Method for refreshing an encrypted message for homomorphic cryptography, and homomorphic cryptography method
Patent Information
- Application Number
- EP2024708715
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-03-03
- Filing Date
- 2024-02-28
- Publication Date
- 2026-01-14
Smart Images

Figure EP2024055063_12092024_PF_FP_ABST
Abstract
Description
[0001]DESCRIPTION TITLE: Method for refreshing an encrypted message for homomorphic cryptography and homomorphic cryptography method TECHNICAL FIELD The technical field is that of homomorphic cryptography methods, devices and systems. TECHNOLOGICAL BACKGROUND Homomorphic cryptography, which allows calculations or data processing to be performed on encrypted data, without first decrypting them, has attracted a lot of attention recently. Indeed, the digital processing of personal data has become ubiquitous in our daily lives. Protecting the confidentiality of this data, and the privacy of the individuals concerned, has therefore become critical, as this personal data tends to circulate more and more in the digital systems environments that we use on a daily basis.In this context, homomorphic encryption and processing techniques appear to be a very promising solution, because they allow data to be processed while preserving the anonymity and privacy of this data in a particularly secure manner, as the latter are not decrypted during processing. Homomorphic cryptography methods therefore respond, among other things, to the technical challenge of allowing: - an external, generally remote, service and processing server to perform "blind" operations on encrypted data, without decrypting it, this server not having the key necessary to decrypt the data, - the encrypted data being provided by another, distinct entity (a client, in the IT sense), which has the encryption key.These data processing operations may consist of performing individual operations, data by data, to format or filter them for example. They may also involve data comparison, sorting or grouping operations. Homomorphic cryptography may be based on the so-called "learning with errors" (LWE) encryption scheme, in which the encrypted message !(", #) = $%(&) is derived from the unencrypted message m according to the following formula: b=m+e+as, where: - s is a secret key, - a is a randomly chosen vector, to project the secret key s, and - e is a random noise component, added to m+as To decrypt the message, a person with the secret key s can calculate the quantity ba.s (equal to m+e), then round the result to remove the noise component e and recover the message m.Of course, the noise term e must be and remain sufficiently small if message m is to be recovered. When two encrypted messages are added together, we obtain an encrypted message, which is an encrypted version of the sum of the two initial unencrypted messages, whose noise component is higher than for the two initial encrypted messages. Thus, to prevent the noise term from increasing and growing during data processing, a refresh procedure, usually called "bootstrapping", is repeatedly performed. This procedure produces a refreshed version of c, i.e., an encrypted message c' which is also decrypted as m (when decrypted using s), but whose noise component is smaller than that of c. The "bootstrapping" procedure usually includes a homomorphic evaluation of the quantity '. * . + ( ' ) with: - + ( ' )is a functional refresh polynomial of degree less than or equal to N-1 whose coefficients are chosen according to the characteristics of the message space and a target function; - and α is the integer closest to 2N(ba.s): -2 / (# 0 ".1)3 Here we mean by homomorphic evaluation, a calculation carried out using encrypted quantities, without prior decryption (without knowing the key s). Here we mean by target function a mathematical function applied to the encrypted message at the same time as the refresh. In the case of a simple refresh, the target function is the identity function. For a polynomial + ( ' ) opportunely chosen, the constant term of ' * . + ( ' ) 456 ( ' 7 89 ) , namely coef : ;X * . v ( X )<, is a refreshed version of c, that is, an encrypted version of µ with a limited noise component e' (usually smaller than the noise component of c, when c comes from previous – homomorphic – data processing operations; in any case, e' is small enough to allow decryption of c', with a low error rate). As is known, the homomorphic calculation of the quantity = ' * . +(')456(' 7 89) can be decomposed into a calculation of a sequence of modular products given by: @ Where the sk are the n components of the vector s. In the above equation, when calculated homomorphically, each product “.” is a modular product: the term on the left, for example ' AIC Or , belongs to S T [ X ] = S[X]U(X 7 89), the term on the right, for example +(') or belongs to TN[X]. Here we define TN[X] = T[X] / (XN +1). Such a product is similar to the product y.µi, y being an integer and µ belonging to T (except that we work on polynomial fields, instead of number fields). The homomorphic calculation of !5>? : ;' * . +(')< is non-immediate because of the presence of the secret key s, which is not known. However, it is known that a modular product such as y.µi or X j .v(X) can be calculated homomorphically by defining the exterior product V W Y (Z) The quantity $% E Y (& ^ ) = ! ^is the encrypted version of the message µi. The quantity is the “TRGSW” encryption of z (the acronym TRGSW comes from the English “Gentry, Sahai, Waters Torus Ring encryption”, adapted from an encryption method that was proposed in the article “Homomorphic encryption from learning with errors: Conceptually-simpler, asymptotically-faster, attribute-based”, by C. Gentry, A. Sahai, and B. Waters, InCrypto'13, 2013). Furthermore, in a known way, it is possible to calculate the product V W Y( ' ABC`E`) \ $% E ( µ ) without knowing the components sk, k = 1…n of the secret key and therefore without knowing the secret key s. Indeed, as the components sk, k = 1…n each belong to B={0,1} (ie: are each binary), the quantity ' ABC`E` is equal to ( ' ABC` 09 ) 1 N 89 which is encrypted as It follows that an encrypted version of ' * . + ( ' ) 456 (' 7 89 ) can be calculated without access to the secret key s using the encrypted version V W Y (1 N ) of the sk components. These encrypted versions of the s components are sometimes called Boostsrap dg keys N = V W Y (1 N ) ("Bootstrap key" in English). Bootstrap keys (usually public) are encrypted versions of the components sk of the secret key s encrypted using another key s'. V W Y(Z) is defined to be equal to h 8 yi b with : _ Q h = j k p, where zj, j=1…l(K+1), are l(K+1) encrypted versions of 0, the _ l(mnQ) null value 0 being encrypted with s': _ q = $% E Y (r), l being a given positive integer; and i b is a matrix whose dimension is (s 89) × (s 89) × t and whose coefficients belong to the torus T, i b l being equal to: B being an integer greater than or equal to 2. The exterior product u \ !, between: An encrypted message c = $% E Y (µ), ! wx zn{ , corresponding to a message µ belonging to the torus TN[X] and The encrypted version@u = V W Y (Z) of a polynomial with integer coefficients y, uw is calculated according to the method detailed below. The K+1 components cj, j=1..K+1 of the encrypted message c = $% E Y(µ) are somehow decomposed using a base B system (like the one used to calculate the V W Y ) Then it is possible to calculate is the row-column matrix product and M b,l (!) is a matrix of dimension (n+1)×l whose form is as follows: With the result u \ ! belongs to x zn{and is an encrypted version of y.µ. In other words, by decrypting this quantity with the key s' we find y.µ. This calculation method can be applied to any message belonging to the torus T. Using the keys BKi introduced above, we obtain for the homomorphic calculation of coef0(X α .v(X)), namely the following equation: The above equation therefore allows refreshing or bootstrapping the encrypted message without needing to know the encryption key. The bootstrapping operation is extremely useful and allows implementing homomorphic cryptography techniques without the encrypted information gradually becoming drowned in noise as processing operations progress. However, it is a complex operation that requires powerful computing resources (in practice, the heaviness of this operation often proves to be a significant obstacle to the development of homomorphic cryptography applications). Furthermore, it is important that the reliability of this operation is high (i.e.: that the risk of losing the initial information is low).Certain parameters, for example the degree N of the polynomials used, or the standard deviation of the noise component initially added to the message during encryption, influence the volume of calculations to be carried out (if this standard deviation is large, the message must be "refreshed" more often). But they also influence the encryption security (if the standard deviation in question is large, the encrypted information is better protected), or the risk of loss of information. In this context, it is therefore desirable to improve the performance of the refresh operation (in terms of volume of calculations, or in terms of reliability). SUMMARY OF THE INVENTION To at least partially resolve the problems mentioned above, the invention relates to a method for homomorphic refreshing of an encrypted message which is more reliable and whose implementation does not require an excessive increase in the complexity of the calculations.A first aspect of the invention relates to a method for refreshing an encrypted message!. ( ", # ) = @$% ( & ) @so as to obtain a new version of the encrypted message c', µ being the plaintext message, with b= µ + e + as, where: - s is a vector comprising n elements in a finite set of integers ^, s being the secret encryption key of the message µ; - a is a vector comprising n elements chosen at random, a being the projection vector of the secret key s; - e is a random noise component, added to µ + as; - c' comprises a random noise component e' of absolute value lower than the noise e; said method comprising a step of homomorphic calculation of the zeroth order coefficient of the polynomial ' * . +('), !5>? : (' * . +(')) , where: - +(') is a functional refresh polynomial, belonging to the set of polynomials defined modulo 1+X N; - the quantity α corresponds to an approximate evaluation of 2N(b - as), N being an integer, said approximate evaluation comprises a sum of terms, each term comprising a rounding of a partial sum equal to a scalar product of a vector "% N and a vector 1^ N , "% N comprising m ordered elements of the vector a and 1^ N comprising m corresponding ordered elements of the vector s, k being between 2 and the integer part of n / m. The refresh method according to the state of the art is based on the calculation of the zero coefficient of the polynomial ' * . +('). This calculation is approximate because the quantity L = @# C 0 "C N 1 N, which is a rounding sum of monomials, is actually calculated as a rounding of a sum: -2 / (# 0 ".1)3 . The method according to the invention is based on a different and more reliable approximation of the quantity α. The rounding sum of partial sums according to the invention is a better evaluation than the rounding of a sum of individual terms according to the prior art. The method according to the invention comprises a step of calculating α as a rounding sum of partial sums. The calculation step is carried out using a calculation device, for example a calculation module. Each partial sum comprises a rounding of a scalar product of a vector "% N and a vector@1^ N . The vector "% N includes m ordered elements of the vector a. The vector 1^ N comprises m ordered elements of the vector s. The index k appearing in "% N and 1^ Nis between 1 and the integer part of n / m, m being the size of the vectors a and s. In other words, the method according to the invention comprises the grouping (or "collapsing" according to English terminology) of the vectors a and s to form sub-vectors of size m, m being smaller than n. The rounding operation is therefore carried out at the level of each scalar product. This technique makes it possible to reduce the error linked to rounding and therefore to carry out the refresh procedure more reliably compared to the state of the art. For example, the grouping of the vectors a and s can be described as follows when n is divisible by m: In the case m = 3, the first group of elements of the grouping of the vector s is then 1 ^ ),@ 1^ ^ = (1 ^ , 1 ^ , 1 ^ ), ^. A similar grouping is performed for the vector a, obtaining the terms = (" Q , " ^ , "^ ), "% ^ = (" ^ , " ^ , " ^ ). A functional refresh polynomial is a polynomial that allows, in a known manner, a bootstrapping or refreshing operation of the encrypted message! ( ", # ) = . The coefficients of the polynomial are chosen according to the properties of the encrypted message space and the function f. Furthermore, the functional refresh polynomial allows a function ? to be applied to the encrypted message !(", #) so as to obtain a refreshed message! ^ = @?(!). If we only want to refresh the encrypted message, we can consider the function ? to be the identity function. By homomorphic calculation of the quantity !5>? : (' * . + ( ' )) a calculation performed using a public encryption of the key s, or bootstrap keys. According to one embodiment of the method according to the invention, the bootstrap keys have the form of public ciphers of the functions ^ ^^,E^^ , the encryption being carried out according to a secret key s'. Here we mean by a Kronecker delta type function which is equal to 1 if ^^ = and equal to zero in other cases. An advantage of the invention is then to improve the reliability of the bootstrap operation without excessively increasing its complexity. More particularly, for m = n we find an exact evaluation of the quantity α. For m = 1 we find the approximate evaluation according to the state of the art. The invention is therefore particularly advantageous for intermediate values of the grouping parameter m for which a reliable homomorphic refresh is obtained without excessively increasing the complexity of the calculations. According to an embodiment of the first aspect of the invention, the approximate calculation of the quantity α comprises the homomorphic evaluation of the following formula: @, the functions ^ ^^,E^^ being in public encrypted form in the calculation, =@ -2 / "^ ^ ^^ 3 , "C Q,^^^ =@ -2 / "^ Q ^^ 02 / # 3 and ^ ^is the set of tuples of size m with value in ^. According to an embodiment of the first aspect of the invention, the refresh method comprises a step of homomorphic evaluation of a sequence of n / m modular products given by them N (') being in public encrypted form in the calculation. According to an embodiment of the first aspect of the invention, the refresh method comprises a step of receiving a public encrypted version ^^^^^ E Y ;^ ^^,E^^ < of ^ ^^,E^^ , the encryption being carried out using a key s'. This makes it possible to evaluate homomorphically the quantity ' * . + ( ' ) . According to an embodiment of the first aspect of the invention, the refreshing method comprises a step of extracting the zero-order coefficient of the polynomial ' * . +(') in the form of TLWEs(!5>? : (' * . +('))namely a cipher of !5>? : ('*. +(') according to the secret key s. It is noted that the X appearing in the polynomials can be indeterminates whose function is the construction of the polynomials themselves. A second aspect of the invention relates to a method of encrypted communication and processing, comprising the following steps: - Encryption of a message µ using a private key s by a client, in the form of an encrypted message c, by a method of the learning with error type; - Transmission of the encrypted message c or of an encrypted database containing the encrypted message c, by the client, to a server separate from the client and not having the private key s, via a communication channel; - Processing of the encrypted message c or of the encrypted database containing the encrypted message c, by the server in a homomorphic manner, in accordance with the method according to the first aspect of the invention; - Emission of the result of said homomorphic processing, by the server.According to one embodiment of the encrypted communication and processing method according to the second aspect of the invention, the step of processing the encrypted message comprises performing a homomorphic operation on the encrypted message c or on a database comprising the encrypted message. For example, the homomorphic operation may be a sum or a multiplication comprising the encrypted message c or the comparison of the encrypted message c and another encrypted message. According to one embodiment of the encrypted communication and processing method according to the second aspect of the invention, the step of transmitting the result of said homomorphic processing comprises transmitting the refreshed encrypted message c' or a message resulting from the operation performed on the encrypted message.A third aspect of the invention relates to a cryptographic processing server comprising at least one communication module and one calculation module: - The communication module being configured to receive, from an entity external to the server, an encrypted message c or an encrypted database containing the encrypted message c, the encrypted message c corresponding to a message m encrypted by a learning with error type method; - The calculation module being programmed to process the encrypted message c, or the encrypted database containing the encrypted message c, in a homomorphic manner, without decrypting the message c, in accordance with the method according to the first aspect of the invention; - The communication module also being configured to transmit the result of said homomorphic processing.A fourth aspect of the invention comprises a cryptographic system comprising: - the cryptographic processing server according to the second aspect of the invention, - a client, configured to encrypt at least the message m, in the form of the encrypted message c, and to communicate the encrypted message c, or an encrypted database containing the encrypted message c, to the server via a communication channel. According to an embodiment of the fourth aspect of the invention, the cryptographic system comprises a plurality of clients. The clients may each have their own communication channel with the server. Alternatively, two or more clients may share the same communication channel with the server. The present technology and its various applications will be better understood upon reading the following description and examining the accompanying figures. BRIEF DESCRIPTION OF THE FIGURES The figures are presented for information purposes only and are in no way limiting.[Fig. 1] schematically represents the operation of grouping the vectors s and a; [Fig. 2a] schematically represents the refresh method according to the first aspect of the invention; [Fig. 2b] schematically represents the encrypted transmission and processing method according to the second aspect of the invention; [Fig. 3] represents the probability of accuracy of the refresh method for different values of the parameter of grouping the vectors s and a. [Fig. 4] represents a cryptographic system according to the fourth aspect of the invention. DETAILED DESCRIPTION [Fig. 1] illustrates the operation of grouping the vectors s and a into smaller sub-vectors. This operation makes it possible to reduce the rounding error in the calculation of the quantity α when implementing the method according to the first aspect of the invention. In the case of [Fig.1] the vectors s and a each have n elements, the elements of s belonging to the integers and the elements of a belonging to the torus T . In this example, the vectors s and a are grouped into ordered subsets of size m, "%. N and 1^ N . In total, if n is divisible by m, there are an / m subsets "% N and 1^ N. If n is not divisible by m, the number of subsets is equal to the integer part of n / m plus a subset of s and a subset of a having the size of the remainder of the division n / m. In this case, the calculation of α includes an additional term with a scalar product between the two subsets of s and a having the size of the remainder of the division n / m. Figure [Fig. 2a] schematically represents the method 100 for refreshing an encrypted message !(", #) = @$%(&)@ according to the first aspect of the invention. The method 100 for refreshing an encrypted message comprises a first step 101 of receiving the encrypted message ! ( ", # ) = @$% ( & ), & being the clear message. It is important to note that the computing device implementing the method 100 does not have the secret key s. Operators having access to the computing module cannot therefore decrypt the message $%(&). The first step 101 of the method 100 according to the first aspect of the invention further comprises receiving a public encrypted version of the key s, the encryption being carried out using the key s'. More specifically, the public encrypted version of the key s is in the form of the ciphertexts of the functions ^ ^^,E^^ . These functions are Kronecher δ type functions: ^ ^^,E^^ = 9 if ^^ = @ 1^ ^ and ^ ^^,E^^ = 9 in other cases. The method 100 according to the first aspect of the invention further comprises a step 102 of homomorphic calculation of the quantity !5>? : (' * . + ( ' ) ). Step 101 includes the homomorphic evaluation of the quantity: Or 'ABC^,^%^ is calculated as "C Q,^^^ =@ -2 / "^ Q ^^ 02 / # 3 and ^ ^ is the set of tuples of size m with values in the possible values of the components of the key, namely the set ^. The functions ^ ^^,E^^ are in public encrypted form in the calculation. The previous formula is valid for all n multiples of m. In particular for m = 1 we find the expression used in the method according to the state of the art. For m = n the calculation of α becomes exact without any approximation. The previous equation can be expressed as follows: It follows that the product ' * +(') can be computed homomorphically as a sequence of n / m modular products in S7[']@. ¡7[']@: According to one embodiment, the bootstrapping polynomial is a polynomial of type ¢ £ (X) = M 7 q P A : Q ¤ q . ' q.@ The coefficients wj are given by the following formula: where -2 / 4 ^ 3 is the closest whole number to 2 / 4 ^ and where ¥-2 / 4 ^ 3U / 3 is the rounded function applied to -2 / 4 ^ 3U / . As described in the patent application PCT / IB2020 / 001147 filed by the applicant, the choice of this type of polynomial makes it possible to apply an arbitrary function g to the encrypted message c during the refresh operation. This embodiment makes it possible to considerably speed up certain data processing procedures. Indeed, the use of the polynomial ¢ £ ( X ) allows to perform a homomorphic operation and to refresh the encrypted message during the same refresh operation. The method 100 according to the first aspect of the invention further comprises a step 103 of extracting the refreshed encrypted message c'. Step 103 comprises the calculation of the quantity TLWEs(' * @+ ( ')), an encrypted version according to the secret key s of the refreshed message c'. The refreshed encrypted message c' comprises a noise component e' smaller than the noise component e associated with the message c. [Fig. 2b] schematically illustrates the encrypted communication and processing method 210. The encrypted communication and processing method 210 comprises a step 211 of encrypting a message µ using a private key s by a client, in the form of an encrypted message c, by a learning-with-error method. The encrypted message c is then transmitted to a server during a transmission step 212. The encrypted message c is transmitted to a server separate from the client. The server does not have the private key s and is configured to implement a homomorphic cryptography technique by processing encrypted signals without decrypting them during a processing step 213.The processing step 213 comprises, for example, the implementation of the method 100 according to the first aspect of the invention. According to an embodiment of the encryption and processing method 210, the step 213 may further comprise the performance of a homomorphic operation on the encrypted message m or on the database comprising the encrypted message m. A homomorphic operation is understood to mean an operation such as a sum, a multiplication or a comparison of encrypted messages carried out without decryption of the messages. The method 210 according to the second aspect of the invention further comprises a step 214 of transmitting the result of the homomorphic processing by the server. The graphs in [Fig. 3] illustrate the probability of accuracy P of the refresh method according to the first aspect of the invention as a function of the standard deviation of the random noise σ.Each pair of curves on the graphs represents the probability of accuracy for the exact calculation and for the approximate calculation according to the method 100 for a value of the grouping parameter m between 1 and 8. The graphs in [Fig. 3] illustrate that the approximate calculation according to the method 100 gives results very close to the exact calculation for small values of m, m being the size of the sub-vectors obtained from the grouping of the vectors a and s. Increasing it by m, the calculation has a less reliable approximation because the number of terms in the rounded sums increases and the approximation moves away from the exact calculation. [Fig. 4] illustrates the cryptographic system 400 according to the fourth aspect of the invention. The cryptographic system 400 comprises a cryptographic server 401 according to the second aspect of the invention. The cryptographic server 401 comprises a calculation module 402 and a communication module 403.The communication module 403 is configured to receive an encrypted message!. ( ", # ) = @$% ( & ) and the encrypted public versions of the key s The calculation module 402 is configured to implement the method 100 according to the invention. In particular, the calculation module is configured to perform a refresh of the encrypted message! ( ", # ) = @$% ( & ) so as to obtain the encrypted message c', c' having a noise component smaller than the noise component of c. According to an embodiment of the cryptographic system 400 according to the fourth aspect of the invention, the calculation module 402 is configured to homomorphically calculate the sequence of modular products in S7 [ ' ] @. ¡7 [ ' ] @: The communication module 403 is further configured to transmit the refreshed message c' resulting from the implementation of the method 210 according to the second aspect of the invention. According to an embodiment of the system 400 according to the fourth aspect of the invention, the server 402 is configured to receive and process a plurality of encrypted messages, for example an encrypted database. According to an embodiment of the system 400 according to the fourth aspect of the invention, the server 401 is configured to perform homomorphic calculations from encrypted messages. For example, the server 401 can perform the sum, the difference or the comparison of several encrypted messages. These operations are performed in a homomorphic manner, namely without the need to decrypt the messages.When the calculation module 403 performs homomorphic calculations from received encrypted messages, the processing method 210 according to the second aspect of the invention is performed on the result of the homomorphic calculations. This makes it possible to reduce the random noise after the homomorphic calculations have been carried out. The cryptographic system 400 according to the invention further comprises several clients 404, 405, 406 capable of communicating with the server 401 via communication channels 404c, 405c, 406c. Each communication channel is bidirectional, allowing the passage of information from the server 401 to the client and from the client to the server 401. Each client 404, 405, 406 is configured to encrypt a message. ( ", # ) = @$% ( & ) and to transmit it to the server 401 via a communication channel 404c, 405c, 406c. Each client is further configured to receive the message c'.
Claims
CLAIMS
1. Method for refreshing (100) an encrypted message! ( ", # ) = @$% ( & ) @so as to obtain a new version of the encrypted message c', µ being the plaintext message, with b= µ + e + as, where: - s is a vector comprising n elements in a finite set of integers ^, s being the secret encryption key of the message µ; - a is a vector comprising n elements chosen at random, a being the projection vector of the secret key s; - e is a random noise component, added to µ + as; - c' comprises a random noise component e' of absolute value lower than the noise e; said method comprising a step of homomorphic calculation (102) of the zero-order coefficient of the polynomial ' * . +('), !5>? : (' * . +(')), where: - +(') is a functional refresh polynomial, belonging to the set of polynomials defined modulo 1+X N; - the quantity α corresponds to an approximate evaluation of 2N(b - as), N being an integer, said approximate evaluation comprises a sum of terms, each term comprising a rounding "C ^,E^^ of a partial sum equal to a scalar product of a vector "% N and a vector 1^ N , "% N comprising m ordered elements of the vector a and 1^ N comprising m corresponding ordered elements of the vector s, k being between 2 and the integer part of n / m, with m strictly greater than 1 and less than n.
2. Refresh method (100) according to the preceding claim characterized in that said approximate evaluation comprises the homomorphic evaluation of the following formula: Or ' ABC^,^%^ is calculated as @, the ^ functions ^^,E^^ being in public encrypted form in the calculation, with "C ^,^^ =@ -2 / "% ^ ^^ 3 , "C Q,^^^ =@ -2 / "% Q^^ 02 / # 3 and ^ ^ is the set of tuples of size m with value in ^.
3. Refresh method (100) according to one of the preceding claims, characterized in that it comprises a step (101) of receiving a public encrypted version the encryption being carried out using a key s'.
4. Refresh method (100) according to one of the preceding claims, characterized in that it comprises a step of extracting (103) the zero-order coefficient of the polynomial ' * . + ( ' ) in the form of a cipher of (!5>? : (' * . +(')) according to the secret key s, TLWEs(!5>? : (' *. +(')).
5. Encrypted communication and processing method (210), comprising the following steps: - Encryption (211) of a message µ using a private key s by a client, in the form of an encrypted message c, by a learning with error type method; - Transmission (212) of the encrypted message c, or of an encrypted database containing the encrypted message c, by the client, to a server separate from the client and not having the private key s, via a communication channel; - Processing (213) of the encrypted message c, or of the encrypted database containing the encrypted message c, by the server in a homomorphic manner, in accordance with the method according to one of the preceding claims. - Transmission (214) of the result of said homomorphic processing, by the server.
6. Encrypted communication and processing method (210) according to the preceding claim, characterized in that the processing step (213) comprises performing a homomorphic operation on the encrypted message or on the database comprising the encrypted message.
7. Cryptographic processing server (401) comprising at least one communication module (402) and one calculation module (403): - The communication module (402) being configured to receive, from an entity external to the server, an encrypted message c or an encrypted database containing the encrypted message c, the encrypted message c corresponding to a message m encrypted by a learning with error type method; - The calculation module (403) being programmed to process the encrypted message c, or the encrypted database containing the encrypted message c, in a homomorphic manner in accordance with the method according to any one of claims 1 to 4; - The communication module (402) also being configured to transmit the result of said homomorphic processing.
8. Cryptographic system (400) comprising: - the cryptographic processing server (401) according to claim 7, - a client (404, 405, 406), configured to encrypt at least the message m, in the form of the encrypted message c, and to communicate the encrypted message c, or an encrypted database containing the encrypted message c, to the server via a communication channel (404c, 405c, 406c).