Novel bootstrap method based on multi-key fully homomorphic encryption

Through the multi-key error learning (MK-LWE) ciphertext two-layer bootstrapping method and RLWE and NTRU hybrid encryption architecture based on grid cryptography, the calculation efficiency and ciphertext size problems of the multi-key full-homomorphic encryption scheme are solved, and efficient multi-party computing is achieved.

CN120528577APending Publication Date: 2025-08-22INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510817335.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The existing multi-key full-homomorphic encryption scheme has low computing efficiency, high bootstrap process complexity, and large key size, making it difficult to adapt to large-scale multi-party computing scenarios.

Method used

The two-layer bootstrapping method of multi-key error learning (MK-LWE) ciphertext based on grid cryptography is adopted, combining self-isomorphic computing and intra-grouping algorithms, and using a hybrid encryption architecture of RLWE and NTRU, a parallel friendly computing model is designed, and the rotation angle and grouping computing strategy is adjusted by self-isomorphicly, reducing the overhead of key switching and supporting a high-performance computing environment.

Benefits of technology

It significantly improves the computing efficiency, improves the bootstrap speed by 3 times, reduces the volume of cipher text by 40%, and reduces the number of homomorphic multiplication by 50%, adapts to large-scale multi-party computing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528577A_ABST
    Figure CN120528577A_ABST
Patent Text Reader

Abstract

The invention discloses a novel bootstrap method based on multi-key fully homomorphic encryption. The method comprises the steps that an ith participant generates an evaluation key Evki, a joint encryption ciphertext ueci, a public key pki and a key switching key mkski of the ith participant; according to a multi-key ciphertext # imgabs0 # rotation polynomial r (X), blind rotation keys {Evki, ueci, pki} i belongs to [k] generated by k participants and k key switching keys {mkski} i belongs to [k], the method comprises the following steps: 1) calculating homomorphic decryption of the ciphertext # imgabs1 # by using a blind rotation algorithm to obtain ACC ''; 2) extracting a constant term of ACC ''to obtain a multi-key LWE ciphertext # imgabs2 # 3) switching the multi-key LWE ciphertext # imgabs3 # from a large modulus to a small modulus q to obtain a ciphertext # imgabs4 # 4) switching the ciphertext # imgabs5 # to an LWE ciphertext ring with a dimension of n to obtain a key switching # imgabs7 # of a ciphertext # imgabs6 #
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and relates to a novel bootstrapping method based on multi-key fully homomorphic encryption. Background Art

[0002] Fully homomorphic encryption (FHE) is a specialized cryptographic system that allows operations to be performed directly on ciphertext without decrypting the data. In many real-world scenarios, computational tasks often involve multiple parties. Participants need to collaborate on data provided by a single party without compromising data privacy. To address this situation, multi-key FHE (MKFHE) schemes have been developed.

[0003] In 2019, Chen et al. proposed a multi-key version of TFHE, which designed a hybrid product to compute the outer product of GSW and RLWE ciphertexts. In 2024, Kwak et al. improved Chen's scheme, achieving nearly linear time complexity. They split a multi-key ciphertext into multiple single-key ciphertexts and then computed blind rotations of these single-key ciphertexts in parallel. In this scheme, computing blind rotations of the single-key ciphertexts accounts for a significant portion of the total runtime, meaning that the primary limitation to the efficiency of MKFHE becomes the bootstrapping algorithm.

[0004] Regarding the bootstrapping technology of multi-key fully homomorphic encryption, the implementation scheme closest to the present invention is the work of Hao Chen et al. in ASIACRYPT 2019, which was subsequently extended by Hyesun Kwak in PKC 2024. References: Chen, H., Chillotti, I., Song, Y. (2019). Multi-Key Homomorphic Encryption from TFHE. In: Galbraith, S., Moriai, S. (eds) Advances in Cryptology–ASIACRYPT 2019. ASIACRYPT2019; Kwak, H., Min, S., Song, Y. (2024). Towards Practical Multi-key TFHE: Parallelizable, Key-Compatible, Quasi-linear Complexity. In: Tang, Q., Teague, V. (eds) Public-Key Cryptography–PKC 2024. PKC 2024.

[0005] The computational environment of the solution: real torus is the set of real numbers modulo 1. For a power-of-two integer N, this paper writes

[0006] Symbolic explanation of the scheme: This paper uses lowercase bold to represent vectors (such as a) and uppercase bold to represent matrices (such as A). The inner product of two vectors a and b is expressed as<a,b> In this paper, we use x←S to indicate that x is uniformly sampled from the set S. For real α≥0, represents the variance α 2 When sampling polynomials from T, we use represents a distribution on T that is independent of the variance β when the real β ≥ 0 2 The N coefficients of the output polynomial are sampled using a Gaussian distribution.

[0007] Hyesun Kwak's hybrid multiplication and outer product algorithm:

[0008] ●Setup(1 λ ): Input security parameter λ, output a set of LWE parameters (ring dimension n, key distribution χ, noise parameter α), a set of RLWE parameters (ring dimension N, key distribution χ′, noise parameter β), two sets of decomposition basis (vector g′=[B′ -1 ,...,B′ -d ] and its inverse process h′: Vector g=[B -1 ,...,B -d ] and its reverse process h:T→R d ), a public random string a←T d .

[0009] KeyGen(i): The i-th user generates an LWE private key z i ←χ′, a RLWE private key s i ←χ and the corresponding public key b i =-s i a+e(mod 1).

[0010] UniEnc(s i ,u): Input a plaintext u∈R, user i calculates and outputs

[0011] d i =r i a+u g+e1 (mod 1)

[0012] F i =[f i,0 |f i,1 ],f i,0 =-s i ·f i,1 +r i g+e2(mod 1)

[0013] ● Input a MK-RLWE ciphertext A joint encryption generated by the i-th user (d i ,F i ) and the associated public key {b j} j∈[k] , calculate and output a MK-RLWE ciphertext as follows:

[0014] 1. Calculation

[0015] u j = <h(c j ),d i For 0≤j≤k

[0016]

[0017] 2. Output in

[0018]

[0019] ● Input a MK-RLWE ciphertext A RLEV ciphertext C i ∈T d×2 , a joint encryption generated by the i-th user (d i ,F i ) and the associated public key {b j} j∈[k] , calculate and output a MK-RLWE ciphertext as follows:

[0020] 1. Calculate (x j ,y j )←c j ⊙C i For 0≤j≤k. Let

[0021] 2. Calculation And output

[0022] Hyesun Kwak's multi-key bootstrapping algorithm:

[0023] BootKeyGen(i): The i-th user generates and publishes a series of blind rotating keys brk i ={brk i,j ←RGSW.Enc(t i ;z i,j )} j∈[n] , a relinearization key rlk i ←UniEnc(s i; t i ),a series of key-switching keys {ksk i,j} j∈N for switching RLWE keys to LWE keys.

[0024] ● Input an MK-LWE ciphertext and the corresponding blind rotation key and public key {b j , brk i}, i∈[k] and output the result of the homomorphic decryption of the ciphertext:

[0025] 1. Initialization

[0026] 2. For 1 ≤ i ≤ k, 0 ≤ j < n, calculate

[0027]

[0028] Defects of existing implementation schemes: The existing schemes have low computational efficiency because: The large number of multiplications required in the bootstrapping process leads to high computational complexity, and the key size required for bootstrapping is large. Summary of the Invention

[0029] Aiming at the defects of the existing schemes, such as the large number of multiplications and the large key size, the purpose of the present invention is to provide a novel bootstrapping method based on multi-key fully homomorphic encryption. The present invention designs a two-layer bootstrapping method based on multi-key learning with error (MK-LWE) ciphertext under the NTRU assumption, and selects an automorphism to calculate the blind rotation. Under the same parameter settings, the computational complexity of the present invention is reduced by nearly half compared with the existing schemes, greatly improving the computational efficiency.

[0030] The present invention aims to solve the key problems in the practical application of multi-key fully homomorphic encryption (MKFHE), and the main functional objectives include:

[0031] (1) Improve computational efficiency: Reduce the time complexity of the bootstrapping operation from a quadratic function of the existing scheme to near-linear to adapt to large-scale multi-party computing scenarios.

[0032] (2) Reduce the ciphertext size: Compress the ciphertext volume by improving the encryption structure and the outer product algorithm, reducing the storage and communication overhead.

[0033] (3) Enhance the parallel computing ability: Design a grouped inner product algorithm to support parallel computing architectures such as multi-core CPUs and GPUs, improving the computational throughput.

[0034] The core technical principle of this invention is based on lattice-based cryptography, combined with multi-key fully homomorphic encryption (MKFHE) and bootstrapping technology, and mainly relies on the following theories and methods:

[0035] (1) Automorphism-based ciphertext rotation: Automorphism technology is used to adjust the rotation angle of the polynomial ring during the ciphertext calculation process to reduce the computational overhead of key switching.

[0036] (2) Through the group inner product algorithm (GIPEval), large-scale ciphertext calculations are decomposed into multiple parallel subtasks to improve computational efficiency.

[0037] (3) Hybrid encryption of RLWE and NTRU: RLWE (Ring Learning With Errors) is used to construct a joint encryption scheme to reduce the ciphertext size while maintaining high security; NTRU (NTRUEncrypt) is used for efficient homomorphic multiplication calculations. Its ciphertext size is about half of RLWE, but it needs to be combined with noise control technology to prevent security vulnerabilities.

[0038] (4) Two-layer bootstrapping architecture: The first layer (MK-LWE bootstrapping): splits the multi-key ciphertext into single-key ciphertext and implements homomorphic decryption through the blind rotation algorithm. The second layer (modulus switching + key switching): downgrades the large modulus ciphertext to a small modulus to reduce computational complexity, and finally switches back to the target key space.

[0039] (5) Parallel-friendly computing model: The group computing strategy is adopted to make the algorithm naturally support parallelization and suitable for high-performance computing environments such as GPU and FPGA.

[0040] This paper proposes an efficient and secure multi-key fully homomorphic encryption bootstrapping scheme, which solves the bottleneck problems of existing schemes through four key technical breakthroughs.

[0041] First, we innovatively combined automorphism technology with group computing to design a parallel-friendly group inner product algorithm. By dynamically adjusting the rotation angle and group computing strategy, we reduced the self-ordering time complexity from quadratic to near-linear, significantly improving computational efficiency.

[0042] Secondly, a hybrid encryption architecture of RLWE and NTRU was constructed, introducing a joint encryption method of public random strings and temporary private keys, which compressed the ciphertext size by about 40% while ensuring security, and optimized the noise control mechanism of NTRU to resist sub-lattice attacks.

[0043] Next, a cross-scheme hybrid outer product algorithm was proposed, which achieved efficient calculation of NTRU ciphertext and MK-RLWE ciphertext for the first time. The number of homomorphic multiplications was reduced by decomposing the basis mapping. At the same time, a dynamic public key collaboration mechanism was designed to simplify key management in multi-party computing scenarios.

[0044] Finally, an innovative two-layer bootstrapping architecture is employed, first implementing MK-LWE bootstrapping through blind rotations, and then downgrading to LWE ciphertext through modulus switching and key switching. This effectively controls noise growth and supports longer computation chains. These technical innovations work together to increase bootstrapping speed by three times (with eight parties involved), reduce ciphertext size by 40%, and reduce the number of homomorphic multiplications by 50%, all while maintaining 128-bit security strength. This addresses key bottlenecks in efficiency, security, and scalability of existing solutions, providing a superior solution for applications such as privacy-preserving computing.

[0045] The technical solution of the present invention is:

[0046] A novel bootstrapping method based on multi-key fully homomorphic encryption, comprising the following steps:

[0047] The i-th participant generates its own evaluation key Evk i , joint encryption ciphertext uec i 、Public key pk i , key switching key mksk i ; i = 1 ~ k, k is the total number of participants;

[0048] According to the multi-key ciphertext Rotation polynomial r(X), blind rotation key {Evk generated by k participants i ,uec i ,pk i} i∈[k] and k key switching keys {mksk i} i∈[k] , perform steps 1) to 4):

[0049] 1) Calculate multi-key ciphertext using blind rotation algorithm Homomorphic decryption is performed to obtain the calculation result ACC″ of the multi-key ciphertext blind rotation;

[0050] 2) Extract the constant term of ACC″ and obtain a multi-key LWE ciphertext

[0051] 3) Multi-key LWE ciphertext Switch from the large modulus to the small modulus q and get the ciphertext

[0052] 4) The ciphertext Switch to the LWE ciphertext ring of dimension n and get the ciphertext Key switching

[0053] Furthermore, the method for obtaining the calculation result ACC of multi-key ciphertext rotation is as follows:

[0054] (1) Split the multi-key ciphertext into k single-key ciphertexts {ct i =(0, a i )} i∈[k] and a determined value b; a i is the i-th random string in the multi-key ciphertext ;

[0055] (2) Calculate and initialize where Δ is the parameter used for message encoding, N is the dimension of the RLWE ciphertext ring, and q is the LWE ciphertext modulus;

[0056] (3) Let i = 0; i++; i ≤ k, homomorphically calculate the inner product {ACC i,m ∶= GIPEval(a i , Evk)} i∈[k],m∈[l] :

[0057] ① Let j = 0; j++; j < n, calculate w j ′ = w j -1 mod 2N; where a j is the j-th random string in the multi-key ciphertext ;

[0058] ② Let m = 0; m++; m < l, initialize where l is the number of groups;

[0059] ③ Let r = 0; r++; Iteratively calculate

[0060] where is the vector NTRU ciphertext outer product operator. For vectors c, c′, ⊙ is the outer product operation, c d-1 is the d-th component of the vector c;

[0061] ④ When m = l - 1, calculate

[0062] ⑤ Output {ACC m} l∈[m] ;

[0063] (4) Let \(i = 0\); \(i++\); \(i\leq k\) and \(m = 0\); \(m++\); \(m < l\), recursively calculate \(ACC := ExtProd(ACC i,m , uec i , ACC, \{pk j \} j∈[k] ):

[0064] ① Let \(j = 0\); \(j++\); \(j\leq k\), calculate \(ACC′(j)=ACC(j)\odot ACC i,m ;

[0065] ② Calculate and output \(ACC := HProd(uec i =(d i,0 , d i,1 ), ACC′, \{pk j \} j∈[k] );

[0066] (5) Output the calculation result of multi-key ciphertext rotation

[0067] Furthermore, the method for calculating and outputting \(ACC := HProd(uec i =(d i,0 , d i,1 ), ACC′, \{pk j \} j∈[k] ) is:

[0068] a: Initialize \(v := 0\);

[0069] b: For \(j = 0\); \(j++\); \(j\leq k\), calculate \(u j =<h(ACC′(j)), d i,0 >, \(v = v+<h(ACC′(j)), pk j >;

[0070] c: For \(j = 0\); \(j++\); \(j\leq k\), calculate h(·) is a mapping function, represents a mapping with decomposition basis \(B\), and its inverse process where the decomposition dimension For any ring element \(a\in R Q , there exists such that i.e., <h(a), g>=a mod Q;

[0071] d: Output a multi-key ciphertext

[0072] Furthermore, the method for each party to generate an evaluation key is: The user inputs a private key of their own for encrypting the LWE ciphertext and a private key f∈R for encrypting the NTRU ciphertext Q , calculate the blind rotation key (brk0,brk1,...,brk n );in, For i <n, Calculate the key switching key ksk corresponding to the automorphism t =NTRU′(f(X t ) / f(X)), Finally, the evaluation key Evk corresponding to the group inner product algorithm is output = (brk0, brk1, ..., brk n ;{ksk t} t∈S ).

[0073] Furthermore, each participant generates a joint encrypted ciphertext by: the user inputs his own private key s = s0 + s1X + ... + s n-1 X n-1 ∈R and a private key f∈R used to encrypt the NTRU ciphertext Q , extract the noise vector and a temporary private key r←χ key , using two public random strings Calculate d0 = r·a com +f·g+e0,d1=-s·b com +r·g+e1; output the jointly encrypted ciphertext uec=(d0,d1).

[0074] Furthermore, the method for each participant to generate a public key is as follows: the user inputs his own private key s for encrypting the RLWE ciphertext, extracts a noise vector With the help of a public random string Output public key

[0075] Furthermore, each participant generates a key switching key by: using the user's own private key s∈R Q , a private key used to encrypt the LWE ciphertext Output a key switching key

[0076] The advantages of the present invention are as follows:

[0077] The multi-key fully homomorphic encryption bootstrapping technology proposed in this paper significantly accelerates the bootstrapping of multi-key ciphertexts through four key technological innovations. The group inner product algorithm based on automorphism optimizes the computational path by leveraging the rotation properties of polynomial rings, reducing the time complexity from O(k²) to nearly O(k). The hybrid architecture of RLWE and NTRU leverages the mathematical properties of lattice cryptography to compress the ciphertext space while maintaining security. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] Figure 1 Flowchart of the MKFHE blind rotation algorithm of the present invention. DETAILED DESCRIPTION

[0079] The present invention will be described in further detail below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0080] The present invention first provides the definitions of some basic symbols as follows:

[0081] 1) Let bold lowercase letters represent vectors, such as a, and bold uppercase letters represent matrices, such as A. represents a set of integers, Denote the set of integers modulo q. represents the 2Nth degree cyclotomic polynomial ring, where N is a power of 2, and R=R / qR represents the quotient ring modulo q.

[0082] 2) In the present invention, LWE ciphertext in is a random string, b=-<a,s> +e+m mod q, s is the private key, e is the noise, and m is the message; multi-key ciphertext in is a random string, s1,...,s k is the private key, e is the noise, and m is the message; RLWE ciphertext (b, a)∈R Q ×R Q , where a=a0+a1X+...+a N-1 X N-1 ∈R Q , b=-a·s+e+m mod Q, s is the private key, e is the noise, and m is the message; NTRU ciphertext c∈R Q , where c = g / f + u / f mod Q, f is the private key, g is the noise, and m is the message; vector NTRU ciphertext Among them [B 0 ,B 1 ,...,B d-1 ] is the tool vector, dimension

[0083] 3) Let χ denote the probability distribution, χ σ represents a distribution with standard deviation σ, a←χ means a is drawn uniformly at random from χ. The symbol ∶= denotes assignment, and a∶=b means assigning a to b.

[0084] 4) Order (or ) represents a mapping with a decomposition basis of B, and its inverse process Denoted as tool vector, where the decomposition dimension For any ring element a∈R Q ,exist Make Right now<h(a),g> =a mod Q.

[0085] 5) The present invention defines the vector outer product operation

[0086] The outer product of vector NTRU and vector NTRU Input two vector NTRU ciphertexts with the same private key Encrypt messages u and v separately, and the outer product operation between them is described as follows: c d-1 is the d-th dimension component of vector c.

[0087] Output a vector NTRU ciphertext of the encrypted message uv with the private key unchanged.

[0088] The process of the present invention is as follows Figure 1 As shown, where vNTRU represents vector NTRU ciphertext, represents the vector NTRU multiplication, and ⊙ represents the outer product.

[0089] The present invention defines that there are k users participating in the calculation. Before the calculation, each user participating in the calculation needs to generate a corresponding public key based on his or her own private key. Initially define two public random strings Each user needs to run the following generation algorithm, of which KeySwitchKeyGen is a well-known algorithm and will not be described in detail:

[0090] Evaluation key generation GIPKeyGen(s,f): The user enters his own private key for encrypting LWE ciphertext

[0091] and a private key f∈R for encrypting the NTRU ciphertext Q Among them, s n-1 is the nth dimension component of the private key s, is an n-dimensional integer set with modulus q, R Q is a polynomial ring with modulus Q; calculate the blind rotation key:

[0092] brk0 is the encrypted message using the private key f NTRU' ciphertext

[0093] For i=0;i++;i <n;

[0094]

[0095] Then compute the key-switching key corresponding to the automorphism:

[0096] ksk t =NTRU′(f(X t ) / f(X)), for Where n is the dimension of the LWE ciphertext ring, q is the LWE ciphertext modulus, N is the dimension of the RLWE ciphertext ring, and Q is the RLWE ciphertext modulus.

[0097] Finally, the evaluation key corresponding to the group inner product algorithm is output: Evk=(brk0,brk1,...,brk n ;{ksk t} t∈S ).

[0098] Joint encryption ciphertext UniEnc(s,u): The user enters his own private key s=s0+s1X+...+s for encrypting RLWE ciphertext n-1 X n-1 ∈R and a private key f∈R used to encrypt the NTRU ciphertext Q , extract the noise vector and a temporary private key r←χ key , using two public random strings calculate:

[0099] d0=r·a com +f·g+e0,

[0100] d1=-s·b com +r·g+e1,

[0101] Output the jointly encrypted ciphertext uec = (d0, d1).

[0102] Public key generation PKGen(s): The user enters his own private key s for encrypting RLWE ciphertext and extracts a noise vector With the help of a public random string Output:

[0103]

[0104] Key switching key generation KeySwitchKeyGen(s,s): The user enters his own private key s∈R for encrypting RLWE ciphertext Q , a private key used to encrypt LWE ciphertext Output a key switching key

[0105]

[0106] For the convenience of the following description, for the k users participating in the calculation, let the evaluation key generated by the i-th user be recorded as Evk i , the joint encrypted ciphertext is recorded as uec i , the public key is recorded as pk i , key switching key mksk i .

[0107] The technical solution of the present invention consists of the following core modules nested with each other, each module works together to achieve efficient multi-key bootstrapping, among which EvalAuto, Extract, ModSwitch, and KeySwitch are well-known algorithms and will not be described in detail. Specifically, a noisy multi-key ciphertext is input. The bootstrapping algorithm of the present invention can efficiently output a multi-key ciphertext with low noise The ciphertext keeps the key and the encrypted message unchanged. The number of groups in the grouping algorithm GIPEval is initially set to l.

[0108] MK-LWE ciphertext bootstrapping algorithm: input multi-key ciphertext It is the input of the algorithm, the object of the present invention, a multi-key ciphertext with great noise, the rotation polynomial r(X) is well known, in the present invention Where q is the LWE ciphertext modulus and t is the LWE plaintext modulus. X itself has no specific numerical meaning, it is just a placeholder used to represent the form of the polynomial. For example, the polynomial 1+2X+3X 2 is an abstract expression, where X does not need to be assigned a specific value. The blind rotation key {Evk i ,uec i ,pk i} i∈[k] and k key switching keys {mksk i} i∈[k] , perform the following operations:

[0109] 1. Homomorphic decryption of multi-key ciphertext using the blind rotation algorithm (1) Split the multi-key ciphertext

[0110] into k single-key ciphertexts {ct =(0,a i =(0,a i )} i∈[k] and a determined value b. Here, is a random string, s1,...,s k is the private key, e is the noise, and m is the message.

[0111] (2) Calculate and initialize Δ is the parameter used for message encoding, N is the dimension of the RLWE ciphertext ring, and q is the LWE ciphertext modulus.

[0112] (3) Let i = 0; i++ (i.e., i = i + 1); i ≤ k, and homomorphically calculate the inner product {ACC i,m := GIPEval(a i ,Evk)} i∈[k],m∈[l] :

[0113] ①: Let j = 0; j++; j < n, and calculate w j ' = w[[ID=W]] j -1 mod 2N;

[0114] ②: Let m = 0; m++; m < l, and initialize Assign a value to the variable ACC m The assignment is := is the assignment symbol.

[0115] ③: Let r = 0; r++; Iteratively calculate the ACC m variable iteratively, such as where is the vector NTRU ciphertext outer product operator defined in this invention;

[0116]

[0117] ④: When m = l - 1, calculate

[0118] ⑤: Output {ACC m} l∈[m] .

[0119] ​(4) Let \(i = 0\); \(i++\); \(i\leq k\) and \(m = 0\); \(m++\); \(m < l\), recursively calculate \(ACC := ExtProd(ACC i,m , uec i , ACC, \{pk j \} j∈[k] ):

[0120] ①: Let \(j = 0\); \(j++\); \(j\leq k\), calculate \(ACC′(j)=ACC(j)\odot ACC i,m ;\(

[0121] ②: Calculate and output \(ACC := HProd(uec i =(d i,0 , d i,1 ), ACC′, \{pk j \} j∈[k] ); where, \(d i,0 =r i \cdot a com +f i \cdot g i +e i,0 , d i,1 =-s i \cdot b com +r i \cdot g<000018​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​4. Calculate ciphertext The key switch switches the ciphertext to the LWE ciphertext ring with dimension n, and outputs

[0130] Experimental data:

[0131] For the number of participants k=2, 4, 8, the present invention provides two sets of parameter selections as shown in the following table for reference, but is not limited to these two sets of parameter selections.

[0132]

[0133] For the number of participants k = 2, 4, 8, and different degrees of parallelism, the running time of the present invention based on two security strengths is shown in the following table.

[0134]

[0135] The comparison of the time for running a NAND gate and the bootstrap key size of the present invention with the existing solution KMS24 is shown in the following table.

[0136]

[0137] While specific embodiments of the present invention have been disclosed for illustrative purposes, intended to facilitate understanding and implementation of the present invention, those skilled in the art will appreciate that various substitutions, variations, and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the disclosure of the preferred embodiments, and the scope of protection claimed in the present invention shall be determined by the scope of the claims.

Claims

1. A novel bootstrapping method based on multi-key fully homomorphic encryption, comprising the following steps: The i-th participant generates its own evaluation key Evk i , joint encryption ciphertext uec i 、Public key pk i , key switching key mksk i ; i = 1 ~ k, k is the total number of participants; According to the multi-key ciphertext Rotation polynomial r(X), blind rotation key {Evk generated by k participants i ,uec i ,pk i } i∈[k] and k key switching keys {mksk i } i∈[k] , perform steps 1) to 4): 1) Calculate multi-key ciphertext using blind rotation algorithm Homomorphic decryption is performed to obtain the calculation result ACC″ of the multi-key ciphertext blind rotation; 2) Extract the constant term of ACC″ and obtain a multi-key LWE ciphertext 3) Multi-key LWE ciphertext Switch from the large modulus to the small modulus q and get the ciphertext 4) The ciphertext Switch to the LWE ciphertext ring of dimension n and get the ciphertext Key switching 2. The method according to claim 1, characterized in that The method for obtaining the calculation result ACC of the multi-key ciphertext blind rotation is: (1) Multi-key ciphertext Split into k single-key ciphertexts {ct i =(0,a i )} i∈[k] and a certain value b; a i Multi-key ciphertext The i-th random string in ; (2) Calculate and initialize Where Δ is the parameter used for message encoding, N is the dimension of the RLWE ciphertext ring, and q is the LWE ciphertext modulus; (3) Let i = 0; i++; i ≤ k, the inner product {ACC i,m :=GIPEval(a i ,Evk)} i∈[k],m∈[l] : ①Let j = 0; j++; j < n, calculate w j ′ = w j -1 mod 2N; where a j is the j-th random string in the multi-key ciphertext ; ② Let m = 0; m++; m < l, initialize where l is the number of groups; ③Let r=0; r++; Iterative calculation in, is the vector NTRU ciphertext outer product operator, for vectors c, c′, ⊙ is the outer product operation, c d-1 is the d-th dimension component of vector c; ④When m=l-1, calculate ⑤ Output {ACC m } l∈[m] ; (4) Let i = 0; i++; i ≤ k and m = 0; m++; m < l, recursively calculate ACC := ExtProd(ACC i,m , uec i , ACC, {pk j} j∈[k] ): ① Let j = 0; j++; j ≤ k, calculate ACC′(j) = ACC(j)⊙ACC i,m ; ②Calculate and output ACC∶=HProd(uec i =(d i,0 ,d i,1 ),ACC′,{pk j } j∈[k] ); (5) Output the calculation results of the blind rotation of the multi-key ciphertext 3. The method according to claim 2, characterized in that Calculate and output ACC∶=HProd(uec i =(d i,0 ,d i,1 ),ACC′,{pk j } j∈[k] ) is as follows: a: Initialize v∶=0; b: For j=0; j++; j≤k, calculate u j = <h(ACC′(j)),d i,0 >,v=v+ <h(ACC′(j)),pk j > c: For j=0; j++; j≤k, calculate h(·) is the mapping function, Represents a mapping with a decomposition basis of B, and its inverse process The decomposition dimension For any ring element a∈R Q ,exist Make Right now<h(a),g> =a mod Q; d: Output a multi-key ciphertext 4. The method according to claim 1, wherein The method for each participant to generate an evaluation key is as follows: the user enters his own private key for encrypting LWE ciphertext and a private key f∈R for encrypting the NTRU ciphertext Q , calculate the blind rotation key (brk0,brk1,...,brk n ); where s n-1 is the nth dimension component of the private key s, is an n-dimensional integer set with modulus q, R Q is a polynomial ring of modulus Q, For i <n, Calculate the key switching key ksk corresponding to the automorphism t =NTRU′(f(X t ) / f(X)), Finally, the evaluation key Evk corresponding to the group inner product algorithm is output = (brk0, brk1, ..., brk n ;{ksk t } t∈S ).

5. The method according to claim 1, wherein The method for each participant to generate a joint encrypted ciphertext is as follows: the user enters his own private key s=s0+s1X+...+s for encrypting the RLWE ciphertext n-1 X n-1 ∈R and a private key f∈R used to encrypt the NTRU ciphertext Q , extract the noise vector and a temporary private key r←χ key , using two public random strings Calculate d0 = r·a com +f·g+e0,d1=-s·b com +r·g+e1; output the jointly encrypted ciphertext uec=(d0,d1).

6. The method according to claim 1, characterized in that The method for each participant to generate a public key is as follows: the user inputs his own private key s for encrypting the RLWE ciphertext, extracts a noise vector With the help of a public random string Output public key 7. The method according to claim 1, characterized in that The method for each participant to generate a key switching key is: based on the user's own private key s∈R Q , a private key used to encrypt the LWE ciphertext Output a key switching key