Grid-based CRS-free multi-key homomorphic encryption method

Through distributed key generation and ciphertext expansion technology, combined with the directional decryption mechanism, the problem of dependence on trusted third parties in traditional multi-key homomorphic encryption schemes is solved, and multi-key homomorphic encryption without CRS is realized, which enhances the security and decentralization of the system and provides flexible privacy protection.

CN120263382APending Publication Date: 2025-07-04QUFU NORMAL UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510442297.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

Traditional multi-key homomorphic encryption schemes rely on public random strings (CRS) generated by trusted third parties, resulting in reduced system resistance and decentralization characteristics, and there is a problem that all user data is threatened when key leaks.

Method used

The distributed key generation protocol is adopted to enable all users to generate keys independently, and the ciphertext of multiple users is expanded to the same dimension through ciphertext expansion technology. Combined with the directional decryption mechanism, the public key information of the target user is embedded in the ciphertext, so as to realize CRS-free multi-key homomorphic encryption in multi-user scenarios, enhancing security and decentralization characteristics.

Benefits of technology

Cross-user homomorphic addition operations are implemented without relying on trusted third parties, which enhances the system's security and privacy protection, and provides a flexible privacy protection mechanism to ensure that only specific users can decrypt the ciphertext after homomorphic operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263382A_ABST
    Figure CN120263382A_ABST
Patent Text Reader

Abstract

The invention relates to the fields of cryptographic algorithms and homomorphic encryption, in particular to an anti-quantum-attack homomorphic encryption method. Along with increasing demands of outsourcing computing and privacy protection application in a multi-user scene, multi-key homomorphic encryption becomes an important research direction. The construction of a traditional multi-key homomorphic encryption scheme generally depends on a common random character string (CRS) model, and a trusted party needs to generate a common parameter for a public key so as to support calculation on a joint ciphertext. Due to the dependence on the central trusted mechanism, the anti-attack capability and the decentralization characteristic of the system are greatly reduced. In order to avoid excessive dependence on trusted third parties and public parameters, a distributed key generation protocol is used in the invention, all users are enabled to independently generate keys thereof, and ciphertexts of a plurality of users are expanded to the same dimension through a ciphertext expansion technology, so that the encryption efficiency is improved. Therefore, multi-key homomorphic encryption in a multi-user scene is realized without depending on a trusted third party, a lattice-based CRS-free multi-key homomorphic encryption method is provided, and the security and decentration characteristic of the scheme are enhanced. Furthermore, the invention provides a directional decryption mechanism and introduces the directional decryption mechanism into the scheme, the public key information of the target user is embedded into the ciphertext, it is ensured that only the specific target user can decrypt the ciphertext after homomorphic operation, and more flexible privacy protection is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of cryptographic algorithms and homomorphic encryption, and more specifically to a homomorphic encryption method resistant to quantum attacks.

[0002] With the increasing demand for outsourcing computing and privacy protection applications in multi-user scenarios, multi-key homomorphic encryption has become an important research direction. The construction of traditional multi-key homomorphic encryption schemes usually relies on the common random string (CRS) model, which requires a trusted party to generate the common parameters for the public key to support the calculation on the joint ciphertext. Due to the dependence on the central trusted institution, the anti-attack ability and decentralization characteristics of the system are greatly reduced.

[0003] To avoid excessive dependence on trusted third parties and common parameters, this paper uses a distributed key generation protocol, enabling all users to independently generate their keys. Through ciphertext expansion technology, the ciphertexts of multiple users are expanded to the same dimension, thus realizing multi-key homomorphic encryption in multi-user scenarios without relying on trusted third parties. A lattice-based CRS-free multi-key homomorphic encryption method is proposed, enhancing the security and decentralization characteristics of the scheme. Further, the present invention proposes a directional decryption mechanism and introduces it into the scheme, embedding the public key information of the target user into the ciphertext to ensure that only the specific target user can decrypt the ciphertext after homomorphic operations, providing more flexible privacy protection. Background Art

[0004] The development of quantum computers poses potential security threats to cryptographic schemes based on number theory problems. Currently, quantum algorithms can solve the problems of large integer factorization and discrete logarithm in polynomial time, so the schemes based on these two assumptions will be broken in the quantum environment. Therefore, due to its good anti-attack performance, lattice-based cryptographic systems have received extensive attention.

[0005] In outsourcing computing scenarios involving multiple users (such as joint analysis, federated learning, etc.), if traditional homomorphic encryption schemes are adopted, all users need to share a key. This approach has obvious security risks: once the key is leaked, the data of all users will be threatened.

[0006] Multi-key homomorphic encryption solves the above problems by allowing each user to encrypt data using their own key, while still supporting the joint calculation of encrypted data. The calculation result can be jointly decrypted by the private keys of multiple users. The common decryption method in multi-key homomorphic encryption is distributed decryption. Each user generates partial decryption information, i.e., decryption shares, according to their private key. The cloud service provider collects the partial decryption information of all users and combines it into the final decryption result.

[0007] In a multi-key homomorphic encryption scheme, in order to enable multiple users to jointly perform homomorphic operations on ciphertexts (e.g., perform homomorphic operations such as addition and multiplication), and at the same time perform collaborative decryption on the ciphertext after homomorphic operations, a mechanism is needed to coordinate and combine the public keys of different users. The Common Random String (CRS) provides a shared public parameter, and all users can generate their own public keys based on this parameter. Through the public parameter provided by the CRS, multiple public keys containing the same parameter are integrated into an aggregated public key. Multiple users can perform homomorphic operations on the ciphertext under the aggregated public key and perform collaborative decryption through a distributed decryption protocol. The CRS model is a model used in cryptographic schemes, mainly for designing and analyzing encryption schemes for multiple users. In a scheme based on the CRS model, a trusted third party pre-generates a set of public parameters and distributes them to all users during the system initialization phase. This set of public parameters has the characteristics of publicity and randomness. Specifically, it is a string generated by a trusted setup process, its content is completely random and unpredictable, and all users can access and use it during the execution of the scheme.

[0008] The introduction of CRS can simplify the scheme design and key generation process, but it also brings some problems: on the one hand, the generation and management of CRS usually require a trusted third party, and this assumption is difficult to achieve in a decentralized system or a scenario with low trust requirements; on the other hand, the security and correctness of the scheme depend on the generation and management of CRS. If the CRS is leaked or tampered with, it may affect the credibility of the scheme.

[0009] To avoid excessive dependence on a trusted third party and public parameters, this paper adopts a distributed key generation protocol and uses ciphertext expansion technology to expand the ciphertexts of users to the same dimension, thus realizing multi-key homomorphic encryption in a multi-user scenario without relying on a trusted third party, and proposes a lattice-based CRS-free multi-key homomorphic encryption method. Further, this paper embeds the public key information of the target user in the ciphertext to ensure that only the target user holding the corresponding private key can decrypt the ciphertext after homomorphic operations, realizing the uniqueness of decryption authority. Summary of the Invention

[0010] This invention proposes a lattice-based CRS-free multi-key homomorphic encryption method, which adopts technologies such as public key encryption, homomorphic encryption, distributed decryption, and distributed key generation, while ensuring the encryption and decryption efficiency, improving data security and privacy protection, and enhancing the security of the system.

[0011] To reduce the dependence on public parameters and enhance the ability of users to independently generate public keys, the present invention proposes a lattice-based multi-key homomorphic encryption method without a CRS. Through a distributed key generation protocol, all users can independently generate their keys. Based on the ciphertext expansion technology, a distributed ciphertext decryption method in a multi-key scenario is designed, thereby realizing homomorphic addition operations across users without public parameters. To further protect the plaintext messages of each user, the present invention embeds the information of the target user in the ciphertext, enabling the encryption process to support specifying the target user as the only decryptor, providing more flexible privacy protection.

[0012] The lattice-based multi-key homomorphic encryption method without a CRS includes nine parts: the Setup algorithm, the keyGen algorithm, the Encode algorithm, the Enc algorithm, the Expand algorithm, the AddEval algorithm, the PartDec algorithm, the FinDec algorithm, and the Decode algorithm.

[0013] (1) System initialization

[0014] The algorithm generates system public parameters ;

[0015] (2) Key generation algorithm

[0016] User and target user Run The algorithm to independently generate key pairs and : , ;

[0017] (3) Encoding

[0018] User Run The algorithm to encode its message vector into a polynomial and output an integer coefficient plaintext polynomial ;

[0019] (4) Encryption algorithm

[0020] User Run The algorithm, using its public key and The public key of To encrypt its plaintext , generating a ciphertext : ;

[0021] (5)Ciphertext Expansion Algorithm

[0022] To enable the ciphertexts of multiple users to perform homomorphic operations and decryption under different public keys, the user runs the algorithm to expand its ciphertext to obtain the expanded ciphertext ;

[0023] (6)Homomorphic Operation Algorithm

[0024] Aggregate the expanded ciphertexts of all users to obtain the aggregated ciphertext : ;

[0025] (7)Partial Decryption Algorithm

[0026] The user runs the algorithm to calculate its decryption share : where ;

[0027] (8)Final Decryption Algorithm

[0028] The target user runs the algorithm and uses its private key to fully decrypt the aggregated ciphertext to recover the final aggregated plaintext value:

[0029]

[0030] (9)Decoding Algorithm

[0031] The target user runs the algorithm to map the aggregated plaintext value back to a complex number vector, obtaining the aggregated plaintext value . Description of the Drawings

[0032] Figure 1 Lattice-based Multi-Key Homomorphic Encryption Method without CRS Detailed Implementation Manner

[0033] The implementation manner of the lattice-based multi-key homomorphic encryption method without CRS of the present invention includes the following nine algorithms:

[0034] (1)System Initialization

[0035] The algorithm performs the following steps to generate system public parameters :

[0036] (1.1)Set the security parameter as , the circuit depth as , the number of users as , and let the dimension of the polynomial ring be , the ciphertext modulus as , and let be the key distribution on , and be the error distribution on ;

[0037] (1.2)Return the system public parameter ;

[0038] (2)Key Generation Algorithm

[0039] User and the target user run the algorithm to independently generate key pairs and :

[0040] (2.1) Select , and set its private key as ;

[0041] (2.2) Select , and set its private key as ;

[0042] (2.3) Randomly sample , , calculate , and set its public key as ;

[0043] (2.4) Randomly sample , , calculate , and set its public key as ;

[0044] (3)Encoding

[0045] User runs the Algorithm to encode its message vector into a polynomial:

[0046] (3.1)The message of user is a complex vector , where is the dimension of the polynomial ring. Scale the complex vector to retain decimal precision and calculate , where is the scaling factor;

[0047] (3.2)Map the complex vector to the polynomial ring through the inverse canonical embedding mapping, i.e., ;

[0048] (3.3)Output the plaintext polynomial with integer coefficients ;

[0049] (4)Encryption algorithm

[0050] User runs the algorithm, uses its public key and the public key of to encrypt its plaintext , generating the ciphertext :

[0051] (4.1) Randomly sample , , set , , , ;

[0052] (4.2) Encrypt its plaintext using the public key and , and perform the following calculations

[0053]

[0054]

[0055]

[0056] The output ciphertext is ;

[0057] (5)Ciphertext expansion algorithm

[0058] To enable the homomorphic operation and decryption of ciphertexts of multiple users under different public keys, the user runs the algorithm to expand its ciphertext as follows:

[0059] (5.1) Define an n -dimensional unit vector

[0060] where only the i -th component is 1 and the rest of the components are 0; ;

[0061] (6) Homomorphic operation algorithm

[0062] Aggregates the expanded ciphertexts of all users to obtain the aggregated ciphertext :

[0063] (6.1) Perform homomorphic calculation: , , , to obtain the aggregated ciphertext ;

[0064] (6.2) The aggregated ciphertext is sent to the target user for decryption;

[0065] (7) Partial decryption algorithm

[0066] The user runs the algorithm to calculate its decryption share :

[0067] (7.1) The user uses its private key to partially decrypt its ciphertext and calculates its decryption share where ;

[0068] (7.2) Sends its decryption share to for final decryption;

[0069] (8) Final decryption algorithm

[0070] The target user Run the algorithm and use its private key to completely decrypt the aggregated ciphertext and recover the final aggregated plaintext value;

[0071] (8.1) After receiving the aggregated ciphertext and the decryption share use its own private key to perform the final decryption, calculate and output the aggregated plaintext value:

[0072]

[0073] (9) Decoding algorithm

[0074] The target user runs the algorithm to map the aggregated plaintext value to the reply number vector;

[0075] (9.1) Use the canonical embedding mapping to map to the vector , ;

[0076] (9.2) Perform an inverse scaling operation on to restore the precision of the original data, i.e., , where is the scaling factor used during encoding;

[0077] (9.3) Output the aggregated plaintext value in the form of a complex number vector .

[0078] Validation of the effectiveness of the present invention

[0079] To verify the effectiveness of the present invention, we analyzed the correctness and homomorphism of the method, and proved that the method satisfies semantic security and simulation security. Therefore, the method of the present invention does not require a trusted third party to pre-generate and distribute the CRS, realizes homomorphic addition operations across users, enhances the security and decentralization characteristics of the scheme, and provides more flexible privacy protection.

[0080] (1) Correctness

[0081] Given the security parameter and the circuit depth , set the modulus , , and is on -bounded distribution. Given Ciphertext under a user's public key and Private keys connected by users , there are

[0082]

[0083] Among them, , and . Therefore, given the plaintext aggregation value and the corresponding aggregated ciphertext , according to algorithm and algorithm definition, it can be calculated

[0084]

[0085] Among them , and . Therefore, if , then the lattice-based multi-key homomorphic encryption method without CRS can decrypt correctly.

[0086] (2) Homomorphism

[0087] This section discusses the additive homomorphism property of the lattice-based multi-key homomorphic encryption method without CRS.

[0088] Given users, is the public key of the th user, is the encrypted ciphertext of the plaintext , is the aggregated ciphertext of all users. To prove that the multi-key homomorphic encryption scheme satisfies additive homomorphism, it is necessary to prove that the result of decrypting the aggregated ciphertext is equal to the aggregated plaintext value of users, that is , and .

[0089]

[0090] Observing the above calculation, the ciphertext after the homomorphic operation is obtained by aggregating the ciphertexts of users. The above process can complete the homomorphic addition operation of the ciphertext. According to the correctness analysis in 4.3.2, the result of decrypting is equal to the aggregated plaintext value . Therefore, the lattice-based multi-key homomorphic encryption method without CRS satisfies additivity.

[0091] (3)Security proof

[0092] Theorem 1 Assume that the RLWE problem is hard. If there does not exist an adversary who can win the following security game with a non-negligible probability , then the lattice-based multi-key homomorphic encryption scheme without CRS is IND-CPA secure, that is, it satisfies semantic security.

[0093] Proof: Given an adversary and a challenger , this theorem is proved by defining the following sequence of games:

[0094] Game 0: Given the public parameters and the vector , the challenger runs the algorithm to generate the public key , and sends to the adversary , where . In this stage has the same distribution as the scheme.

[0095] Game 1: The steps in other stages are the same as those in Game 0 except for the key generation stage. Redefine the distribution of the public key in Game 1. Given the public parameters and the vector , generate the public key , where . According to the hardness and circular security of the RLWE assumption, and are computationally indistinguishable, so and are also computationally indistinguishable. Therefore, the advantage of the attacker in distinguishing Game 0 and Game 1 is negligible.

[0096]

[0097] Within a certain period of time, initiates a challenge to and sends the challenge plaintext . Randomly select , run the algorithm to output the challenge ciphertext , and then send the ciphertext to . Output the guessing result of the scheme, output . If Output 1, otherwise output 0. Protect due to Distinguish and The probability of is negligible. Therefore, the multi-key homomorphic encryption scheme without CRS proposed in this paper is IND-CPA secure, that is, it satisfies semantic security.

[0098] Theorem 2 Given the security parameter , if there exists a probabilistic polynomial-time simulator such that for all adversaries , the advantage of distinguishing the real scheme and the simulated scheme is negligible, then the lattice-based multi-key homomorphic encryption method without CRS satisfies simulation security.

[0099] Proof: Prove the simulation security of the scheme through a series of game sequences.

[0100] : The game defined in Section 4.3.1 .

[0101] : The same as , except that the simulator outputs the simulated value of the decryption share as

[0102]

[0103] On the other hand, according to the correctness analysis of the scheme in 4.3.2,

[0104] Therefore, if the real decryption share is , then there is

[0105]

[0106] Observing the above formula, we can get , so there is , it can be known that and have the same distribution, without knowing the real private key value of the user, the decryption share indistinguishable from the real distribution can be calculated. Therefore, the adversary cannot distinguish the real scheme and the simulated scheme, that is

[0107]

[0108] where Denote the negligible function. Then the lattice-based multi-key homomorphic encryption method without CRS satisfies simulation security.

Claims

1. A lattice-based multi-key homomorphic encryption method without CRS, characterized in that: The lattice-based multi-key homomorphic encryption scheme without CRS consists of nine algorithms, namely: Algorithm, Algorithm, Algorithm, Algorithm, Algorithm, Algorithm, Algorithm, Algorithm, Algorithm. The specific descriptions of each algorithm are as follows: (1) System initialization , The algorithm executes the following steps to generate system public parameters : (1.1) Let the security parameter be , the circuit depth be , the number of users be , let the dimension of the polynomial ring be , the ciphertext modulus be , let be 's key distribution over , and be the error distribution over ; (1.2) Return system common parameters ; (2) Key generation algorithm , User and target user Run the algorithm to independently generate a key pair and : (2.1) Select , and set its private key to ; (2.2) Select , and set its private key to ; (2.3) Random sampling , , calculate , set its public key to ; (2.4) Random sampling , , calculate , set its public key as ; (3) Encoding , User runs an algorithm that encodes its message vector as a polynomial: (3.1)User 's message is a complex vector , where is the dimension of the polynomial ring, scale the complex vector to retain decimal precision, calculate , where is the scaling factor; (3.2) Through the inverse canonical embedding the mapping maps the complex vector to the polynomial ring as follows ; Output the plaintext polynomial with integer coefficients ; (4) Encryption algorithm , User Run the algorithm, using its public key and the public key of to encrypt its plaintext to generate the ciphertext : (4.1) Random sampling , and set , , , ; (4.2) Use the public key and to encrypt its plaintext , and perform the following calculations , , , The output ciphertext is ; (5) Ciphertext Expansion Algorithm ; To enable homomorphic operations and decryption of ciphertexts of multiple users under different public keys, the user runs the algorithm to expand its ciphertext as follows: Definition (5.1) Unit vector in dimension , where only the -th component is 1 and the remaining components are all 0; User (5.2) extends its ciphertext to calculate the extended ciphertext ; (6) Homomorphic operation algorithm ;; Aggregate all users 's extended ciphertext to obtain an aggregated ciphertext : Perform homomorphic computation: , , , to obtain the aggregated ciphertext ; (6.2) Aggregated ciphertext Sent to the target user For decryption; (7) Partial decryption algorithm ; User Run the algorithm and calculate its decryption share : (7.1) User uses its private key to partially decrypt its ciphertext and calculate its decryption share , where ; (7.2) Send its decryption share to be used for final decryption; Final decryption algorithm ; Target user Run the algorithm, using its private key to completely decrypt the aggregated ciphertext and recover the final aggregated plaintext value; (8.1) Receive the aggregated ciphertext and the decryption share After that, use its own private key to perform the final decryption, calculate and output the aggregated plaintext value: (9) Decoding algorithm ; Target user Run the algorithm to map the aggregated plaintext values to the response number vector; (9.1) Use the canonical embedding mapping to map to the vector , ; (9.2) For perform an anti-scaling operation to restore the precision of the original data, that is , where is the scaling factor used during encoding; Output the aggregated plaintext value in the form of a complex vector .

Citation Information

Cited By

  • Block chain privacy protection method and system based on dynamic threshold homomorphic encryption

    CN120639272A

  • Multi-party quantum homomorphic encryption method based on hybrid encryption mechanism

    CN121150908A

  • Car insurance secret state modeling method based on multi-key fully homomorphic encryption

    CN121619099A