Multi-key fully homomorphic encryption method supporting multiple hops
By introducing a trusted third-party and user private key update mechanism in multi-key full homomorphic encryption, the problem of new users joining is solved, the multi-hop function of ciphertext and ciphertext update is realized, and the practicality and efficiency of the algorithm are improved.
Patent Information
- Application Number
- CN202510556913.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-08-15
AI Technical Summary
The existing multi-key full homomorphic encryption algorithm cannot support the joining of users, resulting in inefficiency in multi-hop scenarios and the inability to implement ciphertext calculations for new users, limiting its practicality in application scenarios such as medical data.
By introducing trusted third-party selection public parameters, using the user's private key and extended components to update the ciphertext, implementing a multi-key full homomorphic encryption method, supporting the joining of new users and ciphertext updates, and using BFV algorithm to calculate in a ciphertext-free expansion method.
Without increasing the ciphertext size, it supports joining and ciphertext updates for any new users, improving the practicality and efficiency of multi-key full homomorphic encryption and expanding the scope of application.
Smart Images

Figure CN120498626A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer applications and relates to a multi-key fully homomorphic encryption method supporting multiple hops. Background Art
[0002] In the era of big data and cloud computing, as users' demands for data privacy continue to rise, the need for confidential data computing has become a crucial factor in data computing across various industries. Fully homomorphic encryption possesses the inherent property of ciphertext computing, meaning that computations on ciphertext can guarantee the corresponding operations on plaintext. In 2009, Gentry designed the first fully homomorphic encryption algorithm based on ideal lattices, and since then, a large number of algorithm designs and accelerated implementations have emerged.
[0003] Early fully homomorphic encryption could only support operations between users' own ciphertexts, while multi-key fully homomorphic encryption algorithms support operations between ciphertexts of different users. This property perfectly meets the requirements of secure multi-party computation scenarios. Currently, multi-key fully homomorphic encryption algorithms require a ciphertext expansion algorithm to ensure that ciphertexts of different users can be used for secret state computation. However, this step currently requires a large amount of storage space to implement and is very inefficient, making it impractical in implementation. In 2022, Daza et al. designed a multi-key fully homomorphic encryption algorithm based on the BFV algorithm without a ciphertext expansion algorithm, which can achieve multi-user ciphertext computation with efficiency comparable to the BFV algorithm.
[0004] Currently, the multi-key fully homomorphic encryption algorithm based on the BFV algorithm and the ciphertext expansion algorithm cannot implement user joining, that is, the multi-hop function. It is necessary to determine the participating users before the fully homomorphic encryption algorithm begins. This is very limiting in many application scenarios. For example, in the confidential processing of medical data, the newly added patient data cannot be directly added for calculation, resulting in reduced practicality and efficiency. Summary of the Invention
[0005] The technical problem solved by the present invention is: to overcome the shortcomings of the existing technology and propose a multi-hop multi-key fully homomorphic encryption method that supports multi-hop, taking into account the additivity of the ciphertext components of the BFV-type multi-key fully homomorphic encryption without ciphertext extension and the multiplication property that a single encryption can achieve secrets, and can realize the update of ciphertext to include new users, and has broader application prospects.
[0006] The solution of the present invention is:
[0007] A multi-key fully homomorphic encryption method supporting multi-hop, comprising:
[0008] The trusted third party selects a public string a as the user's public parameter and sends the public parameter to all original users participating in the calculation.
[0009] Assume that the number of original users participating in the calculation is N; for 1≤i≤N, each original user i participating in the calculation randomly selects a private key sk i ; From the n-dimensional discrete Gaussian distribution χ n Select the error polynomial e in i ←χ n , calculate the first component b of the public key i ; Use the public string a as the second component of the public key to obtain the public key pk i ; Each original user i participating in the calculation will take the first component b i Send to a trusted third party; the trusted third party calculates the joint public key pk;
[0010] Select BFV type multi-key homomorphic encryption as the underlying algorithm; each original user i participating in the calculation selects the plaintext m to be encrypted i ; Randomly select polynomial u i ∈R2, from the n-element discrete Gaussian distribution χ n Select the error polynomial e in i,1 ,e i,2 ←χ n ;e i,1 The first error polynomial selected for the original user i participating in the calculation, e i,2 The second error polynomial selected for the original user i participating in the calculation; calculate the ciphertext ct i ;
[0011] In the scenario of supporting multi-hop multi-key fully homomorphic encryption, each original user i participating in the calculation is from the n-ary discrete Gaussian distribution χ n The temporary polynomial r of the original user i is selected to participate in the calculation i and the first error component of the original user i participating in the calculation Randomly select polynomial d i,1 ∈R q ; Calculate the polynomial d i,0 ; Each original user i participating in the calculation is from the n-ary discrete Gaussian distribution χ n The second error component of the original user i is selected to participate in the calculation Calculate polynomial d i,2 ; Generate ciphertext D i =(d i,0 |d i,1 |d i,2 ), as an extended component, and make it public data;
[0012] When a new user with serial number N+1 is added, the public string a is used to generate the private key sk N+1 =s N+1 and public key pk N+1 =(b N+1,a)=([-a·s N+1 +e N+1 ] q ,a);
[0013] For any original user i participating in the calculation, 1≤i≤N, user N+1 uses b N+1 Respectively with the polynomial d i,0 and the polynomial d i,1 Multiply and calculate the updated variable K i , and K i It is sent to the original user i who participated in the calculation;
[0014] Each original user i receives K i =(k i,0 |k i,1 ) After that, the original user i who participated in the calculation actively updates the component L i,0 =[k i,0 +k i,1 s i ] q , and L i,0 Send to a trusted third party;
[0015] For any original user i participating in the calculation, user N+1 randomly selects the error polynomial Calculate the passive update component L of the original user i participating in the calculation i,1 , and all L i,1 and public key pk N+1 Send to a trusted third party;
[0016] The trusted third party calculates the new ciphertext nct decrypted by user 1,…,N,N+1 for any original ciphertext ct=(c0,c1) that can be decrypted by user 1,…,N,N+1; updates the new ciphertext to nct; and updates the new joint public key pk;
[0017] When no new users are added, the original encryption status is maintained and no processing is performed.
[0018] In the above-mentioned multi-key fully homomorphic encryption method supporting multiple hops, the public string a is:
[0019]
[0020] Where q represents the modulus;
[0021] represents the set of integers modulo q;
[0022] R q represents a polynomial ring of modulus q;
[0023] n represents the polynomial ring Rq Dimensionality;
[0024] Any a=a0+a1x+…+a n-1 x n-1 ∈R q represents a polynomial; all coefficients in, Represents real numbers Round down.
[0025] In the above-mentioned multi-key fully homomorphic encryption method supporting multi-hop, the private key sk i for:
[0026]
[0027] Where s i represents the private key of user i;
[0028] represents a polynomial ring with modulus 2;
[0029] represents the binary set {0,1};
[0030] The first component b i for:
[0031] b i =[-a·s i +e i ] q
[0032] The public key pk i for:
[0033] pk i =(b i ,a)=([-as i +e i ] q ,a).
[0034] In the above-mentioned multi-key fully homomorphic encryption method supporting multi-hop, the trusted third party i All b i Add them together to get the joint public key pk:
[0035]
[0036] In the above-mentioned multi-key fully homomorphic encryption method supporting multi-hop, the plaintext m i for:
[0037]
[0038] Where t is the modulus of the plaintext;
[0039] R t represents a polynomial ring with modulus t;
[0040] Represents the set of integers modulo t.
[0041] In the above-mentioned multi-key fully homomorphic encryption method supporting multi-hop, the ciphertext ct i for:
[0042] ct i =(ct i [0],ct i [1])
[0043] Among them, ct i [0] is:
[0044]
[0045] Where Δ represents the scaling factor,
[0046] Among them, ct i [1] is:
[0047] ct i [1]=[a·u i +e i,2 ] q .
[0048] In the above-mentioned multi-key fully homomorphic encryption method supporting multiple hops, the polynomial d i,0 for:
[0049]
[0050] The polynomial d i,2 for:
[0051]
[0052] In the above-mentioned multi-key fully homomorphic encryption method supporting multi-hop, the K i The calculation method is:
[0053] K i =(k i,0 |k i,1 )
[0054] Where k i,0 K i The first polynomial of k i,0 =[b N+1 ·d i,0 ] q ;
[0055] k i,1 K i The second polynomial of k i,1 =[b N+1 ·d i,1 ] q .
[0056] In the above-mentioned multi-key fully homomorphic encryption method supporting multi-hop, the L i,1 The calculation method is:
[0057]
[0058] In the above-mentioned multi-key fully homomorphic encryption method supporting multiple hops, the new ciphertext nct is:
[0059]
[0060] The new joint public key pk is:
[0061]
[0062] The beneficial effects of the present invention compared with the prior art are:
[0063] (1) The present invention can support the addition of any new user and the updating of ciphertext and joint public key under the premise of ensuring that the ciphertext size remains unchanged, which is conducive to promoting the practical application of multi-key homomorphic encryption algorithm;
[0064] (2) When a user pre-joins the operation, the present invention uses its own public and private keys and the extended components of the original user to update the ciphertext so that the private key corresponding to the ciphertext contains the new user, thereby realizing the multi-hop function of multi-key fully homomorphic encryption;
[0065] (3) The present invention takes into account the additivity of the ciphertext components of the BFV-type multi-key fully homomorphic encryption without ciphertext expansion and the multiplication property of the secret that can be achieved by a single encryption, and can realize the update of the ciphertext to include new users, which has a broader application prospect. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] Figure 1 This is a flowchart of the multi-key fully homomorphic encryption that supports multiple hops in the present invention;
[0067] Figure 2 Schematic diagram of the interaction process between users and a trusted third party in the present invention. DETAILED DESCRIPTION
[0068] The present invention will be further described below with reference to the embodiments.
[0069] The present invention provides a multi-key fully homomorphic encryption method that supports multiple hops. It takes into account the additivity of the ciphertext components of the BFV-type multi-key fully homomorphic encryption without ciphertext extension and the multiplication property that a single encryption can achieve secrets. It can realize the update of ciphertext to include new users and has broader application prospects.
[0070] Support multi-hop multi-key fully homomorphic encryption methods, such as Figure 1 As shown, the specific steps include:
[0071] The trusted third party selects a public string a as the user's public parameter and sends the public parameter to all participating users. The public string a is:
[0072]
[0073] Where q represents the modulus;
[0074] represents the set of integers modulo q;
[0075] R q represents a polynomial ring of modulus q;
[0076] n represents the polynomial ring R q Dimensionality;
[0077] Any a=a0+a1x+…+a n-1 x n-1 ∈R q represents a polynomial; all coefficients in, Represents real numbers Round down.
[0078] Assume that the number of original users participating in the calculation is N; for 1≤i≤N, each original user i participating in the calculation randomly selects a private key sk i ; From the n-dimensional discrete Gaussian distribution χ n Select the error polynomial e in i ←χ n , calculate the first component b of the public key i ; Use the public string a as the second component of the public key to obtain the public key pk i ; Each original user i participating in the calculation will take the first component b i Send to a trusted third party; the trusted third party calculates the joint public key pk.
[0079] Private key sk i for:
[0080]
[0081] Where s iRepresents the private key of the original user i who participated in the calculation;
[0082] represents a polynomial ring with modulus 2;
[0083] represents the binary set {0,1};
[0084] The first component b i for:
[0085] b i =[-a·s i +e i ] q
[0086] The public key pk i for:
[0087] pk i =(b i ,a)=([-as i +e i ] q ,a).
[0088] Trusted third party pk i All b i Add them together to get the joint public key pk:
[0089]
[0090] Select BFV type multi-key homomorphic encryption as the underlying algorithm; each original user i participating in the calculation selects the plaintext m to be encrypted i ; Randomly select polynomial u i ∈R2, from the n-element discrete Gaussian distribution χ n Select the error polynomial e in i,1 ,e i,2 ←χ n ;e i,1 The first error polynomial selected for the original user i participating in the calculation, e i,2 The second error polynomial selected for the original user i participating in the calculation; calculate the ciphertext ct i .
[0091] Plaintext m i for:
[0092]
[0093] Where t is the modulus of the plaintext.
[0094] R t Represents the ring of polynomials modulo t.
[0095] Represents the set of integers modulo t.
[0096] Ciphertext ct i for:
[0097] ct i =(ct i [0],ct i [1])
[0098] Among them, ct i [0] is:
[0099]
[0100] Where Δ represents the scaling factor,
[0101] Among them, ct i [1] is:
[0102] ct i [1]=[a·u i +e i,2 ] q .
[0103] In the scenario of supporting multi-hop multi-key fully homomorphic encryption, each original user i participating in the calculation is from the n-ary discrete Gaussian distribution χ n The temporary polynomial r of the original user i is selected to participate in the calculation i and the first error component of the original user i participating in the calculation Randomly select polynomial d i,1 ∈R q ; Calculate the polynomial d i,0 ; Each original user i participating in the calculation is from the n-ary discrete Gaussian distribution χ n The second error component of the original user i is selected to participate in the calculation Calculate polynomial d i,2 ; Generate ciphertext D i =(d i,0 |d i,1 |d i,2 ), as an extended component, and make it public data.
[0104] Among them, the polynomial d i,0 for:
[0105]
[0106] Polynomial d i,2 for:
[0107]
[0108] When a new user with serial number N+1 is added, the public string a is used to generate the private key sk N+1 =s N+1 and public key pk N+1 =(b N+1 ,a)=([-a·s N+1 +e N+1 ] q ,a).
[0109] For any original user i participating in the calculation, 1≤i≤N, user N+1 uses b N+1 Respectively with the polynomial d i,0 and the polynomial d i,1 Multiply and calculate the updated variable K i , and K i It is sent to the original user i who participated in the calculation.
[0110] Among them, K i The calculation method is:
[0111] K i =(k i,0 |k i,1 )
[0112] Where k i,0 K i The first polynomial of k i,0 =[b N+1 ·d i,0 ] q ;
[0113] k i,1 K i The second polynomial of k i,1 =[b N+1 ·d i,1 ] q .
[0114] Each original user i participating in the calculation receives K i =(k i,0 |k i,1 ) After that, the original user i who participated in the calculation actively updates the component L i,0 =[k i,0 +k i,1 s i ] q , and L i,0 Send to a trusted third party.
[0115] For any original user i participating in the calculation, user N+1 randomly selects the error polynomial Calculate the passive update component L of the original user i participating in the calculation i,1 , and all L i,1and public key pk N+1 Send to a trusted third party.
[0116] Among them, L i,1 The calculation method is:
[0117]
[0118] The trusted third party calculates, for any ciphertext ct = (c0, c1) that can be decrypted by the original users 1, ..., N participating in the calculation, a new ciphertext nct that can be decrypted by the original users 1, ..., N, N+1 participating in the calculation; updates the new ciphertext to nct; and updates the new joint public key pk.
[0119] The new ciphertext nct is:
[0120]
[0121] The new joint public key pk is:
[0122]
[0123] The interaction process between users and trusted third parties is as follows: Figure 2 shown.
[0124] Example
[0125] For the tripartite homomorphic operation requirement, that is, N=3, the parameters n=2048 and q=2 can be used. 62 、 For example, here It represents discrete Gaussian sampling with a standard deviation of 3.19 and an expectation of 0, and a security level of λ = 128.
[0126] The trusted third party first calls the pseudo-random string generation algorithm, randomly selects n seeds to generate n 62-bit random strings, set as a0,…,a n-1 ,but Then send a to N users.
[0127] After receiving a, each original user i participating in the calculation randomly selects a binary private key That is, each coefficient of the private key is selected from 0 and 1. Then calculate the public key pk i =(b i ,a)=([-(a·s i +e i )] q ,a), and pk i Send to a trusted third party.
[0128] The trusted third party sums the first components of all user public keys to obtain a joint public key And send pk to all original users who participated in the calculation.
[0129] Each original user i participating in the calculation has a plaintext Randomly select u i ∈R2 and error disturbance e i,1 ,e i,2 ←X n , where X is a discrete Gaussian distribution on an integer, and the ciphertext is obtained
[0130] The following requires that each original user i participating in the calculation adopts a single encryption method with s i To u i Encryption is performed.
[0131] From the discrete Gaussian distribution χ n Choose the polynomial r and the perturbation Randomly select a polynomial d1∈R q ,calculate From the discrete Gaussian distribution χ n Select the perturbation calculate Generate ciphertext D i =(d i,0 |d i,1 |d i,2 ) as an extended component and make it public data.
[0132] For the newly joined user N+1, use the public string a to generate the private key sk N+1 =s N+1 and public key pk N+1 =(b N+1 ,a)=([-as N+1 +e N+1 ] q ,a).
[0133] For all original users i participating in the calculation, 1≤i≤N, user N+1 uses b N+1 Respectively with d i,0 and d i,1 Multiply them together to get K i =(k i,0 |k i,1 )=.[b N+1 d i,0 ] q |[b N+1 d i,1 ] q / and sends it to the original user i who participated in the calculation.
[0134] For all original users i participating in the calculation, 1≤i≤N, user N+1 randomly selects the perturbation e N+1 ←χ n , calculate L i,1 =[d i,2 s N+1 +2e N+1 ] q , and all k i,2 and public key pk N+1 Send to a trusted third party.
[0135] Each original user i participating in the calculation receives K i =(k i,0 |k i,1 ) and then calculate L i,0 =[k i,0 +k i,1 s i ] q , and L i,0 Send to a trusted third party.
[0136] A trusted third party calculates ct = (c0, c1) for any ciphertext (including the ciphertext of each user or the ciphertext after homomorphic operation). Then update the ciphertext to nct, and the joint public key to And send it to all users participating in the calculation.
[0137] When no new users are added, the original encryption status is maintained and no processing is performed.
[0138] Although the present invention has been disclosed above in terms of preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art may make possible changes and modifications to the technical solutions of the present invention by using the methods and technical contents disclosed above without departing from the spirit and scope of the present invention. Therefore, any simple modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solutions of the present invention shall fall within the scope of protection of the technical solutions of the present invention.
Claims
1. A multi-key fully homomorphic encryption method supporting multi-hop, characterized by: include: The trusted third party selects a public string a as the user's public parameter; Send the public parameters to all original users participating in the computation; Assume that the number of original users participating in the calculation is N; for 1≤i≤N, each original user i participating in the calculation randomly selects a private key sk i ; From the n-dimensional discrete Gaussian distribution χ n Select the error polynomial e in i ←χ n , calculate the first component b of the public key i ; Use the public string a as the second component of the public key to obtain the public key pk i ; Each original user i participating in the calculation will take the first component b i Send to a trusted third party; The trusted third party calculates the joint public key pk; Select BFV type multi-key homomorphic encryption as the underlying algorithm; each original user i participating in the calculation selects the plaintext m to be encrypted i ; Randomly select polynomial u i ∈R2, from the n-element discrete Gaussian distribution χ n Select the error polynomial e in i,1 ,e i,2 ←χ n ; e i,1 The first error polynomial selected for the original user i participating in the calculation, e i,2 The second error polynomial selected for the original user i participating in the calculation; calculate the ciphertext ct i ; In the scenario of supporting multi-hop multi-key fully homomorphic encryption, each original user i participating in the calculation is from the n-ary discrete Gaussian distribution χ n The temporary polynomial r of the original user i is selected to participate in the calculation i and the first error component of the original user i participating in the calculation Randomly select polynomial d i,1 ∈R q ; Calculate the polynomial d i,0 ; Each original user i participating in the calculation is from the n-ary discrete Gaussian distribution χ n The second error component of the original user i is selected to participate in the calculation Calculate polynomial d i,2 ; Generate ciphertext D i =(d i,0 |d i,1 |d i,2 ), as an extended component, and make it public data; When a new user with serial number N+1 is added, the public string a is used to generate the private key sk N+1 =s N+1 and public key pk N+1 =(b N+1 ,a)=([-a·s N+1 +e N+1 ] q ,a); For any original user i participating in the calculation, 1≤i≤N, user N+1 uses b N+1 Respectively with the polynomial d i,0 and the polynomial d i,1 Multiply and calculate the updated variable K i , and K i It is sent to the original user i who participated in the calculation; Each original user i receives K i =(k i,0 |k i,1 ) After that, the original user i who participated in the calculation actively updates the component L i,0 =[k i,0 +k i,1 s i ] q , and L i,0 Send to a trusted third party; For any original user i participating in the calculation, user N+1 randomly selects the error polynomial Calculate the passive update component L of the original user i participating in the calculation i,1 , and all L i,1 and public key pk N+1 Send to a trusted third party; The trusted third party calculates the new ciphertext nct decrypted by user 1,…,N,N+1 for any original ciphertext ct=(c0,c1) that can be decrypted by user 1,…,N,N+1; updates the new ciphertext to nct; and updates the new joint public key pk; When no new users are added, the original encryption status is maintained and no processing is performed.
2. The multi-key fully homomorphic encryption method supporting multiple hops according to claim 1, characterized in that: The public string a is: Where q represents the modulus; represents the set of integers modulo q; R q represents a polynomial ring of modulus q; n represents the polynomial ring R q Dimensionality; Any a=a0+a1x+…+a n-1 x n-1 ∈R q represents a polynomial; all coefficients i=0,1,……,n-1; where Represents real numbers Round down.
3. The multi-key fully homomorphic encryption method supporting multiple hops according to claim 2, characterized in that: The private key sk i for: Where s i represents the private key of user i; represents a polynomial ring with modulus 2; represents the binary set {0,1}; The first component b i for: b i =[-a·s i +e i ] q The public key pk i for: pk i =(b i ,a)=([-as i +e i ] q ,a)。 4. The multi-key fully homomorphic encryption method supporting multiple hops according to claim 3, characterized in that: The trusted third party pk i All b i Add them together to get the joint public key pk:
5. The multi-key fully homomorphic encryption method supporting multi-hop according to claim 3, characterized in that: The plaintext m i for: Where t is the modulus of the plaintext; R t represents a polynomial ring with modulus t; Represents the set of integers modulo t.
6. The multi-key fully homomorphic encryption method supporting multi-hop according to claim 5, characterized in that: The ciphertext ct i for: ct i =(ct i [0],ct i [1]) Among them, ct i [0] is: Where Δ represents the scaling factor, Among them, ct i [1] is: ct i [1]=[a·u i +e i,2 ] q 。 7. The multi-key fully homomorphic encryption method supporting multiple hops according to claim 6, characterized in that: The polynomial d i,0 for: The polynomial d i,2 for:
8. The multi-key fully homomorphic encryption method supporting multiple hops according to claim 7, characterized in that: The K i The calculation method is: K i =(k i,0 |k i,1 ) Where k i,0 K i The first polynomial of k i,0 =[b N+1 ·d i,0 ] q ; k i,1 K i The second polynomial of k i,1 =[b N+1 ·d i,1 ] q .
9. The multi-key fully homomorphic encryption method supporting multiple hops according to claim 8, characterized in that: The L i,1 The calculation method is:
10. The multi-key fully homomorphic encryption method supporting multi-hop according to claim 9, characterized in that: The new ciphertext nct is: The new joint public key pk is: