Calculation of Symbolized and Encrypted Values
By encoding values with carry-free or carry-containing partials and using programmable bootstrapping, the method enhances the efficiency and flexibility of homomorphic encryption for large integer computations, addressing accuracy and parallelization issues in existing techniques.
Patent Information
- Application Number
- JP2024569310
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-05-24
- Filing Date
- 2023-05-24
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2043-05-24
AI Technical Summary
Existing homomorphic encryption techniques face challenges with low accuracy and efficiency for integer plaintexts exceeding 7 bits, lack of parallelization, and inflexibility in performing arithmetic operations, particularly multiplication and addition, due to carry propagation and sequential processes.
The method involves encoding and encrypting values using radix decomposition with carry-free or carry-containing partial values, allowing for selective carry reduction and parallelization of operations, and utilizing programmable bootstrapping for efficient arithmetic computations on large values.
This approach significantly improves efficiency and flexibility in performing encrypted computations on large values by reducing the need for carry reduction operations and enabling parallel processing, particularly in multi-threaded and multi-core systems.
Smart Images

Figure 2025519117000001_ABST
Abstract
Description
Technical Field
[0001] The subject matter disclosed in the present invention relates to cryptographic methods for performing encrypted computations, corresponding devices, compiler methods and devices for encrypted computations, and computer-readable media.
Background Art
[0002] Homomorphic encryption methods enable performing encrypted computations: that is, enabling computations performed by a party on encrypted data, such as circuit evaluation, in a state where the party cannot decrypt. For example, input data and computation results may be received and returned in encrypted form. Intermediate data of the computation, such as internal states, may also be in encrypted form.
[0003] Although the result of the computation is returned in encrypted form, when decrypted, the output is expected to be the same as, or very close to, that when the operation is performed on unencrypted data. Homomorphic encryption can be used for outsourced storage and computation while protecting privacy. This enables data to be encrypted and outsourced to a cloud environment for processing and / or storage while remaining encrypted throughout.
[0004] For example, homomorphic encryption methods may be applicable in fields such as healthcare, where privacy regulations can make it difficult to share plain data, but computations on encrypted healthcare data may be permitted. For example, a healthcare model developed to classify healthcare data may be configured to receive healthcare data in encrypted form from a third party, such as a hospital. The healthcare model may classify the healthcare data as, for example, normal or abnormal, or as having a particular medical symptom, disease, or other disorder. Using homomorphic encryption, the healthcare model can be applied to healthcare data received in encrypted form. This means that the parties providing the healthcare model do not have access to the plain healthcare data corresponding to the encrypted healthcare data. The user of the service can decrypt the results of the healthcare model application.
[0005] In particular, there exist homomorphic encryption techniques that can be used, at least in principle, to compute any function on encrypted data. Such techniques are called "fully homomorphic encryption" (FHE) techniques.
[0006] Known implementations of FHE use noisy ciphertexts for security reasons. For example, the encryption of a data item may involve mapping the data item to a point in a key-dependent lattice, to which noise is added. In particular, many known implementations of FHE use LWE-type ciphertexts, whose security depends on the cryptographic hardness of the Learning With Errors problem. Such LWE-type ciphertexts may comprise one or more masked values (e.g., values modulo a particular modulus q, or torus elements), and a body value derived from the masked values and from the plaintext using a cryptographic key, and containing noise. A generalization of this is the GLWE-type ciphertext that encrypts and uses polynomials instead of scalar values. RLWE-type ciphertexts are another type of GLWE ciphertext. Other known implementations of FHE use NTRU-type ciphertexts, for which the same considerations generally apply.
[0007] When a data item has just been encrypted, it is less noisy and the encryption is fresh. For example, since the amount of noise is very small, if the data item is decrypted, at some point in the decryption process the noise can be removed, e.g., by rounding. On the other hand, the noise must be high enough to make attacks on the system sufficiently difficult. For example, as a hypothesis, if there were no noise, many homomorphic encryption schemes could be attacked using linear algebra, or other efficient algorithms such as lattice reduction algorithms. When a data item is encrypted, noise is added that is chosen to make attacks difficult, but homomorphic operations can still be performed and decryption is still possible.
[0008] Most homomorphic operations increase the noise inherent in the homomorphically encrypted data items. When many such operations are performed, the noise can reach a level where unique decryption is no longer possible. In general, it is known to use a technique called bootstrapping to reduce the noise of homomorphically encrypted values. Bootstrapping may use a public key called a bootstrapping key. By using bootstrapping to reduce noise when necessary, it is possible in principle to compute any desired number of homomorphic operations.
[0009] A particular class of fully homomorphic encryption schemes is the TFHE-like homomorphic encryption scheme. Such a scheme is described in I. Chillotti et al., "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks", Cyber Security Cryptography and Machine Learning (CSCML 2021), vol. 12716 of Lecture Notes in Computer Science, pp. 1-19, Springer, 2021 (incorporated herein by reference). TFHE-like schemes are distinguished from other FHE schemes by supporting a relatively very efficient bootstrapping technique; furthermore, at the same time, it enables the evaluation of functions during the bootstrap operation, which is called programmable bootstrapping. Ordinary bootstrapping corresponds to programmable bootstrapping using the identity function.
[0010] Other known implementations of TFHE-like schemes use NTRU-type ciphertexts, and the same considerations generally apply to these as well. In particular, NTRU may be used in combination with the techniques provided by using blind rotation to yield the NTRU-encrypted polynomial product of a test polynomial and a bootstrapping monomial, and / or by applying blind rotation to an NTRU ciphertext as input. Examples of suitable NTRU encryptions are defined in C. Bonte et al., "FINAL: Faster FHE instantiated with NTRU and LWE", Cryptology ePrint Archive, Paper 2022 / 07; and K. Kluczniak, "NTRU-ν-um: Secure Fully Homomorphic Encryption from NTRU with Small Modulus", Cryptology ePrint Archive, Paper 2022 / 089.
[0011] Interestingly, the output of programmable bootstrapping has a noise amount independent of the noise in the input ciphertext. Thus, by performing programmable bootstrapping, the noise in the input ciphertext can be reduced to a fixed amount, and in some cases, a function can be applied to the input ciphertext at the same time. By performing programmable bootstrapping at the appropriate timing, it is possible to perform encrypted computations of unlimited multiplicative complexity.
[0012] Despite the power of the PBS operation, it is still difficult today to efficiently perform arithmetic operations (e.g., multiplication) on relatively large values, such as values defined modulo a modulus greater than 256 or greater than 1024. One reason for this is that PBS scales worse than linearly with the size of the input.
[0013] In the paper "Putting up the Swiss army knife of homomorphic calculations by means of TFHE functional bootstrapping" by P. Clet et al., Cryptology ePrint Archive, Report 2022 / 149, a technique for performing multiplication and addition on ciphertexts relying on a digit decomposition approach is proposed. This means that values are encoded and encrypted by encrypting the elements of the radix decomposition of the value modulo base β. In this article, the authors propose an addition that uses two or more programmable bootstrappings for each ciphertext encrypting the elements of the decomposition. The addition is performed sequentially. Multiplication is performed based on a textbook multiplication approach. Despite these developments, further improvements in cryptographic calculations for large encrypted values are still needed.
Prior Art Documents
Non-Patent Documents
[0014]
Non-Patent Document 1
Non-Patent Document 2
Non-Patent Document 3
[0015] The inventors have noticed several drawbacks in existing approaches.
[0016] Some existing approaches have low accuracy with respect to integer plaintexts using TFHE: that is, when encrypting an integer using a single ciphertext, it is not currently practical to perform arithmetic operations such as multiplication on ciphertexts containing plaintexts exceeding 7 bits.
[0017] Also, existing approaches lack efficiency. Approaches based on converting calculations to Boolean circuits and then evaluating the circuits by gate bootstrapping are significantly slower in practice when the plaintext is not a Boolean value. Also, existing approaches that rely on encoding values using small integers (e.g., 1 or 2 bits) are slow because operations on these small integers are typically constructed using PBS or followed by PBS, and require a costly PBS.
[0018] Another drawback of existing approaches is that they cannot be parallelized. For example, when an integer is encoded by radix decomposition, performing addition or multiplication may involve carry propagation along the MSB of the homomorphic integer, which is a sequential process. This suggests that the speed decreases during homomorphic circuit evaluation when parallelization is possible.
[0019] A further drawback is the lack of flexibility. For example, existing implementations of arithmetic operations involving carry propagation, such as addition or multiplication, cannot flexibly adapt the way arithmetic operations are performed according to the size of the input, and thus cannot optimize performance according to the current use case.
[0020] An object of the present invention is to address at least some of these problems.
Means for Solving the Problems
[0021] According to one aspect of the present invention, there is provided a cryptographic computing method for performing encrypted computations as defined by the claims. According to a further aspect, there is provided a device corresponding to a computer-implemented method as defined by the claims. According to another aspect, there is provided a computer-readable medium as defined by the claims.
[0022] Various aspects relate to performing encrypted computations on one or more sets of encoded and encrypted values. The values may be numerical values, for example, values defined modulo a particular overall modulus q. Such values modulo q may be interpreted, for example, as unsigned integers (e.g., from the range [0, q)), signed integers (e.g., from [−q / 2, q / 2)), fixed-point numbers, etc.
[0023] Such encoded and encrypted values may be encoded and encrypted as the encryption of a plurality of respective subvalues, also referred to herein as "blocks". As an example, the value and the subvalues may be related according to a radix decomposition according to a fixed base β. As discussed in more detail elsewhere, several other ways of relating the value and the subvalues are possible.
[0024] In one embodiment, the encryption of the subvalues is LWE encryption. In one embodiment, the encryption of the subvalues is NTRU encryption.
[0025] Encrypted computations can include applying one or more encrypted operations to a set of encoded and encrypted values, such as arithmetic operations like addition and / or multiplication; function applications such as applying ReLU, sign, exponential, or other univariate functions; and / or other numerical operations. Such encrypted operations may generally take as input one or more encoded and encrypted input values (and optionally, additional inputs such as further encrypted values or unencrypted values), and may yield one or more encoded and encrypted output values. Interestingly, the operations are performed in encrypted form in the sense that they do not leak information about the input and / or output values, and in particular, the input values are not decrypted in order to perform the operations.
[0026] Interestingly, the inventors considered using the encoding of encoded and encrypted values into encrypted partial values that are enabled to hold a carry. The partial values may have an associated message modulus, but may also have a carry message modulus larger than the message modulus. For example, the partial values may be defined according to a radix decomposition where the radix, and thus also the message modulus, is 8, but may be encrypted as values modulo a carry message modulus of 64. Thus, a value may be encoded and encrypted without a carry, which means that the partial values are carry-free partial values smaller than the corresponding message modulus; however, a value may also be encoded and encrypted with a carry, which means that at least one of the partial values is a carry-containing partial value greater than or equal to the corresponding message modulus.
[0027] Values encoded and encrypted with a carry, according to the relationship between the value and the carry-free partial values, and according to corresponding carry-reduction operations, such as according to a radix decomposition using a message modulo β, and reducing the partial value m to m mod β for carry
Number
[0028] The inventors have noticed that a partial value with carry can be used not only within an encrypted operation, but also as an input or output of an encrypted operation. An encrypted operation (e.g., addition, multiplication, another arithmetic operation, or univariate function evaluation) may be applied to at least one input value encoded and encrypted with carry, and may result in at least one output value encoded and encrypted with carry.
[0029] In some cases, encrypted carry reduction may be applied to the output value, and at least one partial value with carry may be reduced to a partial value without carry. However, in other cases, the output value may not be carry-reduced and may be input to a further encrypted operation (e.g., further addition, multiplication, or other arithmetic operation) with carry. In any case, if necessary, encrypted carry reduction may be applied during the encrypted operation, e.g., to an intermediate partial value. Generally, encrypted carry reduction may be applied to ensure that subsequent encrypted operations do not result in a partial value that exceeds the carry message modulus.
[0030] By enabling values encoded and encrypted with a carry as inputs and / or outputs of encrypted operations, and optionally, in some cases, performing carry reduction that does not reduce all carry partial values of the encoded-encrypted values, the efficiency of encrypted computations can be significantly improved for several reasons detailed below. Generally, the techniques provided enable performing encrypted computations efficiently on values encoded and encrypted into multiple partial values, for example, evaluating arithmetic circuits. A configurable encrypted computation technique is provided that enables optimizing the execution from a computational perspective, either before execution or on the fly, by selectively performing encrypted carry reduction on selected partial values.
[0031] In particular, by using multiple partial values, the lack of precision in some existing approaches is improved. This enables performing encrypted computations on values defined modulo a relatively large modulus, examples of which are given later.
[0032] By selective carry reduction, the number of carry reduction operations required can be significantly reduced; for example, compared to existing approaches, encrypted computations can be performed in far fewer programmable bootstrap applications, thereby significantly improving efficiency. For example, multiple additions of encrypted values, or other linear operations, or even multiplications can be performed without performing carry reduction in between. Various parameters can be changed, including the message modulus, the carry message modulus, and the encoding to partial values of the plaintext during encryption. This offers the possibility of optimizing the homomorphic evaluation of a given encrypted computation and improving flexibility and performance.
[0033] Furthermore, the provided technique provides improved parallelization. Since the output of an operation can have a carry, carry reduction between steps is avoided, and thus one or a series of encrypted operations can be performed in parallel for each partial value. For example, when using encoding based on radix decomposition, addition can be performed separately for each partial value. When using encoding based on a residue number system, multiplication and carry reduction can also be parallelized. Thereby, performance is improved especially in multi-threaded and multi-core systems.
[0034] Specifically, the above paper "Putting up the Swiss army knife of homomorphic calculations by means of TFHE functional bootstrapping" is sequential and proposes addition that encrypts the elements of the decomposition using at least two PBSs for each ciphertext. In comparison, the provided technique enables addition to be implemented using only one PBS per ciphertext and only when carry reduction of that ciphertext is required; also, when carry reduction is not required, addition can be fully parallelized. Also, compared to those proposed multiplications, the provided technique is more efficient and can be better parallelized.
[0035] Generally, encrypted computations may be performed in the TFHE setting. This means that the ciphertexts used to encrypt the partial values enable programmable bootstrapping operations. In particular, the ciphertexts can be LWE (Learning With Errors) encryptions, i.e., encryptions based on the cryptographic assumption that the Learning With Errors problem is hard. As is known per se, programmable bootstrapping can evaluate LWE decryption in the exponent of a GLWE-encrypted monomial, implemented, for example, as so-called blind rotation. In particular, programmable bootstrapping may involve computing the encrypted polynomial product of a bootstrapping monomial and a test polynomial that expresses the plaintext value as an exponent. The test polynomial may represent the function applied to the input by programmable bootstrapping. Programmable bootstrapping may use a bootstrapping key that enables programmable bootstrapping but does not enable decryption of the ciphertext. Encrypted carry reduction and / or one or more encrypted operations of the encrypted computation may be implemented using programmable bootstrapping operations.
[0036] Instead of using LWE / GLWE type ciphertexts, it is also possible to use various lattice encryptions. For example, the ciphertexts to which blind rotation is applied and / or the encrypted polynomial products obtained therefrom can be NTRU ciphertexts. For example, the NTRU encryption of a message μ may be defined by adding the quotient of a noise polynomial g and a private key polynomial f to the message, for example,
Number
Number
[0037] In one embodiment, the ciphertext to which blind rotation is applied can be an LWE-type ciphertext. For example, blind rotation can be part of an encrypted computation performed on an LWE-type ciphertext (e.g., not including an NTRU-type ciphertext). Alternatively, an LWE-type ciphertext may be obtained by conversion from an NTRU-type ciphertext, for example, as part of an encrypted computation performed on an NTRU-type ciphertext. It is also possible to apply blind rotation directly to an NTRU-type ciphertext without converting it to LWE. More generally, the ciphertext can be a lattice-type ciphertext whose security is determined by the strength of the lattice problem-based cryptography, with LWE and NTRU being two examples of that.
[0038] In one embodiment, the output value may be calculated by performing a plurality of encrypted operations on a set of encoded and encrypted values, and the encrypted operations are performed without any encrypted carry reduction being performed between or during the encrypted operations. For example, the encrypted operations may include a plurality of additions and / or a plurality of multiplications. For example, performing an encrypted computation may include evaluating an arithmetic circuit that includes encrypted operations. The arithmetic circuit may have, for example, at least 2 (meaning that the output of one multiplication is used directly or indirectly as an input to another multiplication) or at least 3 multiplication depths. By enabling carry, such a computation may in some cases be performed without carry reduction between or with less carry reduction in any case, thereby providing a significant performance improvement.
[0039] In one embodiment, an encrypted operation may be applied by individually applying respective sub-operations to the encryption of each partial value of the input value. In particular, performing the encrypted operation may consist only of performing these sub-operations. This may apply, for example, in the case of a linear operation or in the case of multiplication when using a residue number system representation. In one embodiment, the individually applied encrypted operations may be performed at least partially in parallel, which is advantageous with respect to performance, particularly in the case of multi-threaded and multi-core systems.
[0040] In one embodiment, the encoding of a value as a carryless partial value is based on a radix decomposition of the value. In other words, a value encoded by a set of a carry partial value and a carryless partial value may be computable by reducing the carry of the carry partial value and reconstructing the value from the radix decomposition. The radix decomposition may relate to the base of each base element, and each message modulus corresponds to each base element. Encoding using radix decomposition enables relatively efficient carry reduction for various parts of encrypted computations, particularly arithmetic operations such as addition and / or multiplication and / or division; comparison operations for determining which of two values is larger; and also.
[0041] The base elements may define an overall modulus corresponding to the product of each base element. Thus, a radix decomposition with a given base may be used to encode values modulo that overall modulus. Also, as described elsewhere herein, it is possible to use the base in combination with a modulus smaller than the product of the base elements.
[0042] The base elements may all be the same. For example, they may all be equal to 2 with respect to the radix decomposition of base 2, or they may all be equal to 5 with respect to the radix decomposition of base 5. However, interestingly, this is not necessary. In some embodiments, the base elements of the radix decomposition are not all the same. This provides much higher flexibility when selecting the base elements according to the size requirements of the current application, thereby reducing the overhead of using a modulus that is larger than necessary. In particular, the base elements do not all have to be the same power of 2, nor do they all have to be powers of 2. The inventors have noticed that encrypted computing techniques, especially in the TFHE setting, can also be applied to such more general settings.
[0043] In one embodiment, encrypted carry reduction in the radix decomposition setting may be performed, decomposing the carry-containing partial value of the output value into the encryption of each partial value of the partial value, and adding the encryption of the partial value of the partial value to the encryption of the corresponding partial value of the output value. In this way, the carry-containing partial value can be reduced to a value lower than the message modulus. By repeating this process for each carry-containing partial value, an encoding and encryption of a carry-free value can be obtained.
[0044] In one embodiment, encrypted multiplication of an encoded and encrypted value by an unencrypted scalar may be performed. This encrypted multiplication can be implemented, for example, using programmable bootstrapping, by calculating the encrypted partial values of the scalar multiplication of the partial values of the encoded and encrypted value. When radix decomposition encoding is used, the results of the encrypted multiplications may be combined to obtain the overall result. In this way, multiplication by a relatively large scalar can be performed. For example, in the case of a smaller scalar, it is also possible to directly multiply each encrypted partial value by the scalar itself to obtain each encrypted output partial value. When residue number system encoding is used, each product for each partial value can form the overall result.
[0045] In one embodiment, an encrypted multiplication of the first and second encoded and encrypted values is performed by performing an encrypted multiplication of sub - values of the encoded and encrypted values. In a radix - decomposition setting, the encrypted multiplication of the sub - values can result in an encoded and encrypted value. These encoded and encrypted values can be summed to obtain an overall result. During multiplication, carry reduction may be performed as needed, for example, as indicated by the degree of fullness calculated as described herein. Interestingly, doing so enables a particularly effective multiplication of large encrypted values.
[0046] In one embodiment, an encoded and encrypted value using radix - decomposition encoding is defined modulo a maximum value representable by radix - decomposition, e.g., smaller than the product of base elements. In this way, the number of situations in which radix - decomposition encoding can be used is significantly improved. In terms of efficiency, radix - decomposition encoding preferably uses small base elements, in which case the maximum representable value is the product of such small base elements. Interestingly, the inventors have noticed that radix - decomposition encoding can still be used even when calculations modulo a modulus other than the product of small base elements are desired. Various encrypted operations can be performed as they would when acting modulo the product of base elements, except that the encrypted carry reduction of the most - significant sub - message can be adapted by modifying the carry reduction according to the desired modulus. For example, the modification may be made by multiplying a scalar by the most - significant sub - value and subtracting the result from the value with the most - significant sub - value removed.
[0047] In one embodiment, the encoding of a value as a carryless partial value may be based on a residue number system representation of the value. Such a representation is also known as a CRT (Chinese Remainder Theorem) representation. This representation may be based on a set of relatively prime base elements. For example, each partial value of an encoded and encrypted value may have a message modulus corresponding to a base element.
[0048] In particular, a value encoded and encrypted with carry may correspond to its partial values according to a CRT decomposition using each message modulus β i and according to a carry reduction that modulo-reduces each partial value m i to m i mod β i Similar to radix representations, linear arithmetic operations may be efficiently implemented using a CRT representation. Interestingly, a CRT representation may also enable particularly efficient multiplication and carry reduction, both of which may furthermore be performed individually for each partial value and are thus parallelizable. Also, various other types of operations such as the application of a univariate function are possible using a CRT representation.
[0049] In one embodiment, the encoding of a value as a carryless partial value may be based on a residue number system representation and may furthermore be based on a radix decomposition of the elements of the residue number system representation. This approach is referred to herein as a "hybrid" approach. For example, one, more, or all of the elements of a residue number system may be radix decomposed according to respective (different or equal) bases. Using the hybrid approach, it is possible to efficiently use a CRT approach with relatively large CRT base elements.
[0050]
[0051] In one embodiment, when encoding an element of a residue number system representation using radix decomposition, the modulus by which this element is defined (i.e., the corresponding base element based on the CRT) may be smaller than the maximum value representable by the radix decomposition. Also, as generally described regarding radix decomposition, radix decomposition can still be used in such cases and can be used in a wider range of cases. This combination is particularly beneficial because it enables a better combination of the desiderata of having relatively prime base elements of the CRT and having a radix decomposition using small base elements.
[0052] Some advantages of using a CRT representation, particularly efficient and parallelizable encrypted linear and multiplication operations, also apply when no carry is used with respect to the inputs and outputs of the encrypted operations, for example when encrypted carry reduction is used only within the encrypted operations; when encrypted carry reduction is used immediately after each encrypted operation to yield a carry-free output; or when the encrypted operations contain no carry at all, for example when implemented using programmable bootstrapping without carry. Also conceivable is an encryption calculation method that uses the CRT but does not include encrypted operations applied to encrypted and encoded values without carry.
[0053] In particular, an encryption calculation method is conceivable that includes accessing one or more encoded and encrypted values, where the encoding of the value as a carry-free partial value is based on the residue number system representation of the value; and applying an encrypted operation to at least the encoded and encrypted input values to obtain an encoded and encrypted output value. Also conceivable is an encryption device corresponding to this method.
[0054] In one embodiment, performing carry - encrypted calculations may involve tracking the fill level of sub - values of the encoded and encrypted values. The fill level may indicate, for example, the limit of the sub - value expressed as the maximum value known to the sub - value, or the ratio of the maximum value to the carry message modulus. For example, in the case of a value encoded and encrypted without a carry, the fill level may indicate that the sub - value is less than the corresponding message modulus. In the case of a value encoded and encrypted with a carry, the fill level may indicate that at least one of its sub - values may be greater than or equal to the corresponding message modulus, in other words, it is not guaranteed to be less than the message modulus.
[0055] The fill level may be used to determine whether to perform encrypted carry reduction on the encrypted sub - values during and / or in between encrypted operations. In particular, the fill level may be determined for a carry - sub - value to be calculated by an encrypted operation from one or more input encrypted sub - values. If the limit indicated by the fill level exceeds the corresponding carry message modulus, encrypted carry reduction may be applied to one or more of the input encrypted sub - values before calculating the carry - sub - value, so that the limit of the carry - sub - value no longer exceeds the carry message modulus. Thus, overflow of the sub - value can be avoided.
[0056] Interestingly, by tracking the fill degree during the encrypted calculation, a flexible method for performing the encrypted calculation can be obtained, and whether to perform the encrypted carry reduction can be adaptively determined. Thus, the determination can depend on the current input, such as the public scalar used in the calculation, the limit of the encrypted input provided by the inputter, or the fill degree in a specific iteration of an iterative algorithm. This generally results in a more efficient execution of the encrypted calculation. Also, since no explicit specification is required for when to perform the carry reduction, it becomes easier to specify the encrypted calculation. This can make the provided technique particularly suitable for people outside the field of encrypted calculation.
[0057] For example, the encrypted calculation may be executed such that in the first execution, the encrypted carry reduction of a specific encrypted partial value is performed, while in the second execution, this encrypted carry reduction is avoided. Also, the operations of the encrypted calculation performed multiple times may or may not include the encrypted carry reduction depending on the fill degree of their inputs. For example, an encrypted multiplication or other encrypted operation may include the encrypted carry reduction for the encrypted partial values calculated during the operation in the first execution of the multiplication, but may not include it in the second execution.
[0058] According to a further aspect of the present invention, there is provided a compiler method and device as defined by the claims. As the inventors have realized, it is not necessary to track the fill degree during encrypted calculations. Many of the advantages of using the fill degree can also be achieved when the fill degree is calculated as part of a compiler method that compiles the calculation into a quasi - homomorphic executable file. That is, this quasi - homomorphic executable file may enable efficient performance of encrypted calculations, in particular by performing encrypted carry reduction operations only when necessary. The quasi - homomorphic executable file may be executable by an encrypted calculation engine, and cause the encrypted calculation engine to perform encrypted calculations on one or more sets of encoded and encrypted values as described herein. The quasi - homomorphic executable file may include, for example, one or more instructions for performing encrypted carry reduction operations as described herein, either as part of an encrypted operation or in between executions of encrypted operations. The compiler method includes determining a fill degree indicating a limit of a partial value with carry for a partial value with carry to be calculated; and, if the limit exceeds the corresponding carry message modulus, generating an instruction for the encrypted calculation engine to apply encrypted carry reduction before calculating the partial value with carry. The compiler method may include optimizing one or more parameters of the encrypted calculation, such as numbers and values regarding messages and carry message moduli, for the encrypted calculation to be compiled into an executable file.
[0059] In one embodiment, one or each message modulus is not a power of two. In particular, existing techniques for encrypted computations in the TFHE setting generally use powers of two for their moduli, but the inventors have noticed that this is not necessary and that the techniques provided can be used even when one or more message moduli are not powers of two. Instead, or in addition, in one embodiment, one or more of the carry message moduli are not powers of two. This allows the operations to be better adapted to the current situation, for example, to perform calculations on values defined by law with a modulus that matches the calculations and ranges for the current input values.
[0060] In one embodiment, the message modulus is at least 3, and / or at least 5, and / or at least 10. The use of larger values for the message modulus has the advantage of higher precision for a single ciphertext and fewer ciphertexts being required to represent the value. Also, calculations, especially those without carry reduction, can be made more efficient.
[0061] In one embodiment, the carry message modulus may be at least 4 times, at least 8 times, or at least 32 times the size of the corresponding message modulus. Thus, in terms of bits, substantially at least 2, at least 3, or at least 5 carry bits can be provided. By using a carry message modulus that is significantly larger than the message modulus, the number of operations that can be performed before carry reduction is required, or the number of sub-steps of the operation, is increased, increasing efficiency.
[0062] In one embodiment, one or each carry message modulus is at most 128, at most 256, or at most 512. For example, the efficiency of operations such as carry reduction using programmable bootstrapping typically scales worse than linearly with the size of the carry message modulus. By keeping the carry message modulus limited, the computational cost of such operations remains limited.
[0063] In one embodiment, the modulus in which the encrypted value is defined is at least 1024, at least 4096, or at least 16384. Interestingly, despite the use of such large moduli, the techniques provided still enable relatively efficient computations for those values.
[0064] In one embodiment, one or more bits are extracted from one or more partial values of the encoded and encrypted value; the extracted bits are converted into a GGSW ciphertext; and a function evaluation may be applied to the one or more encoded and encrypted values by applying a lookup table to the GGSW ciphertext. As described in more detail elsewhere, this is a particularly efficient way of implementing a function, especially for relatively large values, such as messages and / or carry message moduli and / or values with a relatively large number of partial values.
[0065] In one embodiment, the encrypted computation may at some point include the evaluation of a multi-variable function (e.g., a two-variable function) on a plurality of encrypted input values, such as sub-values. An important example of a multi-variable function is, for example, the encrypted multiplication of the first and second sub-values of the same encrypted and encoded value or different encrypted and encoded values. For example, such encrypted multiplication may occur as part of the encrypted multiplication of encrypted and encoded values or as part of a different type of encrypted operation. In either case, the evaluation of the multi-variable function is by determining the combined encryption representing each encrypted input value; and by applying a one-variable function to the combined encryption (which corresponds to applying the multi-variable function to each input value), for example, by applying programmable bootstrapping to the combined encryption.
[0066] This is a particularly efficient way to perform multi-variable function evaluation and also combines well with the determination of fill factor and the use of carry. In particular, when the input values are encrypted with carry, there may actually be sufficient room in the plaintext space to store the combined encryption. Encrypted carry reduction may be performed if necessary to ensure that the combined encryption does not overflow the carry message modulus.
[0067] Techniques provided for improved computation on encrypted data can be applied to a wide range of practical applications. Such practical applications include performing an encrypted evaluation of a software program while having no access to the plain data. For example, it is possible to evaluate medical diagnostic software with respect to medical data while actually having no access to the medical data. The medical data may include medical images. Medical images can include, for example, but not limited to, multi-dimensional image data, such as two-dimensional (2D), three-dimensional (3D), or four-dimensional (4D) images, acquired by various acquisition modalities such as standard X-ray imaging, computed tomography (CT), magnetic resonance imaging (MRI), ultrasound (US), positron emission tomography (PET), single photon emission computed tomography (SPECT), and nuclear medicine (NM).
[0068] In one embodiment, the techniques provided can be used to evaluate a neural network against encrypted inputs. Those involved in evaluating the neural network may or may not have plaintext access to the trained parameters of the neural network, such as weights and biases. In general, the techniques provided herein, such as improved polynomial multiplication, programmable bootstrapping, and external product, improve the efficiency of evaluating the neural network and / or reduce the memory and transmission requirements regarding the ciphertexts or key materials used.
[0069] Embodiments of the method can be implemented on a computer as a computer-implemented method, or in dedicated hardware, or in a combination of both. Executable code relating to embodiments of the method can be stored in a computer program product. Examples of computer program products include memory devices, optical storage devices, integrated circuits, servers, online software, and the like. Preferably, the computer program product includes non-transitory program code stored in a computer-readable medium for performing embodiments of the method when the program product is executed on a computer.
[0070] In one embodiment, the computer program includes computer program code configured to perform all or part of the steps of the method embodiment when the computer program is executed on a computer. Preferably, the computer program is embodied on a computer-readable medium.
[0071] Further details, aspects, and embodiments are described by way of example only with reference to the drawings. The elements in the figures are illustrated in a concise and clear manner and are not necessarily drawn to scale. In the figures, elements corresponding to those already described may have the same reference numerals.
Brief Description of the Drawings
[0072]
Figure 1a
Figure 1b
Figure 1c
Figure 2a
Figure 2b
Figure 3a
Figure 3b
Figure 3c
Figure 3d
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
[0073] The subject matter disclosed herein can be implemented in many different forms, but one or more specific embodiments are shown in the drawings and described in detail herein. The present disclosure should be regarded as an exemplification of the principles of the subject matter disclosed herein and is not intended to be limited to the specific embodiments shown and described.
[0074] In the following, for ease of understanding, the elements of the embodiments are described in terms of their operations. However, it will be apparent that each element is configured to perform the functions described as being performed by them.
[0075] Furthermore, the subject matter disclosed herein is not limited to the embodiments alone, but also includes any other combination of features described herein or recited in different dependent claims.
[0076] First, some general information and notations applicable to several embodiments are presented. Throughout this specification, the parameter q represents a modulus for encoded and encrypted values, e.g., a positive integer.
Number
Number
Number
Number
Number
Number
Number
[0077] The Chinese Remainder Theorem (CRT) states the following. Let R be a ring and for some
Number
Number
[0078] In this specification, CRT represents a morphism from \(R\) to \(R / I_0\times R / I_1\times\cdots\times R / I_n\). The inverse CRT, denoted as iCRT, maps \(R / I_0\times R / I_1\times\cdots\times R / I_n\) to \(R\). n to \(R / I_0\times R / I_1\times\cdots\times R / I_n\). The inverse CRT, denoted as iCRT, maps \(R / I_0\times R / I_1\times\cdots\times R / I_n\) n to \(R\).
[0079] Various embodiments use LWE (Learning With Errors) encryption. Generally, an LWE - type ciphertext can include one or more mask values and a body value derived from the mask values and the plaintext value. The values are typically integers modulo a given modulus \(q\). Various embodiments also use GLWE (Generalized Learning With Error) - type ciphertexts. A GLWE - type ciphertext can include one or more mask polynomials and a body polynomial derived from the mask polynomials and the plaintext polynomial. A GLWE - type ciphertext can be defined modulo \(q\) and a quotient polynomial \(p(X)\). An LWE ciphertext can be regarded as a particular kind of GLWE ciphertext where the quotient polynomial has degree 1. Another particular kind of ciphertext is the RLWE (Ring Learning With Errors) ciphertext where the number of mask polynomials is 1.
[0080] In particular, the GLWE ciphertext of a message \(m\) under a secret key
Number
Number
Number
[0081] Throughout this specification, an integer q is used to represent the ciphertext modulus, but it should be noted that multiple ciphertext moduli may be used in encrypted multiplication. For example, modulus switching is used to align ciphertexts under the same q as needed.
[0082] The above example describes a symmetric variant of the GLWE secret key. The techniques provided herein equally apply to publicly known variants of the public key as well. In the latter case, for example, the above secret key may be used as a private key and the public key may include the encryption of one or more zeros. See, for example, R. Rothblum, "Homomorphic encryption: From private - key to public - key", Theory of Cryptography (TCC 2011), vol. 6597 of Lecture Notes in Computer Science, pp. 219 - 234, Springer, 2011, which is incorporated herein by reference.
[0083] Various embodiments operate in the TFHE setting, which means that ciphertexts that support programmable bootstrapping (PBS) are used. Programmable bootstrapping can take a ciphertext as input and output a ciphertext of the same message that includes noise independent of the input or a function of that message. PBS may involve evaluating the homomorphic decryption of the input ciphertext in the exponent of a polynomial. Generally, in TFHE - like schemes, it is possible to select a secure set of cryptographic parameters while conforming to the required precision and minimizing the computational cost. Interestingly, such parameters can be selected independently of the amount of homomorphic operations and the depth of the circuit being evaluated. Examples of encryption schemes in the TFHE setting that can be combined with the techniques provided herein are described in the following references: - [DM15] L. Ducas et al., "FHEW: bootstrapping homomorphic encryption in less than a second", proceedings EUROCRYPT 2015; - [CGGI16] I. Chillotti et al., "Faster fully homomorphic encryption: Bootstrapping in less than 0.1 seconds", proceedings ASIACRYPT 2016; - [CGGI17] I. Chillotti et al., "Faster packed homomorphic operations and efficient circuit bootstrapping for TFHE", proceedings ASIACRYPT 2017; - [BIPPS22] C. Bonte et al., "FINAL: Faster FHE instantiated with NTRU and LWE", Cryptology ePrint Archive, Paper 2022 / 07.
[0084] Various embodiments deal with performing encrypted computations on encrypted values as encrypted sub - values. In this specification, these values are typically represented, for the sake of explanation, as integers modulo a particular modulus. Such values modulo an integer can be considered equivalent to elements of a discretized torus, as is done in some of the references listed above. In particular, various references use
Number
Number
Number
Number
Number
[0085] Due to the programmable bootstrapping operations in TFHE-like schemes, these schemes become attractive options for a wide range of applications. Since bootstrapping is relatively efficient compared to many other FHE schemes, for example, it becomes much more feasible to perform relatively complex calculations having at least 10, at least 50, or at least 100 multiplication depths. In particular, the cryptographic parameters of TFHE-like schemes can be selected based on the desired accuracy and the resulting computational cost, regardless of the amount of homomorphic operations and their circuit depths. In contrast, in other FHE schemes, bootstrapping is very inefficient, and in fact, these schemes are typically applied in a levelled manner, which means that their parameters are selected according to a given calculation so that it can be performed without the need for bootstrapping. However, such a levelled approach is not feasible for more complex calculations, and thus in such cases, TFHE-like schemes are particularly beneficial.
[0086] Generally, the security of GLWE-based ciphertexts is based on the distribution of the secret key and the following three main parameters: n = kN, where N is the degree of the quotient polynomial, k is the number of random mask polynomials of the ciphertext, and n is the length of the secret key; q, the modulus; and σ, the statistical parameter of the noise, e.g., its standard deviation. Given these parameters, the method for estimating the security level provided is known per se. See, for example, M. Albrecht et al., “On the concrete hardness of Learning with Errors”, Journal of Mathematical Cryptology, 9(3):169-203, 2015, which is incorporated herein by reference.
[0087] In embodiments herein, the parameters of the TFHE-like LWE-based and GLWE-based ciphertexts used can be selected based on the desired security level and also based on the desired accuracy of operations such as linear combinations of LWE ciphertexts and / or the application of programmable bootstrapping, in other words, the noise level resulting from applying these operations. Interestingly, in the TFHE setting, the security parameter can be selected independently of the computational complexity, e.g., independently of the multiplication depth of the computation. This is different from non-TFHE-like schemes where the security parameter is typically chosen to limit or eliminate bootstrapping.
[0088] In particular, the LWE-based ciphertexts and / or GLWE-based ciphertexts used in the TFHE setting herein may use a relatively small modulus, e.g., up to 32 bits, up to 64 bits, or up to 128 bits. This modulus is typically selected independently of the computations to be performed and, for example, is selected according to the desired accuracy and / or efficiency. The parameters N, k, and / or σ can typically also be selected independently of the computations to be performed so as to achieve the desired security level. For example, N may be set to at least 512 and / or up to 2048 or 4096, e.g., 1024. For example, in one embodiment, RLWE is used with N being at least 512 and / or up to 2048 or 4096, e.g., 1024, and k = 1. Such values for N are typically not used in non-TFHE-like encryption schemes, where such values would severely limit the computations that can be performed; instead, in non-TFHE-like schemes, both q and N are typically selected based on the desired security level and thus q may be much larger.
[0089] FIG. 1a schematically shows an example of an embodiment of an encrypted computing device 110. The device 110 may be for performing encrypted computations on one or more sets of encoded and encrypted values.
[0090] Symbolized and encrypted values may be encoded and encrypted as the encryption of a plurality of respective partial values. Here, a partial value may have a corresponding message modulus and a carry message modulus greater than the message modulus. Among the encoded and encrypted values, one or more values may be encoded and encrypted without carry. In this case, the partial value without carry may be smaller than the corresponding message modulus. Among the encoded and encrypted values, one or more values may be encoded and encrypted with carry. In this case, at least one partial value with carry may be greater than or equal to the corresponding message modulus. The remaining zero or more partial values may be partial values without carry.
[0091] Device 110 may include a processor system 130, a storage 140, and a communication interface 150. The storage 140 may include local storage, such as a local hard drive or electronic memory. The storage 140 may include non-local storage, such as cloud storage. In the latter case, the storage 140 may include a storage interface to the non-local storage. For example, the storage 140 may be for storing one or more encoded and encrypted values to be calculated. The storage 140 may include additional data for use in blind rotation, such as a bootstrap key, as discussed elsewhere.
[0092] Device 110 can communicate internally with other devices, external storage, input devices, output devices, and / or one or more sensors over a computer network. The computer network can be the Internet, an intranet, a LAN, a WLAN, etc. The computer network can be the Internet. Optionally, the device may include a connection interface 150 configured to communicate with other devices when required. For example, the connection interface may include a connector, such as a wired connector, such as an Ethernet connector, an optical connector, etc., or a wireless connector, such as an antenna, such as a Wi-Fi, 4G, or 5G antenna. Communication, such as internal communication, may use other communication protocols or media, such as an internal data bus.
[0093] In device 110, communication interface 150 may be used to transmit or receive digital data. For example, device 110 may be configured to receive or transmit one or more encoded and encrypted values and / or data representing LWE encryption, such as representing input and / or output of encrypted computations. As another example, communication interface 150 may be used to receive data representing a bootstrapping key.
[0094] The execution of device 110 may be implemented by a processor system 130, such as one or more processor circuits, such as a microprocessor, examples of which are shown herein. Device 110 may include multiple processors, and the processors may be distributed in different locations. For example, device 110 may use cloud computing.
[0095] The processor subsystem 130 can be configured to apply encrypted operations to at least an input value that is encoded and encrypted with carry to obtain an output value that is encoded and encrypted with carry. The processor subsystem 130 can be further configured to apply encrypted carry reduction to the output value that is encoded and encrypted with carry to obtain further encoding and encryption of the output value in which at least one carry-bearing partial value is reduced to a carry-free partial value.
[0096] The processor subsystem 130 may be configured to obtain one or more inputs to an encrypted computation, where the inputs include, for example, one or more encoded and encrypted values and / or one or more values that are encrypted but not encoded, and these values can optionally be converted by the processor subsystem 130 into encoded and encrypted values as described herein. The encoded and encrypted values provided as inputs are typically encoded and encrypted without carry, although it is also possible in principle to obtain inputs with carry. Along with the inputs, the processor subsystem 130 may obtain limits of the encrypted values, for example as a fill level.
[0097] The processor subsystem 130 may be configured to output one or more outputs of an encrypted computation, where the outputs include, for example, one or more encoded and encrypted values and / or one or more values that are encrypted but not encoded, and these values are determined, for example, by the processor subsystem 130 converting encoded and encrypted values into encrypted values as described herein. When outputting encoded and encrypted values, the processor subsystem 130 can be configured to apply an encrypted carry reduction operation to output values that are encrypted and encoded without carry.
[0098] For example, the processor subsystem 130 can obtain inputs and / or outputs from / to the storage 130 and / or from / to other parties via the communication interface 150.
[0099] Some of the figures show functional units that can be functional units of the processor system. For example, the figures can be used as a blueprint for the organization of the possible functions of the processor system. In most figures, the processor circuitry is not shown separately from the units. For example, the functional units shown in FIGS. 2-6 (see below) can be stored, for example, in the electronic memory of the device 110 and implemented in whole or in part by computer instructions executable by the microprocessor of the device 110 in a device such as the device 110. In hybrid embodiments, the functional units are implemented partly in hardware, for example as a coprocessor, for example an arithmetic and / or cryptographic coprocessor, and partly in software stored in and executed by the device 110.
[0100] For example, the device 110 can be a device for performing encrypted calculations. The encrypted calculations may use homomorphic encryption methods. For example, the device 110 may be used to perform encrypted calculations, for example even when the data is received in encrypted form from, for example, a data provider and even when the device 110 cannot decrypt the data, the device can perform calculations. The calculations may include encrypted operations and / or carry reduction as described herein.
[0101] For example, the storage 140 can store encrypted data items received, for example, from one or more data providers or generated as intermediate or final results of calculations, for example outputs. Typically, most or all of the data items on which the device 110 performs calculations are encrypted using a key unknown to the device 110. That is, the device 110 may not be configured to obtain the plain data items corresponding to the encrypted data items, such as those stored in the storage 140. The encryption / decryption key may be available in encrypted form, but the decryption key in plain form is secret to the device 110.
[0102] For example, a processor system may be configured to perform a sequence of homomorphic encryption operations. The encrypted operations may include linear operations such as addition, subtraction, and / or scalar multiplication; multiplication; univariate function evaluation; and the like. Interestingly, using the provided techniques, multiple encrypted arithmetic operations, such as an arithmetic circuit having a multiplication depth of at least 2, at least 3, or at least 5, can be performed on a set of encoded and encrypted values, and performing the above does not include encrypted carry reduction.
[0103] FIG. 1b schematically shows an example of an embodiment of a compiler device 119 for compiling calculations into a homomorphically executable file. The homomorphically executable file may be executable by an encrypted calculation engine, and cause the encrypted calculation engine to perform encrypted calculations on one or more sets of encoded and encrypted values, such as those described herein by the device 110 of FIG. 1a. The homomorphically executable file may include, for example, one or more instructions for performing encrypted carry reduction operations as described herein, either as part of the encrypted operations or in between the execution of the encrypted operations. The device 119 can perform the encrypted calculations itself. For example, the device 110 of FIG. 1a can be combined with the device 119 of FIG. 1b.
[0104] Device 110 may include a processor system 139, a storage 149, and a communication interface 159. The processor system 139, the storage 149, and the communication interface 159 may be implemented as discussed for the respective components in FIG. 1a. The storage 149 may be for storing a description of a homomorphic computation to be compiled into a homomorphic executable file, which is stored, for example, as program code or as an instruction graph or the like. The communication interface 159 may be used to receive a computation to be compiled. The communication interface 159 may be used to transmit a homomorphic executable file.
[0105] The processor subsystem 139 may be configured to generate a homomorphic executable file by converting operations into homomorphic computation instructions, as is known per se in the art. Interestingly, the processor subsystem 139 may be configured to track the padding degree of the encoded and encrypted values used in the encrypted computation and the partial values of the encrypted values. In this way, if required, an encrypted carry reduction operation may be included in the homomorphic executable file. In particular, the processor system 139 may be configured to determine, for a partial value with carry to be computed, a padding degree indicating the limit of the partial value with carry. If the limit exceeds the corresponding carry message modulus, the processor subsystem 139 can generate an instruction for the encrypted computing engine to apply encrypted carry reduction before computing the partial value with carry. The processor subsystem 139 may be configured to optimize one or more parameters of the encrypted computation, such as numbers and values related to the message and the carry message modulus, for the encrypted computation to be compiled into an executable file.
[0106] FIG. 1c schematically shows an example of an embodiment of an encrypted computing system 100. The system 100 is configured to perform computations encrypted using homomorphic encryption, such as fully homomorphic encryption.
[0107] The system 100 in this example includes a compiler device 111, a data provider device 113, and an encrypted computing device 112. The compiler device 111 can be combined with the encrypted computing device 112 or the data provider device 113 into a single device. The device 112 can be configured to receive encrypted data items from the data provider 113. At least one or more data items can be received in an encrypted form. One or more additional data items can be received in plain form. The device 112 can be configured to receive from the compiler device 111 a homomorphic executable file for performing encrypted calculations.
[0108] The device 112 can perform the calculations described herein on the received data items and, in some cases, on the data items stored. Interestingly, the calculations can be performed by the device on the encrypted data without decrypting the data, for example, without converting the encrypted data items to plain form data.
[0109] The device 112 in this example may be based on the device 110 of FIG. 1a and may include, for example, the processor system 130, the storage 140, and / or the communication interface 150 of FIG. 1a. The devices 111, 112, 113 may each be based on the device 119 of FIG. 1b and may each include, for example, the processor system 139, the storage 149, and / or the communication interface 159 of FIG. 1b.
[0110] Optionally, the compiler device 111 or the data provider device 113 may be further configured to generate key material for the encrypted computing device 112 to perform encrypted computations, including a bootstrapping key for performing programmable bootstrapping as discussed herein, for example. The device that generates the key material may provide the bootstrapping key 151 to the device 112, for example, transmit it via the computer network 150, or upload it to shared storage. The key material may be generated by a separate key generation device (not shown in this figure).
[0111] Although not shown in this figure, the encrypted computing system 100 may include multiple, for example, two, three, or four or more encrypted computing devices. The encrypted computations may be distributed among the multiple encrypted computing devices. The encrypted computing devices may typically exchange encrypted intermediate computation results with each other as, for example, an encoded and encrypted value including a plurality of encrypted partial values. Each encrypted multiplication device may be implemented similarly to the encrypted computing device 112 and may perform encrypted operations and / or encrypted carry reduction operations as described herein.
[0112] A homomorphic encryption scheme can be applied in many settings. For example, the encrypted computing device 112 may be operated by a cloud provider. The cloud provider may provide computing services and storage services to its clients. By adopting homomorphic encryption, a data provider device 113, such as a client of the cloud provider, can send data in an encrypted form. The cloud provider can still perform the required computations and / or the required storage, but cannot know what corresponds to the plain data. For example, the data provider device 113 may use a type of encryption key corresponding to a specific homomorphic encryption system used to encrypt data items. When the computation result is received by the data provider 113 from the encrypted computing device 112, the corresponding decryption key can be used to decrypt the encrypted data item. The encryption key and the decryption key may be the same and typically are the same.
[0113] For example, the encrypted computing system 100 may be configured to train a machine learning model, such as an image classifier, such as a medical model, with the encrypted computing device not having access to the plain data item. For example, in some cases, linear regression may be performed on the input data even without bootstrapping. For example, in some cases, backpropagation may be performed on the input data using bootstrapping. The resulting model parameters may be returned to an entity that owns the decryption key. This enables multiple providers of medical data to pool their data by sending their individual data to a cloud provider. The cloud provider then returns the model parameters without having access to the plain data. The encryption key may be equal to the decryption key.
[0114] After the model is trained, the encryption computing system 100 can be used, for example, to provide a model for use with medical data. This can be done using either plain model parameters or encrypted model parameters, and in either case, encrypted data is used, such as encrypted input data, intermediate data, and output data. Usually, the use of plain model parameters is much more efficient. In either case, the effect of the system is that calculations, such as image classification, such as medical image classification, are performed without the computer knowing the plain data items. For example, a mammogram may be evaluated for cancer, but in the encrypted computing device 112, the image is never plain, and neither any encrypted computing device 112 or an association of such devices knows the result of the cancer evaluation. From a privacy perspective, it may be acceptable to operate on a plain model with respect to encrypted privacy-sensitive data, but it may not be acceptable to operate on plain privacy-sensitive data.
[0115] Other uses include database services, such as searching for encrypted data within an encrypted database; for example, the computation can be a comparison of an input item and a database item. For example, multiple computations may be combined to create a database index that matches an index. For example, the database may be a genomic database and the input may be a gene sequence. For example, system 100 may be used for protected control of a device. For example, a device, even a large device such as a power plant, may send sensor values to an encrypted computing device 112 and receive an encrypted control signal in return. The control signal is computed from the sensor signal. An attacker of the system may be able to determine the content of data to and from one or more encrypted computing devices 112, or even access intermediate data of these devices, but since the data is encrypted, it does not help the attacker. Even if all of the encrypted computing devices 112 of system 100 are completely destroyed, the data is not exposed because the decryption keys are not known to these devices. The computation of the control signal may include mathematical operations such as linear algebra, averaging, matrix multiplication, polynomial evaluation, etc., all of which can be performed with homomorphic encryption operations. In any case, such uses include computations involving arithmetic operations on relatively large values that can be efficiently implemented as described herein.
[0116] For example, a pool of encrypted data items may be maintained within an encryption computing system; subsets of these may be received, and another subset may become, for example, intermediate results of encrypted computations. For example, the encryption computing device 112 may be configured to apply a homomorphic encryption operation to one, two, or three or more encrypted data items within the pool, such as a collection of input values and / or intermediate values and / or output values. The result may be a new encrypted data item that may be stored in the pool. For example, one or more of the values are encoded and encrypted, while zero or more other values may be directly encrypted without being encoded. The pool may be stored in the storage of the encryption computing system. This may be local storage or distributed storage. In the latter case, it may happen that one or more encrypted data items are represented multiple times within the pool. Encrypted, particularly encoded and encrypted, data items may be transmitted from one computing device to another, for example if their values are needed elsewhere. The pool may be implemented in various forms, such as a register file, an array, various data structures, and the like.
[0117] Encrypted data items can represent all kinds of data. For example, an encrypted data item may represent a number that needs to be averaged, or a number used in linear regression. For example, an encrypted data item may represent an image. For example, each pixel of an image may correspond to one or more encrypted data items. For example, a grayscale pixel may be represented by a gray level, and the gray level may be represented by a single encrypted data item. For example, 256 gray levels may be encoded within a single encrypted data item. For example, a color pixel may be represented by a plurality of color levels, such as RGB levels, and the color levels may be represented by a tuple of encrypted data items. For example, three 256-level colors may be encoded as respective encoded values, or encoded and encrypted values.
[0118] A set of homomorphic encryption operations may be defined for computation. For example, from the homomorphic encryption operations, a network or circuit of operations that together implement the computation may be constructed by, for example, a compiler device as described with respect to FIG. 1b, or by the computing device itself. For example, the operations may include Boolean operations. The way the homomorphic encryption operations are combined, for example, which operation is applied to which operand within a pool, determines the computation being performed. For example, the computation may be represented as a list of homomorphic encryption operations to be performed, along with an indication of which encrypted data items they are performed on. The network or circuit can indicate to the encrypted computing device 112 when to perform encrypted carry reduction, and / or the encrypted computing device 112 can determine whether to perform an encrypted carry reduction operation based on tracking the fill degree of the partial values being computed.
[0119] FIGS. 2a and 2b schematically show an example of a look-up table for programmable bootstrapping.
[0120] In various embodiments, the encrypted computation is encrypted computation in the TFHE setting. In this setting, the encryption scheme used, e.g., LWE encryption, may support programmable bootstrapping operations. As is known per se, such programmable bootstrapping may evaluate LWE decryption in the exponent of a GLWE encrypted monomial. As is known per se, by using each test polynomial in the programmable bootstrapping operation, programmable bootstrapping may be used to evaluate various functions with respect to the LWE encryption to which it is applied. As explained elsewhere, programmable bootstrapping may be used to perform encrypted carry reduction, but may also be used for various other operations such as the evaluation of univariate functions.
[0121] Here, an example of a programmable bootstrapping operation is discussed. Bootstrapping may evaluate a univariate function and at the same time reduce the noise of the input ciphertext. Throughout this specification, the notation PBS is used to represent programmable bootstrapping. The function evaluated on the input may sometimes be represented as a look-up table (LUT). The look-up table may correspond to a test polynomial that may be multiplied by a GLWE encrypted monomial. By computing a GLWE encrypted monomial and multiplying it by the test polynomial, the look-up table may effectively be rotated to output the correct element in the table.
[0122] A visual representation of the polynomial storing the LUT is shown in FIG. 2a. In this example, an array is shown, and each element 201 - 204 of the array represents a coefficient of the polynomial
Number
[0123] In various cases, redundant look-up tables may be used. In particular, for a given value r, an r-redundant LUT where the coefficients are repeated r times in succession may be used. This is shown in Figure 2b. The LUT for the function f is represented in this example as an array including respective blocks 210, 211, 212 of 16 repetitions of each output value. To reduce noise in the input ciphertext, a PBS with redundancy may be used.
[0124] The PBS may use a bootstrapping key. The bootstrapping key may include a GGSW encryption of each element of the secret key used to encrypt the input LWE ciphertext of the PBS. Bootstrapping may include a modulus switching operation,
Number
Number
[0125] Throughout this specification, the following notation may be used to represent performing a programmable bootstrapping operation:
Number
Number
[0126] For example, using techniques known per se from "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks", PBS can be performed with the following computational complexity: [Number] where [Number] is the case.
[0127] Various existing implementations of the programmable bootstrapping operation, such as the implementation of "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks", can perform the operation on input ciphertexts whose most significant bit is zero.
[0128] As an example, it is possible to use NTRU - type encryption for the input ciphertext and / or for the encrypted polynomial product. More generally, the techniques provided can be applied to any binding rotation that results in an encrypted polynomial product of a test polynomial and a bootstrapping polynomial modulo a quotient polynomial different from X N + 1, for example, any accumulator - based blind rotation.
[0129] In particular, regarding the use of NTRU for encrypted polynomial products, it should be noted that the "blind rotation" algorithm under discussion itself uses the abstract accumulator ACC. As discussed, this accumulator can be implemented based on GLWE, but this is not essential. For example, other types of accumulators based on NTRU are also possible. Based on NTRU ciphertexts, gadget encryption similar to GGSW encryption can be defined, and using it, the outer product can be defined. A detailed example can be found in C. Bonte et al., "FINAL: Faster FHE instantiated with NTRU and LWE", https: / / ia.cr / 2022 / 074. Thus, the accumulator may be implemented based on NTRU, and its value may contain elements, for example,
Number
[0130] As an example, applying blind rotation to the LWE ciphertext c encrypting μ using this type of NTRU-based accumulator results in an encrypted polynomial product of a specific scaled plaintext -m’·Δ in with respect to the bootstrapping monomial
Number
Number
Number
Number
[0131] Instead of or in addition to the encrypted polynomial, the input ciphertext need not also be an LWE-type ciphertext. In particular, as discussed in the “FINAL” reference, blind rotation can be applied to NTRU-type ciphertexts. As discussed in the “FINAL” reference, it is also possible to obtain an input LWE ciphertext by converting from an NTRU ciphertext.
[0132] Even in such cases, it is desirable to define a test polynomial P f such that the product of the encrypted polynomials contains the desired output value at the fixed coefficient.
[0133] Interestingly, the techniques provided herein can also be used in combination with programmable bootstrapping without padding, which means that programmable bootstrapping can operate on input ciphertexts having any most significant bit. Such programmable bootstrapping is provided, for example, by I. Chillotti et al., “Improved programmable bootstrapping with larger precision and efficient arithmetic circuits for TFHE”, proceedings ASIACRYPT 2021. In such cases, when using Encode as described elsewhere in this document,
Number
Number
[0134] Yet another way to perform programmable bootstrapping is to extract each bit of the ciphertext and convert them to GGSW ciphertexts using, for example, circuit bootstrapping which is known per se; by applying a lookup table to each GGSW ciphertext. As is known per se, the latter may be performed particularly efficiently using mixed packing, such as horizontal packing and / or vertical packing. Also, in this technique for performing programmable bootstrapping, padding bits may not be required, for example the most significant bit may hold an arbitrary value. This technique is discussed in more detail with respect to FIG. 4.
[0135] In general, programmable bootstrapping may include a key-switching operation that is performed such that the output ciphertext is an encryption under the same key as the input ciphertext. Throughout this specification, the notation PBS-KS may be used to denote such programmable bootstrapping that includes key-switching. In this case, the key material PUB used for programmable bootstrapping may include a key-switching key for performing this key-switching. In general, performing key-switching is optional. The complexity of PBS-KS is:
Number
Number
[0136] FIG. 3a schematically shows an example of a carry partial value.
[0137] In various embodiments, a value may be encoded and encrypted as an encryption of a plurality of respective sub - values, for example corresponding to each digit of a radix decomposition of the value. In accordance with this correspondence, each sub - value may be associated with a particular modulus called a message modulus. For example, when using a radix decomposition with base β, the message modulus may be set to β. Thus, a value may be encoded and encrypted by encoding it as sub - values modulo a message modulus and encrypting these sub - values.
[0138] However, interestingly, in various embodiments described herein, a sub - value may be stored with a carry. This means that the sub - value is defined modulo a carry - message modulus p that is larger than the message modulus. Thus, a sub - value may be larger than the message modulus.
[0139] Each sub - value may be encrypted according to the same encryption key, but this is not necessary. In the latter case, various operations on the encoded and encrypted values, such as carry propagation described herein, may use key - switching, for example, from the encryption key of one sub - value to the encryption key of another sub - value, as needed.
[0140] For example, as shown in FIG. 3a, a ciphertext may encrypt a value characterized by: - An optional padding bit 301 set to zero as the most significant bit; - A carry - message modulus p, 302 and a message modulus β, 303 such that β ≤ p, for example a radix decomposition base (note that p and β need not be powers of two); - A value x, for example a value x without a carry that is less than β, or a value x with a carry that is greater than or equal to β and less than p.
[0141] For example, the carry message modulus p may be at least 4 times the message modulus β, at least 8 times the message modulus, or at least 32 times the message modulus. For example, the carry message modulus may be at most 128, at most 256, or at most 512. Given a message of a particular size (e.g., at most 8 bits or at most 16 bits), the remaining accommodation of the carry message modulus may be used for the carry.
[0142] For example, the figure shows a message modulus β = 4 = 2 2 and a carry message modulo p = 16 = 2 2+2 having values. Encryption using this message modulus and carry message modulus may have a 2-bit carry, which are set to 0 in the case of a carry-free value and can be advantageously used in encrypted operations.
[0143] For example, a carry-free value m scales the value according to the following algorithm and then the scaled version [Number] is encrypted, for example [Number] by using in, can be LWE encrypted. This exemplary algorithm takes an integer between 0 and p and provides 1-bit padding and more accommodation for calculating leveled operations.
[0144] [Table 1]
[0145] The encrypted operation may increase the encrypted value, in particular making it larger than the message modulus. In particular, the most significant part (e.g., the most significant bit) of the encrypted value corresponding to the value obtained by dividing the encrypted value by the message modulus may represent a carry, which may be referred to herein as a "carry buffer".
[0146] Two examples of this are shown with respect to FIGS. 3b and 3c. FIG. 3b shows the calculation of the encrypted addition of two values 311, 312 encrypted without a carry (e.g., having a carry buffer set to zero and padding bits). As shown in this figure, the value encrypted by the resulting ciphertext 313 may exceed the message modulus, i.e., the value may be a partial value with a carry. In this particular case, as shown, one carry bit 314 may be consumed by the addition.
[0147] A further example is shown in FIG. 3c. This figure shows the scalar multiplication of an encryption 321 of a value without a carry, which results in an encrypted value 322, with a scalar (i.e., an unencrypted value) μ<β. In this case, the number of carry bits 323 that may be affected is proportional to the size of the constant.
[0148] Returning to FIG. 3a. As shown with respect to FIGS. 3b and 3c, various encrypted operations may result in values that are encoded and encrypted with a carry; i.e., values having a partial value with a carry greater than or equal to the corresponding message modulus. Or at least, for some partial values, it may not be guaranteed that they do not contain a carry. It is possible to directly perform an encrypted carry reduction operation on such a value with a carry to reduce the value below the message modulus, but the inventors have noticed that this is not always necessary. In some cases, it is possible to leave the partial value encrypted with a carry and use such a value encoded and encrypted with a carry as an input to another encrypted operation.
[0149] However, at some point, encrypted carry reduction may be required, for example, when the encrypted operation or sub-operation to be applied may result in a value that exceeds the corresponding carry message modulus. Thus, at some point during the encrypted calculation, it may be determined whether to perform encrypted carry reduction on the carry value.
[0150] Interestingly, to determine whether to perform encrypted carry reduction, the inventors considered tracking the degree of filling of the carry partial value calculated as part of the encrypted operation. The degree of filling may indicate the limit of the carry partial value. The degree of filling may be regarded as metadata associated with the ciphertext. The degree of filling may indicate whether it is possible to apply an encrypted, for example, leveled homomorphic operation to the ciphertext, or whether its carry needs to be emptied first. If it is still possible to calculate the leveled operation, the degree of filling may quantify the amount of the leveled operation that can still be performed.
[0151] The fill degree is typically calculated dynamically while performing encrypted calculations, but as discussed elsewhere, it may also be calculated by a compiler device. Tracking the fill degree during calculations may be referred to herein as a "smart" variant form of performing encrypted calculations along with encrypted carry reduction. Smart encrypted calculations may automatically determine whether certain conditions are verified and whether the carry buffer must be emptied or whether another leveled operation can still be performed. In that sense, smart encrypted calculations can be regarded as an improvement of gate bootstrapping to a setting where the partial values do not need to be binary and the carry is preserved between encrypted operations and more leveled operations can be performed during bootstrapping. Interestingly, since smart encrypted calculations can automatically determine whether to perform encrypted carry reduction, it may not be necessary to determine when to perform encrypted carry reduction during the design time of encrypted calculations.
[0152] In particular, the ciphertext can be used to encrypt partial values at specific intervals defined by the fill degree. The encrypted partial values may be used as inputs for leveled homomorphic operations, resulting in different, typically larger intervals. In particular, the most significant part of the partial value may be filled with a carry. This part of the encrypted partial value may be called a carry buffer.
[0153] In particular, the encrypted value m (e.g., a partial value of an encoded and encrypted value) encrypted under the secret key s is a so-called Arith ciphertext C defined as follows ari and can be represented with the associated fill degree:
Equation
Equation
[0154] In particular, the filling degree can be defined as follows. [Number] Let be the carry message modulus, [Number] Let be the message modulus (which may or may not be a power of 2), for example, a radix decomposition base such that β ≤ p. Let ct be the ciphertext encrypting the value m < p. Let μ be the known worst case for m, for example, the largest integer that m can take, and 0 ≤ m ≤ μ. [Number] at [Number] The filling degree of can be defined as the following value: [Number]
[0155] Using this definition, when the degree of the ciphertext ct reaches 1, this means that this ciphertext may be encrypting the value p - 1, and this value is the largest integer that such a ciphertext can store without consuming (or without duplicating if no padding bits are used) the padding bits. Thus, when deg ≈ 1, carry reduction can be performed. In other words, for the partial value with carry to be calculated, the resulting filling degree thereof can be determined, and if it is greater than 1, carry reduction can be performed before encrypting the partial value with carry.
[0156] The above is used as an exemplary definition of fill factor throughout this specification, although other definitions are possible. For example, the fill factor may be defined by the integral size of the interval of possible values of that value, or the fill factor may be defined by the minimum and maximum possible encrypted values. In either case, the fill factor may indicate the limit of the carry partial value, and if it is determined that the limit exceeds the corresponding carry message modulus for the carry partial value to be calculated, encrypted carry reduction may be applied before calculating the carry partial value.
[0157] In particular, the fill factor of an encrypted value may be more granular than indicating whether the value contains a carry, and may be more granular than counting the integer of carry bits that the value has. Thereby, a more accurate worst-case estimate of the carry bit consumption level is obtained, making it possible to increase the number of leveled arithmetic operations before carry extraction is performed.
[0158] Here, methods are exemplified by which the fill factor can be calculated for various homomorphic arithmetic operations on encrypted values, particularly addition, subtraction, and scalar multiplication. In general, the fill factor can be determined by determining the limits of the output of the operation based on the limits of each input. Such limits generally depend on the way the operation is implemented and can often be derived from the implementation.
[0159] Furthermore, a permission check is defined for homomorphic operations, showing a way to determine whether an operation can be performed without exceeding the carry message modulus. As discussed elsewhere in this specification, operations on encoded and encrypted values can be implemented for such operations on encrypted values.
[0160] In the following discussion, two Arith ciphertexts
Number
Mathematics
Mathematics
[0161] In particular, the padding degree may be calculated for encrypted addition. In the following, this is illustrated for the homomorphic addition of two ciphertexts
Mathematics
Mathematics
Mathematics
[0162]
Table 2
[0163] This algorithm can be applied when the input is compatible and
Mathematics
Mathematics
Mathematics
[0164] As another example, the padding degree may be determined for an encrypted negative. In particular, this is illustrated below for the homomorphic modular negation of the ciphertext C ari that encrypts the message m. The output is a new ciphertext that encrypts the negation of the original message with an updated padding degree deg out .
Number
Number
[0165] This value is useful for the Neg algorithm. By the definition of the degree,
Number
Number
[0166] Therefore, z can represent the smallest multiple of β such that μ ≤ z. This value can represent the worst case for negation.
[0167]
Table 3
[0168] This algorithm can be applied when
Number
Number
Number
[0169] Another example is the calculation of padding for encrypted subtraction. Below, the homomorphic modular subtraction of two LWE ciphertexts
Number
Number
Number
[0170]
Table 4
[0171] If the inputs are compatible,
Number
Number
Number
[0172] Another example is encrypted scalar multiplication, or in other words, the multiplication of a known value by a party performing encrypted multiplication. Below, the homomorphic scalar multiplication between a ciphertext C ari and an integer μ known as such is illustrated. The output is a new ciphertext
Number
[0173]
Table 5
[0174] This algorithm can be applied when μ·(C ari ::deg) ≤ 1. The computational complexity of the scalar multiplication algorithm
Number
Number
[0175] An alternative way of performing multiplication is by using programmable bootstrapping. Programmable bootstrapping typically resets the fill level to the fill level of a value that does not hold a carry.
[0176] FIG. 3d schematically shows an example of an embodiment of an encrypted multiplication operation of first and second encrypted values. For example, the values can be sub - values of each encrypted and encoded value for which the product is calculated. A method of calculating the fill level is also illustrated.
[0177] This technique for calculating the encrypted multiplication of two ciphertexts can be an independent concern and can be used, for example, in encrypted calculations that do not include values that are encoded and encrypted with a carry, or even in encrypted calculations that do not include any encoded and encrypted values at all. Thus, such encrypted calculations involve accessing a set of encrypted values and performing encrypted calculations, which can include calculating one or more encrypted multiplications as discussed with respect to this figure.
[0178] The encrypted multiplication operation is the most significant part of the product of two encrypted values 331, 332, for example, the product of two values defined modulo β
Number
[0179] The encrypted multiplication operation can be performed by first determining a combined encryption 333 that includes both a first partial value and a second partial value; and then applying programmable bootstrapping 334 to the combined encryption 333 to obtain a result 335. In particular, to obtain the combined encryption 333, the first encrypted value 331 may be scaled, or in other words, shifted; and the shifted ciphertext 336 may be added to the unscaled second encrypted value 332.
[0180] In particular, the least significant part of the product can be calculated as follows:
[0181]
Table 6
[0182] This technique
Number
Number
Number
[0183] Instead of the LSB, a similar algorithm can be used to calculate the MSB. For the final programmable bootstrapping, different lookup tables are used:
[0184]
Table 7
[0185] As described above, the computational complexity of this algorithm is:
Number
[0186] More generally, a combined encryption representing each encrypted input value is determined; for example, by applying a univariate function to the combined encryption obtained by programmable bootstrapping, multivariate function evaluation can be performed on one or more input ciphertexts, such as encrypted partial values. MulLSB and MulLSB are examples of this, but this technique also works for other multivariate (e.g., bivariate) functions. Interestingly, in this way, a single programmable bootstrapping can be used to efficiently evaluate multivariate functions.
[0187] Specifically, consider a bivariate function, such as a lookup table l(m1,m2). In this case, two messages m1 and m2 may be combined, for example, by shifting one of the two ciphertexts. Thereby, the message can be effectively shifted higher within the MSB. The shifted ciphertext may be added to another ciphertext. For example, ciphertext ct2 may be multiplied by (μ1 + 1) and added to ct1. In this way, even in the worst-case scenario, information cannot be mixed. This can be possible when both the ciphertext and the result of the combination (e.g., multiplication and addition with a constant) comply with the conditions regarding degree and noise. When two messages are combined into a single ciphertext, the bivariate function l can be evaluated as a univariate LUT l' in concatenation.
[0188] If the degrees of the ciphertexts involved in the computation and their error amounts enable the steps leading to the concatenation to be performed, the same technique can be applied to multi-variable functions having three or more inputs. The output degree may be calculated when the function is multi-variable, just as it is calculated for single-variable functions.
[0189] Return to Figure 3a.
[0190] Here, an alternative to the encrypted multiplication of Figure 3d is discussed, which may be preferred in some situations as it is less efficient but requires less precision. How the padding can be determined for this alternative is also shown.
[0191] In this example, two ciphertexts
Number
Number
Number
Number
Number
[0192]
Table 8
[0193] The above procedure is applicable to compatible inputs where the parameters of Arith::Sub are appropriate for its algorithm,
Number
Number
Number
[0194] Another example of an operation where the filling degree can be determined is the extraction of the carry of the ciphertext. This operation may be used to implement encrypted carry reduction, as discussed elsewhere. In particular, the following algorithm takes an Arith ciphertext with a specific filling degree as input, performs PBS, extracts the part of the message that overflows the base β, and converts it into another Arith ciphertext.
[0195]
Table 9
[0196] This procedure can be applied when C ari ::deg ≤ 1. The computational complexity is
Number
[0197] Another operation by which the filling degree can be determined is the extraction of a message modulo the message modulus. In particular, the following algorithm takes as input an Arith ciphertext with a specific filling degree, performs PBS, extracts the part of the message that does not overflow β, and makes it into another Arith ciphertext.
[0198]
Table 10
[0199] The above procedure can be applied when C ari ::deg ≦ 1. The computational complexity can be
Number
[0200] Furthermore, a base change operation may be defined. In some cases, for example, to ensure compatibility between ciphertexts, it may be necessary to change the base of C ari ∈ Arith s (m) ciphertext during encrypted computation. For this purpose, an algorithm can be defined that takes C ari and the base (p out , β out ) as input and returns the ciphertext that encrypts m with the new base
Number
Number
[0201] This algorithm may be used when C ari ::deg · (C ari ::p - 1) < p out and the computational complexity [Number] may have.
[0202] In a further operation, the encrypted value may be multiplied by a scalar (i.e., a value known to the party performing the encrypted calculation), and at the same time the base (β, p) of the ciphertext may be changed. This operation may be implemented as follows:
[0203] [Table 11]
[0204] This algorithm may be used when C ari ::deg ≤ 1, and the computational complexity [Number] may have.
[0205] In general, for carry values calculated during encrypted calculations, such as the carry partial values of encoded and encrypted values, a padding may be determined, and if so indicated by the padding, encrypted carry reduction may be applied to the input used to calculate the carry value.
[0206] For this purpose, it may be verified whether the carry buffer may overflow when calculating the carry value, and if so, the carry may be reduced by clearing the carry (e.g., in the case of CRT representation) or propagating the carry (e.g., in the case of radix representation) as appropriate. Regarding the encoded and encrypted values to be calculated, it may be the case that none of the partial values, or one or more, or all of the partial values are carry-reduced. In the case of an operation having a plurality of input values (e.g., addition), the carry reduction may generally not be applied to any of the input values, may be applied to one or more of the input values, or may be applied to all of the input values. The encrypted operation thus obtained by verifying whether the carry buffer may overflow for each sub-operation corresponding to the original operation and performing carry reduction in that case may be referred to as the "smart version" of the encrypted operation.
[0207] FIG. 4 schematically shows an example of a value encoded and encrypted based on radix decomposition, also referred to as RadModInt representation.
[0208] In particular, the value is related to the relationship
Number
Number
Number
[0209] In particular, the value 0 ≦ m < M can be encoded and encrypted by encoding the value according to the following procedure and then encrypting the resulting encoded partial value:
[0210] [Table 12]
[0211] Note that this encoding can be combined, as desired, with programmable bootstrapping using padding bits or PBS without padding.
[0212] By using radix decomposition, encrypted calculations can be performed on values defined modulo the overall modulus M, where M is the product of base elements. The base elements can be, for example, at most 32, at most 64, or at most 128. The base elements need not be powers of two. One, several, or all of the base elements can be at least 3, at least 5, or at least 10. For example, a base of size κ of at least 2, at least 4, or at least 8 may be used. The use of such base elements allows calculations on partial values to be implemented relatively efficiently. The overall modulus can be, for example, at least 256, at least 512, or at least 1024. Thus, calculations can be made possible even for values that cannot be implemented efficiently without decomposition into partial values.
[0213] Using radix decomposition, modular integers can be implemented as a chain of κ encrypted blocks modulo β i (0 ≦ i < κ). For the blocks, a pair including a message modulus and a carry message modulus [Number] can be defined. The pair
Number
Number
[0214] This is shown as an example in Figure 4. In this example, three respective blocks 401 - 403 are used, i.e., κ = 3. For all 0 ≦ i < κ, β i = 4 and p i = 16; and M = 4 3 is. In this figure, a fresh RadModInt with partial values that do not hold carry is shown. In particular, it can be seen that the plaintext of block 401 includes padding bits 404, carry message modulus 405, and message modulus 406.
[0215] Interestingly, when using radix decomposition, various parameters of the encrypted calculation including, but not limited to, modulus M and base
Number
[0216] Here, some examples of encrypted operations that can be performed on encrypted and encoded values using radix decomposition will be discussed in detail. First, some notations are introduced. Under the secret key s, the base
Number
[0217] Hereinafter, the i-th rad encoded and encrypted part of the ciphertext [Number] encrypted partial value is sometimes denoted as C rad [i], and similarly for the base elements [Number] may be denoted as. [Number] (where i ≤ j) is [Number] a shorthand notation for, and similarly [Number] is abbreviated as. C rad ∈ RadModInt s (m) has a size of κ = |C rad | is denoted.
[0218] As explained elsewhere, each encrypted partial value [Number] can be encrypted according to different cryptographic keys, and key switching is used to convert between the cryptographic keys as needed.
[0219] Furthermore, C rad The compatibility of ciphertexts can be defined as follows.
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
[0220] The following is the ciphertext C ari ∈ Arith as the base
Number
Number
Number
[0221]
Table 13
[0222] This algorithm can be used when μ ≤ p - 1 and has a computational complexity
Number
[0223] The following shows the operations for increasing the number of sub - values used to encode and encrypt values using radix decomposition. For this purpose, the encoding and encryption may be extended with encryption of zero. Interestingly, this operation is very efficient for radix - decomposition - based encoding. This operation may be denoted as RadModIntCT::Padding,
Number
Number
Number
Number
Number
Number
Number
Number
Number
[0224] Below, an addition operation between two values encrypted using radix decomposition,
Number
Number
Number
Number
[0225]
Table 14
[0226] This operation can be used when the inputs are compatible and
Number
Number
[0227] The following illustrates the subtraction between two values
Number
Number
Number
Number
[0228]
Table 15
[0229] This operation can be used for inputs that are compatible with each other and
Number
Number
[0230] Shown below is an encrypted carry reduction operation that can be used to reduce a carry - part value of an encoded and encrypted value to a carry - free part value. For this purpose, a carry - part value can be decomposed into the encryption of each sub - value of the part value. The resulting encryption can then be added to the encryption of the corresponding sub - value of the output value. In this way, the carry of that sub - value can be propagated to a higher - index sub - value. In particular, C rad ∈RadModInt s (m) is taken as the ciphertext. For example, carry reduction may be applied to the encrypted sub - value C rad [α] at index α ∈ [0, κ - 1].
[0231]
Table 16
[0232] This operation is
Number
Number
Number
Number
[0233] The following illustrates an encrypted carry reduction operation in which a value encoded and encrypted with a carry can be converted to encoding and encryption without a carry. For this purpose, starting from the least significant partial value, the encrypted carry reduction can be applied to each partial value. In this way, each carry can be propagated. The carry reduction can be skipped if the partial value does not hold a carry even after the previous carry reduction. In particular, C rad ∈RadModInt s (m) is the ciphertext. The following algorithm can be used:
[0234]
Table 17
[0235] This operation is for ∀i ∈ [0, κ - 1], the parameter
Number
Number
[0236] The following illustrates an encrypted operation in which a value encoded and encrypted using radix decomposition is multiplied by a scalar, e.g., a known integer λ. In this example, by multiplying each partial value by the scalar, possibly in parallel. This algorithm is suitable for relatively small λ.
[0237]
Table 18
[0238] This operation is
Number
[0239] The following illustrates an encrypted but not encoded value, for example, an encrypted operation in which a partial value of an encoded and encrypted value is multiplied by a scalar λ. Interestingly, this operation can also be used for relatively large scalars. This operation can result in the encoding and encryption of the product. Each partial value of the encoded and encrypted product can be calculated by a respective programmable bootstrapping operation corresponding to each partial value of the scalar. In particular, for an integer λ and C that is clear ari ciphertext C ari ∈Arith s (m), the scalar multiplication with can result in a ciphertext at the base [Number] of C rad can become a ciphertext. This can be implemented as follows.
[0240] [Table 19]
[0241] This operation can be used when μ ≤ p - 1. The computational complexity is [Number] can become
[0242] The following illustrates an encrypted operation in which an encoded and encrypted value is multiplied by a scalar λ. This operation can be implemented by performing a scalar multiplication of each partial value by the scalar λ, resulting in each encoded and encrypted product, and then combining the resulting encoded and encrypted products. Interestingly, this operation can also be used with relatively large scalars. In particular,
Number
[0243]
Table 20
[0244] This operation can be used when the subroutines RadModIntCT::ScalarMulDecomp and RadModIntCT::Add can be applied to their respective inputs. The computational complexity can be
Number
[0245] The following illustrates an encrypted multiplication between each value that is encrypted but not encoded, e.g., between partial values of one or two different encoded and encrypted values. The encrypted multiplication can result in an encoded and encrypted value. The input values can be combined into a single encrypted value by scaling and addition, and each partial value of the encoded and encrypted value can be determined by applying respective programmable bootstrapping. In particular, two compatible C ari Ciphertext
Number
Number
Number
Number
[0246]
Table 21
[0247] This operation is performed when Arith::ScalarMul can be
Number
Number
[0248] The encrypted multiplication of an encrypted but not encoded value and an encoded and encrypted value is illustrated below. This operation multiplies each partial value of the encoded and encrypted value by the encrypted but not encoded value to yield each encoded and encrypted product; it can be implemented by combining the encoded and encrypted products. In particular, C ari ∈ Arith s (m1) and C rad ∈ RadModInt s (m2), then the homomorphic multiplication of m1 and m2 can be implemented as follows:
[0249]
Table 22
[0250] This operation can be used when for all i ∈ 0, κ - 1, RadModIntCT::MulDecomp and RadModIntCT::Add can be applied to their respective arguments. The computational complexity can be [Number] as follows.
[0251] The encrypted multiplication of the first and second encoded and encrypted values is illustrated below. This multiplication multiplies the respective sub - values of the first and second encoded and encrypted values, and these multiplications result in encoded and encrypted results; the encoded and encrypted results can be combined, for example, by addition. In particular, for example, with respect to the operation OneBlockMul discussed above, the encrypted multiplication can be implemented by multiplying each sub - value of the first encoded and encrypted value by the second encrypted value. In particular, for two ciphertexts [Number] and [Number] given, [Number] the multiplication decomposition between the pair of blocks [Number] can be calculated. Note that the encoded and encrypted inputs [Number] and [Number] do not have to be compatible. In this example, the result of the multiplication is [Number] It is expressed based on
[0252]
Table 23
[0253] This operation can be used when for all i ∈ [0, κ1 - 1], RadModIntCT::OneBlockMul and RadModIntCT::Add can be applied to their respective parameters. The computational complexity can be
Number
[0254] It is also possible to perform an encrypted evaluation of a univariate function on values encoded and encrypted using radix decomposition. For example, the univariate function to be evaluated can be an inverse function or a division. This operation can be implemented in various ways.
[0255] One way to evaluate a univariate function is by applying tree programmable bootstrapping. Using tree programmable bootstrapping to evaluate a large lookup table for multiple ciphertexts encoding one input of a lookup table is known per se from A. Guimaraes et al., "Revisiting the functional bootstrap in TFHE", IACR Trans. Cryptogr. Hardw. Embed. Syst., 2021(2):229 - 253, 2021 (incorporated herein by reference). This reference uses plaintext integers encrypted in the same base β. Interestingly, the inventors have noticed that these techniques are applicable to the setting of the present invention even when not all of the base elements of the radix decomposition are the same. In this way, multi - radix tree programmable bootstrapping may be obtained.
[0256] Specifically,
Number
Number
Number
Number
[0257] In particular, let B = {β
[0258] | i ∈ 0, κ - 1}, and i let be the component of x associated with β. In an iterative process, define β
Number
Number
Number
[0259] Regarding the computational complexity, in the worst case, for all i ∈ [0, κ - 1], β i = β max . Thus, the worst-case complexity in terms of PBS is
Number
[0260] Here, a particularly efficient technique for performing function evaluation on encrypted and encoded values is discussed. This technique works by extracting the bits required to evaluate the function from each encrypted partial value, converting the extracted bits into GGSW ciphertexts, and applying a lookup table to each GGSW ciphertext. This technique is illustrated for univariate function evaluation but also applies to multivariate function evaluation.
[0261] The inventors have noticed that in the context of the present invention, this approach has several advantages over the use of programmable bootstrapping directly based on blind rotation (however, it should be understood that this approach may also indirectly use programmable bootstrapping based on blind rotation, for example, for conversion to GGSW).
[0262] By performing bitwise operations at the level of individual partial values, blind rotation using polynomials that exponentially scale the size of the message modulus and / or the carry message modulus is avoided. As a result, the proposed univariate function evaluation can function for partial values with larger message moduli and / or carry message moduli. For example, the size of the message modulus and / or the carry message modulus of the partial values can be at least 10 bits, at least 13 bits, at least 15 bits, or at least 16 bits. By using larger moduli for the partial values, the efficiency of calculating the encoded and encrypted values can be significantly improved. In particular, the encrypted partial values may have more storage space for carries and / or fewer partial values may be required to represent a given value, so less carry reduction may be needed.
[0263] Furthermore, at the level of the overall encoded and encrypted values, the proposed univariate function evaluation also provides a significantly improved scaling of the size of the encrypted values. This is because, for example, using mixed packing rather than Tree-PBS, the look-up tables can be applied much more efficiently to each GGSW ciphertext. In particular, while Tree-PBS can scale the number of partial values exponentially, the application of the look-up table to the bit GGSW ciphertext can be done much more efficiently, for example even linearly, with respect to the number of partial values.
[0264] Another advantage of the proposed univariate function evaluation is that padding bits are not required for the most significant bits of the encrypted values. For example, it is not necessary to ensure that the most significant bits remain zero, as in some existing implementations of programmable bootstrapping. This means that higher precision can be obtained with a given ciphertext modulus q.
[0265] Improved single-variable function evaluation allows each encrypted partial value to be rounded to the desired precision before applying the LUT, providing further efficiency improvements. Further, multiple single-variable function evaluations can be performed on the same input using the same GGSW-encrypted bits, making it particularly efficient to apply multiple functions.
[0266] The proposed WoP-PBS can take as input a bootstrapping key and an LUT L that may or may not be encrypted. WoP-PBS can output a homomorphic evaluation of the LUT on the input message, e.g., an LWE or GLWE encryption of L[m].
[0267] In particular, bits can be extracted from the encrypted partial values by using programmable bootstrapping scaled to operate on each bit as the least significant bit, and extracting each least significant bit. This operation can be efficiently performed using generalized programmable bootstrapping, as proposed, for example, in I. Chillotti et al., "Improved programmable bootstrapping with larger precision and efficient arithmetic circuits for TFHE", which is incorporated herein by reference. In particular, generalized programmable bootstrapping may include modular switching that reads the bit immediately adjacent to the bit to be extracted and may be used to evaluate a rescaled sign function on the j-th bit.
[0268] Often, all bits of the input value can be extracted, but if the function does not depend on one or more bits (e.g., if the function uses only some of the least significant bits), extracting these bits may be avoided, further improving efficiency.
[0269] When using the generalized programmable bootstrapping described above, as described in "Improved programmable bootstrapping with larger precision and efficient arithmetic circuits for TFHE",
Number
[0270] To convert bits to GGSW ciphertexts, it is possible to use, for example, circuit bootstrapping. See, for example, I. Chillotti et al., "Faster packed homomorphic operations and efficient circuit bootstrapping for TFHE", proceedings of ASIACRYPT 2017 (incorporated herein by reference). Note that for circuit bootstrapping, its second step can be improved in the same way as H. Chen et al., "Onion ring ORAM: efficient constant bandwidth oblivious RAM from (leveled) TFHE", proceedings CCS 2019 (incorporated herein by reference). That is, the initial non-functional LWE-to-GLWE KS can be applied to the output of programmable bootstrapping, and a product of an outer product and the GGSW encryption of a GLWE secret key may be performed. Thereby, the size of the public evaluation key may be reduced, and the efficiency can be improved by using the FFT.
[0271] By using packing lookup table evaluation, a lookup table can be efficiently applied to a GGSW ciphertext. For example, see I. Chillotti et al., "Faster packed homomorphic operations and efficient circuit bootstrapping for TFHE", proceedings of ASIACRYPT 2017, which is incorporated herein by reference. In general, such packing LUT evaluation may use mixed packing, of which horizontal packing and vertical packing are two specific examples.
[0272] Interestingly, the above approach works for encoded and encrypted values regardless of whether a carry is used; it also works for values that are encrypted but not encoded as respective partial values. In the latter case as well, many of the advantages discussed apply. Thus, methods and encrypted computing devices that perform encrypted computations using the univariate function evaluation described without necessarily using a carry or encoded and encrypted values are conceivable. In general, improved univariate function evaluation typically internally uses programmable bootstrapping based on blind rotation (e.g., circuit bootstrapping may include a certain number of programmable bootstrappings), but at a higher level, especially when applied with a large message modulus, it should be noted that improved univariate function evaluation may be used to replace programmable bootstrapping performed in encrypted computations.
[0273] In particular, univariate function evaluation based on conversion to bits can be implemented as follows:
[0274] [Table 24]
[0275] The above example shows vertical packing, but it is also possible to use horizontal packing or mixed packing. Further, as shown above, it is also possible to output GLWE ciphertexts instead of LWE ciphertexts. Further, the above example generalizes to the evaluation of multivariate functions using multiple (e.g., at least two or at least three) encoded and encrypted inputs by extracting the desired bits from each input and applying a lookup table to the bits from each input.
[0276] As discussed elsewhere, performing encrypted computations may involve tracking the fill levels of each carry partial value. If the carry partial value to be computed has a fill level indicating that it may exceed the corresponding carry message modulus, encrypted carry reduction may be applied before computing the carry partial value. In particular, the encrypted carry reduction operation may be performed before or during the encrypted operation as needed. An operation configured to automatically perform carry reduction if necessary to ensure that the carry buffer does not overflow is called a "smart" operation.
[0277] FIG. 5 schematically shows an example of a value encoded and encrypted based on a residue number system representation. A way is shown in which various encrypted operations can be applied to the encoded and encrypted values in an encrypted computation.
[0278] Such encrypted computations may involve the use of carries in the encoded and encrypted values, but this is not necessary, and for example, carry reduction may be applied immediately after each operation or sub-operation described herein, such that the encrypted operation is applied only to the encoded and encrypted values without carries.
[0279] In particular, the mapping between a value and its partial values may follow a residue number system representation based in particular on the Chinese Remainder Theorem (CRT). The encoded and encrypted values are each message modulus βi can be encrypted as an encryption of κ partial values using 0 ≦ i ≦ κ-1. Typically, the modulus β i , β j , i≠j are pairwise relatively prime and enable reconstruction of the value from the partial values using the CRT. In general, any modulus can be used as the carry message modulus, for example, the partial values can use a common carry message modulus. To encrypt a value into an encrypted value, the CRT representation of the value may be calculated and each element of the representation may be encrypted. Similarly, the inverse CRT may be used to decrypt the encrypted value.
[0280] Interestingly, the use of residue number system encoding can provide particularly efficient encrypted carry reduction. In particular, carry reduction may be performed by performing a respective modulo reduction for each partial value, for example, a carry may not be transferred from one partial value to the next. This makes carry reduction fast and multi-threaded. For example, one, more, or all of the message moduli can be at least 2 and / or at most 32. For example, one, more, or all of the message modules can be at least 3, at least 5, or at least 10. In particular, the figure shows an encrypted value encoded and encrypted as an encryption of three respective partial values 501, 502, 503 defined modulo respective message moduli 504, 505, 506 each equal to 25, 29, and 32. Thus, the encrypted value can be defined modulo κ = 3 and M = 32×29×25. In this example, a common carry message modulus 507 equal to 64 is used.
[0281] In particular, encoding a value into partial values can be determined as follows:
[0282]
Table 25
[0283] Here, some notations related to encoding based on the residue number system are introduced.
Number
Number
[0284] To encode and encrypt the value m mod τ, each of its residues m i = m mod β i can be encrypted as κ different Arith ciphertexts.
[0285] To decrypt the value m encoded and encrypted using this CRT representation over multiple Arith ciphertexts, first, the Arith ciphertexts encrypting the partial values can be decrypted. Then, the encrypted integer can be decrypted modulo τ as if it were known itself.
[0286] Therefore,
Number
Number
Number
Number
Number
Number
Number
[0287] Two CrtModInt ciphertexts
Number
Number
Number
Number
[0288] Here, various operations on values encoded and encrypted using the CRT are discussed. Interestingly, when using the CRT representation, in many cases, the encrypted operations can be applied by individually applying each sub-operation to the respective encryption of each partial value of the input value. This makes the operations more efficient to implement and parallelizable. This is particularly true for addition, subtraction, and multiplication.
[0289] In particular, homomorphic addition can be implemented by adding blocks with the same index, for example, as follows:
[0290] [Table 26]
[0291] If the inputs are compatible, this operation can be applied, and Arith::Add can be applied for all 0 ≤ i < κ. The computational complexity can be [Number] as follows.
[0292] Also, homomorphic subtraction can be implemented by subtracting blocks with the same index, for example, as follows:
[0293] [Table 27]
[0294] If the inputs are compatible, this operation can be applied, and Arith::Sub can be applied for all 0 ≤ i < κ. The computational complexity can be [Number] as follows.
[0295] Multiplication by a scalar, known to those skilled in the art of performing encrypted multiplication, can be performed by multiplying each block by a scalar u modulo the respective message modulus β i as follows, for example:
[0296] [Table 28]
[0297] If Arith::ScalarMul can be applied for all \(0\leq i < \kappa\), this operation can be applied. The computational complexity can be
Number
[0298] An alternative way to implement scalar multiplication is, for example, by applying programmable bootstrapping.
[0299] Interestingly, when using the CRT representation, encrypted carry reduction can be applied to the carry - attached partial values by, for example, using programmable bootstrapping to reduce the carry - attached partial values modulo the corresponding message modulus. This may not affect other partial values, and thus, carry reduction for multiple or all partial values of the encoded and encrypted values can be done individually and, in some cases, in parallel. Propagation may not be required. For example, a single carry - attached partial value can be carry - reduced as follows:
[0300]
Table 29
[0301] This operation can be applied when \(C crt [i]::deg\leq1\), and the computational complexity can be
Number
[0302] For each \(C\) that makes up CrtModInt ari Regarding the ciphertext \(\beta\) i By extracting the message modulo \(\beta\), multiple partial values can be carry - reduced, for example, as follows:
[0303]
Table 30
[0304] This operation can be applied when C crt [i]::deg ≤ 1 for all 0 ≤ i < κ. The computational complexity can be [Number] as follows.
[0305] The homomorphic multiplication can be implemented by multiplying the corresponding partial values x mod β i and y mod β i for each i ∈ [0, κ - 1] with β as the modulus, for example as follows: i This operation can be applied when Arith::MulLSB can be applied for all i ∈ [0, κ - 1]. The computational complexity can be
[0306] [Table 31]
[0307] as follows. Other techniques, such as Arith::MulLSB [Number] can also be used for multiplying partial values. 3PBS For applying a univariate function to the encoded and encrypted value C
[0308] using CRT, various techniques may be used. In particular, it is possible to use tree programmable bootstrapping or apply a lookup table to the extracted bits encrypted with GGSW, both of which will be discussed further with respect to Figure 4. For some functions, it may also be possible to evaluate the univariate function by applying the univariate function to each partial value individually. This can be, for example crt [Number] Functions that can be expressed in terms of the sums and products above, such as arithmetic functions, may apply. In such cases, univariate functions can be applied, for example, as follows:
[0309]
Table 32
[0310] This operation has CrtModInt[i]::deg < 1 for all i such that 0 ≦ i < κ, and the function
Number
Number
[0311] FIG. 6 schematically shows an example of a value encoded and encrypted based on a radix decomposition. In this case, interestingly, the value is defined using a modulus M that is smaller than the maximum value representable by the radix decomposition. This has the advantage that the modulus M does not need to be equal to the product of the base elements.
[0312] In particular, to encode and encrypt a value modulo M, the base
Number
Number
[0313] For example, this figure shows the case where the modulus 601 is M = 1433. Note that 1433 is a prime number, and thus, a radix or CRT representation cannot be directly used for the decomposition with respect to this modulus. This figure shows a common base element β = 2 5 , 602, κ = 3, and a common carry message modulus
Number
Number
[0314] The encrypted operations can be performed in the same manner as discussed with respect to FIG. 4, except that the carry reduction may involve applying a correction resulting from modular reduction modulo M. The latter can be done by performing an encrypted modular reduction of the encryption of the most significant partial value of the output value. In particular, as discussed elsewhere, the carry and message can be extracted from the most significant block and the modulus can be computed homomorphically by redistributing it across the remaining blocks. Several approaches are possible in this regard, as discussed in more detail elsewhere.
[0315] More specifically, under the secret key s, an integer decomposed according to the base
Number
Number
Number
Number
Number
Number
Number
Number
Number
[0316] In the above definition, the modulus Q is set to be in the most significant block κ - 1. Note that it is possible to add one or more Arith ciphertext blocks to the MSB of the RadModInt + structure. The algorithms described herein for performing homomorphic modulus reduction can be configured to perform modulus reduction on the RadModInt + ciphertext using the additional Arith ciphertext blocks.[[]]
[0317] Two RadModInt + ciphertexts
Number
Number
Number
Number
Number
Number
Number
[0318] As discussed with respect to FIG. 4, various operations can be performed. Here, some examples thereof will be discussed.
[0319] In particular, modular addition can be calculated in the same manner as in the case of RadModInt ciphertext. For this purpose, the RadModInt + ciphertext can be regarded as a RadModInt ciphertext. This operation is
Number
[0320] Also, modular subtraction can be performed in the same manner as in the case of RadModInt + ciphertext by regarding the RadModInt ciphertext as a RadModInt ciphertext. This operation is
Number
[0321] Modular padding can also be performed in the same manner as in the case of RadModInt + ciphertext by regarding the RadModInt ciphertext at the output as a RadModInt ciphertext. Generally, the input resulting from the decomposition can be RadModInt. This operation is
Number
[0322] Applying encrypted carry reduction to the carry - with partial value can also be done, for RadModInt + viewing the ciphertext as a RadModInt ciphertext and can be done in the same way as for RadModInt ciphertext. This operation
Number
[0323] When reducing the most - significant partial value, modular reduction can be performed. Here, two possible methods of performing modular reduction are discussed. Their relative efficiency may depend on the distance between the modulus M and the limit M max and
[0324] The first method of performing modular reduction is to apply programmable bootstrapping to the most - significant encrypted partial value, propagate the partial values to their respective encrypted partial values, thereby obtaining a reduced value modulo Q.
[0325] In particular, carry reduction may include emptying and propagating the carry for the partial values of the encoded and encrypted values, except for the most - significant partial value. Thereby, all carries except the carry in the most - significant block may be emptied. This may be done when the carry in the most - significant block can support this carry - free propagation. In the most - significant block, programmable bootstrapping can be used to extract and transform both the carry and the message. The transformed and extracted carry and message can be redistributed to their respective blocks.
[0326] Here, the parameters shown in FIG. 6, namely Q = 1433, κ = 3,
Number
Number
Number
[0327] As a detailed example, the modular reduction can be implemented as follows:
[0328]
Table 33
[0329] This operation
Number
Number
[0330] Note that it is possible to evaluate each programmable bootstrapping as a single programmable bootstrapping using the "PBS many LUT" technique disclosed in "Improved programmable bootstrapping with larger precision and efficient arithmetic circuits for TFHE".
[0331] An alternative technique for performing modulo reduction is based on a linear relationship modulo a smaller Q between the partial value corresponding to the most significant base element and the set of partial values corresponding to the remaining base elements. Based on such a relationship, the encoded and encrypted values can be modulo-reduced to the encoded and encrypted values where the most significant partial value is zero. In particular, to obtain the linear relationship, the product of the base elements excluding β κ-1 modulo Q [Number] Can be decomposed with base = (β0, β1, …, β κ-1 ): [Number]
[0332] This method can be used when ν κ-1 = 0 in the decomposition. In this case, the constant ν jThe most significant block multiplied by κ-2 can be added to the j-th block, and then the new most significant block can be set to zero. This technique is particularly efficient when the elements ν0, ν1, …, ν
[0333] are small, and even zero. For some applications, it may be possible to select an appropriate modulus Q such that this modulo reduction becomes efficient, thereby obtaining particularly efficient encrypted computations.
Number
Number
[0334] Another example where this modulo reduction is particularly efficient is, as before, Q = 1087, κ = 3,
Number
Number
[0335] Note that this technique can be efficiently implemented without programmable bootstrapping. Optionally, carry propagation via bootstrapping can be done later. For example, this technique can be implemented as follows:
[0336]
Table 34
[0337] This procedure has coefficient ν κ-1 = 0 in the decomposition ν, and for all j ∈ [0; κ - 2], Arith::ScalarMul is applied to the ciphertext
Number
Number
[0338] RadModInt + For all partial values of an encoded and encrypted value using RadModInt, performing an encrypted carry reduction operation can be done by applying encrypted carry reduction to each partial value except the most significant partial value, and applying the encrypted modulus to the most significant partial value. In particular, this operation can be implemented as follows:
[0339]
Table 35
[0340] RadModInt + ::ClearCarry can reduce a partial value with carry to a partial value without carry, but due to the addition performed in modular reduction, RadModInt + ::Note that the overall result of ClearAllCarries may have a partial value with carry. Optionally, for example, RadModInt + ::Additional encrypted carry reduction using ClearCarry can be applied to reduce such a partial value with carry to a partial value without carry, if desired, for example, if it enables it to perform one or more subsequent operations.
[0341] The above procedure can be applied when RadModInt + ::ClearCarry can be applied for all i ∈ [0, κ - 2], and when RadModInt + ::ModularReduction 1,2 can be applied to the result. Depending on which modular reduction is used, the computational complexity can be
Number
Number
[0342] Scalar multiplication can be performed as discussed for RadModInt ciphertexts using the SmallScalarMul operation. This may be particularly suitable for relatively small scalars. For this purpose, RadModInt + ciphertexts may be viewed as RadModInt ciphertexts. This operation
Number
[0343] Scalar multiplication can be performed as discussed for RadModInt + ciphertexts viewing the RadModInt ciphertexts as RadModInt ciphertexts and using the ScalarMulDecomp operation. In particular, the respective sub - values of the encoded and encrypted values can be multiplied, and the resulting encoding and encryption can be combined. Scalar multiplication may further include performing modular subtraction. The overall scalar multiplication operation
Number
[0344] One way to implement the modular reduction in this case is to include one or more additional sub - values in the encoded and encrypted product so that exact multiplication is supported, that is, so that the encoded and encrypted product can be calculated without modular reduction (the number of sub - values to be added is appropriately chosen for the scalar to be multiplied); perform the exact multiplication; and apply the respective modular reduction to each of the added sub - values and the original most significant sub - value, for example, from the most significant to the least significant.
[0345] An alternative is to perform the respective modular reduction iteratively on each of the resulting encodings and encryptions before combining them. In this case, the addition of further sub - values can be avoided.
[0346] The multiplication of symbolized and encrypted values is RadModInt + The ciphertext may be treated as a RadModInt ciphertext and performed as discussed for RadModInt ciphertexts. In particular, the first symbolized and encrypted value may be multiplied by each partial value of the second symbolized and encrypted value, and the results may be combined. The multiplication may include modular subtraction. The overall multiplication is [Number] may be denoted as
[0347] To perform modular reduction, one or more partial values may be included in the symbolized and encrypted product so that the exact multiplication of the symbolized and encrypted values can be performed (the number of partial values is appropriately selected for the values to be multiplied); the exact multiplication can be performed; modular reduction can be applied to the added blocks and the original most significant partial value, for example, from the most significant to the least significant
[0348] Another way to perform modular reduction is to perform modular reduction iteratively during the calculation, for example, before overlaying the results in the most significant block. This may eliminate the need to add additional partial values
[0349] FIG. 7 schematically shows an example of a symbolized and encrypted value based on a residue number system representation and further based on a radix decomposition of the elements of the residue number system representation. Such a representation is referred to herein as "hybrid" symbolization and encryption. In particular, the symbolized and encrypted value may include one or more respective symbolizations and encryptions according to the residue number system representation of each partial value defined according to the residue number system representation
[0350] Interestingly, by doing so, it is possible to combine the advantages of the residue number system representation that can avoid many carry propagations without having the problem of requiring many small relatively prime numbers. In particular, by using a hybrid approach, it is possible to perform encrypted calculations that use relatively large moduli relatively efficiently. For example, the modulus may be at least 2 10 , at least 2 20 , or at least 2 30 . For example, the number of residues in the residue number system representation may be at most or at least 3, at most or at least 6, or at most or at least 10.
[0351] For example, this figure shows hybrid encoding and encryption using a modulus of (4 5 ) × 1433 × 17 × (3 4 ). This modulus may be decomposed into four residues 4 5 , 710; 1433, 720; 17, 730; and 3 4 , 740 according to the residue number system. For each residue of the residue number system decomposition, the encoding and encryption of a given value may include each set of one or more encrypted values that represent each element of the residue number system decomposition of the value.
[0352] In particular, for zero, one, or two or more residues of the residue number system, as discussed with respect to FIG. 5, the corresponding elements may be encrypted as encrypted but not encoded values where the message modulus is equal to the residue. This is the case for the residue 17, 730 in the figure, which may be encrypted as the encryption 740 with the residue itself as the modulus.
[0353] For zero, one, or two or more additional residues, the corresponding elements may be encoded as encoded and encrypted values according to the radix decomposition of the elements. Here, the residue may be equal to the maximum value representable by radix decomposition using, for example, the encoding and encryption of FIG. 4; and / or the residue may be less than the maximum value representable by radix decomposition using, for example, the encoding and encryption of FIG. 6.
[0354] This is shown in the figure, with a remainder of 4 5 , an element modulo 710 can be encoded and encrypted as five partial values 711 - 715 modulo 4, as discussed with respect to Figure 4 for example; with a remainder of 3 4 , an element modulo 740 can be encoded and encrypted as four partial values 741 - 743 modulo 3. In this example, an element with a remainder of 1433, modulo 720, can be encoded and encrypted as three partial values 721 - 723 modulo 2, as discussed with respect to Figure 6 for example 5 for example
[0355] In particular, given a list of a plurality of relatively prime integers (Q0,..., Q κ-1 ), the hybrid approach may be used to encode and encrypt the value m mod τ. The value may be encoded and encrypted by determining each element of the CRT representation of the value m mod Q [Number] for i ∈ [0, κ - 1], where each value is encrypted, encoded - encrypted as RadModInt, and / or encoded and encrypted as if encrypted with RadModInt i Here, a detailed example is provided where RadModInt is used for all remainders. This example may apply when RadModInt or a single encryption is used for one, multiple, or all remainders. In this example + the ModInt ciphertext encrypting the integer
[0356] under CRT - based (Q0,..., Q + ) is [Number] where the ModInt ciphertext encrypting the integer κ-1 under CRT - based (Q0,..., Q [Number] is [Number] may be defined as follows. Here, for all 0 ≦ i ≦ κ - 1 [Number] where m ≡ m i mod Q i In this example, the i-th RadModInt mod that constitutes C + ciphertext is [Number] denoted as. Then, |C mod [i]| = κ i , and C mod [i] :: Q = Q i holds.
[0357] ModInt ciphertext [Number] and [Number] are: [Number] (where [Number] ), and when the ciphertext [Number] and [Number] are compatible for all i ∈ [0, κ - 1], it can be defined as compatible.
[0358] In general, various calculations including encrypted operations and encrypted carry reduction can be performed as discussed with respect to the normal residue number system based encoding and encryption of FIG. 5. For example, encrypted addition, subtraction, scalar multiplication, carry reduction, clearing of all carries, multiplication, and / or univariate function evaluation can be applied.
[0359] When performing such calculations involves performing subcomputations on one or more elements of the CRT representation, the subcomputations can be applied to the respective encoded and encrypted elements using the techniques discussed with respect to FIG. 4 or FIG. 6. For example, operations on ModInt can be calculated individually for each component RadModInt + (m mod Q i ), i ∈ [0, κ - 1], where instead of using an Arith-based algorithm, the RadModInt + -based algorithm described herein is used to calculate for [Number] of ModInt.
[0360] FIG. 8 schematically shows an example of an embodiment of an encryption method 800 for performing encrypted calculations on a set of one or more encoded and encrypted values. The method 800 can be computationally implemented. The values can be encoded and encrypted as the encryption of a plurality of respective sub-values. The sub-values can have a corresponding message modulus and a carry message modulus larger than the message modulus. The values can be encoded and encrypted without carry by sub-values without carry smaller than the corresponding message modulus. The values can be encoded and encrypted with carry by at least one sub-value with carry greater than or equal to the corresponding message modulus.
[0361] Method 800 may include accessing (810) one or more encoded and encrypted values. Method 800 may include applying an encrypted operation to at least an input value that is encoded and encrypted with carry to obtain an output value that is encoded and encrypted with carry (820). Method 800 may include applying encrypted carry reduction to the output value that is encoded and encrypted with carry to obtain further encoding and encryption of the output value in which at least one carry-bearing partial value is reduced to a carry-free partial value (830).
[0362] FIG. 9 schematically shows an example of an embodiment of a compiler method 900 that compiles a computation into a homomorphically executable file. The homomorphically executable file is executable by an encrypted computing engine, and the encrypted computing engine may be caused to perform an encrypted computation on a set of one or more encoded and encrypted values as described herein, for example, according to method 800 of FIG. 8. The homomorphically executable file may include, for example, as part of the encrypted operation or in between performing the encrypted operations, one or more instructions for performing an encrypted carry reduction operation as described herein. The compiler method 900 may be computer implemented.
[0363] The compiler method 900 may include determining (910) a fill level indicating a limit of a carry-bearing partial value for a carry-bearing partial value to be computed; and, if the limit exceeds a corresponding carry message modulus (920), generating (930) an instruction for causing the encrypted computing engine to apply encrypted carry reduction before computing the carry-bearing partial value.
[0364] As will be apparent to those skilled in the art, there are many different ways to perform methods 800, 900. For example, the order of steps can be performed in the order shown, but the order of steps can be changed, or some steps may be executed in parallel. Further, other method steps may be inserted between steps. The inserted steps may represent improvements to the method as described herein, or may be unrelated to the method. For example, some steps may be executed at least partially in parallel. Further, a given step may not be fully completed before the next step is started. It is also possible to combine methods 800, 900. For example, method 800 for performing encrypted calculations may be performed according to a homomorphic executable file previously compiled according to method 900.
[0365] Some embodiments of the method may be implemented using software that includes instructions for causing a processor system to perform method 800 or 900. The software may include only the steps performed by a particular sub-entity of the system. The software may be stored on a suitable storage medium such as a hard disk, floppy disk, memory, optical disk, etc. The software may be transmitted as a signal along a wire or wirelessly, or using a data network such as the Internet. The software may be made available for download and / or for remote use on a server. Embodiments of the method may be implemented using a bitstream arranged to configure programmable logic, such as a field programmable gate array (FPGA), to perform this method.
[0366] It should be understood that the subject matter disclosed herein extends to computer programs configured to practice the subject matter disclosed herein, particularly computer programs on or in a carrier wave. The program may be in any form of object code, such as source code form, object code form, intermediate source form of code, and partially compiled form, or any other form suitable for use in implementing the embodiments of the method. Embodiments relating to computer program products include computer-executable instructions corresponding to each of the processing steps of at least one of the methods described. These instructions may be divided into subroutines and / or stored in one or more files that may be linked statically or dynamically. Another embodiment relating to computer program products includes computer-executable instructions corresponding to each of at least one of the devices, units, and / or components of the described system and / or product.
[0367] Typically, for example, the devices described herein in FIGS. 1a - 1c comprise one or more microprocessors that execute appropriate software stored in the system; for example, the software may be downloaded and / or stored in a corresponding memory, such as volatile memory like RAM or non-volatile memory like flash. Alternatively, the system may be implemented, in whole or in part, in programmable logic, such as a field programmable gate array (FPGA). The system may be implemented, in whole or in part, as a so-called application specific integrated circuit (ASIC), such as an integrated circuit (IC) customized for those specific applications. For example, the circuit may be implemented in CMOS using a hardware description language such as Verilog or VHDL. In particular, the system may include a circuit for the evaluation of cryptographic primitives.
[0368] The processor circuit may be implemented distributively, for example, as a plurality of sub-processor circuits. The storage may be distributed across a plurality of distributed sub-storages. Part or all of the memory may also be an electronic memory or a magnetic memory. For example, the storage may have a volatile part and a non-volatile part. A part of the storage may be read-only.
[0369] FIG. 10 shows a computer-readable medium 1000 having a writable portion 1010. The computer-readable medium 1000 is shown in the form of an optically readable medium. The computer-readable medium 1000 can store data 1020, which, when executed by a processor system, may represent an embodiment of a method for performing encrypted calculations and / or instructions to cause the processor system to perform a compiler method according to an embodiment.
[0370] Alternatively, or in addition, the data 1020 may represent a quasi-homomorphic executable file compiled according to the compiler method described herein.
[0371] Alternatively, or in addition, the data 1020 may represent a set of one or more encoded and encrypted values, including zero or more values encoded and encrypted without carry and one or more values encoded and encrypted with carry, as described herein.
[0372] The data 1020 may be embodied as a physical mark on the computer-readable medium 1000 or by magnetization of the computer-readable medium 1000. However, any other suitable embodiments can also be considered. Further, although the computer-readable medium 1000 is shown here as an optical disk, it should be understood that the computer-readable medium 1000 may be any suitable computer-readable medium such as a hard disk, solid-state memory, flash memory, etc., and may be non-recordable or recordable.
[0373] FIG. 11 shows a schematic diagram of a processor system 1140 according to an embodiment of a device for performing encrypted calculations or determining test polynomials. The processor system includes one or more integrated circuits 1110. The architecture of the one or more integrated circuits 1110 is schematically shown in this figure. Circuit 1110 includes a processing unit 1120, such as a CPU, for executing computer program components to execute a method according to an embodiment and / or to implement its modules or units. Circuit 1110 includes a memory 1122 for storing programming code, data, etc. A part of the memory 1122 may be read-only. Circuit 1110 may include a communication element 1126, such as an antenna, a connector, or both. Circuit 1110 may include a dedicated integrated circuit 1124 for performing some or all of the processing defined by the method. The processor 1120, the memory 1122, the dedicated IC 1124, and the communication element 1126 can be interconnected via an interconnection 1130, such as a bus. The processor system 1110 can be configured for contact and / or non-contact communication, using an antenna and / or a connector respectively.
[0374] For example, in one embodiment, the processor system 1140, such as a device for performing encrypted calculations or compilations, may include a processor circuit and a memory circuit, and the processor is configured to execute software stored in the memory circuit. For example, the processor circuit may be an Intel Core i7 processor, an ARM Cortex-R8, etc. In one embodiment, the processor circuit may be an ARM Cortex M0. The memory circuit may be a ROM circuit or a non-volatile memory, such as a flash memory. The memory circuit may be a volatile memory, such as an SRAM memory. In the latter case, the device may also include a non-volatile software interface configured to provide software, such as a hard drive, a network interface, etc.
[0375] Device 1110 is shown as including one of each of the components described above, although the various components may be replicated in various embodiments. For example, processor 1120 may include a plurality of microprocessors configured to perform the methods described herein independently, or a plurality of processors configured to perform steps or subroutines of the methods described herein in cooperation to implement the functions described herein. Further, when device 1110 is implemented in a cloud computing system, the various hardware components may belong to separate physical systems. For example, processor 1120 may include a first processor in a first server and a second processor in a second server.
[0376] Note that the above-described embodiments are illustrative rather than limiting of the subject matter disclosed herein, and those skilled in the art will be able to design many alternative embodiments.
[0377] In the claims, any reference signs in parentheses shall not be construed as limiting the claims. The use of the verb "comprise" and its conjugations does not exclude the presence of elements or steps other than those recited in the claims. The article "a" or "an" preceding an element does not exclude the possibility that more than one of the element exists. Expressions such as "at least one of" following a list of elements represent a selection of any one or more of the listed elements or any sub-set of the listed elements. For example, the expression "at least one of A, B, and C" shall be understood to include only A, only B, only C, both A and B, both A and C, both B and C, or all of A, B, and C. The subject matter disclosed herein may be implemented by hardware comprising several different elements and by a suitably programmed computer. In apparatus claims listing several parts, several of these parts may be embodied by the same item of hardware. The mere fact that certain means are recited in mutually different dependent claims does not indicate that a combination of these means cannot be used advantageously.
[0378] In the claims, the references in parentheses represent reference signs in the drawings that illustrate embodiments or expressions of embodiments, thereby facilitating understanding of the claims. These reference signs shall not be construed as limiting the claims.
Claims
1. A cryptographic method (800) for performing encrypted calculations on one or more sets of encoded and encrypted values, wherein the values are encoded and encrypted as the encryption of a plurality of respective partial values, and the partial values have a corresponding message modulus and a carry message modulus greater than the message modulus, wherein the values are encoded and encrypted without carry by a carry-free partial value smaller than the corresponding message modulus, wherein the values are encoded and encrypted with carry by at least one carry-bearing partial value greater than or equal to the corresponding message modulus, the method comprising: accessing (810) one or more encoded and encrypted values, applying an encrypted operation to at least the input value encoded and encrypted with carry to obtain an output value encoded and encrypted with carry (820), applying encrypted carry reduction to the output value encoded and encrypted with carry to obtain further encoding and encryption of the output value in which at least one carry-bearing partial value is reduced to a carry-free partial value (830) A cryptographic method (800) comprising.
2. The encryption of the partial value is LWE encryption, the LWE encryption supports a programmable bootstrapping operation, the programmable bootstrapping evaluates LWE decryption at the exponent of a GLWE-encrypted monomial, and the encrypted carry reduction uses the programmable bootstrapping operation, the method (800) of claim 1.
3. Calculating an output value by performing a plurality of encrypted arithmetic operations on a set of encoded and encrypted values, said performing including encrypted carry reduction, the method (800) according to claim 1 or 2.
4. The encrypted operation is applied by individually applying respective sub-operations to the respective encryptions of the partial values of the input value, and the individually applied encrypted operations are performed at least partially in parallel, the method (800) according to any one of claims 1 to 3.
5. The encoding of the value as a carry-free partial value is based on the residue number system representation of the value, the method (800) according to any one of claims 1 to 4.
6. The encoding is further based on the radix decomposition of the elements of the residue number system representation, the method (800) according to claim 5. **Claim 7** Encoding of a value as a carryless partial value, based on a radix decomposition of the value, of the method (800) according to any one of claims 1 to 4. **Claim 8** Applying encrypted carry reduction includes decomposing a carry-bearing partial value of an output value into encryptions of respective partial values of the partial value, and adding the encryptions of the partial values of the partial value to the encryption of the corresponding partial value of the output value, of the method (800) according to claim 6 or 7. **Claim 9** Performing encrypted multiplication of an encoded and encrypted value by a scalar by calculating respective encrypted partial values of the scalar multiplication of the partial values of the encoded and encrypted value, of the method (800) according to any one of claims 6 to 8. **Claim 10** Performing encrypted multiplication of a first encoded and encrypted value and a second encoded and encrypted value by performing encrypted multiplication of encryptions of partial values of the first and second encoded and encrypted values, wherein the encrypted multiplication of the encryptions of the partial values results in an encoded and encrypted value, of the method (800) according to any one of claims 6 to 9. **Claim 11** An element of a residue number system, or a value encoded and encrypted without carry, is defined with a modulus smaller than the maximum value representable by radix decomposition, of the method (800) according to any one of claims 6 to 10. **Claim 12** Applying an encrypted operation includes determining a fill level indicating a limit of a carry-bearing partial value for the carry-bearing partial value to be calculated, and applying encrypted carry reduction before calculating the carry-bearing partial value if the limit exceeds a corresponding carry message modulus, of the method (800) according to any one of claims 1 to 11. **Claim 13** The message modulus is not a power of two, and / or is at least 3, and / or is at least 5, and / or is at least 10, of the method (800) according to any one of claims 1 to 12. **Claim 14** The carry message modulus is at least 4 times, at least 8 times, or at least 32 times the corresponding message modulus, of the method (800) according to any one of claims 1 to 13. **Claim 15** The method (800) according to any one of claims 1 to 14, comprising performing one or more encrypted linear operations, and / or one or more encrypted multiplications, and / or one or more univariate function evaluations.
16. The method (800) according to any one of claims 1 to 15, comprising extracting one or more bits from one or more partial values of an encoded and encrypted value, converting the extracted bits into a GG-SW ciphertext, and applying a lookup table to the GG-SW ciphertext to apply a function evaluation to one or more encoded and encrypted values.
17. A computer-implemented compiler method (900) for compiling a computation into a homomorphically executable file, wherein the homomorphically executable file is executable by an encrypted computation engine, and the encrypted computation engine is caused to perform the encrypted computation according to any one of claims 1 to 16, and the method comprises determining a fill level indicating a limit of a carry partial value for a carry partial value to be computed (910); when the limit exceeds the carry message modulus of the carry partial value (920), generating an instruction for causing the encrypted computation engine to apply encrypted carry reduction before computing the carry partial value (930); A computer-implemented compiler method (900) comprising.
18. An encryption device (110, 112) for performing an encrypted computation on a set of one or more encoded and encrypted values, wherein the value is encoded and encrypted as an encryption of a plurality of respective partial values, the partial values having a corresponding message modulus and a carry message modulus greater than the message modulus, the value is encoded and encrypted without carry by a carry-free partial value smaller than the corresponding message modulus, the value is encoded and encrypted with carry by at least one carry partial value greater than or equal to the corresponding message modulus, the device (110, 112) comprises a storage (140) for storing one or more encoded and encrypted values, A processor subsystem (130) configured to apply an encrypted operation to at least an input value encoded and encrypted with carry to obtain an output value encoded and encrypted with carry, and to apply an encrypted carry reduction to the output value encoded and encrypted with carry to obtain further encoding and encryption of an output value in which at least one carry-bearing partial value is reduced to a carry-free partial value A cryptographic device (110, 112) comprising the same. **Claim 19** A compiler device (119) for compiling a calculation into a homomorphically executable file, the homomorphically executable file being executable by an encrypted calculation engine, the encrypted calculation engine performing the encrypted calculation according to any one of claims 1 to 16, the device comprising A storage (149) for storing data representing a calculation to be compiled into a homomorphically executable file A processor subsystem (139) configured to determine a filling degree indicating a limit of a carry-bearing partial value with respect to the carry-bearing partial value to be calculated, and when the limit exceeds the carry message modulus of the carry-bearing partial value, generate an instruction to cause the encrypted calculation engine to apply an encrypted carry reduction before calculating the carry-bearing partial value A compiler device (119) comprising the same. **Claim 20** A temporary or non-temporary computer-readable storage medium (1000) containing data (1020), the data (1020) being Instructions that cause a processor system to perform the method according to any one of claims 1 to 16 when executed by the processor system, and / or Instructions that cause a processor system to perform the method according to claim 17 when executed by the processor system, and / or A set of one or more encoded and encrypted values including zero or more values encoded and encrypted without carry and one or more values encoded and encrypted with carry represented by The values are encoded and encrypted as the encryption of a plurality of respective partial values, the partial values having a corresponding message modulus and a carry message modulus greater than the message modulus The value is encoded and encrypted without carry by a carry-free partial value smaller than the corresponding message modulus, and the value is encoded and encrypted with carry by at least one carry partial value greater than or equal to the corresponding message modulus. A temporary or non-temporary computer-readable storage medium (1000).
Citation Information
Patent Citations
Medical Information Management Systems and Management Act
JP2005535360A
Homomorphic Processing Unit (HPU) for Accelerating Secure Computation under Homomorphic Encryption
JP2020537756A
Method and processing device for performing a lattice-based cryptographic operation
US20190312728A1
Method and Apparatus for Configuring a Reduced Instruction Set Computer Processor Architecture to Execute a Fully Homomorphic Encryption Algorithm
US20200213079A1