System for secure multi-party exact homomorphic encryption and computer-implemented method for performing secure multi-party exact homomorphic encryption

The SMPEHE system addresses scalability issues in homomorphic encryption by using a multi-party approach with polynomial sets and elementary gates, enabling secure and efficient computation on encrypted data with post-quantum security.

JP2025118530AInactive Publication Date: 2025-08-13ス ジェン-ヤオ
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025005999
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-16
Filing Date
2025-01-16
Publication Date
2025-08-13
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 2025118530000172
    Figure 2025118530000172
  • Figure 2025118530000173
    Figure 2025118530000173
  • Figure 2025118530000174
    Figure 2025118530000174
Patent Text Reader

Abstract

To provide a system and computer-implemented method for secure multi-party exact homomorphic encryption.SOLUTION: A system comprises: a key generation module within a first participant to produce an encryption mapping comprising an ordered product of elementary gates, generate a multivariate polynomial set, serving as a public encryption key, via the encryption mapping, form an encryption operator serving as a private key, and create an encrypted polynomial set representing a computational instruction based on an encrypted action; a message encryption module within a second participant to encode a plaintext message into a first ciphertext using the public key provided by the first participant, and transmit the first ciphertext to a third participant; and a computation module within the third participant to receive the first ciphertext, and perform a computation on the received first ciphertext by evaluating the encrypted polynomial set.SELECTED DRAWING: None
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This disclosure relates generally to systems for encryption, and more particularly to systems for secure multi-party exact homomorphic encryption and computer-implemented methods for performing secure multi-party exact homomorphic encryption. [Background technology]

[0002] Related Applications This application claims priority to U.S. Provisional Patent Application No. 63 / 621,188, filed January 16, 2024, the entire disclosure of which is incorporated herein by reference.

[0003] Homomorphic encryption (HE) allows users to perform computations on encrypted messages without prior decryption, thereby providing a high level of security for data processing. Improvements to homomorphic encryption (HE) remained relatively limited over the next 30 years until Gentry's proposal in 2009. Gentry's paper made arbitrary cryptographic computation theoretically possible, subject to unlimited resources. However, noise accumulation poses an obstacle to the implementation of this technique. This problem is particularly pronounced due to the exponential increase of noise with the number of multiplications.

[0004] Quantum computing has recently attracted a great deal of attention due to its significant impact on data processing as well as information security. An interesting research area related to security risks is quantum public key encryption (QPKE). Its basic approach involves generating a one-way function to generate a quantum state that acts as a public key for encrypting a message. The main obstacle to QPKE is that it requires large-scale quantum operations, which falls under the challenge of scaling quantum computers.

[0005] Quantum homomorphic encryption (QHE) is another research area that has received increasing attention for protecting data operations. Typically, encrypted computations are performed using fault-tolerant Clifford+T circuits. Specifically, physical qubits outnumber logical qubits by at least several hundred times, which negates the accessibility of QHE. An alternative form replaces current HE with its quantum version. In addition to suffering from the drawbacks of the HE schemes mentioned above, the method under consideration consumes a large number of qubits and, as a result, faces the scalability barrier of quantum computers.

[0006] The series of episodes reveals a structure called a Quotient Algebra Partition (QAP), which exists universally in finite-dimensional unitary Lie algebras. Assuming that this structure carries over to all stabilizer codes, a general methodology for fault-tolerant quantum computation in QAP (abbreviated as QAPFTQC) derives an algorithmic procedure that ensures that all actions in all error-correcting codes are fault-tolerant. Fault-tolerant quantum computation is therefore derived by applying this encoding to codewords. [Prior art documents] [Non-patent literature]

[0007] [Non-Patent Document 1] "A FULLY HOMOMORPHIC ENCRYPTION SCHEME", Craig Gentry, A DISSERTATION SUBMITTED TO THE DEPARTMENT OF COMPUTER SCIENCE AND THE COMMITTEE ON GRADUATE STUDIES OF STANFORD UNIVERSITY IN PARTIAL FULFILLMENT OF THE REQUIREMENTS FOR THE DEGREE OF DOCTOR OF PHILOSOPHY Summary of the Invention [Problem to be solved by the invention]

[0008] Accordingly, the inventors of the present invention introduce a system for secure multi-party exact homomorphic encryption and a computer-implemented method for performing secure multi-party exact homomorphic encryption. [Means for solving the problem]

[0009] The inventive concept provides a system for secure multi-party exact homomorphic encryption (SMPEHE), the system including a first participant as a model provider / data recipient, a second participant as a data provider / data owner, and a third participant as a computation provider, the system further comprising a key generation module, a message encryption module, and a computation module.

[0010] The key generation module is in the first participant and is configured to generate an encryption mapping including an ordered product of elementary gates, generate through the encryption mapping a multivariate polynomial set that serves as a public encryption key, form an encryption operator that serves as a private key, and create an encrypted polynomial set that represents a computation instruction based on the encrypted action.

[0011] The message encryption module is in the second participant and is configured to encode the plaintext message into a first ciphertext with a public key provided by the first participant and transmit the first ciphertext to the third participant.

[0012] The computation module is in the third participant and is configured to receive the first ciphertext and perform a computation on the received first ciphertext by evaluating the encrypted polynomial set.

[0013] In accordance with the inventive concept, the computation module is further configured to output a second ciphertext and transmit the second ciphertext to the first participant.

[0014] According to the inventive concept, the system further comprises a decryption module in the first participant, the decryption module being configured to decrypt the second ciphertext by using the private key to retrieve the computation result.

[0015] According to the inventive concept, the encryption mapping is generated by combining elementary gates, including negation, Toffoli, CNOT, and multi-controlled gates, to form an encryption transformation.

[0016] In accordance with the inventive concept, a public cryptographic key is a multivariate polynomial set that is generated through a corresponding cryptographic mapping.

[0017] According to the inventive concept, an encrypted polynomial set is generated by an encrypted action consisting of a desired operation, a cryptographic mapping, and a cryptographic operator, and the polynomial set is used to perform a calculation on a first ciphertext.

[0018] In accordance with the inventive concept, a computation module evaluates, in parallel or sequentially, the encrypted polynomial set on the first ciphertext to generate the second ciphertext.

[0019] In accordance with the inventive concept, the first ciphertext sent by the second participant is a tensor product state of multiple individual ciphertexts.

[0020] According to the inventive concept, an encrypted polynomial set is generated from an encrypted action defined as follows:

[0021]

number

[0022] where R en,j and R cv,j is the encryption transformation,

number

number

[0023] In accordance with the inventive concept, the encrypted action

number

[0024] According to the inventive concept, there is a first communication between a first participant and a second participant, the first communication occurring in parallel or sequentially and including the distribution of a public encryption key from the first participant to the second participant.

[0025] According to the inventive concept, there is a second communication between the first participant and a third participant, the second communication occurring in parallel or sequentially.

[0026] In accordance with the inventive concept, the second communication includes transmitting a computational instruction from the first participant to a third participant and transmitting a second ciphertext from the third participant to the first participant.

[0027] According to the inventive concept, there is a third communication between the second participant and the third participant, the third communication occurring in parallel or sequentially and including the distribution of the first ciphertext from the second participant to the third participant.

[0028] The inventive concept further provides a computer-implemented method for performing secure multi-party exact homomorphic encryption (SMPEHE), involving a first participant as a model provider / data recipient, a second participant as a data provider / data owner, and a third participant as a computation provider, the method including:

[0029] S10. Randomly selecting E≦D elements from a group of D parties in the first participant;

[0030] S20. Generate E distinct key pairs, each of which is a cryptographic mapping R for j=1, 2, …, E. en,j public encryption key, which is a multivariate polynomial set generated by

number

[0031] S30. E operations on n qubits M j Prepare the operation M j Each of these is composed of elementary gates;

[0032] S40. E encryption transformations R of n qubits cv,j where the encryption transformation R cv,j Each of these is composed of elementary gates;

[0033] S50. jth encryption action

number

number

number

number

[0034] S60. Public Key Collection

number

[0035] S70. Encrypted polynomial set

number

[0036] According to the inventive concept, the method further comprises, for j=1, 2, ..., E:

[0037] S80.E plaintext messages

number

[0038] S90. Plaintext m j Each of these is converted into the corresponding public key

number

[0039] S100. Tensor product state of ciphertext

number

[0040] S110. Send the ciphertext tensor product state |c> to the third participant.

[0041] According to the inventive concept, the method may further comprise:

[0042] S120. Encrypted polynomial set

number

[0043] S130.Input

number

number

number

[0044] S140. Second Ciphertext

number

[0045] S150. Sending the second ciphertext |s> to the first participant.

[0046] According to the inventive concept, the method further comprises:

[0047] S160. Second ciphertext |s j > each of them with the corresponding private key R cv,jDecrypt using and recover the calculation result.

[0048] According to the inventive concept, the encryption mapping R en,j Each of the is composed of a basic gate selected from the group consisting of negation, Toffoli, CNOT, and multi-controlled gates.

[0049] According to the inventive concept, a public key

number

[0050] In accordance with the inventive concept, the encrypted polynomial set

number

[0051] According to the inventive concept, the first ciphertext c j Each of these is a plaintext message m j public key for

number

[0052] In accordance with the inventive concept, the tensor product state of the first ciphertext is securely transmitted to a third participant without revealing the plaintext message.

[0053] In accordance with the inventive concept, the encrypted polynomial sets are evaluated independently or sequentially for the first input ciphertext to optimize computational efficiency.

[0054] According to the inventive concept, the private key R cv,j Decrypt the second ciphertext using

[0055] In accordance with the inventive concept, the method further comprises distributing the public encryption key from the first participant to the second participant in parallel or sequentially.

[0056] According to the inventive concept, the method further comprises:

[0057] Sending the computational instructions in parallel or serially from the first participant to the third participant, and sending the second ciphertext in parallel or serially from the third participant to the first participant.

[0058] In accordance with the inventive concept, the method further comprises transmitting the public encryption key from the second participant to the third participant in parallel or sequentially. [Brief explanation of the drawings]

[0059] [Figure 1] FIG. 1 is a process diagram of an EHE according to an embodiment of the inventive concept. [Figure 2] FIG. 1 is a process diagram of a SMPEHE according to an embodiment of the inventive concept. [Figure 3] 1 is a schematic diagram of the basic gates used in the algorithm according to the inventive concept; [Figure 4] FIG. 1 illustrates (a) a process for an embodiment of the inventive concept in which messages and computations are mapped to the same space, and (b) a process for an embodiment of the inventive concept in which messages and computations are mapped to different encryption spaces. [Figure 5] FIG. 1 is a schematic flow diagram according to an embodiment of the inventive concept. [Figure 6] FIG. 10 is a schematic flow diagram according to another embodiment of the inventive concept. [Figure 7] FIG. 10 is a schematic flow diagram according to another embodiment of the inventive concept. DETAILED DESCRIPTION OF THE INVENTION

[0060] The concept of the present invention is described by the following specific embodiments. After reading the disclosure of this specification, those skilled in the art can easily understand other advantages and functions of the concept of the present invention. Any changes or adjustments made to their relative relationships without changing the substantial technical content are also considered to be within the scope that can be implemented by the concept of the present invention.

[0061] Moreover, the words "exemplary" or "embodiment" are used herein to mean serving as an example, example, or illustration. Any aspect or design described herein as exemplary or an embodiment is not necessarily to be construed as preferred or advantageous over other aspects or designs. Rather, use of the words "exemplary" or "embodiment" is intended to illustrate concepts and techniques.

[0062] As used in this application, the word "or" is intended to mean an inclusive "or" rather than an exclusive "or." That is, unless otherwise specified or clear from the context, "X uses A or B" is intended to mean any of the natural inclusive permutations. That is, if X uses A, X uses B, or X uses both A and B, then "X uses A or B" is satisfied under any of the foregoing examples. Additionally, the articles "a" and "an," as used in this application and the appended claims, should generally be construed to mean "one or more" unless otherwise specified or clear from the context to lead to the singular form.

[0063] Please refer to FIGS. 1 and 2, which are process diagrams of processes for Exact Homomorphic Encryption (EHE) and Secure Multi-Party Exact Homomorphic Encryption (SMEHE), according to method embodiments of the inventive concept.

[0064] The inventive concept provides a system for SMPEHE, which may include a first participant as a model provider / data recipient, a second participant as a data provider / data owner, and a third participant as a communication provider, and the system may further include a key generation module, a message encryption module, and a calculation module.

[0065] According to the inventive concept, the key generation module can be within the first participant and is configured to generate an encryption mapping including an ordered product of elementary gates, generate via the encryption mapping a multivariate polynomial set serving as a public encryption key, form an encryption operator serving as a private key, and create an encrypted polynomial set representing a computation instruction based on the encrypted action.

[0066] According to the inventive concept, the message encryption module may be within the second participant and is configured to encode the plaintext message into a first ciphertext using a public key provided by the first participant and transmit the first ciphertext to the third participant.

[0067] According to the inventive concept, the computation module may be within the third participant and is configured to receive the first ciphertext and perform computation on the received first ciphertext by evaluating the encrypted polynomial set.

[0068] In accordance with the inventive concept, the computation module may be further configured to output a second ciphertext and transmit the second ciphertext to the first participant.

[0069] According to the inventive concept, the system may further comprise a decryption module in the first participant, the decryption module being configured to decrypt the second ciphertext by using the private key to retrieve the calculation result.

[0070] According to the inventive concept, an encryption mapping can be generated by combining elementary gates, including negation, Toffoli, CNOT, and multi-controlled gates, to form an encryption transformation.

[0071] In accordance with the inventive concept, the public cryptographic key can be a multivariate polynomial set generated through a corresponding cryptographic mapping.

[0072] In accordance with the inventive concept, an encrypted polynomial set can be generated by an encrypted action consisting of a desired operation, a cryptographic mapping, and a cryptographic operator, and the polynomial set can be used to perform a calculation on a first ciphertext.

[0073] In accordance with the inventive concept, the computation module may evaluate the encrypted polynomial set in parallel or sequentially on the first ciphertext to generate the second ciphertext.

[0074] In accordance with the inventive concept, the first ciphertext sent by the second participant may be a tensor product state of multiple individual ciphertexts.

[0075] In accordance with the inventive concept, the encrypted action

number

[0076] According to the inventive concept, there is a first communication between a first participant and a second participant, the first communication occurring in parallel or sequentially and including the distribution of a public encryption key from the first participant to the second participant.

[0077] According to the inventive concept, there is a second communication between the first participant and a third participant, the second communication occurring in parallel or sequentially.

[0078] In accordance with the inventive concept, the second communication includes transmitting a computational instruction from the first participant to a third participant and transmitting a second ciphertext from the third participant to the first participant.

[0079] According to the inventive concept, there is a third communication between the second participant and the third participant, the third communication occurring in parallel or sequentially and including the distribution of the first ciphertext from the second participant to the third participant.

[0080] Please refer to Figure 5, which is a schematic flow diagram in accordance with an embodiment of the inventive concept, in conjunction with Figures 1 and 2. The inventive concept further provides a computer-implemented method for performing secure multi-party exact homomorphic encryption (SMPEHE), involving a first participant as a model provider / data recipient, a second participant as a data provider / data owner, and a third participant as a communication provider. The method may include:

[0081] S10. Randomly selecting E≦D elements from a group of D parties in the first participant;

[0082] S20. Generate E distinct key pairs, where each distinct key pair is a cryptographic mapping R en,j public encryption key, which is a multivariate polynomial set generated by

number

[0083] S30. E operations on n qubits M j Here, the operation M j Each of these is composed of elementary gates;

[0084] S40. E encryption transformations R of n qubits cv,j where the encryption transformation Rcv,j Each of these is composed of elementary gates;

[0085] S50. jth encryption action

number

number

number

number

[0086] S60. Public encryption key collection

number

[0087] S70. Encrypted polynomial set

number

[0088] Please refer to Figure 6, which is a schematic flow diagram according to an embodiment of the inventive concept, in conjunction with Figures 1 and 2. In accordance with the inventive concept, the method further includes, for j=1, 2, ..., E:

[0089] S80.E plaintext messages

number

[0090] S90. Plaintext m j Each of these is converted into the corresponding public key

number

[0091] S100. Tensor product state of ciphertext

number

[0092] S110. Send the ciphertext tensor product state |c> to the third participant.

[0093] See Figure 7, which is a schematic flow diagram according to an embodiment of the inventive concept. In accordance with the inventive concept, the method further comprises:

[0094] S120. Encrypted polynomial set

number

[0095] S130.Input

number

number

number

[0096] S140. Second Ciphertext

number

[0097] S150. Sending the second ciphertext |s> to the first participant.

[0098] Please further refer to Figure 7 in conjunction with Figures 1 and 2. In accordance with the inventive concept, the method further comprises:

[0099] S160. Second ciphertext |s j > each of them with the corresponding private key R cv,j The second ciphertext |s j > can be the ciphertext of the jth element in the cryptographic evaluation.

[0100] According to the inventive concept, the encryption mapping R en,j Each of the is composed of a basic gate selected from the group consisting of negation, Toffoli, CNOT, and multi-controlled gates.

[0101] According to the inventive concept, a public key

number

[0102] In accordance with the inventive concept, the encrypted polynomial set

number

[0103] According to the inventive concept, the first ciphertext c j Each of these is a plaintext message m j public encryption key

number

[0104] In accordance with the inventive concept, the tensor product state of the first ciphertext is securely transmitted to a third participant without revealing the plaintext message.

[0105] In accordance with the inventive concept, the encrypted polynomial sets are evaluated independently or sequentially for the first input ciphertext to optimize computational efficiency.

[0106] According to the inventive concept, the private key R cv,j Decrypt the second ciphertext using

[0107] In accordance with the inventive concept, the method further comprises distributing the public encryption key from the first participant to the second participant in parallel or sequentially.

[0108] According to the inventive concept, the method further comprises:

[0109] Sending the computational instructions in parallel or serially from the first participant to the third participant, and sending the second ciphertext in parallel or serially from the third participant to the first participant.

[0110] In accordance with the inventive concept, the method further includes transmitting the first ciphertext from the second participant to the third participant in parallel or serially.

[0111] Please refer to Figure 1, which is a process diagram of EHE according to an embodiment of the inventive concept. The process is as follows: (1) a first participant sends a public key P w,k (R en ;x) and releases this key, after which (2) a second participant obtains the public key and encodes the message m into a ciphertext c.

[0112] Next, (3) the ciphertext c is transmitted from the second participant to the third participant. After that, (4) the first participant transmits the computation instructions / model P n,w (U cv ;z) to a third participant for further processing. Once the computation is done, (5) the resulting ciphertext s is sent by the third participant back to the first participant. Finally, the first participant obtains the private key R cv The calculation result s is decrypted via and the final output of the process is obtained.

[0113] See FIG. 2, which is a process diagram of a SMPEHE according to an embodiment of the inventive concept.

[0114] According to this embodiment, the process comprises: (1) a first participant sends a public key

number

[0115] Then, (3) the aggregated ciphertext c is then sent from the second participant to the third participant. Then, (4) the first participant sends the computation instructions / model

number

[0116] Finally, (5) the third participant calculates the ciphertext

number

[0117] According to an embodiment of the inventive concept, a multivariate polynomial of k variables

number

number

number

[0118] In this embodiment, the formula provides a basic representation of polynomials in the binary field Z2.

[0119] The polynomial f(x) can serve as the basis for encoding and transforming data in the EHE framework in the system of the inventive concept, where public encryption keys are generated as multivariate polynomial sets.

[0120] According to an embodiment of the inventive concept, an elementary gate of k qubits

number

number

[0121] In this embodiment, the elementary gates can operate on k-qubit quantum states, and the gates perform the transformation

number

number

[0122] In this embodiment, the basic gates can include a negation gate, a controlled-NOT (CNOT) gate, a Toffoli gate, and a multi-controlled gate, as shown in FIG.

[0123] All elementary gates are one-dimensional preserving transformations that map one underlying quantum state to another, see Figure 3 for a schematic illustration. This set guarantees computational universality because AND and OR can be rephrased as Toffoli gates with ancilla qubits. These gates can operate on quantum states to enable transformations within the EHE framework.

[0124] Each of the elementary gates used in the inventive concept is designed to be one-dimensionally conserving, avoiding the large memory requirements associated with simulating a full quantum state. This design can support the feasibility of implementing the system on conventional computing platforms such as CPUs and GPUs, without the need for quantum hardware.

[0125] According to an embodiment of the inventive concept, elementary gates are applied to quantum states, in this embodiment, the elementary gates are capable of generating multivariate polynomials over the binary field Z2, operating on variables and formulated as the following transformation rules:

[0126]

number

[0127] where x s ∈Z2 is a binary variable,

number

[0128] According to an embodiment of the inventive concept, a first encryption mapping R is generated which is an ordered product of randomly selected elementary gates. en We can define a first encryption operator R en is applied to generate a set of w multivariate polynomials that serve as public encryption keys for encoding a k-qubit plaintext into a w-qubit first ciphertext, where w≧k, for message encryption.

[0129] The first encryption mapping is constructed to encode plaintext into ciphertext by applying a transformation to an input polynomial. In accordance with the inventive concept, the output can be a set of w multivariate polynomials that can form a public encryption key.

[0130] The transformation rule in Equation 1 effectively reveals a polynomial representation of the elementary gates. When this mapping is applied, the variable x s is the product x if the sth qubit corresponds to the target bit. θ In actual operation, elementary gates operate on the variables of a monomial.

number

[0131] According to an embodiment of the inventive concept, a desired operation M of n qubits (n>w) is introduced, where M is represented as a circuit composed of n-qubit elementary gates. In this embodiment, the operation M can serve as a computation that is homomorphically encrypted and executed.

[0132] According to an embodiment of the inventive concept, the second encryption mapping R cv is defined, and R cv is the ordered product of randomly chosen n-qubit elementary gates. The second encryption mapping R cv can introduce cryptographic complexity.

[0133] According to an embodiment of the inventive concept, a desired operation M can be encoded into a cryptographic action U, where the desired operation M is a first cryptographic operator R en and a second encryption operator R cv through the encryption action U. The process can ensure that the operation M is transformed into a secure encrypted form that is compatible with the ciphertext computation.

[0134] According to an embodiment of the inventive concept, an encrypted polynomial set is generated from the encrypted action U, and the encrypted polynomial set can be evaluated in the ciphertext to obtain the encrypted computation.

[0135] According to an embodiment of the inventive concept, an encrypted action U can allow a computation to be performed in the encrypted domain, and a polynomial set can act as an intermediary for evaluating the encrypted operation.

[0136] The computation can be performed homomorphically by the system of the inventive concept without decrypting the ciphertext. The evaluation process, called cryptographic evaluation, establishes a duality between polynomial evaluation and state calculation, thereby allowing the integrity of the encrypted computation to be verified.

[0137] According to an embodiment of the inventive concept, a second binary string ζ is introduced, which determines how the variables interact within the monomial. Based on the second binary string ζ, the monomial x θ Modified form

number

[0138]

number

[0139] where s∈[k] and

number

number

[0140] In this embodiment, a second binary string ζ is used to modify the interaction of the monomials through control bits, introducing additional degrees of freedom in the transformation of variables.

[0141] According to an embodiment of the inventive concept, a monomial x θ is the modified form

number

[0142]

number

[0143] where x i ∈Z2 can represent variables, and ζ i ∈Z2 can change the interaction of each variable based on its binary value, and ε i can determine the control bit configuration.

[0144] According to the concept of the present invention, the most general form of a basic gate operating on k variables over Z2 can be expressed as Equation 2.

[0145] According to the inventive concept, generalizing Equation 1 to Equation 2 extends the transformation rule by incorporating a second binary string ζ.

[0146] In accordance with the inventive concept, generalization can improve the capabilities of the framework in the inventive concept's system to support more complex polynomial transformations and to represent and process non-linear relationships in encrypted polynomial sets.

[0147] According to an embodiment of the inventive concept, a first encryption mapping R is provided as a product operation R, which is a k-qubit ordered product of elementary gates. en can be further defined as follows:

[0148]

number

[0149] where:

number

number

[0150] According to the inventive concept,

number

[0151] According to the inventive concept, an ordered product R can encapsulate the successive application of these gates to transform a plaintext state into an encrypted representation.

[0152] According to the inventive concept, the use of elementary gates, for example negation, CNOT, Toffoli gates, can be used as building blocks for cryptographic mappings.

[0153] In accordance with an embodiment of the inventive concept, the inverse product operation

number

number

[0154]

number

[0155] In this embodiment, the inverse operation can ensure symmetry, facilitating invariant properties that are important for encryption and decryption processes within the SMPEHE framework of the system of the inventive concept.

[0156] According to an embodiment of the inventive concept, for each elementary state |x>, a product operation R and its inverse

number

[0157]

number

number

[0158] According to the concept of the present invention, an elementary gate of k qubits

number

[0159]

number

[0160] where r∈[k], θ=ε1ε2…ε k , and

number

[0161] The equation in Equation 3 can be viewed as an evaluation duality between a state and its associated polynomial. In particular,

number

number

number

number

number

number

number

[0162] R and its reciprocal

number

[0163] According to the inventive concept, successive application of gates in R allows for the introduction of layers of cryptographic complexity by exploiting the non-commutative properties of elementary gates for enhanced security.

[0164] equivalence

number

[0165] According to an embodiment of the inventive concept, an initial set of multivariate polynomials P in {g j (x)|j∈[w]} is prepared, and g j(x) corresponds to each polynomial f(x), and g j Each of (x) is expressed as follows:

[0166]

number

[0167] where c τ,j ∈Z2 are binary coefficients,

number

[0168] In this embodiment, the polynomial set can be structured and can be compatible with subsequent cryptographic transformations, allowing efficient computation in the SMPEHE framework in the system of the inventive concept.

[0169] According to an embodiment of the inventive concept, a first encryption operator R en is the initial polynomial set P in is applied to each polynomial in the

number

[0170] In this embodiment, the first encryption operator R en is P in Each polynomial g in j (x) to the corresponding encrypted polynomial f j (x). The transformation can be expressed as:

number

[0171] Polynomials can be transformed into a secure form while preserving structural integrity.

[0172] The algorithm is w,k (R en x), a first encryption operator R comprising a certain number of multi-controlled gates of higher rank ≥ 2 for the purpose of generating polynomials of higher degree; en Priority is given to R en Within the configuration of

number

number

[0173] In this embodiment, the condition w≧k ensures sufficient encryption power of the plaintext. w,k (R en ;x) can serve as a reusable key for encoding plaintext into ciphertext.

[0174] According to an embodiment of the inventive concept, a plaintext |m> may be provided, where the plaintext consists of k quantum bits. The plaintext may be encoded into a first ciphertext |c>, where the ciphertext consists of w quantum bits. The ciphertext may be encoded by a public encryption P w,k (R en ;x), where:

[0175] |c>=|f1(m)f2(m)…f w (m)>

[0176] where:

number

number

[0177] In this embodiment, the plaintext |m> can serve as the data to be encrypted using the EHE framework of the inventive concept, and the public encryption P w,k (R en ;x) can serve as a functional basis for encoding plaintext into ciphertext. In particular, the ciphertext |c> is a multivariate polynomial set given a public key P w,k (R en ;x) rating.

[0178] According to the inventive concept, the number of distinct polynomial sets generated by all permutations of the elementary gates that make up an operator R is the smallest number in h!, where h is the size of the largest set of pairwise non-commutative gates in R.

[0179] In an embodiment of the inventive concept, the notion of a maximal set of pairwise non-commutative gates in R is introduced to ensure that the pairwise non-commutative gates satisfy A·B ≠ B·A and their order affects the resulting transformation. Additionally, the size of the maximal set is denoted as h, which captures the structural complexity of R.

[0180] As a result, there is an encryption mapping R whose maximal set is of size h. en The public key P generated by w,k (R en Attempting to reconstruct ;x) incurs a combinatorial complexity of at least h!

[0181] An encryption mapping R constructed from multiple disjoint subsets of mutually non-commutative gates. en About h l !·h l-1The total complexity is given by !...h1! (h r , r∈[l]). This establishes a cryptographic complexity criterion based on the structural properties of the cryptographic operator R. This result allows us to directly quantify the security strength of the cryptographic mapping of the inventive concept.

[0182] According to an embodiment of the inventive concept, a first encryption mapping R en The first ciphertext |c> with w qubits is

number

[0183] The complexity of attacking a w-qubit reversible message encryption IME is determined by the complexity criterion T de-NC >T ICRP >T XL >2 W It is proved that, where T de-NC is the complexity of the decomposition non-commutativity of this IME, and T ICRP is the complexity of solving the reversible circuit reconstruction problem (ICRP) of this IME, and T XL is the complexity of attacking this IME via the XL algorithm, and 2 W is the complexity of attacking this IME via brute force methods.

[0184] The IME complexity criteria imply that attacking the private key is more difficult than cracking the public key or the ciphertext.

[0185] Based on the complexity criterion, the security strength of an IME can be easily increased with little effort, and its minimum strength grows linearly with the length of the input plaintext.

[0186] Based on the complexity criteria, the public key P w,k (R en The security of IME using ;x) is based on post-quantum standard 2 128 and further exceed the proposed threshold of hyper-quantum resistance, 21024 Achieve this.

[0187] The security requirements of IME exceed post-quantum standards, particularly meeting advanced privacy demands above a security level of 256 bits.

[0188] The security requirements of the IME protect information from quantum attacks, including Grover's algorithm, quantum annealing, and quantum Groebner basis algorithms.

[0189] See also Figure 2. The IME is a set of E independent key pairs.

number

number

number

number

[0190] In multi-party IME, E messages / plaintexts

number

number

[0191] In multi-party IME, each individual ciphertext c j is R en,j via m j is decrypted to

[0192] Multi-party IME follows similar security criteria as IME, and de-NC >T ICRP >T XL >2 W where:

number

[0193] Due to duality, ciphertext

number

number

number

number

number

number

[0194] According to the concept of the present invention, the duality relation and R en The accuracy of the decryption is provided by the reversibility of the elementary gates used in (2), whereby the plaintext can be recovered exactly from the ciphertext without error, and in this respect the system of the inventive concept can be distinguished from noisy decryption methods of conventional systems.

[0195] In accordance with the inventive concept, an encrypted polynomial set can be generated from an encrypted action defined as follows:

[0196]

number

[0197] where R en,j and R cv,j is the encryption transformation,

number

number

[0198] In accordance with the inventive concept, the encrypted action

number

[0199] According to an embodiment of the inventive concept, the encrypted action U cv is defined, where

number

number

[0200]

number

[0201] where:

number

number

number

number

number

[0202] The inventive concept borrows the mechanism of QAPFTQC to encrypt the computation.

[0203] The k-qubit plaintext is then subjected to a first encryption operator R en Suppose that the second encryption operator R is encoded into w qubit ciphertext via a set of multivariate polynomials generated by cv With this, the n-qubit operation M, which is the circuit of the elementary gate, performs the encryption action

number

number

[0204] This encryption action is a simplified form of the fault-tolerant encoding in QAPFTQC. cv We rewrite the circuit as a set of n multivariate polynomials. Based on poetic duality, we obtain the cryptographic evaluation by evaluating this set of polynomials on the ciphertext. Finally, we use R cv can serve as a private cryptographic evaluation key to decrypt the encrypted calculations.

[0205] If w=n, then the messages and computations are mapped into the same cryptographic space as shown in Figure 4(a).

[0206] See further FIG. 1. In this embodiment, the public key R cv The polynomial set P generated by w,k (Rcv ;x) encodes |m> into ciphertext |c>. In the strength of the binary relation, this ciphertext can instead be written as

number

number

number

number

number

number

number

[0207] Related States

number

number

number

number

number

number

[0208] According to the inventive concept,

number

number

number

[0209] In addition, the encryption action U cv enables secure computation by maintaining a cryptographic state throughout the process and keeping data confidential.

[0210] According to an embodiment of the inventive concept, a first encryption operator R enGiven a w-qubit ciphertext |c> of a k-qubit plaintext |m> derived from an n-qubit action M (n>w≧k), generate the following set of encrypted polynomials:

[0211]

number

[0212] Here, β i (z) is the encryption polynomial set P n,w (U cv ;z) is the ith polynomial in (

number

[0213] Here, the encrypted operation

number

number

number

[0214] The proof is similar to that above, but

number

number

number

number

number

number

number

number

[0215] According to an embodiment of the inventive concept, U cv e sections that make up the encryption circuit U cv,q can be made parallel (q∈[e]) to generate successive evaluations of the following set of encrypted polynomials:

[0216]

number

[0217] In an embodiment of the inventive concept, the first encryption mapping R en The ciphertext |c>, a w-qubit ciphertext derived from U, encodes the k-qubit plaintext |m>, where |c> can serve as the input for an encrypted computation action. cvcan further transform the ciphertext |c> in the encryption domain. Then, the encrypted polynomial set P n,w (U cv ;z) is generated, where each β i (z) is U cv The transformed variable z under the action of i It can respond to.

[0218] In another embodiment of the inventive concept, the encrypted action U cv e sections of the encryption circuit U cv,q The circuit can be divided into sections, each of which can handle a subset of the computation independently, facilitating parallel execution. cv Each of these is stored in the encrypted domain as a variable z i can be applied to.

[0219] For every circuit q, the encrypted polynomial set P n,w (U cv,q ;z) is generated,

number

[0220] All section circuits U cv,q are applied, the resulting polynomial sets can be successively combined. n,w (U cv,q ;z) into a final encrypted polynomial set to complete the computation.

[0221] The complexity of attacking a computational coding that is an encryption evaluation of n qubits against a w-qubit ciphertext is 2 W Higher than.

[0222] In cryptography, attacking a private key is more difficult than cracking a public key or ciphertext.

[0223] In cryptographic evaluation, security strength can be easily increased with little effort, and the maximum strength grows linearly with the length of the input ciphertext.

[0224] In cryptographic evaluation, security is evaluated based on the post-quantum standard 2 128 and further exceed the proposed threshold of hyper-quantum resistance, 2 1024 Achieve this.

[0225] The security requirements of the cryptographic evaluation exceed post-quantum standards, in particular meeting advanced privacy demands above a security level of 256 bits.

[0226] The SMPEHE is subject to security criteria and requirements similar to those of the EHE.

[0227] The security requirements of the cryptographic evaluation protect information from quantum attacks, including Grover's algorithm, quantum annealing, and quantum Groebner basis algorithms.

[0228] According to the inventive concept, there is a first communication between a first participant and a second participant, the first communication occurring in parallel or sequentially and including the distribution of a public encryption key from the first participant to the second participant.

[0229] According to an embodiment of the inventive concept, a first communication between a first participant and a second participant may refer to the distribution of a public encryption key from the first participant to the second participant, which may enable the second participant to encrypt their plaintext data into ciphertext.

[0230] In an embodiment, the ciphertext |c> is a multivariate polynomial set for an input message x=m. w,k (R en ;x) rating.

[0231] In this embodiment, the second participant can use the public encryption key to convert the plaintext message m into the first ciphertext |c>. The process of accessing the public encryption key is a fundamental step in the first communication between the participants.

[0232] According to the inventive concept, there is a second communication between the first participant and a third participant, the second communication occurring in parallel or sequentially.

[0233] In accordance with the inventive concept, the second communication includes transmitting a computational instruction from the first participant to a third participant and transmitting a second ciphertext from the third participant to the first participant.

[0234] According to the inventive concept, the second communication between the first and third participants can involve two main steps: sending a computation command and sending a computation result.

[0235] In an embodiment of the inventive concept, a first participant can send an encrypted polynomial set that can represent a computation instruction to a third participant, allowing the third participant to perform the computation on the encrypted data. After performing the computation, the third participant can also send the result of the encryption computation, called a second ciphertext, back to the first participant, who can decrypt the result using the private key.

[0236] In an embodiment, the encrypted computation, called a cryptographic evaluation, is the product of evaluating an encrypted polynomial set against the input ciphertext. The result of the encrypted computation is the evaluated polynomial set, which is returned as an encrypted output. The encrypted result is sent to the first participant for decryption.

[0237] In this embodiment, the first participant sends an encrypted polynomial set to the third participant as a computation instruction. The encrypted polynomial set encodes the function to be computed. After evaluating the polynomial set, the third participant sends the result back to the first participant as an encrypted output, i.e., a second ciphertext. This explicitly indicates that the encrypted computation result is being sent from the third participant to the first participant.

[0238] According to the inventive concept, there is a third communication between the second participant and the third participant, the third communication occurring in parallel or sequentially and including the distribution of the first ciphertext from the second participant to the third participant.

[0239] In accordance with the inventive concept, a third communication between the second and third participants involves sending a first ciphertext (i.e., an encrypted message) from the second participant to the third participant. The third communication can enable the computation provider to receive encrypted data upon which computations are performed.

[0240] In an embodiment of the inventive concept, the ciphertext |c> is obtained by enumerating the public key P w,k (R en ;x). The encrypted message is sent to a computation provider. The encrypted polynomial set and ciphertext can be processed sequentially or in parallel to optimize computational efficiency.

[0241] In this embodiment, the second participant encrypts the plaintext using a public key provided by the first participant, followed by the formation of a first ciphertext. The transmission of the first ciphertext from the second participant to the third participant ensures that the encrypted data reaches the third participant for further processing. The data flow, including the ciphertext transmission, can be implemented using either a parallel or sequential method, depending on the architecture.

[0242] The third communication ensures that the computation provider receives the necessary encrypted data to perform the cryptographic evaluation (computation on the encrypted data).

[0243] This communication path supports flexible parallel or serial data transfer methods, but is primarily focused on securely transferring encrypted input data without exposing the plaintext.

[0244] The above description of the detailed embodiments is presented only to disclose the features and functions of the inventive concept, and is not intended to limit the scope of the inventive concept. Those skilled in the art will understand that all modifications and variations according to the spirit and principles of the disclosure of the inventive concept are within the scope of the appended claims.

Claims

1. 1. A system for secure multi-party exact homomorphic encryption (SMPEHE), the system including a first participant as a model provider / data recipient, a second participant as a data provider / data owner, and a third participant as a communications provider, the system comprising: a key generation module within the first participant configured to generate a cryptographic mapping comprising an ordered product of elementary gates, generate through the cryptographic mapping a multivariate polynomial set serving as a public cryptographic key, form a cryptographic operator serving as a private key, and create an encrypted polynomial set representing a computation instruction based on the encrypted action; a message encryption module within the second participant configured to encode a plaintext message into a first ciphertext using the public key provided by the first participant and transmit the first ciphertext to the third participant; and a computation module within the third participant configured to receive the first ciphertext and perform a computation on the received first ciphertext by evaluating the encrypted polynomial set; The system further comprising:

2. 10. The system of claim 1, the computation module is further configured to output a second ciphertext and transmit the second ciphertext to the first participant. A system characterized by:

3. 3. The system of claim 2, The system further comprises a decryption module within the first participant; the decryption module is configured to decrypt the second ciphertext by using the private key to retrieve a calculation result. A system characterized by:

4. 4. The system of claim 3, The encryption mapping is generated by combining elementary gates, including negation, Toffoli, CNOT, and multi-controlled gates, to form an encryption transformation. A system characterized by:

5. 5. The system of claim 4, the public encryption key is a multivariate polynomial set generated through the corresponding encryption mapping; A system characterized by:

6. 10. The system of claim 1 or 5, the encrypted polynomial set is generated by the encrypted action consisting of a desired operation, the encryption mapping, and the encryption operator, and the polynomial set is used to perform a calculation on the first ciphertext. A system characterized by:

7. 7. The system of claim 6, the computation module evaluates, in parallel or sequentially, encrypted polynomial sets on the first ciphertext to generate the second ciphertext; A system characterized by:

8. 8. The system of claim 7, the first ciphertext sent by the second participant is a tensor product state of a plurality of individual ciphertexts; A system characterized by:

9. 9. The system of claim 8, The encrypted polynomial set is generated from an encrypted action defined as follows: [Equation 1] Here, R en,j and R cv,j is the encryption transformation, [Equation 2] is R en,j is the reciprocal of M j is an operation that includes basic gates, [Equation 3] is n j -w j is the identity operator for qubits, A system characterized by:

10. 10. The system of claim 9, said encrypted action [Equation 4] Each circuit in t and j for t t The polynomial is further divided into sections to generate a refined encryption polynomial set. A system characterized by:

11. 11. The system of claim 10, a first communication exists between the first participant and the second participant; the first communication may occur in parallel or serially and may include distribution of a public encryption key from the first participant to the second participant; A system characterized by:

12. 12. The system of claim 11, a second communication exists between the first participant and the third participant; the second communication is performed in parallel or sequentially and includes transmitting the computational instructions from the first participant to the third participant and transmitting the second ciphertext from the third participant to the first participant. A system characterized by:

13. 12. The system of claim 11, a third communication exists between the second participant and the third participant; the third communication may occur in parallel or serially and includes distribution of the first ciphertext from the second participant to the third participant; A system characterized by:

14. 1. A computer-implemented method for performing secure multi-party exact homomorphic encryption (SMPEHE), involving a first participant as a model provider / data recipient, a second participant as a data provider / data owner, and a third participant as a communications provider, the method comprising: S10. Randomly selecting E≦D elements from the group of D parties in the first participant; S20. Generate E independent key pairs, each of the independent key pairs being, for j=1, 2, ..., E, Encryption Mapping R en,j The public key is a multivariate polynomial set generated by [Equation 5] and, A private key R corresponding to the public key en,j and, generating a S30. E operations M of n quantum bits j and preparing the operation M j Each of the gates is composed of a basic gate. S40. E encryption transformations R of n quantum bits cv,j generating the encryption transformation R cv,j Each of the gates is composed of elementary gates. S50. jth encryption action [Equation 6] Based on the above, a set of E encrypted polynomials is obtained. [Equation 7] where M j is the desired operation on the jth element, [Equation 8] is R en,j is the reciprocal of [Equation 9] is n j -w j The identity operator for qubits is S60. Public key collection [Equation 10] and S70. Encrypted polynomial set [0011] to the third participant; Including, 10. A computer-implemented method comprising:

15. 15. The computer-implemented method of claim 14, The method is as follows: for j=1, 2, ..., E: S80. E plaintext messages [0012] each of which is k j qubit states, where k j ≦w j That is, preparation and S90. Plaintext m j each of the public keys [0013] The first ciphertext c j and S100. Tensor product state of ciphertext [0014] and S110. Sending the ciphertext tensor product state |c> to the third participant; 20. The computer-implemented method of claim 19, further comprising:

16. 16. The computer-implemented method of claim 15, The method comprises: S120. The encrypted polynomial set [Equation 15] among L independent third participants; S130. Input [0016] For the encrypted polynomial set [Equation 17] wherein: [Equation 18] is n j -w j Evaluating the null state of the qubits, S140. The second ciphertext [Equation 19] and S150. Sending the second ciphertext |s> to the first participant; 20. The computer-implemented method of claim 19, further comprising:

17. 17. The computer-implemented method of claim 16, The method comprises: S160. The second ciphertext |s j > by the corresponding private key R cv,j and recovering the result of the calculation; 20. The computer-implemented method of claim 19, further comprising:

18. 16. The computer-implemented method of claim 15, The encryption mapping R en,j each of which is composed of a basic gate selected from the group consisting of negation, Toffoli, CNOT, and multi-controlled gates; 10. A computer-implemented method comprising:

19. 20. The computer-implemented method of claim 18, said public key [Equation 20] Each of the encryption mappings R en,j to an initial set of polynomials, including linear and nonlinear polynomials, 10. A computer-implemented method comprising:

20. 18. The method of claim 17, the encrypted polynomial set [0000] encodes a computation instruction for an operation to be executed by the third participant; 10. A computer-implemented method comprising:

21. 16. The computer-implemented method of claim 15, The first ciphertext c j Each of the plaintext messages m j For the public key [Equation 22] and is generated by evaluating j ≦w j is obtained, 10. A computer-implemented method comprising:

22. 17. The computer-implemented method of claim 16, the tensor product state of the first ciphertext is securely transmitted to the third participant without revealing the plaintext message.

10. A computer-implemented method comprising:

23. 17. The computer-implemented method of claim 16, the encrypted polynomial sets are evaluated independently or sequentially for the first input ciphertext to optimize computational efficiency; 10. A computer-implemented method comprising:

24. 18. The computer-implemented method of claim 17, The private key R cv,j decrypting the second ciphertext using 10. A computer-implemented method comprising:

25. 16. A computer-implemented method according to claim 11 or 15, comprising: The method further includes distributing the public encryption keys from the first participant to the second participant in parallel or serially.

10. A computer-implemented method comprising:

26. 18. The computer-implemented method of any one of claims 12, 16, or 17, comprising: The method comprises: transmitting computational instructions from the first participant to the third participant in parallel or serially; transmitting the second ciphertext from the third participant to the first participant in parallel or serially; 20. The computer-implemented method of claim 19, further comprising:

27. 17. A computer-implemented method according to claim 13 or 16, comprising: the method further comprising transmitting the first ciphertext from the second participant to the third participant in parallel or serially; 10. A computer-implemented method comprising:

Citation Information

Patent Citations

  • Quantum security multi-party computing method based on quantum homomorphic encryption

    CN113660085A

  • Key generating device, encryption device, decryption device, multiplication type knapsack encryption system, multiplication type knapsack decryption method, and program

    JP2007171412A

  • Method and apparatus for efficient multiplication of multiple parties

    JP2007510947A

  • Method of designing one-way computational system in QAP-based homomorphic encryption

    US20230188342A1

  • Method of Designing of Multi-Party System in QAP-Based Homomorphic Encryption

    US20230188343A1