexts are obtained.

10. A computing device comprising a memory and a processor, wherein the memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 1 to 9 is implemented.