Cryptographic processing device, cryptographic processing method, and cryptographic processing program

By employing a cryptographic processing device that applies step polynomial functions to enable multiplication between ciphertexts, the system addresses the inefficiencies in existing fully homomorphic encryption systems, particularly in error reduction, thereby enhancing operational efficiency and practicality.

JP7672722B2Active Publication Date: 2025-05-08AKUSERU KK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023002303
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-07-19
Filing Date
2023-01-11
Publication Date
2025-05-08
Estimated Expiration
2043-01-11

AI Technical Summary

Technical Problem

Existing fully homomorphic encryption systems, such as those based on the Learning with Errors (LWE) problem, face significant challenges in efficiently performing all arithmetic operations due to error accumulation during operations, which necessitates bootstrapping to reduce errors. This process is computationally expensive and impractical for large datasets.

Method used

The implementation of a cryptographic processing device that enables multiplication between ciphertexts by applying a step polynomial function to the multiplier plaintext and generating a ciphertext with a step polynomial, allowing for the extraction of constant terms and calculation of the multiplication result without decryption.

Benefits of technology

This approach enables the realization of four arithmetic operations (addition, subtraction, multiplication, and division) in Integer-wise type TFHE, significantly improving the efficiency and practicality of fully homomorphic encryption by reducing the computational overhead associated with error reduction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007672722000049
    Figure 0007672722000049
  • Figure 0007672722000050
    Figure 0007672722000050
  • Figure 0007672722000051
    Figure 0007672722000051
Patent Text Reader

Abstract

To achieve four arithmetic operations of integer-wise type TFHE.SOLUTION: An encryption processing apparatus processes a cryptography. The cryptography is a complete homomorphic cryptography having a value obtained by providing an error with a predetermined variance to a predetermined value as a plain sentence associated with integers, and allowing predetermined operation of the integers without decryption. The encryption processing apparatus calculates a new first cryptography cb' by using a predetermined polynomial expression for a first cryptography cb being a multiplier, generates a higher-order cryptography cc with a higher degree than the new first cryptography cb', and by using the predetermined polynomial expression for the higher-order cryptography cc and a second cryptography ca being a multiplicand, obtains a third cryptography cc' corresponding to a result of multiplication of the first cryptography and the second cryptography.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a cryptographic processing device, a cryptographic processing method, and a cryptographic processing program. [Background technology]

[0002] Homomorphic encryption is an encryption method that allows data processing to be performed on encrypted data without decrypting the data. Additive homomorphic encryption is an encryption in which there is an operation between ciphertexts that corresponds to the addition between plaintexts, and multiplicative homomorphic encryption is an encryption in which there is an operation between ciphertexts that corresponds to the multiplication between plaintexts. Additive homomorphic encryption, which treats finite cyclic groups as integers and performs only additive operations (addition and subtraction), and multiplicative homomorphic encryption, which performs only multiplicative operations (multiplication), have long been known. Finite cyclic groups allow integer multiplication by repeated addition, so integer multiplication using plaintext is possible, and exponentiation calculations using plaintext are also possible by repeated multiplication. There is also ring homomorphic encryption, which processes both additive and multiplicative operations while keeping the data encrypted, and fully homomorphic encryption (FHE), which allows all operations including additive and multiplicative operations. One type of fully homomorphic encryption is based on the Learning with Errors (LWE) problem, which involves adding small errors to plaintext during encryption that do not affect decryption.

[0003] In fully homomorphic encryption based on the LWE problem, errors accumulate as calculations are performed, so bootstrapping is performed to reduce the error components while still encrypting the data before the errors become too large to make decryption possible. The computation time of bootstrapping accounts for most of the computation time required for fully homomorphic encryption. In addition, because bootstrapping handles a huge amount of data, the amount of computation required is enormous. Therefore, in fully homomorphic encryption, it has been difficult to obtain the computation results within a practical time frame. A technique that dramatically improves this problem is TFHE (Fast Fully Homomorphic Encryption over the Torus), which is shown in Non-Patent Document 1 (referred to as the above paper in the following description). There are two types of homomorphic encryption: bit-wise homomorphic encryption, which has a binary plaintext and uses logical operations as the base, and integer-wise homomorphic encryption, which uses an entire integer as a single ciphertext as the plaintext. The TFHE described in Non-Patent Document 1 is a bit-wise type. Note that the plaintext of TFHE is a real number between 0 and 1 that is associated with a circular group. Therefore, by associating integers with intervals that divide the range of the circular group from 0 to 1 in order, it is possible to apply it as an integer-wise homomorphic encryption that has integers as plaintexts (see Non-Patent Document 2). [Prior art documents] [Patent documents]

[0004] [Non-Patent Document 1] TFHE:Fast Fully Homomorphic Encryption over the Torus. Journal of Cryptology, 33:34-91, 2020, I. Chillotti, N. Gama, M. Georgieva, and M. Izabachene [Non-Patent Document 2] Integerwise Functional Bootstrapping on TFHE, 2020, Hiroki Okada, Shinsaku Kiyomoto, and Carlos Cid Summary of the Invention [Problem to be solved by the invention]

[0005] If TFHE can be used as a homomorphic encryption method capable of integer-wise arithmetic operations, processing can be performed more efficiently than calculating each bit one by one. The above paper shows that the TLWE ciphertext used in TFHE is additively homomorphic to plaintexts in circular groups, and it is trivial that addition (subtraction) operations can be performed. On the other hand, as for multiplication, although the multiplication of integers and circular groups (ciphertexts) is defined because circular groups are Z-modules, it cannot be said to be trivial because multiplication between circular groups is not defined. One aspect of the present invention is to enable multiplication of ciphertexts and more completely realize the four arithmetic operations of integer-wise TFHE. [Means for solving the problem]

[0006] According to one aspect, the present invention provides a cryptographic processing device that processes a ciphertext, the ciphertext having a value obtained by adding an error having a predetermined variance to a predetermined value as a plaintext associated with an integer, the ciphertext being a fully homomorphic ciphertext that allows a predetermined operation between integers to be performed without decryption, A function for obtaining a stepwise polynomial is applied to a multiplier plaintext obtained when a first ciphertext, which is a multiplier, is decrypted, and a function for obtaining a ciphertext having as plaintext the first stepwise polynomial, the coefficient of which increases stepwise by the value of the multiplier plaintext, is applied to the first ciphertext, A third ciphertext is generated having the first stepwise polynomial as plaintext, and a constant term of a polynomial obtained by rotating the coefficients of the plaintext polynomial of the third ciphertext is extracted according to the second ciphertext which is the multiplicand, thereby calculating a fourth ciphertext as the result of the operation, which is a ciphertext corresponding to the result of multiplication of the plaintexts of the first ciphertext and the second ciphertext. According to one aspect of the present invention, there is provided a cryptographic processing device for processing a ciphertext, the ciphertext being a fully homomorphic ciphertext having a plaintext corresponding to an integer, the plaintext corresponding to a predetermined value to which an error having a predetermined variance has been added, and which allows a predetermined operation between integers to be performed without decryption; A function for obtaining a stepwise polynomial is applied to a multiplier plaintext obtained when a first ciphertext, which is a multiplier, is decrypted, and a function for obtaining a ciphertext having as plaintext the first stepwise polynomial, the coefficient of which increases stepwise by the value of the multiplier plaintext, is applied to the first ciphertext,A third ciphertext is generated having the first echelon polynomial as plaintext, and a fifth ciphertext is homomorphically added to the ciphertext calculated by extracting a constant term of a polynomial obtained by rotating the coefficients of the plaintext polynomial of the third ciphertext according to the second ciphertext, which is the multiplicand, to calculate a fourth ciphertext resulting from the operation, which is a ciphertext corresponding to the result of a fused multiply-add operation between the plaintexts of the first ciphertext, the second ciphertext, and the fifth ciphertext. Effect of the Invention

[0007] According to one aspect of the present invention, the four arithmetic operations of an integer-wise TFHE can be more completely realized. [Brief description of the drawings]

[0008] [Figure 1] FIG. 2 is a diagram illustrating a functional configuration of a cryptographic processing device according to a first embodiment of the present invention. [Diagram 2] 2 is a diagram for explaining in detail a calculation process based on the functional configuration of FIG. 1. [Diagram 3] FIG. 1 is an image diagram for explaining a circular group that the TLWE cipher has as plaintext. [Figure 4] This is an image diagram of binary gate bootstrapping operation. [Diagram 5] FIG. 1 is a diagram illustrating an integer-wise application of TFHE. [Figure 6] FIG. 2 is a diagram illustrating an integer-wise TFHE according to the present embodiment. [Figure 7] FIG. 2 is a diagram illustrating an integer-wise TFHE according to the present embodiment. [Figure 8] FIG. 2 is a diagram illustrating an integer-wise TFHE according to the present embodiment. [Figure 9] FIG. 2 is a diagram illustrating an integer-wise TFHE according to the present embodiment. [Figure 10] 11 is a flowchart illustrating a multiplication process according to the present embodiment. [Figure 11] 11 is a flowchart illustrating a multiplication process according to the present embodiment. [Figure 12] FIG. 11 is a diagram illustrating a functional configuration of a cryptographic processing device according to a second embodiment of the present invention. [Figure 13] FIG. 13 is a diagram for explaining a calculation process based on the functional configuration of FIG. 12. [Figure 14] 10 is a diagram showing ciphertexts input and output to Gate Bootstrapping of the present embodiment. FIG. [Figure 15] FIG. 1 is a block diagram illustrating an embodiment of a computing device. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. In the following description, alphanumeric characters enclosed in [] indicate that it is a vector, and alphanumeric characters enclosed in {} indicate that it is a set. In addition, in this specification, the term "logical operation" refers to a binary or multi-valued operation.

[0010] [First Example] FIG. 1 is a diagram illustrating the functional configuration of a cryptographic processing device according to a first embodiment of the present invention. The cryptographic processing device 1 includes a control unit 10, a storage unit 20, a communication unit 25, and an input unit . The control unit 10 includes a reception unit 11, a first calculation unit 12, a second calculation unit 13, a third calculation unit 14, a fourth calculation unit 15, a first bootstrap unit (calculation unit) 16, a second bootstrap unit (calculation unit) 17, a third bootstrap unit (calculation unit) 18, a fourth bootstrap unit (calculation unit) 19, a key exchange unit 30, and an output unit 35. The control unit 10 also includes a fifth bootstrap unit (calculation unit) 21 and a sixth bootstrap unit (calculation unit) 22 that function as pre-processing units. The cryptographic processing device 1 performs signed multiplication of integer-wise TLWE ciphertexts using the entire circle group that constitutes the ciphertext. Signed multiplication is multiplication using negative integers having a minus sign. Furthermore, the cryptographic processing device 1 can also multiply ciphertexts of positive integers by using a half plane (right half plane) of the circular group as a simpler multiplication method. This will be described later as [Second embodiment]. In [Second embodiment], the fifth bootstrap unit 21 and the sixth bootstrap unit 22 as pre-processing units and the fourth calculation unit 15 are not required.

[0011] The reception unit 11 receives an input of a ciphertext to be subjected to an operation via the communication unit 25 or the input unit 26. Alternatively, the reception unit 11 receives an input of a ciphertext from another process executed by the cryptographic processing device 1. The first arithmetic unit 12 performs a first homomorphic operation on the ciphertext output from a fourth arithmetic unit 15, which will be described later. The second arithmetic unit 13 performs a second homomorphic operation on the ciphertext output during the processing by the third bootstrap unit 18. The third arithmetic unit 14 performs a third homomorphic operation on the ciphertext output during the processing by the fourth bootstrap unit 19 . The fourth arithmetic unit 15 performs a fourth homomorphic operation on the ciphertext output from the second bootstrap unit 17 .

[0012] The first bootstrap unit 16 performs first gate bootstrap on the ciphertext that has been pre-processed by the fifth bootstrap unit 21 . The second bootstrap unit 17 performs second gate bootstrap on the ciphertext after the key exchange output from the key exchange unit 30 and the ciphertext after the pre-processing by the sixth bootstrap unit 21 . The third bootstrap unit 18 performs third gate bootstrap on the ciphertext output from the first arithmetic unit 12 . The fourth bootstrap unit 19 performs fourth gate bootstrap on the ciphertext output from the third bootstrap unit 18 . The fifth bootstrap unit 21 performs fifth gate bootstrap as pre-processing on the input ciphertext. The sixth bootstrap unit 22 performs sixth gate bootstrap as pre-processing on the input ciphertext. The key exchange unit 30 performs Private Key Switching, which will be described later, to exchange the private key of the ciphertext output from the first Bootstrapping 15. Essentially, Private Key Switching is performed to obtain a TRLWE ciphertext having a step-like polynomial as plaintext from the TLWE ciphertext of the multiplier, and the purpose of Private Key Switching is not to exchange the private key of the ciphertext. As long as a TRLWE ciphertext having a step-like polynomial as plaintext (plaintext polynomial) can be obtained, another method may be used.

[0013] The first calculation unit 12, the second calculation unit 13, the third calculation unit 14, and the fourth calculation unit 15 are calculation processing units that realize homomorphic calculations described below by software. The first bootstrap unit 16, the second bootstrap unit 17, the third bootstrap unit 18, and the fourth bootstrap unit 19 are arithmetic processing units that realize the gate bootstrapping process described below by software. The key exchange unit 30 is a calculation processing unit that realizes private key switching by software. At least one of the first calculation unit 12, the second calculation unit 13, the third calculation unit 14, the fourth calculation unit 15, the first bootstrap unit 16, the second bootstrap unit 17, the third bootstrap unit 18, the fourth bootstrap unit 19, the key exchange unit 30, and the output unit 35 may be realized in hardware.

[0014] The output unit 35 outputs the final calculation result to the outside of the cryptographic processing device 1 or to another processing process executed by the cryptographic processing device 1. The storage unit 20 can store input ciphertext, temporary files and temporary data used in operations on the ciphertext, and output ciphertext. Furthermore, the storage unit 20 can store an encrypted database 60 . The communication unit 25 connects the cryptographic processing device 1 to a network, enabling communication with external devices. By storing the encrypted database 60 in the storage unit 20 and providing the communication unit 25, the cryptographic processing device 1 can function as a database server. In this case, the cryptographic processing device 1 can accept an encrypted query from a terminal device as an external device, perform a search on the encrypted encrypted database 60, and respond with encrypted search results to the terminal device. The input unit 26 inputs, to the cryptographic processing device 1, ciphertext to be processed and a query for the encrypted database 60.

[0015] FIG. 2 is a diagram for explaining in detail the calculation process based on the functional configuration of FIG. The configuration shown in Figure 2 uses the Gate Bootstrapping proposed in the above paper. The Gate Bootstrapping of TFHE proposed in the above paper is described in detail below. As described above, the cryptographic processing device 1 performs integer-wise TLWE ciphertext multiplication, where TLWE ciphertext ca is the ciphertext of plaintext integer a serving as a multiplicand, and TLWE ciphertext cb is the ciphertext of plaintext integer b serving as a multiplier. In FIG. 2(a), the cryptographic processing device 1 inputs the TLWE ciphertext cb to a fifth bootstrap unit 21 to perform fifth gate bootstrapping as pre-processing prior to the multiplication process, and obtains a new TLWE ciphertext cb1. Furthermore, as a pre-processing, the cryptographic processing device 1 inputs the TLWE ciphertext ca to the sixth bootstrap unit 22 to perform sixth gate bootstrapping, and obtains a new TLWE ciphertext ca1. The cryptographic processing device 1 inputs the new TLWE ciphertext cb1 after the fifth bootstrapping to the first bootstrapping unit 16 and performs the first bootstrapping to obtain a TLWE ciphertext cb'. The first bootstrapping is a ciphertext obtained by multiplying the 2t division of the circle group in the TLWE ciphertext cb1. 2 This is a process for converting the data into a division. Furthermore, the cryptographic processing device 1 inputs the TLWE ciphertext cb' to the key exchange unit 30, and performs private key switching on the TLWE ciphertext cb' using the key switching key KS1 to obtain a TRLWE ciphertext cc having a step-like polynomial (plaintext polynomial) as plaintext. Furthermore, the cryptographic processing device 1 inputs the TRLWE ciphertext cc to the second bootstrap unit 17, and performs second bootstrap (BlindRotate, SampleExtract) using the TRLWE ciphertext cc and the TLWE ciphertext ca1 as input to obtain a TLWE ciphertext cc1. Here, the private key switching is described as being performed by the key exchange unit 30, but the private key switching can be considered as a part of the second bootstrapping. In that case, the second bootstrapping unit 17 performs the private key switching, and the cryptographic processing device 1 does not need to include the key exchange unit 30.

[0016] The cryptographic processing device 1 inputs the TLWE ciphertext cc1 to the fourth arithmetic unit 15, and performs a fourth homomorphic operation to obtain a TLWE ciphertext cc' from cc1-cb'. The obtained TLWE ciphertext cc' is a ciphertext corresponding to the multiplication result ab of plaintext integer a and plaintext integer b. However, the plaintext of the TLWE ciphertext cc' has a denominator of 2t 2Therefore, it cannot be used in the next or subsequent multiplication with the ciphertext whose denominator is 2t. Therefore, the cryptographic processing device 1 continues to perform processing to make the denominator of the plaintext 2t.

[0017] The cryptographic processing device 1 inputs the TLWE ciphertext cc' to the first arithmetic unit 12 and performs an operation of multiplying the TLWE ciphertext cc' by t. The cryptographic processing device 1 inputs the t-multiplied TLWE ciphertext cc' to the third bootstrapping unit 18 and performs third bootstrapping to obtain a TLWE ciphertext cl. In detail, the third bootstrapping unit 18 performs BlindRotate and SampleExtract on the t-multiplied TLWE ciphertext cc' to obtain a TLWE ciphertext cd. The cryptographic processing device 1 inputs the TLWE ciphertext cd to the second arithmetic unit 13 and performs an operation cc'×t+cd-(0,1 / 4) of adding the TLWE ciphertext cd to the t-multiplied TLWE ciphertext cc'. The cryptographic processing device 1 (third bootstrapping unit 18) performs Public Key Switching on the result and obtains a TLWE ciphertext cl corresponding to the lower bits of the multiplication result.

[0018] In order to obtain the higher bits of the multiplication result as necessary, in FIG. 2(b), the cryptographic processing device 1 inputs the ciphertext cl corresponding to the lower bits of the multiplication result to the fourth bootstrapping unit 19 and performs the fourth bootstrap to obtain the TLWE ciphertext cl'. In detail, the fourth bootstrapping unit 19 performs BlindRotate and SampleExtract on the TLWE ciphertext cl to obtain the TLWE ciphertext cl'. The cryptographic processing device 1 inputs the TLWE ciphertext cl' and the TLWE ciphertext cc' to the third arithmetic unit 14 and performs an arithmetic operation cc'-cl' to subtract cl' from cc' to calculate the TLWE ciphertext cu. The cryptographic processing device 1 (fourth bootstrapping unit 19) performs Public Key Switching on the TLWE ciphertext cu which is the arithmetic result of the third arithmetic unit 14, and obtains the TLWE ciphertext cu' corresponding to the higher bits of the multiplication result. The lower and upper bits of the multiplication result refer to a certain number of lower bits and the remaining bits when the multiplication result is expressed in binary. This is the expression when t is a power of 2, and even if the value is different, the expression only changes and the essential meaning remains the same.

[0019] As will be described later, the polynomials used in the fifth and sixth bootstraps in pre-processing are adjusted by adding an offset of 1 / 2 (1 / 2 of a slice into which the circular group is divided) to each term of the polynomial so that new TLWE ciphertexts ca and cb with consecutive positive and negative values ​​on the circular group {T} are obtained. An offset of 1 / 2 (0.5) of a slice is also added to each term of the stepped plaintext polynomial of the key switching key KS1. As a result, in the ciphertext corresponding to the multiplication result, positive and negative values ​​are consecutively arranged on the circular group {T}, making it possible to store more information than in the case where no offset is added. As explained below, the ciphertext of the multiplication result is 2 In order to express the offset of 1 / 2 (0.5), which is a non-integer, in the first bootstrap, the TLWE ciphertext cb' used in the calculation is divided into 2t parts from the TLWE ciphertext cb. 2 twice as much as 4t 2 The process of dividing is performed.

[0020] This section provides details on Gate Bootstrapping as explained in TFHE. Gate Bootstrapping is a technique for making fully homomorphic encryption practical, which was previously considered impractical due to the huge amount of data and computation time required. The TFHE in the above paper uses a cryptosystem called TLWE cryptosystem, which is an LWE (Learning with Errors) cryptosystem constructed on a circular group, to realize various homomorphic logical operations (and ultimately any operation such as addition and multiplication) between TLWE ciphertexts at high speed and with small data size while reducing errors during calculation.

[0021] The input for Gate Bootstrapping in TFHE is a TLWE ciphertext encrypted with a private key. In TFHE, fully homomorphic encryption (FHE) is realized based on TLWE ciphertext. TLWE cryptography is a special case of LWE cryptography, which is a type of lattice cryptography (LWE cryptography defined on a circular group). It is known that TLWE encryption is additively homomorphic, and additive operations between TLWE-encrypted plaintexts can be performed without decrypting the ciphertext.

[0022] FIG. 3 is an image diagram for explaining a circular group that the TLWE cipher has as a plaintext. The TLWE cipher advances from 0 with real number precision and returns to 0 when it reaches 1. Any point on the circle group {T} shown in Figure 3 is used as the plaintext, and the vicinity of 0 (including error) and the vicinity of μ (including error) are used as plaintext. Points on the circle group {T} are also referred to herein as "elements." A cryptographic processing device that handles TFHE performs common homomorphic operations such as additive operations between such TLWE ciphertexts, and by using Gate Bootstrapping to keep the error in the operation results within an appropriate range, it realizes fully homomorphic encryption (FHE) that allows logical operations to be performed again (at a later stage).

[0023] [TLWE cipher] Explain the TLWE cipher. As an element on the circle group {T}, prepare a vector [a] consisting of N uniformly distributed random numbers. Also prepare a secret key vector [s] consisting of N random numbers chosen from the binary values ​​0 and 1. If the mean is the plaintext μ and e is a random number with a Gaussian (normal) distribution and a predetermined variance α, then the set ([a],[s]·[a]+e) is an example of a TLWE ciphertext. The average value of e when an infinite number of TLWE ciphertexts are generated for the same plaintext μ is the plaintext μ, where μ is a plaintext without errors and e is a plaintext with errors. Note that "·" represents the inner product of vectors. The same applies hereafter. If we define the above [s]·[a]+e as b, the TLWE ciphertext can be expressed as ([a], b). φ s (([a],b))=b-[s]·[a]=e is the function that decrypts TLWE ciphertext. Since TLWE ciphertext encrypts plaintext by adding the inner product of the secret key vector and random number vector and an error, it is possible to decrypt the TLWE ciphertext with an error by calculating the inner product of the secret key vector and random number vector. At this time, if the secret key vector is unknown, the components that make up the inner product cannot be calculated, and therefore decryption is not possible.

[0024] This TLWE encryption is additively homomorphic, meaning that addition operations between TLWE ciphertexts can be performed without decrypting the ciphertexts. Add the two TLWE ciphertexts ([a],b) and ([a'],b') as is to obtain ([a]+[a'],b+b'), and then use the above decryption function φ s If you enter φ s (([a]+[a'],b+b'))=(b+b')-[s]·([a]+[a'])=(b-[s]·[a])+(b'-[s]·[a'])=φ s ([a],b)+φ s ([a'],b') This gives us the sum of the two plaintexts. This proves that the TLWE ciphertext is an "additively homomorphic encryption". In the TFHE described in the above paper, various calculations are achieved by repeatedly performing additive operations on the TLWE ciphertext with errors added to the plaintext, and reducing the errors by gate bootstrapping.

[0025] In what follows, a "trivial ciphertext" such as ([0],μ) is a TLWE ciphertext that can be decrypted with any private key, i.e., a ciphertext that can be decrypted with any private key to decrypt the same plaintext. In ([0],μ), [0] represents the zero vector. "Trivial ciphertext" can be treated as TLWE ciphertext, but it essentially contains the plaintext as is. The TLWE ciphertext ([0],μ) is decrypted by the decryption function φ s When multiplied by φ s Since (([0],μ))=μ-[s]·0=μ, and the secret key [s] is multiplied by the zero vector [0] and disappears, the plaintext μ can be easily obtained. Such a ciphertext is nothing but a trivial ciphertext for the plaintext μ.

[0026] We explain the finite cyclic groups used in Gate Bootstrapping of TFHE. Gate Bootstrapping utilizes the properties of the quotient ring of a polynomial ring as a finite cyclic group. Explain that there are finite cyclic groups in the quotient ring of a polynomial ring. A polynomial of degree n is generally n x n +a n-1 x n-1 It is expressed as +...+a0. All these sets form a commutative group for the sum of polynomials f(x) + g(x). Also, the product of polynomials, f(x)g(x), has properties similar to a commutative group, except that an inverse does not necessarily exist. Such a group is called a monoid. The distributive law holds for sums and products of polynomials as follows: f(x){g(x)+g'(x)}=f(x)g(x)+f(x)g'(x) Therefore, if we define the sum and product of polynomials as elements, they form a "ring", which is called a polynomial ring.

[0027] In TFHE, we use a polynomial ring whose coefficients are the circle group {T}, and denote such a polynomial ring as T[X]. Let T(X) be a polynomial ring, and let T[X](X n If we decompose it into the form X+T[X], and then take out and collect only the second term (the remainder), this also has the properties of a "ring," so we obtain the remainder ring of the polynomial ring. In TFHE, the quotient ring of a polynomial ring is defined as T[X] / (X n +1).

[0028] The polynomial ring T[X] / (X n +1), using any coefficient μ(μ∈T), Polynomial F(X)=μX n-1 +μX n-2 +···+μX+μ Take out. When we multiply an element F(X) in the quotient ring of a polynomial ring by X, we get μX n-1 +μX n-2 +···+μX-μ, and the coefficient of the top term changes from positive to negative and appears as a constant term. This is because the terms with degrees n-2 or less remain constant even after multiplying by X. n +1 cannot be divided, but the highest degree term is μX n =μ(X n +1)-μ. n Since we are considering the remainder when dividing by +1, only the remainder -μ on the right-hand side remains. Multiplying it by X again gives us μX n-1 +μX n-2 +···+μX 2 The same thing happens again: -μX-μ (the coefficient of the top term flips from positive to negative and appears as a constant term). Repeat this process n times to get -μX n-1 -μX n-2 ...-μX-μ and the coefficients of all terms are negative.

[0029] If we continue multiplying by X, -μX n-1 -μX n-2 -μX+μ -μX n-1 -μX n-2 +μX+μ The coefficient of the top term flips from negative to positive and appears as a constant term. If you repeat this 2n times, you get the element F(X)=μX n-1 +μX n-2 Returning to +···+μX+μ, in this way, the top-order coefficient (μ) appears in the bottom-order constant term with its sign inverted (-μ), resulting in an overall shift of one term. That is, polynomial F(X)=μX n-1 +μX n-2 +···+μX+μ is the quotient ring T[X] / (X n +1), it is a finite cyclic group of order 2n. In TFHE, the cryptographic processing device realizes fully homomorphic encryption by utilizing the properties of a polynomial F(X) based on a remainder ring of such a polynomial ring. Regardless of whether the exponent of X is positive or negative, multiplying an element F(X) of the quotient ring of a polynomial ring n times by X reverses the signs of all the terms, and multiplying it 2n times restores the signs of all the terms. Also, X -1 Since multiplying by is the inverse operation of multiplying X, -1 If you continue to multiply it, the opposite change will occur compared to multiplying it by X, -1 Multiplying it n times inverts all the terms, and multiplying it 2n times returns it to its original state. From the above, we can see that the element F(X) of the quotient ring of the polynomial ring has the same structure as X or X -1 Multiplying it n times will invert the signs of all the terms, and multiplying it 2n times will restore the signs of all the terms. In this cyclic group, because it can be rotated in either direction, it is sometimes expressed as -n times or -2n times for convenience. Note that this is merely a convenient expression for explaining the theory, and when implementing the present invention, for example, X a When multiplying by -b times, X -a Even if you apply it b times, X 2n-a It is also possible to apply the above formula b times, and if the same result can be achieved, other transformations can also be performed.

[0030] [TRLWE cipher] In addition to the TLWE cipher, Gate Bootstrapping uses a cipher called the TRLWE cipher. This section explains the TRLWE encryption. The R in TRLWE stands for ring, and TRLWE is an LWE encryption scheme built on rings. Like TLWE, TRLWE is also an additively homomorphic encryption scheme. The ring in TRLWE cryptography is the remainder ring T[X] / (X n +1). To obtain the TRLWE encryption, we use the polynomial ring T[X] / (X n +1) at random. In practice, the n coefficients of the n-1 degree polynomial are selected from the circle group {T} as uniformly distributed random numbers. If the degree of the polynomial is n-1, then X n Let polynomial a(X) be a polynomial of degree n-1, since it cannot be divided by +1 and there is no need to consider the remainder.

[0031] Randomly select n values ​​from the two values ​​0 and 1 and construct the polynomial s(X) that will be the secret key below. s(X)=s n-1 X n-1 +s n-2 X n-2 +···s1X+s0 n random numbers e i The average value is the plaintext μ i Let the random numbers be Gaussian (normal) distributed with variance α, and then construct the following polynomial e(X) from these. e(X)=e n-1 X n-1 +e n-2 X n-2 +···e1X+e0 s(X) a(X) + e(X) is expressed as f(X)(X n +1)+b(X) to obtain b(X). As a result, the TRLWE ciphertext obtained is (a(X), b(X)). Like the TLWE encryption, the TRLWE encryption uses random numbers for encryption, so an infinite number of ciphertexts can be generated for the same secret key and plaintext. In addition, the TRLWE encryption code has the same structure as the TLWE encryption code. s ((a(X),b(X))=b(X)-s(X)·a(X)+g(X)(X n +1), φ s T[X] / (X nThe decryption function is defined as g(X) being the element of b(X) + 1. In other words, (b(X)-s(X) a(X))mod(X n +1) serves as the decoding function. mod means the remainder of the division.

[0032] [Gadget Decomposition] Explain Gadget Decomposition. The coefficients of the polynomial used in the TRLWE ciphertext are real numbers between 0 and 1, which are elements of the circle group {T} in FIG. 3, and have only a decimal part. The operation of decomposing this into several bits in binary notation is defined as Gadget Decomposition (Dec) in TFHE of the above paper. For example, if the degree n of the polynomial F(X) of the TRLWE ciphertext is n=2, then one unit of division is Bg=2. 2 Then, decompose it into l=3 elements, where each element is between -Bg / 2 and Bg / 2. The TRLWE ciphertext is a combination of two polynomials, such as (a(X), b(X)) above. Therefore, the TRLWE ciphertext d can be regarded as a two-dimensional vector whose elements are polynomials that are the elements of the remainder ring of the polynomial ring. For example, d=[0.75X 2 +0.125X+0.5,0.25X 2 +0.5X+0.375] Therefore, in the following, each element is written as Bg -1 =Decompose into the form of a sum of powers of 0.25.

[0033] On the circle group {T}, 0.75=-0.25, so d=[0.75X 2 +0.125X+0.5,0.25X 2 +0.5X+0.375] =[-0.25X 2 +0.125X+0.5,0.25X 2 +0.5X+0.25+0.125] = [0.25 × (-X 2+2)+0.25 2 ×2X+0.25 3 ×0,0.25×(X 2 +2X+1)+0.25 2 ×2+0.25 3 ×0] It can be broken down as follows. Therefore, when Gadget Decomposition is performed, Dec(d) = [-X 2 +2,2X,0,X 2 +2X+1,2,0] This becomes the vector.

[0034] We also define an operator H that converts a vector back to a ciphertext. Based on the above example, The matrix TIFF0007672722000001.tif3034 is the inverse transform operator H. The TRLWE ciphertext d is obtained by calculating Dec(d) H. The lower bits are rounded off.

[0035] For a TRLWE ciphertext d, the operation of obtaining [v] such that ||d-[v]·H|| is the minimum value can also be said to be a gadget decomposition, where || is the norm (length) of the vector. Generate 2l TRLWE ciphertexts Zi=(a(X),b(X)), calculated using a polynomial generated from random numbers whose coefficients of e(X) have a mean of 0 and a variance of α. Then, the plaintext μ is encrypted as follows to obtain the following ciphertext k. TIFF0007672722000002.tif2643The ciphertext that can be expressed as this ciphertext k will be called the TRGSW ciphertext. The TRGSW ciphertext constitutes the Bootstrapping Key used below.

[0036] Explain Bootstrapping Key. The Bootstrapping Key is used as a method to encrypt a private key for use in Gate Bootstrapping. In addition to the secret key [s] (Nth degree) used for the TLWE ciphertext, each element of the secret key [s'] for encrypting the secret key [s] for use in Gate Bootstrapping is selected as a binary value of 0 or 1. The degree of the private key [s'] must be the same as the degree n of the polynomial used in the TRLWE encryption. Create a TRGSW ciphertext for each element of the private key [s]. When decrypted with the private key [s'], φ s’ Create 2l (el) TRLWE ciphertexts Zj such that (Zj)=0. And, according to the structure of the TRGSW ciphertext above, Let's say TIFF0007672722000003.tif2539. The set of TRGSW ciphertexts constructed using different Zj for each element of the secret key [s] is called the Bootstrapping Key (BK). In other words, BK is a set of N TRGSW ciphertexts.

[0037] The cross product of the TRGSW ciphertext BKi and the TRLWE ciphertext d is BKi×d=Dec(d)·BKi It is defined as: Gadget Decomposition is an operation to obtain [v] such that ||d-[v]·H|| is the minimum value for the TRLWE ciphertext d. Therefore, [v] = Dec(d) and the error (ε a (X),ε b Using (X), [v] H=d+(ε a (X),ε b (X)). As a result, BKi×d=Dec(d)·BKi The result is TIFF0007672722000004.tif2243. The left half calculates the dot product, and the right half calculates [v] H=d+(ε a (X),ε bSubstituting (X), we get The result is TIFF0007672722000005.tif1490, which is the same as calculating the sum of the three ciphertexts c1, c2, and c3 below. TIFF0007672722000006.tif1945TRLWE encryption is an additively homomorphic encryption method, so adding two ciphertexts together is the same as adding two plaintexts together. C1 is Z j Since it is the sum of several times of s’ The expected values ​​of each coefficient in (c1) are all zero. Also, the decoded φ s’ In (c3), since the magnitude of the absolute value of each coefficient of the plaintext polynomial can be adjusted by the system parameters, the magnitude is set to be sufficiently small, including the subsequent calculations.

[0038] Then, φ s’ (BKi×d)=φ s’ (s i × d), but s i Whether s is 0 or 1, the calculation result is the sum of the three ciphertexts c1, c2, and c3. i It is not possible to determine whether it is 0 or 1. Assuming that there are two TRLWE ciphertexts d0 and d1 corresponding to the two plaintext polynomials μ0 and μ1, and substituting d = d1 - d0 and finally adding d0, the CMux function shown below is completed. CMux(BK i ,d0,d1)=BKi×(d1-d0)+d0=Dec(d1-d0)·BK i +d0 The CMux function is i If μ0 is 0, the TRLWE ciphertext of the plaintext polynomial μ0 is output without being decrypted, and s i If is 1, the TRLWE ciphertext of the plaintext polynomial μ1 is output without decryption. The CMux function can compute the TRLWE ciphertext for which the plaintext polynomial is either μ0 or μ1, but the choice cannot be known from the result without decrypting it.

[0039] TFHE's binary gate bootstraping is performed using the various pieces of information described above. Binary Gate Bootstrapping consists of three steps: (1) BlindRotate, (2) SampleExtract, and (3) Public Key Switching, as described below.

[0040] FIG. 4 is a conceptual diagram of the operation of binary gate bootstrapping. Binary Gate Bootstrapping reduces the error of the homomorphic operation result between TLWE ciphertexts with respect to the plaintext through the three steps described below. In the following explanation, unless otherwise specified, the plaintext refers to the result of an operation between plaintexts that is the result of an operation between TLWE ciphertexts. In the circle group {T} in Figure 3, plaintexts in the ranges 0 to 0.25(1 / 4) and 0.75(3 / 4) to 1 are converted into a TLWE ciphertext of 0, and plaintexts in the range 0.25(1 / 4) to 0.75(3 / 4) are converted into a ciphertext of 0.25(1 / 4). During this conversion, the error added to the plaintext is within the range of ±1 / 16.

[0041] (1) BlindRotate BlindRotate is performed as the first step in Gate Bootstrapping. BlindRotate is the process that creates the TRLWE ciphertext. In BlindRotate, we convert the trivial TRLWE ciphertext (0,T(X)) with polynomial T(X) as plaintext into X -φs(c’) The TRLWE ciphertext multiplied by is obtained without decryption. 0 indicates the 0th degree polynomial 0. Here, φs(c') is the plaintext obtained by applying the LWE ciphertext c' below to the decryption function. In BlindRotate, the following polynomial F(X) is used as a test vector, which is a finite cyclic group as described above. F(X)=μX n-1+μX n-2 +…μX+μ where μ=1 / 8 X n / 2 The following polynomial T(X) obtained by multiplying T(X)=F(X) X n / 2 Prepare the following.

[0042] Suppose there is a TLWE ciphertext c obtained by encrypting plaintext μ1 with a secret key [s]. Each element of this TLWE ciphertext c = ([a], b) is multiplied by 2n and rounded off to obtain the LWE ciphertext c' = ([a'], b'). When the LWE ciphertext c'=([a'],b') is decrypted, μ1'=φ s (c') ≒ 2n × φ s (c) = 2nμ1. Because of rounding errors, the numbers may not match perfectly, but the larger n is, the smaller the error becomes. Prepare a trivial TRLWE ciphertext (0,T(X)) with polynomial T(X) as plaintext, A0=X -b’ ×(0,T(X))=(0,X -b’ ×T(X)). 0 indicates the 0th degree polynomial 0. In this case, since b' is an integer, the power can be naturally defined. In practice, it is sufficient to rotate the coefficients of each term of the polynomial of the TRLWE ciphertext a predetermined number of times. Hereafter, the above-mentioned Bootstrapping Key, BK i Using, in order, A i =CMux(BK i ,A i-1 ,X a’i A i-1 Here too, since a'i is an integer, the power of X can be naturally defined. Similarly, instead of calculating the power of X, we calculate the TRLWE ciphertext A i-1 It is sufficient to rotate the coefficients of each term of the polynomial, which is an element of the polynomial, a predetermined number of times.

[0043] Then, s i When is 0, the plaintext remains unchanged, and s i When is 1, X a’iare multiplied in order. Therefore, If you repeat this with TIFF0007672722000007.tif2849, The result is TIFF0007672722000008.tif749. Where: Since TIFF0007672722000009.tif629 is equal to the decoding function φs(c') with its sign inverted, The result is TIFF0007672722000010.tif741. Here, φ s’ (A n ) is the polynomial T(X) plus X -1 is a polynomial multiplied by μ1' times, and A n is the ciphertext. At this point, we should clarify that the error component of the error-added plaintext e of the initially set TLWE ciphertext c is expressed as the amount of rotation of the polynomial T(X), and is not expressed as the magnitude of the coefficient values ​​of each term. TFHE essentially reduces the error by this mechanism. In addition, for the plaintext μ1 of the TLWE ciphertext c related to BlindRotate, we add X to the polynomial T(X). -1 Since a unique value (up to 2n values ​​by inverting n coefficients and their signs) corresponding to the number of times μ1' (= 2nμ1) is multiplied is obtained as the coefficient of the constant term of the plaintext polynomial, this can be considered as a kind of look-up table.

[0044] (2)SampleExtract TRLWE ciphertext A obtained by BlindRotate in (1) n The plaintext polynomial φ obtained by decrypting s’ (A n ), counting from the lower terms, we get n / 2-φ s The coefficient of the (c')th term is -μ, and if it becomes negative, the coefficient of the term from the top down will be -μ. TRLWE Ciphertext A n The plaintext polynomial φ obtained by decrypting s’ (A n ), if we look only at the constant term of φ s(c') is greater than or equal to n / 2 and less than 3n / 2, i.e., φ s If (c) is 1 / 2±1 / 4, the constant term is μ. Otherwise, if φs(c) is ±1 / 4, the constant term is -μ. SampleExtract is the TRLWE ciphertext A obtained by BlindRotate in (1). n From this, we can obtain the plaintext polynomial φ without decrypting it. s’ (A n ) to obtain the TLWE ciphertext cs. As mentioned above, the error added to the initial input TLWE ciphertext c and the error added by rounding only affect the position of the boundary where the plaintext μ and -μ of the constant term switch, and the effect on the magnitude of the coefficient of the constant term is negligibly small. In other words, it can be interpreted as eliminating input errors. Also, the range within which the boundary where the plaintext value of the constant term changes can be moved without any problems is the error limit for which bootstrap processing can be performed correctly, and this is the mechanism that creates the trade-off described below.

[0045] The process for obtaining the TLWE ciphertext cs will now be described. All TRLWE ciphertexts have degree n, Taking TIFF0007672722000011.tif1134 and a polynomial, it can be expressed as (A(X),B(X)). When this is decrypted with the private key [s'], the polynomial of the private key is Put it as TIFF0007672722000012.tif636, It can be expanded as TIFF0007672722000013.tif7116.

[0046] For this, the following calculation is carried out: I get TIFF0007672722000014.tif82136. Since it is a "modulus ring of a polynomial ring", (X n +1), we get the remainder The result is TIFF0007672722000015.tif18156.

[0047] moreover, If you put TIFF0007672722000016.tif1046, The file name becomes TIFF0007672722000017.tif38143. The coefficients of each term of the plaintext polynomial can be found from TIFF0007672722000018.tif776. Of these, what we need is the coefficient of the constant term, so if we extract the coefficient for j=0, we get The result is TIFF0007672722000019.tif638. If you put TIFF0007672722000020.tif620, It can be transformed into a TLWE cipher decryption function, such as TIFF0007672722000021.tif8114.

[0048] In other words, the TRLWE ciphertext A obtained by BlindRotate in (1) n =(A(X),B(X)), the coefficients are When extracted as TIFF0007672722000022.tif1055, the original TRLWE ciphertext A n A new TLWE ciphertext ([a”], b1) is obtained, whose plaintext is the same as the constant term of the plaintext polynomial corresponding to a. This new TLWE ciphertext is the output of SampleExtract, and has two plaintexts: -μ or μ. The obtained TLWE ciphertext is added to the trivial ciphertext ([0],μ) whose plaintext is μ to obtain the TLWE ciphertext cs=([a”],b1)+([0],μ). Specifically, since μ=1 / 8 in the polynomial F(X) serving as the test vector, ciphertexts of −1 / 8 and 1 / 8 are obtained at this stage. Adding to this the trivial TLWE ciphertext ([0],1 / 8) with plaintext μ=1 / 8 gives us -1 / 8+1 / 8=0 1 / 8+1 / 8=1 / 4 From this, a new TLWE ciphertext cs is obtained, which has one of the two plaintext values ​​0 or 1 / 4.

[0049] (3) Public Key Switching The TLWE ciphertext cs obtained by SampleExtract in (2) is encrypted with the private key [s'], not the private key [s]. Therefore, it is necessary to replace the key of the TLWE ciphertext cs with the secret key [s] without decrypting the TLWE ciphertext cs, and return it to a state encrypted with the secret key [s]. Therefore, we will explain the Public Key Switching technique. The secret key [s] of the TLWE ciphertext used in TFHE is an N-dimensional vector. This is used to encrypt the secret key [s'] of the n-th vector used when creating the Bootstrapping Key. That is, TIFF0007672722000023.tif746 and the elements of the circle group {T}, real numbers between 0 and 1, are encrypted as shifted values ​​for each digit when expressed in binary. The private key is [s]. The "number of digits" t is a system parameter. When decrypted with the private key [s], The result is TIFF0007672722000024.tif737. This is the "key switching key". As mentioned above, the TLWE ciphertext cs = ([a], b) obtained in (2) is a value of 0 or 1 / 4 encrypted with the private key [s']. The number of elements of [a] is n, the same as the private key [s']. If we convert each of these into a t-bit fixed-point number, we get It can be written in the format TIFF0007672722000025.tif735. At this stage the error increases, but the maximum absolute value can be constrained by system parameters. As part of the Public Key Switching process, the following TLWE ciphertext cx is calculated. The term TIFF0007672722000026.tif862([0],b) is a trivial ciphertext, so when decrypted it gives b. When the result of decrypting the TLWE ciphertext cx is calculated, The file is TIFF0007672722000027.tif8118. s' i Since is a constant for j, we can factor it out as Enter TIFF0007672722000028.tif749 and substitute the formula that was decomposed into fixed decimal points above. TIFF0007672722000029.tif977As a result, The file will be TIFF0007672722000030.tif530, which means the key change was successful.

[0050] The TLWE ciphertext cx obtained here is encrypted with the same secret key [s] as the TLWE ciphertext c that was input to Gate Bootstrapping. By performing the public key switching process, the TLWE ciphertext is restored to the TLWE ciphertext encrypted with the private key [s], and s If (c) is within ±1 / 4, then the plain text φ s (cx) is 0, φ s If (c) is in the range of 1 / 2±1 / 4, then the plaintext φ s (cx) is now 1 / 4. Through the above process, the result of Gate Bootstrapping was a TLWE ciphertext that was one of two values, 0 or 1 / 4, with an error within ±1 / 16. The maximum error does not depend on the input TLWE ciphertext c, but is fixed by the system parameters. Therefore, the system parameters are set so that the maximum error value is within ±1 / 16 of the input TLWE ciphertext. This makes it possible to perform the NAND operation any number of times. The NAND operation is a complete operation in the field of logical operations. In other words, if the NAND operation can be realized, all logical operations are possible by combining it. Therefore, by expressing any numerical value in binary, all operations including addition and multiplication become possible.

[0051] The errors in the "plaintext" of the TLWE ciphertext output from Gate Bootstrapping are the error added by rounding off the TLWE ciphertext, the error added by CMux, the error when it is converted to fixed decimal by Public Key Switching, etc. All of these errors can be constrained by system parameters, and the system parameters can be adjusted so that the error taking all of these into consideration is ±1 / 16. This completes the TFHE Gate Bootstrapping process.

[0052] As described above, TFHE is a bit-wise homomorphic encryption method that has 0 or non-0 as plaintext and performs logical operations. However, as explained in Figure 3, the plaintext is a real number between 0 and 1 that is associated with the circular group {T}. Therefore, by associating integers with the intervals that divide the circular group {T} in order, it can be used as an integer-wise homomorphic encryption method that has integers as plaintext. The above paper shows that the TLWE ciphertext used in TFHE is additively homomorphic to plaintexts in circular groups, and it is obvious that addition (subtraction) operations can be performed on it. Multiplication is further possible using the method described below. By enabling multiplication, TFHE can be used as a homomorphic encryption that can perform integer-wise arithmetic operations more completely, in addition to the already known addition and some multiplication. This allows processing to be performed more efficiently than if calculations were performed one bit at a time using bit-wise TFHE.

[0053] FIG. 5 is a diagram illustrating an integer-wise application of TFHE. As shown in Figure 5, the range of values ​​from 0 to 1 associated with the circular group {T} is divided into t parts. In a TLWE ciphertext, the possible values ​​of the plaintext are the t values ​​obtained by dividing the range of values ​​from 0 to 1, -(t / 2) to (t / 2)-1, and (t / 2)-1 is the maximum value of the integer that can be recorded in one TLWE ciphertext. As shown in FIG. 5, when t=10 and the range of 0 to 1 is divided into 10 parts, the ciphertext can express integers of -5, -4, -3, -2, -1, 0, 1, 2, 3, and 4. These integer values ​​are assigned to intervals centered on -5 / t, -4 / t, -3 / t, -2 / t, -1 / t, 0 / t, 1 / t, 2 / t, 3 / t, and 4 / t, which are obtained by dividing the range of 0 to 1 of the circular group {T} into t=10 parts. In this way, as shown in FIG. 5, it is possible to assign consecutive integers counterclockwise from the area centered on 1 / 2, which is the minimum value when expressed as an integer.

[0054] As shown in Figure 5, 0 (1) on the circular group {T} is within the range of -1 / (2t) to 1 / (2t). The position of the plaintext of the ciphertext on the circular group {T} within the range (position on the circular group {T}) can be adjusted as necessary by adding or subtracting an offset based on, for example, 1 / (2t) to the state in Figure 5. Although there is no essential difference, in the embodiment described below, the meaning of the division number t of the circle group is different from that described in FIG.

[0055] 6 to 9 are diagrams for explaining the integer-wise TFHE in this embodiment. As shown in FIG. 6, the encrypted texts of the multiplier and multiplicand in this embodiment are obtained by dividing the entire range (0 to 1) of the circular group {T} into 2t parts. In addition, in FIG. 6 to FIG. 9, the range 0 to 1 of the circle group {T} may be set to −0.5 to 0.5. Increasing the value of t and dividing the circular group {T} into smaller parts allows for larger integer values ​​to be recorded in the TLWE ciphertext, but dividing it too finely results in a problem in that the margin of error added to the plaintext becomes too small, reducing the strength of the cipher. This point will be explained later. An integer value is assigned to each 1 / (2t) interval into which the circular group {T} is divided, and the possible plaintext integer values ​​of a TLWE ciphertext range from -t to t-1. t-1 is the maximum integer value that can be recorded in a single TLWE ciphertext, and -t is the minimum integer value that can be recorded in a single TLWE ciphertext. As in the case of Figure 5, Figure 6(b) shows the state where no offset is added to the plaintext (the offset to the plaintext is 0). Figure 6(a) shows the state where an offset of, for example, +1 / (4t) is added to the plaintext of the ciphertext shown in Figure 6(b). By adding an offset, it is possible to change the slicing of the circle group {T}. In the following description, the right and left halves of the circle group are assumed to conform to the state shown in FIG. 6(a) to which an offset of 1 / (4t) has been added.

[0056] In the state where no offset is added, shown in FIG. 6(b), 0(1) on the circle group {T} is within the slice from -1 / (4t) to 1 / (4t). By adding an offset as shown in Figure 6(a), the integer 0 can be associated with the slice (0 / 2t) starting from 0 on the circular group {T}. Other slices start from X / 2t (X is a plaintext integer). This allows 0 on the circular group to refer to the term of degree 0 of the test vector polynomial used when performing processing using bootstrapping, so adding an offset in this way has the advantage of making the order of coefficients more natural and easier to see. However, this is not a fundamental requirement, so a different offset can be adopted by making appropriate adjustments to the test vector, pre-processing, post-processing, etc. In Fig. 6(a), the plaintext with the offset is located in the center of each slice (e.g., the slice starting from 3 / (2t)) within the error range of ±1 / (4t). In this case, the mean of the normal distribution is, for example, 3 / (2t)+1 / (4t), and in most cases it is distributed within the error range of ±1 / (4t), so that the plaintext is distributed in the center of the slice starting from 3 / (2t). In Fig. 6(a), the plaintext with an offset is shown only for the slice 3 / (2t), but this is merely an example, and all slices have plaintext with an offset added to the starting value. The same is true for Fig. 7.

[0057] The ciphertext in Figure 6 is created by dividing the right half of the circular group {T} into t pieces and the left half into t pieces. The right half of the circular group {T} corresponds to 0 and positive plaintext integers (0 to t-1), and the left half corresponds to negative plaintext integers (-1 to -t). The width of one block (slice) is 1 / (2t). Integer values ​​are assigned to 2t slices of the range 0 to 1 (-1 / 2 to 1 / 2) of the circle group {T}, starting from -t / (2t) to (t-1) / (2t). Non-negative integers are assigned to slices starting at 0 / (2t), 1 / (2t), …, (t-3) / (2t), (t-2) / (2t), (t-1) / (2t) in the right-plane, while negative integers are assigned to slices starting at -t / (2t), -(t-1) / (2t), -(t-2) / (2t) …, -1 / (2t) in the left-plane. These slices are centered on the starting value with an offset of +1 / (4t). The 1 / (4t) offset is equivalent to half the slice width of 1 / (2t). If the 1 / (4t) offset is expressed as an integer, it can be conveniently expressed as an offset of +0.5.

[0058] As shown in Figure 6(a), when the range of the circular group is divided into 16 parts with 2t=16 (t=8), the right half of the circular group {T} can represent integers from 0 to 7 (=t-1), and the left half can represent integers from -8 (=-t) to -1. In other words, the entire ciphertext can represent integers from -8, -7, -6, -5, -4, -3, -2, -1, 0, 1, 2, 3, 4, 5, 6, and 7. These integer values ​​are assigned to the intervals that divide the range of the circle group {T} into 2t = 16 intervals, starting with -8 / (2t), -7 / (2t), -6 / (2t), -5 / (2t), -4 / (2t), -3 / (2t), -2 / (2t), -1 / (2t), 0 / (2t), 1 / (2t), 2 / (2t), 3 / (2t), 4 / (2t), 5 / (2t), 6 / (2t), and 7 / (2t). Integers are assigned counterclockwise from the range starting with 1 / 2. Note that, taking the above offset of 0.5 into account, a slice on the right side starting at, say, 1 / (2t) is a slice centered at 1.5 / (2t), and a slice on the left side starting at, say, -8 / (2t) is a slice centered at -7.5 / (2t). The integers expressed with the offset included are, counterclockwise from the top, -7.5, -6.5, -5.5, -4.5, -3.5, -2.5, -1.5, -0.5, 0.5, 1.5, 2.5, 3.5, 4.5, 5.5, 6.5, and 7.5.

[0059] The cryptographic processing device 1 realizes multiplication of Integer-wise TLWE ciphertexts by the following method. The cryptographic processing device 1 executes BlindRotate using a step-like polynomial and simultaneously performs Integer-wise multiplication of ciphertexts. In this embodiment, in order to obtain a step-like polynomial from the encrypted text of the multiplier, the Private Key Switching described in the above paper (Non-Patent Document 1) is used as an example. First, the Private Key Switching will be described. The key switching key used for private key switching is referred to as key switching key KS1 to distinguish it from the key switching key KS used for public key switching. The result of executing Private Key Switching using key switching key KS1 can be defined as f(c) = TRLWE_Enc(f'(TLWE_Dec(c)). In other words, the function f that can calculate the ciphertext obtained by applying the function f' to the plaintext obtained by the cryptographic processing device 1 decrypting the TLWE ciphertext c and performing the TRLWE encryption process without decryption is the private key switching performed using the key switching key KS1. The TRLWE ciphertext can be obtained from the TLWE ciphertext by using the key switching key KS1. A person who creates the key switching key KS1 knows the private keys [s] and [s'] and can generate the following key switching key KS1. TIFF0007672722000031.tif1963A person performing private key switching, for example the cryptographic processing device 1, can perform the following calculation from the TLWE ciphertext c([a], b) using the key switching key KS1, even without knowing the private keys [s] and [s']. Furthermore, since the key-switching key KS1 is essentially a collection of TRLWE ciphertexts, the private keys [s] and [s'] cannot be derived from the key-switching key KS1.

[0060] The cryptographic processing device 1, in a manner similar to the case of the above-mentioned Public Key Switching, converts the elements of the TLWE ciphertext into The file is broken down into TIFF0007672722000032.tif1933. a i,j and b j is a i Or, it is the value of each digit when b is expressed in binary and can take the value 0 or 1. Then, the cryptographic processing device 1 Calculate TIFF0007672722000033.tif973. To see what this would be calculated without the private key, we rearrange the formula to get: The result is TIFF0007672722000034.tif62135. From the above calculation results, the TRLWE ciphertext c' is obtained without decrypting the initial TLWE ciphertext c, where the plaintext is the result of substituting the plaintext of the TLWE ciphertext for f'. The function f' needs to be a function that can be safely switched between the encryption and decryption processes and the evaluation process of the function f'. In terms of obtaining the ciphertext of the evaluation result of an arbitrary function without decrypting the TLWE ciphertext, it is also possible to use bootstrapping or public key switching in a similar way. In this embodiment, a function that obtains the following stepped polynomial is set as f'(x), and the key switching key KS1 is calculated in advance. TIFF0007672722000035.tif1163

[0061] Let us return to the explanation of how to multiply the ciphertext. The cryptographic processing device 1 sets the system parameters of TFHE. At this time, the cryptographic processing device 1 sets the range of error added to the plaintext in the ciphertext obtained after Gate Bootstrapping to ±1 / (8t 2 Set the system parameters so that the Suppose we have a TLWE ciphertext ca of a multiplicand (the number to be multiplied) and a TLWE ciphertext cb of a multiplier (the number to be multiplied). The TLWE ciphertexts ca and cb of the multiplier and multiplicand are TLWE ciphertexts with the structure shown in FIG. 6(a), in which the right half plane is divided into t pieces and the entire circular group {T} is divided into 2t pieces. In this embodiment, in each of the TLWE ciphertext ca and the TLWE ciphertext cb, the right half plane of the circle group {T} corresponds to plaintexts that are non-negative integers, and the left half plane corresponds to plaintexts that are negative integers. The TLWE ciphertext ca has as plaintext the real number a / (2t)+1 / (4t) corresponding to the integer a, which cannot be known without the private key. The TLWE ciphertext cb has as plaintext the real number b / (2t)+1 / (4t) corresponding to the integer b, which cannot be known without the secret key. The plaintexts of the TLWE ciphertexts ca and cb are a / (2t) and b / (2t) because the entire circular group is divided into 2t parts. As explained above, the +1 / (4t) offset added to the plaintext aligns the slice of the circular group starting from 0 with the integer 0, and positions the plaintext in the center of the slice. Since multiplication is commutative, the multiplier and multiplicand, i.e., the plaintext integers a and b, and the TLWE ciphertexts ca and TLWEcb, can be interchanged.

[0062] As explained with reference to FIG. 6(a), an offset a / (2t)+1 / (4t) is added to the plaintext in the TLWE ciphertext ca and the TLWE ciphertext cb. When the ciphertexts with an offset added to the plaintext are multiplied together, an offset equivalent to the product of the offsets is added to the plaintext resulting from the multiplication. This offset component disappears in subsequent operations, so it does not affect the calculation result (multiplication result). The offset value 1 / (4t) is an example and is not limited to this, but the polynomial and parameters must be adjusted depending on the offset value.

[0063] In Figure 6(a), on the left half of the circle group {T}, which handles negative numbers, integers -t to -1 are expressed counterclockwise from the top using slices starting from -t / (2t) to -1 / (2t). On the right half of the circle group {T}, which deals with 0 and positive numbers (non-negative numbers), integers 0 to t-1 are represented using slices starting from 0 / (2t) to t-1 / (2t), going counterclockwise from the bottom.

[0064] [Pre-processing] Prior to multiplication of the ciphertexts, the cryptographic processing device 1 performs the following pre-processing, in which the values ​​of the left half-plane of the circular group {T}, which handles negative numbers, are flipped upside down for each of the TLWE ciphertext ca of the multiplicand and the TLWE ciphertext cb of the multiplier. FIG. 7 shows the circle groups corresponding to the pre-processed TLWE ciphertext ca1 and the TLWE ciphertext cb1. In the pre-processing, the cryptographic processing device 1 calculates a step-like one-variable polynomial function (one-variable function) f id Perform the 5th Gate Bootstrapping and the 6th Gate Bootstrapping using TIFF0007672722000036.tif1061. Gate Bootstrapping includes BlindRotate, SampleExtract, and Public Key Switching. To calculate a one-variable function on an encrypted integer value, a method that extends the Gate Bootstrapping method described in the above paper (Non-Patent Document 1) can be used. This method is described in the paper "Bootstrapping in FHEW-like Cryptosystems, Daniele Micciancio and Yuriy Polyakov Duality Technologies February 23, 2020." In the disclosed method, the coefficient of the test vector is not set to a constant μ, but rather the result of the function is set to obtain a different result depending on the value of the TLWE ciphertext.

[0065] A one-variable function f id For input of a ciphertext of a non-negative integer 0 to t-1, it outputs a ciphertext of the same non-negative integer 0 to t-1 and adds an offset of 0.5 to the plaintext. id For an input of a ciphertext of a negative integer -t to -1, it outputs a ciphertext of integers -1 to -t and adds an offset of 0.5 to the plaintext integer. As shown in Figure 6, in the TLWE ciphertext ca and TLWE ciphertext cb, the width of the slice that one integer corresponds to is 1 / (2t), and adding an offset of 0.5 to the plaintext integer is equivalent to adding an offset of 1 / (4t) to the plaintext real number a / (2t), etc. The +1 / (4t) offset part for the plaintext is included in the integer representation and expressed as +0.5.

[0066] In Figure 6(a), if the plaintext is on the right half of the circle group {T}, the one-variable function f id As a result of the above pre-processing using, the plaintext integers of the new TLWE ciphertext ca1 and TLWE ciphertext cb1 remain within the same slice (area) of the circular group {T}, as shown in Figure 7. On the other hand, if the plaintext is on the left half of the circular group {T}, as a result of the above pre-processing, the plaintext integers of the new TLWE ciphertext ca1 and TLWE ciphertext cb1 are upside down in the circular group {T}, as shown in Figure 7. In other words, in the right half of Figure 7, integers from 0 to t-1 are assigned to slices from 0 / (2t) to 7 / (2t) counterclockwise from the bottom, and the order of plaintext integers is the same as in Figure 6(a). On the other hand, on the left half, integers from -1 to -t are assigned to slices from -t / (2t) to -1 / (2t) in a counterclockwise direction from the top, reversing the order from that in Figure 6(a). In Fig. 7 after pre-processing, the integers, from the top of the circle group {T}, are -1, -2, -3, -4, -5, -6, -7, -8, 0, 1, 2, 3, 4, 5, 6, and 7. Positive and negative values ​​are lined up consecutively in the circle group {T}.

[0067] In FIG. 6(a), for example, if the TLWE ciphertext ca is a ciphertext of -1, the plaintext is in the interval -1 / (2t)~0 on the circle group {T}. As a result of the above preprocessing, in the TLWE ciphertext ca1, the one-variable function f id The most significant block of the term is inverted and appears at the bottom. Therefore, in Fig. 7, the plaintext of the TLWE ciphertext ca1 is -1 / 2+1 / (4t) as a value on the circle group {T}. This plaintext corresponds to the integer -t (=-8) in Fig. 6(a), but after preprocessing, -1 is assigned as the plaintext integer in Fig. 7. In Figure 6(a), for example, if the TLWE ciphertext ca is a ciphertext of -t, the plaintext is distributed around -t / (2t)+1 / (4t) on the circular group {T} (a value slightly larger than -1 / 2), so the plaintext is in the section on the circular group {T} closest to -1 / 2. As a result of the above preprocessing, in the TLWE ciphertext ca1, the one-variable function f id The term in the lowest block of appears with a sign inversion. Therefore, in Fig. 7, the plaintext of the TLWE ciphertext ca1 is -1 / (2t)+1 / (4t) as a value on the circle group {T}. This plaintext corresponds to the integer -1 in Fig. 6(a), but after preprocessing, -t (=-8) is assigned as the plaintext integer in Fig. 7.

[0068] In general, the plaintext of a TLWE ciphertext ca, whose plaintext is a non-negative number, becomes a / (2t)+1 / (4t) in the pre-processed TLWE ciphertext ca1, and the plaintext integer remains a. In contrast, the plaintext of the TLWE ciphertext ca, whose plaintext is a negative number, is -(t+1+a) / (2t)+1 / (4t) in the pre-processed TLWE ciphertext ca1. If we look at only the numerator of the plaintext, if the plaintext integer a is -1, then -(t+1+a)=-{t+1+(-1)}=-t, and if the plaintext integer a is -t, then -(t+1+a)=-{t+1+(-t)}=-1. The same is true for the TLWE ciphertext cb. In this way, when the plaintext is a non-negative number, the plaintext to which an integer is assigned changes as a result of pre-processing. However, the integer before pre-processing is assigned to the plaintext after pre-processing. Therefore, as a result of pre-processing, the order of plaintext integers assigned to plaintexts in the left half, where negative numbers are assigned, is reversed, although the order of plaintext integers assigned to plaintexts in the left half does not change between Figure 6(a) and Figure 7.

[0069] In Figure 7, where t=8 (2t=16), the 0.5 offset is added to the plaintext of the ciphertext, so the plaintexts in the center of the slice, going left (counterclockwise) from the top, are -7.5 / (2t), -6.5 / (2t), -5.5 / (2t), -4.5 / (2t), -3.5 / (2t), -2.5 / (2t), -1.5 / (2t), -0.5 / (2t), 0.5 / (2t), 1.5 / (2t), 2.5 / (2t), 3.5 / (2t), 4.5 / (2t), 5.5 / (2t), 6.5 / (2t), and 7.5 / (2t). These slices are assigned the following values, going counterclockwise from the top of the cycle group {T}: -1, -2, -3, -4, -5, -6, -7, -8, 0, 1, 2, 3, 4, 5, 6, 7. The integers representing the offset of 0.5 from the top of the cycle group {T} are -0.5, -1.5, -2.5, -3.5, -4.5, -5.5, -6.5, -7,5, 0.5, 1.5, 2.5, 3.5, 4.5, 5.5, 6.5, 7.5. If the number of divisions remains at 2t, the numerator of the plaintext will not be an integer, so the number of divisions is doubled to 4t, especially for the TLWE ciphertext cb, which is the multiplier. In this case, the plaintexts are -15 / (4t), -13 / (4t), -11 / (4t), -9 / (4t), -7 / (4t), -5 / (4t), -3 / (4t), -1 / (4t), 1 / (4t), 3 / (4t), 5 / (4t), 7 / (4t), 9 / (4t), 11 / (4t), 13 / (4t), and 15 / (4t).

[0070] The cryptographic processing device 1 thereafter uses the new TLWE ciphertext ca1 and TLWE ciphertext cb1 after Gate Bootstrapping (after pre-processing).

[0071] (1) After the above pre-processing, the cryptographic processing device 1 (first bootstrap unit 16) performs the first bootstrap process by computing a test vector polynomial T(X) Using TIFF0007672722000037.tif1064, we perform BlindRotate on the TLWE ciphertext cb1 of the multiplier, and then generate the trivial ciphertext (0,1 / 8t 2 ) to obtain the TLWE ciphertext cb'(LEVEL1). The new TLWE ciphertext cb1 after preprocessing is divided into 2t parts as shown in Figure 7. The first Bootstrapping divides the circle group into 4t parts by BlindRotate. 2 Divide the plaintext denominator to 4t 2 This is done to make it As will be described later, in this embodiment, the result of multiplication between ciphertexts obtained by dividing the entire circular group {T} into 2t pieces is recorded in one TLWE ciphertext cc1 during the multiplication calculation. 2 This is the number of divisions of the TLWE ciphertext cc' resulting from the multiplication (2t 2 ) is twice as large. The number of divisions of the TLWE ciphertext cb' is 4t 2 By using this number, no scale change is required when subtracting the TLWE ciphertext cb' from the TLWE ciphertext cc1 to obtain the TLWE ciphertext cc' that is the multiplication result, as described below. This also has the effect of doubling the coefficient part of the polynomial f'(X) used when assembling the key switching key KS1, to 2i+1, and canceling out the addition of an offset of +0.5, which is converted to an integer +1.

[0072] In Figure 7, the TLWE ciphertext cb1 is expressed using the entire circle group {T}, which corresponds the plaintext integers from -t to t-1 to -0.5 to 0.5. However, as a result of BlindRotate, the TLWE ciphertext cb' shown in Figure 8 uses the range around 0, approximately from -1 / (4t) to 1 / (4t). Specifically, when t=8, the TLWE ciphertext cb1 in Figure 7 after preprocessing divides the circle group {T} into 2t=16, while the TLWE ciphertext cb' in Figure 8 divides it into 4t 2 = 256. Therefore, the plaintext, which was expressed using the entire circle group {T} in the TLWE ciphertext cb, is expressed in 1 / 16 of the circle group of the TLWE ciphertext cb'. This range corresponds to a range of approximately -1 / (4t) to 1 / (4t) around 0, which is equivalent to one slice in the circle group of the TLWE ciphertext cb. In FIG. 8, the intervals from 1 / (4t) to 0.5 and 0.5 to -1 / (4t) are unused (not assigned). 2 = 256 divisions finer than -t / 4t 2 ~(t-1) / 4t 2 These correspond as integers to the integers -8, -7, -6, -5, -4, -3, -2, -1, 0, 1, 2, 3, 4, 5, 6, and 7.

[0073] If the plaintext integer b is a negative integer, in FIG. 7, −1 to −t (the left half) is upside down from the state in FIG. 6(a) by the above pre-processing. For the preprocessed TLWE ciphertext cb1, the circle group of (1) is 4t 2 Divide the plaintext denominator to 4t 2 When bootstrapped to obtain the TLWE ciphertext cb', the plaintext of the TLWE ciphertext cb' after bootstrap is b / (4t 2 ) If the plaintext b before pre-processing is negative, when b is -1, the plaintext b after pre-processing is -t, and the first bootstrap result is that the lowest block is sign-inverted to -1 / (8t 2 ) Then, the trivial ciphertext (0,1 / 8t 2 ) to subtract -1 / (4t 2 )=b / (4t 2 ) On the other hand, when b=-t, the preprocessing result is -1, and the first bootstrap result is that the sign of the top block is inverted to -(t-1) / (4t 2 )-1 / (8t 2 ) Then, the trivial ciphertext (0,1 / 8t 2 ) is subtracted to get -t / (4t 2 )=b / (4t 2 )

[0074] By processing (1), the circle group is 4t 2 The TLWE ciphertext cb' converted into a partition is obtained. Regarding the ciphertext of the multiplier, the negative plaintext integers that were upside down in advance are upside down again as a result of the first bootstrap of (1). The negative numbers are assigned from the top of the left half as -8, -7, -6, -5, -4, -3, -2, -1. Also, the test vector has an offset (1 / 8t 2 ), but after the first bootstrap, the trivial ciphertext (0,1 / 8t 2 ) is eliminated by homomorphic subtraction. Therefore, in the ciphertext cb' shown in Figure 8, the division method without offset (±1 / 8t 2 (distributed in the range of ).

[0075] (2) The encryption / decryption processing device 1 (key exchange unit 30) performs private key switching on the TLWE ciphertext cb' using a key switching key KS1 prepared in advance, to obtain a TRLWE ciphertext cc having a step-like polynomial as plaintext. The private key of the obtained TRLWE ciphertext cc is [s']. The result of decrypting the TRLWE ciphertext cc with the private key [s'] is TIFF0007672722000038.tif11156. Therefore, the plaintext of the TRLWE ciphertext cc is the stepwise plaintext polynomial TIFF0007672722000039.tif1052, and by dividing the right half of the circular group into t parts (0, 1, 2, 3...) and the left half into t parts (-1, -2, -3...), the result is a polynomial whose coefficient increases in a stepped manner for each value of the plaintext b of the TLWE ciphertext cb. When the TLWE ciphertext cb has the value 3 as plaintext, as a result of Private Key Switching, the coefficients of the degree terms corresponding to the right half of the circle group are 1.5, 4.5, 7.5, 10.5, and 13.5, which are multiples of the TLWE ciphertext cb plaintext (3) plus 1.5, which is half the value of b, as an offset. This polynomial is the function to obtain the key switching key KS1 above. Derived from TIFF0007672722000040.tif1163.

[0076] f in preprocessing id Corresponding to the addition of an offset of 0.5 to the plaintext in , an offset of 0.5 is also added to the plaintext in the plaintext polynomial (key-switching key KS1) of the TRLWE ciphertext cc. The offset of 0.5 (1 / 2) comes from i+(1 / 2), which is the division of 2i+1 in the key-switching key KS1 by 2. More appropriately, the coefficient part i+(1 / 2), which includes the +0.5 offset, is scaled by a factor of 2, and the offset addition is made an integer of +1. As explained in (1), the TLWE ciphertext cb' is b / (4t 2 ), when b is negative, the plaintext polynomial of the TLWE ciphertext cc has all negative terms, and the coefficients decrease by b, as opposed to the case when b is positive.

[0077] (3) The cryptographic processing device 1 (second bootstrapping unit 17) performs second bootstrapping. The cryptographic processing device 1 performs BlindRotate on the TRLWE ciphertext cc (LEVEL1) using the TLWE ciphertext ca (LEVEL0) and performs SampleExtract to obtain the TLWE ciphertext cc1 (LEVEL1). The secret key of the TLWE ciphertext cc1, which is the ciphertext of LEVEL1, is [s']. (i) If the plaintext integer a is not a negative integer (it is 0 or positive), the TLWE ciphertext ca' obtained by multiplying the TLWE ciphertext ca by 2n is φ s Since (ca')=(an) / t+n / (2t), we have (an) / t+n / (2t) as the plaintext. Therefore, φ s’ In the plaintext polynomial (cc), the term whose exponent is near (an) / t+n / (2t) is obtained as a constant term. This is the coefficient of the term where i=a in the above plaintext polynomial. Therefore, φ s (cc1)=(2a+1)b / (4t 2 ) and the TLWE ciphertext cc1 is (2a+1)b / (4t 2 ). The TLWE ciphertext cc1 is a ciphertext corresponding to the product of plaintext integer a and plaintext integer b, and at this stage the product of plaintext integer a and plaintext integer b has been obtained.

[0078] Specifically, the result of the second bootstrap is 1.5, 4.5, 7.5, 10.5, and 13.5, which are obtained by adding half of the integers that are multiples of 3 based on the plaintext polynomial of the TLWE ciphertext cb' to them, and then obtaining the value of the plaintext integer a+1 of ca (because a includes 0), when the plaintext integer a of ca is 2, the third value of 7.5 is obtained as the TLWE ciphertext cc'. In fact, the value 2.5×3=7.5 is obtained as the solution to (a+0.5)×b, and the multiplication is performed correctly. The offset of 0.5 added to a will be removed later.

[0079] (ii) When the plaintext integer a is a negative integer, only the left half of the TLWE ciphertext ca is upside down as a result of pre-processing, and the TLWE ciphertext ca has -(t+1+a) / (2t)+1 / (4t) as plaintext. Therefore, the TLWE ciphertext ca' obtained by multiplying the pre-processed TLWE ciphertext ca1 by 2n is φ s Since (ca')={-(t+1+a)}n / t+n / (2t)=-n-{(a+1)}n / t+n / (2t), we have -n-{(a+1)}n / t+n / (2t) as the plaintext. Polynomial surplus group T(X) / (X n +1) is a finite cyclic group, so X -1 When multiplied by -n times, all terms become negative. Therefore, in BlindRotate, all coefficients of the plaintext polynomial of the TLWE ciphertext cc1 are inverted, and then φ s (ca')+n=-{(a+1)}n / t+n / (2t) is X -1 This can be interpreted as multiplying by . In other words, in the plaintext polynomial after BlindRotate, the term whose exponent is near {-(a+1)n} / t+n / (2t) is obtained as a constant term. In other words, it is the negative of the coefficient of the term where i=-(a+1) in the above plaintext polynomial. Therefore, φ s’ (cc1)=-{-2(a+1)+1}b / (4t 2 )=-(-2a-1)b / (4t 2 )=(2a+1)b / (4t 2 ) which is the same as when the plaintext is a positive integer. As shown above, the TLWE ciphertext cc1 is the ciphertext corresponding to the product of the plaintext integer a and the plaintext integer b.

[0080] This is the effect of adding the term +1 / 2 to the polynomial of f' used to calculate the key switching key KS1. If you do not add the +1 / 2 term, if the plaintext integer a is a positive integer, then ab / (2t 2 ), and if it is a negative integer (including 0), then (a+1)b / (2t 2 ) Since the result is the same for a = 0 and a = -1 (plaintext integer a is a negative integer), it is impossible to determine which was originally the case unless a and b are separated by sign. As for the pre-processing of the TLWE ciphertext cb and the process of (1), these two bootstraps calculate the linear function g(x) = 1 / (2t) × x. The above-mentioned paper "Bootstrapping in FHEW-like Cryptosystems, Daniele Micciancio and Yuriy Polyakov Duality Technologies February 23, 2020" introduces a method for evaluating any function that satisfies certain conditions. In this embodiment, by using pre-processing of the TLWE ciphertext cb and two bootstraps as in (1), any odd function can be evaluated for both positive and negative ranges without any specific conditions, even if it is not a linear function.

[0081] Here, SampleExtract extracts the TLWE ciphertext of the constant term (4t 2 Therefore, to eliminate the 1 / 2 term, we subtract the TLWE ciphertext cb' from the TLWE ciphertext cc1 to obtain the TLWE ciphertext cc'. In order to calculate 1 / 2, the TLWE ciphertext cb' is halved in size when it is calculated, and the key-switching key KS1 is doubled in size. This allows the numerator of the key-switching key KS1 to be an integer. φ s’ (cc')=φ s’ (cc1)-cb'=(2a+1)b / (4t 2 )-b / (4t 2 )=ab / 2t 2 Then, the TLWE ciphertext cc' is ab / 2t as the plaintext. 2 has. This results in the TLWE ciphertext cc'(LEVEL1) corresponding to the product of a and b. As shown in Figure 9, the TLWE ciphertext cc' is obtained by dividing the circle group {T} by 2t 2 This is a divided ciphertext.

[0082] The TLWE ciphertext cc' shown in Figure 9 is a result of multiplication. The left and right halves of the circle group {T} are 2Divide each into individual parts, and the whole circle group is 2t 2 It is divided into pieces. 2t 2 -1 is the maximum value that the TLWE ciphertext can have as a result of any intermediate multiplication. For t=8, the right half of the circle group is t 2 = 64, and on the right half of the circle group {T}, t 2 = 64 integers, 0, 1, 2, 3, 4, 5, 6, 7, ... 63. On the left half of the circle group {T}, t 2 =It can represent 64 integers: -64, -63, -62, ... -1. The whole range of the circle group {T} from 0 to 1 is called 2t 2 = 128 parts, and the ciphertext can represent the integers -64, -63..., -4, -3, -2, -1, 0, 1, 2, 3, 4..., 62, and 63.

[0083] These integer values ​​are expressed as the whole range of the circle group from 0 to 1 in 2t 2 1 / 2t divided into pieces 2 Each section is assigned to a different time slot. For t=8, 2 3 Since =8, the TLWE ciphertexts ca and cb of the multiplier and multiplicand record 3-bit integers in the circular group (right half). The multiplication result of 3-bit integers is a 6-bit integer, and the TLWE ciphertext that records this is 6 = 64 divisions, i.e. t 2 Divide into pieces. However, the ciphertext of the multiplication result has a different number of divisions of the circular group from the ciphertexts of the multiplier and multiplicand. The denominator of the plaintext of the TLWE ciphertexts ca and cb is 2t, while the denominator of the plaintext of the TLWE ciphertext cc' is 2t. 2 The number of divisions of the circular group in the ciphertext is different before and after the multiplication. The TLWE ciphertext cc' cannot be used for multiplication with a ciphertext whose plaintext denominator is 2t, such as the TLWE ciphertexts ca and cb.

[0084] It is necessary to convert the TLWE ciphertext cc' into a ciphertext whose plaintext denominator is 2t (to match the number of divisions of the circular group before and after the multiplication of the ciphertext). Therefore, the cryptographic processing device 1 performs the conversion required for this at high speed. This conversion is, for example, 6-bit (t 2 The method involves extracting the lowest 3 bits (t division) and the highest 3 bits (t division) from the multiplication result of (t division) to obtain the same t-division ciphertext as before the multiplication.

[0085] The denominator of the plaintext of the ciphertext to be multiplied by the TLWE ciphertext cc' is 2t 2 However, as the number of divisions of the circle group increases with each multiplication, the allowable error range becomes smaller, so this is not desirable when used in complex configurations. On the other hand, this type of configuration is called Leveled-FHE, and it may be used as is depending on the application, for example, when only one convolution (inner product) operation is required. In this embodiment, in order to perform a high-speed conversion to match the number of divisions of the circular group before and after multiplication of the ciphertext, for example, a 6-bit (2t 2 From the multiplication result (2t division), the lowest 3 bits (2t division) and the highest 3 bits (2t division) are extracted to obtain the same 2t-division ciphertext as before the multiplication. In addition, since the result of the multiplication can easily exceed t, the result is decomposed into a quotient and remainder when divided by t. The quotient is the most significant 3 bits, and the remainder is the least significant 3 bits.

[0086] For example, if t=8, 0 to 63 (8 2Even if bootstrapping t = 64) with a sawtooth polynomial (coefficients 0123 to 67012...) and a step polynomial (coefficients 000011112222...), it is possible to obtain the quotient and remainder when dividing the multiplication result by t. However, since the degree N of the vector used in TFHE is considered to be 635 and the degree n of the polynomial is considered to be 1024, the rounding error of 635 is accumulated at the stage of multiplying the 635 coefficients of the TLWE ciphertext by 2n just before BlindRotate. In addition, the interval obtained by dividing the degree n of the polynomial according to the division number of the interval from 0 to 0.5 corresponds to one integer, but with 64 divisions, the width is only 16, so only an error of ±8 is allowed. This causes a problem that the calculation error rate is too high.

[0087] There is an option to increase the degree of the polynomial n or decrease the degree of the vector N, but this would sacrifice encryption strength and computation speed. Increasing the degree of the polynomial increases the computational complexity of the multiplications performed by CMux to O(n 2 ) while decreasing the degree of the vector reduces the freedom in analysis, making the cipher easier to decode. Therefore, in this embodiment, the following method is used to sufficiently suppress the error rate while ensuring that the denominator of the plain text is 2t 2 Calculate the ciphertext (quotient ciphertext, remainder ciphertext) whose denominator is 2t from the plaintext.

[0088] (4) The cryptographic processing device 1 (third bootstrap unit 18) multiplies the TLWE ciphertext cc' by t, performs Public Key Switching to drop it to LEVEL 0, adds a trivial ciphertext (0, 1 / (4t)), and then performs BlindRotate and SampleExtract with the test vector polynomial μ=1 / 4. The (0,1 / (4t)) added is an offset to make the boundary between 0 and -1 0 on the circle group {T}. Multiplying the TLWE ciphertext cc' by t results in a plaintext denominator of 2t, but we would like to use the range from 0 to 0.5 on the circular group {T} as the lower bits of the multiplication result. This is because the lower bits are always positive. However, when this calculation is actually performed, the result also falls within the range from 0.5 to 1. Therefore, the result of multiplying by t is a TLWE ciphertext cd(LEVEL1) with 1 / 4 as plaintext if the plaintext is in the range of 0 to 0.5, and -1 / 4 if the plaintext is in the range of 0.5 to 1. The TLWE ciphertext cd, which is the ciphertext of LEVEL1, has the secret key [s'].

[0089] (5) The cryptographic processing device 1 (second calculation unit 13) calculates cc'×t+cd-(0,1 / 4)+(0,1 / (4t)). The cryptographic processing device 1 (third bootstrap 18) performs public key switching on the calculation result to obtain a TLWE ciphertext cl(LEVEL0) with the secret key [s]. This obtains the lower bits of the multiplication result. The TLWE ciphertext cl is decrypted to φ s The ciphertext is (cl)=(ab mod t) / (2t)+1 / (4t). If the upper bits are not needed, you can stop here.

[0090] If we consider that the remainder is always positive, then even if the plaintext of the TLWE ciphertext cc' is negative, the plaintext of the TLWE ciphertext cl will be positive. Once the quotient is calculated, t × quotient + remainder = ab holds regardless of whether it is positive or negative, so there is no mathematical contradiction. When the multiplication result is stored in a single variable and a modular division instruction is used to calculate it on a computer, the result will vary depending on the language processing system and CPU architecture, but it will be exactly the same as the process of decomposing t as a power of 2 using shift and AND operations, that is, expressing it in binary and simply dividing the bits. Since the calculation is performed using t-times the TLWE ciphertext, the range of values ​​corresponding to one integer symbol is expanded by t times, making it possible to relatively tolerate errors due to rounding. Also, by performing addition and multiplication using the TLWE ciphertext with the secret key [s'], the effect of public key switching, which adds a relatively large error, can be reduced.

[0091] When the higher-order bits of the multiplication result are required, the following operation is performed. (6) The information processing device 1 (fourth bootstrap unit 19) calculates the following test vector polynomial for the TLWE ciphertext cl of the lower bits: Perform BlindRotate and SampleExtract using TIFF0007672722000041.tif1049 to obtain the TLWE ciphertext cl' (LEVEL1). The TLWE ciphertext cl' has a secret key of [s']. The TLWE ciphertext cl' has a plaintext denominator of 1 / 2t 2 This is a ciphertext in which the lower bits of the multiplication result (ab mod t) are stored using the interval from 0 to 1 / (2t). Since it is assumed that the remainder is not a negative number, it is considered that only the right half of the circular group is used, so adding an offset to the test vector polynomial does not affect the result.

[0092] (7) The cryptographic processing device 1 calculates cu=cc'-cl'+(0,1 / (4t)) to obtain the TLWE ciphertext cu. Perform public key switching on the TLWE ciphertext cu, and switch the private key from [s'] back to [s] to obtain the TLWE ciphertext cu'. In other words, ab / 2t 2 From (ab mod t) / 2t 2 Make the numerator a multiple of t by subtracting , and then reduce the numerator and denominator by t. And then, The result is TIFF0007672722000042.tif1184. In this case, the error components added to the plaintexts of the TLWE ciphertexts cc' and cl' follow a normal distribution, so the error added to the plaintext of the TLWE ciphertext cu also follows a normal distribution due to reproducibility. Therefore, the TLWE ciphertext cu' can be used as is for the next calculation. In other words, by subtracting the ciphertext that is a remainder modulo 8 from the ciphertext in which the right half is divided into 64, the ciphertext will always have a plaintext that is a multiple of 8. In other words, every 8th block is used. When comparing this with the ciphertext in which the right half is divided into 8, the division method can be considered to be the same, with only the variance of the error being different, so the TLWE ciphertext cu can essentially be treated as the ciphertext in which the right half is divided into 8. This is because the error components added to the plaintext in the TLWE ciphertext cc' and TLWE ciphertext cl' follow a normal distribution. The error added to the plaintext in the TLWE ciphertext cu obtained by cc'-cl' also follows a normal distribution due to a property called reproducibility. Therefore, the TLWE ciphertext cu' of the most significant bits of the multiplication can be used as is in the next calculation without bootstrapping. Both the TLWE ciphertext cu' and the TLWE ciphertext cl are at LEVEL 0, with the private key restored to [s] by public key switching at the end. By eliminating this process and performing public key switching on the TLWE ciphertext ca and TLWE ciphertext cb during preprocessing, it is possible to use LEVEL 1 as the input and output. As described above, in this embodiment, the right half of the circular group {T} is used as an unsigned integer (0 or a positive integer), and the left half of the circular group {T} is treated as a signed integer (negative integer). By fully utilizing the circular group {T}, which is the plaintext space of the TLWE ciphertext, it becomes possible to pack in a lot of information (effectively 1 bit more than in [Second embodiment] described below). This makes it possible to reduce the amount of calculations by targeting a small number of ciphertexts when constructing a multiple-precision integer, for example.

[0093] By looping CMux, it can also be used as an alternative to Private Key Switching. The cryptographic processing device 1 includes: multiplier The result of BlindRotating the TLWE ciphertext cb (the pre-processed TLWE ciphertext cb1) is taken as a TRLWE ciphertext c1. The TRLWE ciphertext c1 has a polynomial in the plaintext. The cryptographic processing device 1 multiplies each coefficient of the TLWE ciphertext ca (the pre-processed TLWE ciphertext ca1) by 2t and rounds it off to obtain a TLWE ciphertext ca''. By rounding off after multiplying by 2t, all elements of the TLWE ciphertext ca'' are integers. At this time, φ s (ca'')=a holds, and therefore the plaintext of the TLWE ciphertext ca'' is the same as the plaintext of the TLWE ciphertext ca, which is a. The TLWE ciphertext ca'' is composed of caa and cab. And caa and cab correspond to the above elements [a] and b that compose the TLWE ciphertext ([a], b), respectively. The cryptographic processing device 1 sets A0=cab×c1, and repeatedly performs the following calculation of CMux, including multiplication of caa and cab by the TRLWE ciphertext c1, where BK is the Bootstrapping Key. TIFF0007672722000043.tif665This CMux calculation is a modification of BlindRotate explained in the above paper (modified BlindRotate). caa i The two TRLWE ciphertexts, cab×c1+cab×c1 and cab×c1, are converted into s based on the Bootstrapping Key. i Either one is selected depending on the value (0 or 1). s i When is 1, A i As caa i ×c1+cab×c1 is selected, and s i When is 0, A i Then, cab×c1 is selected. This is repeated up to the nth time. As a result, a new TRLWE ciphertext A has the plaintext result of multiplying the TLWE ciphertext ca'' by the plaintext polynomial of the ciphertext c1 according to the elements of the original TLWE ciphertext ca'' and the secret key vector in the Bootstrapping Key. n It is possible to obtain the following. As mentioned above, the elements caa and cab of the TLWE ciphertext ca'' are all integers, so scalar multiplication can be performed on the circular group coefficients of the elements of the TRLWE ciphertext c1. In addition, since the coefficients are both circular groups, addition is also possible. By carrying out the above calculations, This means that TIFF0007672722000044.tif679 has been calculated. That is, the integer ( multiplicand ) is multiplied by the multiplier TRLWE ciphertext c1 to obtain the ciphertext of the multiplication result. This operation is equivalent to multiplying the plaintext of the TLWE ciphertext ca'' which is the multiplicand by the coefficient of the polynomial which is the plaintext of the ciphertext c1. Ciphertext A n The constant term of the plaintext polynomial is ab / 2t 2 Thus, we were able to obtain the same ciphertext as the TLWE ciphertext cc'. The subsequent processes are the same as those from (4) onwards, and the cryptographic processing device 1 performs processes of calculating the TLWE ciphertext cd from the TLWE ciphertext cc', and successively calculating the TLWE ciphertexts cl, cl'cu'.

[0094] FIG. 10 is a flowchart illustrating the multiplication process of this embodiment. In step S101, the cryptographic processing device 1 (the sixth bootstrap unit 22) performs the following operation on the TLWE ciphertext ca of the multiplier: id Then, the sixth bootstrap is performed using the above to obtain a new TLWE ciphertext ca1. In step S102, the cryptographic processing device 1 (the fifth bootstrap unit 21) performs F idThen, a fifth bootstrap is performed using the above-mentioned ciphertext cb1 to obtain a new TLWE ciphertext cb1. Steps S101 and S102 are performed in no particular order. In step S103, the cryptographic processing device 1 (first bootstrap unit 16) performs first bootstrap on the TLWE ciphertext cb1 of the multiplier to obtain a TLWE ciphertext cb'. In step S104, the cryptographic processing device 1 (key exchanging unit 30) performs private key switching on the TLWE ciphertext cb' to obtain a TRLWE ciphertext cc. In step S105, the cryptographic processing device 1 (second Bootstrapping unit 17) performs BlindRotate on the TRLWE ciphertext cc by using the TLWE ciphertext ca1, and in step S106 performs SampleExtract to obtain a TLWE ciphertext cc1. In step S107, the cryptographic processing device 1 (fourth arithmetic unit 15) performs cc1-cb' to obtain a TLWE ciphertext cc'. In step S108, the cryptographic processing device 1 (first arithmetic unit 12) performs cc'×t. The cryptographic processing device 1 (third bootstrap unit 18) performs BlindRotate on the t-fold TLWE ciphertext cc' in step S109 and SampleExtract in step S110 to obtain a TLWE ciphertext cd. The cryptographic processing device 1 (second arithmetic unit 13) performs cc'×t+cd(0,1 / 4) in step S111, and the cryptographic processing device 1 (third bootstrap unit 18) performs public key switching in step S112 to obtain a TLWE ciphertext cl. Through the above process, the lower-order bits (3 bits) of the multiplication result of integer-wise TLWE ciphertexts can be obtained.

[0095] FIG. 11 is a flowchart illustrating the multiplication process of this embodiment. In step S201, the cryptographic processing device 1 (fourth Bootstrapping unit 19) performs BlindRotate on the TLWE ciphertext cl by using the TLWE ciphertext ca, and in step S202 performs SampleExtract to obtain a TLWE ciphertext cl'. In step S203, the cryptographic processing device 1 (the third arithmetic unit 14) performs cc'-cl' to obtain a TLWE ciphertext cu. In step S204, the cryptographic processing device 1 (the fourth bootstrap unit 19) performs public key switching on the TLWE ciphertext cu to obtain a TLWE ciphertext cu'. Through the above process, the most significant bits of the multiplication result of integer-wise TLWE ciphertexts can be obtained. <Second Example>

[0096] In the second embodiment described below, the TLWE ciphertexts ca and cb of the multiplier and multiplicand are ciphertexts having plaintexts shown in Fig. 6. However, the ciphertexts to be operated on use only the right half plane of the circular group {T}. The multiplication performed in the following description is a multiplication between ciphertexts having unsigned (positive integer) plaintexts. Assuming that only positive integers are handled as plaintexts, multiplication can be performed at high speed with fewer processes than the signed multiplication described above. In the second embodiment, the cryptographic processing device 1 generates a TRLWE ciphertext having a step-like polynomial as a plaintext from the TLWE ciphertext of the multiplier by using Private Key Switching presented in the above paper (Non-Patent Document 1).Then, the cryptographic processing device 1 realizes multiplication by performing Blind Rotation on the obtained TRLWE ciphertext by the TLWE ciphertext of the multiplicand. In this [Second Example], the left half of the circle group {T} is not used for the plaintext of negative integers, so a one-variable function f id Bootstrapping using a step-like polynomial (one-variable function f idIn addition, an offset of 0.5 is not added to the plaintext (polynomial coefficient) in the key switching key KS1, and 0.5 is not returned at the end.

[0097] FIG. 12 is a diagram for explaining the functional configuration of a cryptographic processing device based on a second embodiment of the present invention. FIG. 13 is a diagram for explaining a calculation process based on the functional configuration of FIG. The second embodiment shown in FIGS. 12 and 13 differs from FIGS. 1 and 2 in that it does not have the fifth calculation unit 21, the sixth calculation unit 22, and the fourth calculation unit 15 which perform pre-processing, and in that the second calculation unit directly outputs the TLWE ciphertext cc′. The steps (1) to (7) for performing the multiplication process will now be described. (1) The cryptographic processing device 1 (the first bootstrap unit 16) calculates a test vector polynomial Gate bootstrap is performed on the TLWE ciphertext cb using TIFF0007672722000045.tif1150 to obtain the TLWE ciphertext cb'. As a result of this gate bootstrap, the denominator of the ciphertext goes from 2t to 2t 2 The TLWE ciphertext cb obtained by dividing the right half of the circle group into t=8 is t 2 = 64 divided TLWE ciphertext cb'. The TLWE ciphertext cb is a ciphertext in which integers from 0 to (t-1) correspond to 0 to 0.5 (right half) of the circular group divided into t=8 parts. At this point, the numerator of the plaintext of the TLWE ciphertext cb' is the same as the TLWE ciphertext cb, so the TLWE ciphertext cb' is 2 = 64 divisions of the circle group, with integers from 0 to (t-1) corresponding to the lower half of the right half of the circle group (0 to 0.5). Other parameters of the TLWE ciphertext cb and the TLWE ciphertext cb' will be described later. As will be described later, in practice, the level of the ciphertext cb and the level of the ciphertext cb' are related.

[0098] (2) The encryption / decryption processing device 1 (key exchange unit 30) performs private key switching on the TLWE ciphertext cb' using the key switching key KS1 to obtain a TRLWE ciphertext cc. The private key of the ciphertext cc is [s']. In the second embodiment, a function that obtains the following step-like polynomial is set as f''(x), and the key switching key KS1 is calculated in advance. TIFF0007672722000046.tif1153TRLWE The result of decrypting the ciphertext cc with the private key [s'] is The result is TIFF0007672722000047.tif10130. The plaintext of the ciphertext cc is the plaintext polynomial TIFF0007672722000048.tif940, and the right half of the circular group is divided into t parts (0, 1, 2, 3...) to obtain a polynomial whose coefficients increase in a stepped manner for each value of the plaintext of the TLWE ciphertext cb. When the TLWE ciphertext cb has a plaintext value of 3, as a result of Private Key Switching, a plaintext polynomial is obtained in which the coefficients of the degree terms corresponding to the right half of the circular group are 0, 3, 6, 9, and 12, which are multiples of the plaintext of the ciphertext cb (3).

[0099] (3) In the second bootstrap, the cryptographic processing device 1 (second bootstrap unit) performs BlindRotate on the TRLWE ciphertext cc using the TLWE ciphertext ca, and performs SampleExtract to obtain a TLWE ciphertext cc'. The private key of the ciphertext cc' is [s']. The TLWE ciphertext ca' obtained by multiplying the TLWE ciphertext ca by 2n has an / t as the plaintext, since {a / (2t)}×2n. Therefore, φ s’ Among the plaintext polynomials in (cc'), the exponent is an / t+n / (2t 2 ) is taken as the constant term. That is, φ s’ (cc')=ab / (2t 2 ) and the TLWE ciphertext cc' is ab / (2t 2) The product of plaintext integer a and plaintext integer b is obtained, and the TLWE ciphertext cc' is the ciphertext corresponding to the product of plaintext integer a and plaintext integer b. Specifically, as a result of the second bootstrap, among the integers 0, 3, 6, 9, and 12 that are multiples of 3 based on the plaintext polynomial of the TLWE ciphertext cb', in order to obtain the value of the a+1th plaintext integer (because a includes 0) of the TLWE ciphertext ca, when the plaintext integer a of the TLWE ciphertext ca is 2, the third value of 6 is obtained as the TLWE ciphertext cc'. In fact, the value 2×3=6 is obtained as the solution to a×b, and the multiplication is performed correctly. The process for calculating the TLWE ciphertext cl of the lower bits of the multiplication result and the TLWE ciphertext cu' of the higher bits is the same as the process from (4) onwards in the case of signed multiplication described above, so a detailed description will be omitted. It is also possible to substitute for Private Key Switching by looping CMux.

[0100] The process flow according to the second embodiment is the same as that in the flowchart of FIG. 9, except that the preparatory processes of steps S101 and S102 are not performed, and the ciphertext cc′ is directly calculated in step S106 without performing the subtraction process in step S107.

[0101] [Third Example] The cryptographic processing device 1 further performs homomorphic addition of the TLWE ciphertext ce having an integer e as a plaintext, or a trivial ciphertext having an integer e as a plaintext, to the TLWE ciphertext cc' obtained in the process of multiplying the TLWE ciphertext ca having the integer a as a plaintext and the TLWE ciphertext cb having the integer b as a plaintext, as described in [First Embodiment] and [Second Embodiment], thereby being able to calculate a ciphertext having an integer a×b+e as a plaintext in a procedure almost identical to the multiplication of the TLWE ciphertext ca and the TLWE ciphertext cb described below.

[0102] Simply adding the ciphertext corresponding to e after multiplying the ciphertext corresponding to a×b may result in a carry or a borrow due to the addition. Therefore, in order to calculate the ciphertext indicating the carry or borrow, it is necessary to perform BlindRotate multiple times on the comparison result between the plaintext a×b and the plaintext e, which requires a large amount of calculation time. In contrast, in the third embodiment, by incorporating addition of the ciphertext corresponding to the plaintext e into the process of multiplying the ciphertexts ca and cb, it is not necessary to perform Blind Rotation for carry-over and carry-down in addition to the third and fourth gate bootstrapping, and it is possible to significantly speed up the FMA (Fused Multiply-Add) calculations. The procedure for calculating the integer a×b+e is the same as the multiplication procedure described in [First embodiment] and [Second embodiment], except that the TLWE ciphertext ce is added homomorphically along the way, and the number of BlindRotates is also the same. In the following description, the method for calculating the ciphertext of the integer a×b+e is simply shown as a multiplication method. It is also possible to incorporate homomorphic subtraction instead of homomorphic addition to calculate the ciphertext of the integer a×be.

[0103] An operation of the form a×b+e is known as FMA, or fused multiply-add. FMA can be used to calculate the dot product (dot product distance) between vectors, which can be used for applications such as biometric authentication. As a simple example, when calculating the inner product [a]·[b] of a three-dimensional vector [a]=(ciphertext of element a1, ciphertext of element a2, ciphertext of element a3) in which three elements are encrypted, and a three-dimensional vector [b]=(ciphertext of element b1, ciphertext of element b2, ciphertext of element b3), the results of multiplication performed on each element are all added up. Thus, the cryptographic processing device 1 calculates the ciphertext of a1·ciphertext of b1+ciphertext of a2·ciphertext of b2+ciphertext of a3·ciphertext of b3. When performing the above calculations without using FMA, three BlindRotate operations are required to simply calculate the multiplication result of the ciphertext of a1 and the ciphertext of b1, the multiplication result of the ciphertext of a2 and the ciphertext of b2, and the multiplication result of the ciphertext of a3 and the ciphertext of b3. From here, homomorphic addition must be performed the number of elements (the degree of the vector)-1 times to sum up each multiplication result. Here, if there are no particular constraints on the values ​​of each element, carryover and borrowing must be taken into account, so an additional bootstapping or BlindRotate is required to determine this. In other words, the number of BlindRotates explained in [First embodiment] and [Second embodiment] is tripled, and an additional BlindRotate twice the number of BlindRotates required for carry and borrow processing is performed throughout the calculation of the inner product.

[0104] On the other hand, when FMA is used, the calculation of the ciphertext of a1·ciphertext of b1+ciphertext of a2·ciphertext of b2+ciphertext of a3·ciphertext of b3 can be performed as follows. The cryptographic processing device 1 corresponds the TLWE ciphertext cc' obtained during the multiplication of the ciphertext of a1 and the ciphertext of b1 to the above TLWE ciphertext ce, and corresponds the multiplication of the ciphertext of a2 and the ciphertext of b2 to the multiplication of the above TLWE ciphertext ca and TLWE ciphertext cb, thereby making it possible to perform the calculation of the ciphertext of a1 · b1 ciphertext + the ciphertext of a2 · b2 ciphertext in one go for the first half of the multiplication procedure (up to obtaining the TLWE ciphertext cc') and the entire multiplication procedure in one go. Furthermore, the cryptographic processing device 1 associates the ciphertext resulting from the calculation of the ciphertext of a1·b1·ciphertext of a2·b2 obtained above with the ciphertext ce, and associates the multiplication of the ciphertext of a3 and the ciphertext of b3 with the ciphertext ca and ciphertext cb, thereby making it possible to perform the calculation of the ciphertext of a1·b1+ciphertext of a2·b2+ciphertext of a3·b3 in a single multiplication step. By using FMA, the calculation corresponding to the dot product of vectors can be performed by performing two operations that are almost equivalent to multiplication and one operation that is the first half of the multiplication, which is less computational effort than performing three multiplications in total. It can be said that this is much faster than the case without FMA, which requires three multiplications plus carry and borrow operations. The same can be done if the vector has two elements, or more than three elements.

[0105] Also, if the error tolerance allows, it is possible to increase the number of TLWE ciphertexts added to the TLWE ciphertext cc'. For example, let ce1 be the TLWE ciphertext cc' obtained in the middle of the multiplication of the ciphertext of a1 and the ciphertext of b1. Similarly, let ce2 be the TLWE ciphertext cc' obtained in the middle of the multiplication of the ciphertext of a2 and the ciphertext of b2. By associating the ciphertext resulting from the homomorphic addition of TLWE ciphertexts, ce1+ce2, with the ciphertext ce, and associating the multiplication of the ciphertext of a3 and the ciphertext of b3 with the ciphertext ca and the ciphertext cb, it is possible to perform the calculation of the ciphertext of a1·b1+ciphertext of a2·b2+ciphertext of a3·b3. In this case, the first half of the multiplication operation is performed twice, and the entire procedure of the multiplication operation is performed once. As explained below, in both cases, the homomorphic addition corresponding to a×b+e is performed when the denominator of the plaintext is 2t 2 It is desirable to do this at a stage where the denominator of the plaintext is 2t 2 It is desirable to perform homomorphic subtraction at the stage where the denominator is 2t 2 At this stage, the range of integers that can be stored in a single TLWE ciphertext is -t 2 From 2 This is because the range is wide, i.e. -1, and therefore there is no need to take into account the occurrence of carry-over or carry-down due to homomorphic addition or homomorphic subtraction.

[0106] Specifically, the cryptographic processing device 1 realizes the FMA through the following process. In addition to the first and second embodiments shown in FIGS. 2 and 13, the cryptographic processing device 1 also includes ab / (2t2 ) as plaintext, e / 2t 2 ciphertext ce with plaintext e / 2t 2 The trivial ciphertext (0,e / 2t 2 ) to obtain a new TLWE ciphertext cc'. The new TLWE ciphertext cc' is 2 It is possible to take. The cryptographic processing device 1 performs processing on this new ciphertext cc′ by the first calculation unit 12, the second calculation unit 13, and the third bootstrap unit 18 in the same manner as in the first and second embodiments, to obtain (ab+e) / 2t 2 The TLWE ciphertext cl has (ab+e mod t) / 2t as plaintext. Furthermore, the cryptographic processing device 1 performs processing on the TLWE ciphertext cl by the fourth bootstrap unit 19, and obtains (ab+e mod t) / 2t 2 The cryptographic processing device 1 inputs the TLWE ciphertext cl' to the third calculation unit 14 and performs homomorphic subtraction between the TLWE ciphertext cl' and a new TLWE ciphertext cc' corresponding to ab+e to obtain a TLWE ciphertext cu. The TLWE ciphertext cu is expressed as {(ab+e)-(ab+e mod t)} / 2t 2 As a plaintext, the cryptographic processing device 1 obtains a TLWE ciphertext cu′ by public keyswitching the TLWE ciphertext cu.

[0107] In the case of signed multiplication using the entire circle group described in the first embodiment, for example, in FIG. 2, the fourth calculation unit 15 performs the TLWE ciphertext ce or the trivial ciphertext (0,e / 2t 2) is homomorphically added to calculate a new TLWE ciphertext cc'. The new TLWE ciphertext cc' calculated by the fourth arithmetic unit 15 is processed by the first arithmetic unit 12, the third bootstrap unit 18, and the second arithmetic unit 13, and if necessary, is further processed by the fourth bootstrap unit 19 and the third arithmetic unit 14. Alternatively, after the fourth calculation unit 15 calculates the TLWE ciphertext cc′, the first calculation unit 12 calculates the ciphertext ce or the trivial ciphertext (0, e / 2t 2 ) may be homomorphically added to calculate a new TLWE ciphertext cc′, which may then be multiplied by t, and the result may be processed by the third bootstrap unit 18 and the second arithmetic unit 13.

[0108] In the case of unsigned multiplication using only the right half plane of the circular group described in [Second embodiment], after the second bootstrap unit 17 calculates the TLWE ciphertext cc′ in FIG. 13, for example, the first calculation unit 12 calculates the TLWE ciphertext ce or the trivial ciphertext (0,e / 2t 2 ) is homomorphically added to calculate a new TLWE ciphertext cc′, which is then multiplied by t, and the result is processed by the third bootstrap unit 18 and the second arithmetic unit 13. If necessary, further processing is performed by the fourth bootstrap unit 19 and the third arithmetic unit 14.

[0109] In either case, it is preferable to perform homomorphic addition or homomorphic subtraction of the ciphertext of the integer e to the new TLWE ciphertext cc' before multiplying the new TLWE ciphertext cc' by t using the first calculation unit 12 to make the denominator of the plaintext 2t. 2 +e / 2t 2 The denominator of the plaintext is 2t 2 At this stage, the range of integers that can be stored in a single TLWE ciphertext is -t 2 From 2 Since it is wide, ranging from -1, it has the advantage that there is no need to consider carry-over or carry-down that occurs when performing homomorphic addition and subtraction. On the other hand, even when homomorphic addition is performed during the multiplication process, when homomorphic addition / subtraction is performed on the ciphertext of integer e to the ciphertext obtained by multiplying TLWE ciphertext cc' by t in the first calculation unit 12, the calculation between plaintexts is performed as ab / 2t+e / 2t. In this case, the range of integers that can be stored in one TLWE ciphertext is narrow, from -t to t-1, and it is necessary to take into account the occurrence of carry-over and carry-down due to homomorphic addition / subtraction, so additional bootstapping or blind rotation is required to determine this.

[0110] [Fourth Example] The cryptographic processing device 1 applies signed multiplication in [First embodiment], unsigned multiplication in [Second embodiment], and FMA in [Third embodiment], and can speed up multiple-precision arithmetic (multiplication) using a technique called the Karatsuba algorithm. When calculating the product Z of multiplicand X and multiplier Y, if you divide dividend X and multiplier Y in half based on base k, X = x1 k + x0 Y = y1 k + y0 and the product Z is Z = z2 k 2 +z1·k+z0 This can be expressed as:

[0111] To calculate the ciphertext of z2, z1, and z0 that make up the product Z, z2 = ciphertext of x1 × ciphertext of y1 z0 = ciphertext of x0 × ciphertext of y0 z1 = ciphertext of x1 × ciphertext of y0 + ciphertext of x0 × ciphertext of y1 If the Karatsuba algorithm is not used, four multiplications would be required in total to perform the calculation. This is the same calculation method as calculating a two-digit integer using normal long division. Generally, multiplication becomes more complicated as the number of digits increases, so by dividing the multiplier and multiplicand in half, the number of digits handled in each multiplication can be halved. By repeating this recursively, the value can be reduced to a number of digits that allows direct multiplication.

[0112] In contrast, in the Karatsuba algorithm, the ciphertext of z1, among z2, z1, and z0, is -(ciphertext of x1 - ciphertext of x0) x (ciphertext of y1 - ciphertext of y0) + ciphertext of z2 + ciphertext of z0 is required. (Ciphertext of x1 - ciphertext of x0) and (ciphertext of y1 - ciphertext of y0) are the results of homomorphic subtraction between ciphertexts. Depending on the values ​​of plaintext x1 and plaintext x0, and the values ​​of plaintext y1 and plaintext y0, the result of homomorphic subtraction may be negative. Even if both results of homomorphic subtraction are positive, -(ciphertext of x1 - ciphertext of x0) × (ciphertext of y1 - ciphertext of y0) requires signed multiplication. Therefore, for (ciphertext of x1-ciphertext of x0) x (ciphertext of y1-ciphertext of y0), signed multiplication is performed using the entire circle group of [Example 1]. The ciphertext corresponding to plaintext x1-plaintext x0 corresponds to ciphertext ca, and the ciphertext corresponding to plaintext y1-plaintext y0 corresponds to ciphertext cb. If we associate the ciphertext of z2+z0-(ciphertext of x1-ciphertext of x0) x (ciphertext of y1-ciphertext of y0) with the above TLWE ciphertext ce, and associate (ciphertext of x1-ciphertext of x0) x (ciphertext of y1-ciphertext of y0) with the multiplication of the above TLWE ciphertext ca and TLWE ciphertext cb, then the ciphertext of z1 can be calculated in a single multiplication process, just like in the [Third Embodiment]. In addition, for the ciphertext of z2+z0, it is necessary to use the TLWE ciphertext obtained as the TLWE ciphertext cc' before being decomposed into the upper and lower parts.

[0113] FIG. 14 is a diagram showing ciphertexts input and output to and from Gate Bootstrapping of this embodiment. In the above description, it has been described that Gate Bootstrapping is performed in the order of BlindRotate, SampleExtract, and Public Key Switching, particularly in the first Bootstrapping, as shown in FIG. 14(a). Alternatively, as shown in FIG. 14(b), Public Key Switching can be executed first in Gate Bootstrapping, and then BlindRotate and SampleExtract can be executed. TLWE ciphertext has a concept of levels according to security strength. In Gate Bootstrapping in Fig. 14(a), the input and output TLWE ciphertexts are LEVEL 0. When BlindRotate is performed on the LEVEL 0 TLWE ciphertext and SampleExtract is performed on the output TRLWE ciphertext, the TLWE ciphertext obtained is LEVEL 1, but as a result of Public Key Switching, a LEVEL 0 TLWE ciphertext is output. In contrast, in the method shown in Figure 14(b), the TLWE ciphertext that is the input and output of Gate Bootstrapping is set to LEVEL 1, and first Public Key Switching is performed to lower it to LEVEL 0, and then BlindRotate is performed. When SampleExtract is performed on the output TRLWE ciphertext, a TLWE ciphertext of LEVEL 1 is output.

[0114] The ciphertext of LEVEL0 consists of an N-order vector [a] of elements on the circular group {T} encrypted with an N-order secret key [s]. On the other hand, the ciphertext of LEVEL1 obtained as a result of SampleExtract consists of an n-order vector [a'] of elements on the circular group {T} encrypted with an n-order secret key [s']. The LEVEL0 ciphertext has a smaller number of coefficients (the degree of the vector), which is the difficulty of the LWE problem, than the LEVEL1 ciphertext, so the amount of computation required for homomorphic addition is smaller than that of LEVEL1. On the other hand, the problem with LEVEL0 ciphertext is that the security strength is likely to decrease if the allowable error added to the plaintext is reduced, because the security of LWE-based ciphers is guaranteed by the error added to the plaintext. The larger the error added to the plaintext and the greater the number of coefficients (the degree of the vector), the more difficult it becomes to calculate (decrypt) the TLWE cipher. On the other hand, the smaller the error added to the plaintext and the fewer the number of coefficients (the degree of the vector), the easier it is to calculate (decrypt) the TLWE cipher. In particular, in the case of TFHE applied to the integer-wise type, the larger the plaintext (integer) value stored in the TLWE ciphertext becomes, the more finely it is necessary to divide the range of values ​​from 0 to 1 in the circular group {T}, and there is also the problem of errors during decryption, which will be described later, so the error needs to be reduced. In that case, as mentioned above, the security strength is likely to decrease, so in order to reduce the error, it is necessary to ensure security by increasing the number of coefficients in the ciphertext (the degree of the vector).

[0115] In order to ensure the security of ciphertexts that are easier to calculate (decrypt) by reducing the error added to the plaintext, it is desirable to move Public Key Switching to the beginning of Gate Bootstrapping and use LEVEL1 ciphertexts, which have a large number of coefficients (vector order) and are therefore easier to reduce the error range, as the input and output of Gate Bootstrapping. Then, after converting to LEVEL0 at the beginning of Gate Bootstrapping, the ciphertext is not returned to LEVEL0 at the end. By not returning to LEVEL0, the calculation of the TLWE ciphertext can be performed safely in the next stage as well. The time required for BlindRotate is proportional to the number of coefficients (vector degree) of the input TLWE ciphertext, because the number of CMux is the same as the degree. Therefore, when the ciphertext of LEVEL1 is input, the time required for BlindRotate is longer in proportion to the number of coefficients (vector degree) than when the ciphertext of LEVEL0 is input. Even if the LEVEL1 ciphertext is used as the input for Gate Bootstrapping to ensure the security of the ciphertext, the increase in the required time can be avoided by performing BlindRotate using the LEVEL0 TLWE ciphertext converted by Public Key Switching as the input.

[0116] Furthermore, reducing the error added to the plaintext poses the problem of errors during decryption in addition to the security strength mentioned above. As described above, in TFHE applied to the integer-wise type, the range of values ​​from 0 to 1 corresponding to the circular group {T} is divided into 2t parts. By increasing the value of t and dividing the circular group into smaller parts, the integer values ​​that can be recorded in the TLWE ciphertext can be made larger. The maximum value that can be stored is determined by the number of parts t into which the circular group is divided, but when trying to store a large value, the error range must be made smaller, which can lead to problems such as a decrease in security strength and an increase in the decryption error rate. In homomorphic encryption of the LWE system, including TFHE, the errors added to the plaintext are normally distributed, and it is not possible to strictly set the "error range." Although the error still tends to be concentrated near 0, in principle, this simply makes it possible to concentrate the error more in the specified range. If the error falls outside the set range, the plaintext will be interpreted as a different plaintext, which may result in unexpected calculation results. The calculation itself does not become impossible, but rather a different result is obtained. How much of a probability of obtaining a different calculation result can be tolerated is up to the application to which homomorphic encryption is applied.

[0117] In order to best balance the three goals of reducing the probability of errors occurring in calculations, reducing the number of BlindRotates to speed up calculations, and maintaining high security, it is necessary to set the system parameters so that the overlap of the error ranges falls within a certain value. The error may be set so as to satisfy conditions that are of particular importance depending on the system or device to which this embodiment is applied. [Application example] The processing performed by the cryptographic processing device 1 can be applied as follows. For example, consider a case where you want to aggregate data for a specific field within a certain range from a database where the fields and records are encrypted with TLWE encryption (for example, you want to find the average annual income of people aged 30 to 39). In this case, the cryptographic processing device 1 is a database server that manages an encrypted database, accepts queries encrypted with TLWE encryption from a terminal device connected via a network, etc., and returns a response to the query to the terminal device in a state encrypted with TLWE encryption. Indexes cannot be created on encrypted databases, so comparisons and aggregations across the entire database are required.

[0118] The cryptographic processing device 10 performs a comparison operation to compare all records in the encrypted database with the query using the functions of the first calculation unit 12, the second calculation unit 13, the third calculation unit 14, the fourth calculation unit 15, the first bootstrap unit 16, the second bootstrap unit 17, the third bootstrap unit 18, the fourth bootstrap unit 19, the fifth bootstrap unit 21, the sixth bootstrap unit 22, and the key exchange unit 30. The comparison operation is a subtraction between the ciphertexts of the record and the query, and the positive or negative result of the subtraction indicates the equivalence of the comparison operation. The cryptographic processing device 1 can further perform an aggregation operation on records that match the query in the comparison operation. In the aggregation operation, the cryptographic processing device 1 calculates a sum by adding up the records that match the query in the comparison operation, and further calculates an average value using division. Thus, processing a query against an encrypted database requires the four basic arithmetic operations of addition, subtraction, multiplication, division, etc., on the integers that make up the ciphertext, as well as comparisons (which are equivalent to checking whether the result of a subtraction is positive or negative). In particular, when calculating a weighted average value, multiplication of the record and the weighting coefficient is required. When bit-wise ciphertext is used, full adder operations are likely to be used frequently in the processing. The number of full adders required increases as the bit length of the integers handled increases. The four arithmetic operations are homomorphic arithmetic operations between encrypted numerical values ​​that are regarded as the ciphertext of each bit when the permutation using the input ciphertext is expressed in binary. The cryptographic processing device 1 of this embodiment does not perform arithmetic operations on a bit-by-bit basis using a full adder on bit-wise ciphertext, but performs arithmetic operations and comparisons between integer-wise ciphertexts that have integers as plaintext, thereby making it possible to significantly reduce the execution time of a query.

[0119] Not only in database aggregation, but also in various data processing applications using ciphertext, arithmetic operations and comparisons between integers are frequently used. Other examples include fuzzy authentication and fuzzy search. Fuzzy authentication is, for example, biometric authentication using biometric data, and it is an absolute requirement that the biometric data, which remains unchanged throughout a person's life, be encrypted and kept secret. Fuzzy authentication performs authentication based on the correspondence between the biometric authentication data presented in the authentication request and the biometric authentication data registered in a database, but it does not check for a perfect match between the two, but rather judges whether they match based on a threshold value. Fuzzy search is a vague search method that presents data close to the query as a search result from a database, even if the query and the record do not match exactly. In fuzzy authentication and fuzzy search, like the comparison and aggregation operations in the encrypted database described above, the encrypted database and the query are compared, and the comparison operation must be performed using data encrypted by homomorphic encryption. When calculating the inner product as the degree of match between the presented biometric authentication data and the registered biometric authentication data, multiplication is required.

[0120] In addition, Euclidean distance is often used for comparison in fuzzy authentication and fuzzy search. Calculating Euclidean distance requires a square operation. In bit-wise homomorphic encryption, multiplication takes time of O(N 2) full adder must be operated. Even a comparison operation using a simple subtraction requires the operation of a full adder of O(N). The cryptography processing device 1 of this embodiment does not perform arithmetic operations on a bit-wise ciphertext by using a full adder, but performs arithmetic operations and comparisons between Integer-wise ciphertexts having integers as plaintexts, thereby making it possible to significantly reduce the processing time required for fuzzy authentication and fuzzy search.

[0121] FIG. 15 is a block diagram illustrating an embodiment of a computer device. The configuration of the computer device 100 will be described with reference to FIG. The computer device 100 is, for example, a cryptographic processing device that processes various types of information. The computer device 100 includes a control circuit 101, a storage device 102, a reading / writing device 103, a recording medium 104, a communication interface 105, an input / output interface 106, an input device 107, and a display device 108. The communication interface 105 is connected to a network 200. The components are connected to each other via a bus 110. The cryptographic processing device 1 can be configured by appropriately selecting some or all of the components described in the computer device 100.

[0122] The control circuit 101 controls the entire computer device 100. The control circuit 101 is, for example, a processor such as a Central Processing Unit (CPU), a Field Programmable Gate Array (FPGA), an Application Specific Integrated Circuit (ASIC), or a Programmable Logic Device (PLD). The control circuit 101 functions as, for example, the control unit 10 in FIG.

[0123] The storage device 102 stores various data. The storage device 102 is, for example, a memory such as a Read Only Memory (ROM) and a Random Access Memory (RAM), a Hard Disk (HD), or a Solid State Drive (SSD). The storage device 102 may store an information processing program that causes the control circuit 101 to function as the control unit 10 in Fig. 1. The storage device 102 functions as, for example, the storage unit 20 in Fig. 1.

[0124] When performing information processing, the cryptographic processing device 1 reads out a program stored in the storage device 102 into the RAM. The cryptographic processing device 1 executes a program read into the RAM in the control circuit 101, thereby executing processes including one or more of the reception process, the first calculation process, the second calculation process, the third calculation process, the fourth calculation process, the first bootstrap processing, the second bootstrap processing, the third bootstrap processing, the fourth bootstrap processing, the fifth bootstrap processing, the sixth bootstrap processing, the key exchange process, and the output process. The program may be stored in a storage device of a server on the network 200 as long as the control circuit 101 can access the program via the communication interface 105 .

[0125] The reading / writing device 103 is controlled by the control circuit 101 and reads / writes data from / to a removable recording medium 104 . The recording medium 104 stores various data. For example, the recording medium 104 stores an information processing program. For example, the recording medium 104 is a non-volatile memory (non-transient recording medium) such as a Secure Digital (SD) memory card, a Floppy Disk (FD), a Compact Disc (CD), a Digital Versatile Disk (DVD), a Blu-ray (registered trademark) Disk (BD), or a flash memory.

[0126] The communication interface 105 communicably connects the computer device 100 to other devices via the network 200. The communication interface 105 functions as, for example, the communication unit 25 in FIG. The input / output interface 106 is, for example, an interface that is detachably connected to various input devices. The input devices 107 connected to the input / output interface 106 include, for example, a keyboard and a mouse. The input / output interface 106 communicably connects the various input devices connected to the computer device 100. The input / output interface 106 outputs signals input from the various input devices connected to the control circuit 101 via the bus 110. The input / output interface 106 also outputs signals output from the control circuit 101 to the input / output devices via the bus 110. The input / output interface 106 functions as, for example, the input unit 26 in FIG. 1.

[0127] The display device 108 displays various information. The display device 108 is, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), a plasma display panel (PDP), an organic electroluminescence display (OLED), etc. The network 200 is, for example, a LAN, wireless communication, a P2P network, or the Internet, and communicatively connects the computer device 100 to other devices. It should be noted that the present embodiment is not limited to the embodiment described above, and various configurations or embodiments can be adopted without departing from the spirit of the present embodiment. [Explanation of symbols]

[0128] 1 encryption processing device, 10 control unit, 20 memory unit, 25 communication unit, 26 input unit, 100 computer device, 101 control circuit, 102 storage device, 103 reading / writing device, 104 recording medium, 105 communication interface, 106 input / output interface, 107 input device, 108 display device, 110 bus, 200 network

Claims

1. A cryptographic processing device for processing a ciphertext, comprising: the ciphertext is a fully homomorphic ciphertext that has a value obtained by adding an error having a predetermined variance to a predetermined value as a plaintext associated with an integer and that enables a predetermined operation between integers without decryption, applying a function for obtaining a stepwise polynomial to a multiplier plaintext obtained when a first ciphertext, which is a multiplier, is decrypted, and applying the function for obtaining a ciphertext having as plaintext the first stepwise polynomial, the coefficient of which increases stepwise by the value of the multiplier plaintext, to the first ciphertext, thereby generating a third ciphertext having the first stepwise polynomial as plaintext; a constant term of a polynomial obtained by rotating the coefficients of the plaintext polynomial of the third ciphertext in accordance with the second ciphertext which is a multiplicand, thereby calculating, as a fourth ciphertext which is a calculation result, a ciphertext corresponding to a result of multiplication of the plaintexts of the first ciphertext and the second ciphertext; 4. A cryptographic processing device comprising:

2. A cryptographic processing device for processing a ciphertext, comprising: the ciphertext is a fully homomorphic ciphertext that has a value obtained by adding an error having a predetermined variance to a predetermined value as a plaintext associated with an integer and that enables a predetermined operation between integers without decryption, applying a function for obtaining a stepwise polynomial to a multiplier plaintext obtained when a first ciphertext, which is a multiplier, is decrypted, and applying the function for obtaining a ciphertext having as plaintext the first stepwise polynomial, the coefficient of which increases stepwise by the value of the multiplier plaintext, to the first ciphertext, thereby generating a third ciphertext having the first stepwise polynomial as plaintext; a fifth ciphertext is homomorphically added to a ciphertext calculated by extracting a constant term of a polynomial obtained by circulating a coefficient of a plaintext polynomial of the third ciphertext in accordance with the second ciphertext which is a multiplicand, thereby calculating, as a fourth ciphertext of the operation result, a ciphertext corresponding to a result of a fused multiply-add operation between the plaintexts of the first ciphertext, the second ciphertext, and the fifth ciphertext; 4. A cryptographic processing device comprising:

3. 2. The cryptographic processing device according to claim 1, 2. The cryptographic processing device according to claim 1, wherein an offset of 1 / 2 is added to the coefficients of the first step polynomial.

4. 4. The cryptographic processing device according to claim 3, calculating a new first ciphertext in which the order of negative plaintexts is reversed from the first ciphertext by using a second stepwise polynomial having a coefficient offset of 1 / 2 for the first ciphertext; calculating the third ciphertext having the first step polynomial as a plaintext based on the new first ciphertext; 4. A cryptographic processing device comprising:

5. 2. The cryptographic processing device according to claim 1, calculating a sixth ciphertext based on a result of a homomorphic operation between the fourth ciphertext and a new ciphertext obtained by multiplying the fourth ciphertext by a predetermined number, the new ciphertext being calculated by extracting a constant term of a polynomial obtained by circulating coefficients of the plaintext polynomial of the third ciphertext in accordance with the second ciphertext; 4. A cryptographic processing device comprising:

6. 3. The cryptographic processing device according to claim 2, a sixth ciphertext is calculated based on a result of a homomorphic operation between the fourth ciphertext and a new ciphertext calculated by multiplying the fourth ciphertext by a predetermined number by adding the fifth ciphertext to a ciphertext calculated by extracting a constant term of a polynomial obtained by circulating a coefficient of a plaintext polynomial of the third ciphertext in accordance with the second ciphertext and the fourth ciphertext, the new ciphertext being calculated by using a predetermined polynomial on the ciphertext; 4. A cryptographic processing device comprising:

7. 7. The cryptographic processing device according to claim 5, the sixth ciphertext is a remainder obtained by dividing a result of the multiplication by the predetermined number, and when the predetermined number is a power of 2, is a lower-order bit of the result of the multiplication; 4. A cryptographic processing device comprising:

8. 7. The cryptographic processing device according to claim 5, a seventh ciphertext is calculated based on a result of a homomorphic operation performed on the fourth ciphertext by using a predetermined polynomial on the sixth ciphertext to calculate a new ciphertext; 4. A cryptographic processing device comprising:

9. 9. The cryptographic processing device according to claim 8, the seventh ciphertext is a quotient obtained by dividing the multiplication result by the predetermined number, and if the predetermined number is a power of 2, is the most significant bit of the multiplication result; 4. A cryptographic processing device comprising:

10. 3. The cryptographic processing device according to claim 1, a calculation unit that calculates a new ciphertext by using a predetermined polynomial on the ciphertext, the calculation unit performing a process of reducing the number of coefficients on the input ciphertext before calculating the new ciphertext by using the predetermined polynomial; 4. A cryptographic processing device comprising:

11. 3. The cryptographic processing device according to claim 1, By performing the predetermined calculation, a process related to fuzzy authentication or fuzzy search is performed using the input ciphertext.

4. A cryptographic processing device comprising:

12. 3. The cryptographic processing device according to claim 1, performing the predetermined operation to process a query to an encrypted database based on the input ciphertext; 4. A cryptographic processing device comprising:

13. 3. The cryptographic processing device according to claim 1, By carrying out the predetermined calculation, a Karatsuba algorithm is carried out based on the input ciphertext.

4. A cryptographic processing device comprising:

14. 1. A processor-implemented cryptographic processing method for processing ciphertext, comprising: the ciphertext is a fully homomorphic ciphertext that has a value obtained by adding an error having a predetermined variance to a predetermined value as a plaintext associated with an integer and that enables a predetermined operation between integers without decryption, The processor, applying a function for obtaining a stepwise polynomial to a multiplier plaintext obtained when a first ciphertext, which is a multiplier, is decrypted, and applying the function for obtaining a ciphertext having as plaintext the first stepwise polynomial, the coefficient of which increases stepwise by the value of the multiplier plaintext, to the first ciphertext, thereby generating a third ciphertext having the first stepwise polynomial as plaintext; a constant term of a polynomial obtained by rotating the coefficients of the plaintext polynomial of the third ciphertext in accordance with the second ciphertext which is a multiplicand, thereby calculating, as a fourth ciphertext which is a calculation result, a ciphertext corresponding to a result of multiplication of the plaintexts of the first ciphertext and the second ciphertext; 13. A cryptographic processing method comprising:

15. 1. A processor-implemented cryptographic processing method for processing ciphertext, comprising: the ciphertext is a fully homomorphic ciphertext that has a value obtained by adding an error having a predetermined variance to a predetermined value as a plaintext associated with an integer and that enables a predetermined operation between integers without decryption, The processor, applying a function for obtaining a stepwise polynomial to a multiplier plaintext obtained when a first ciphertext, which is a multiplier, is decrypted, and applying the function for obtaining a ciphertext having as plaintext the first stepwise polynomial, the coefficient of which increases stepwise by the value of the multiplier plaintext, to the first ciphertext, thereby generating a third ciphertext having the first stepwise polynomial as plaintext; a fifth ciphertext is homomorphically added to a ciphertext calculated by extracting a constant term of a polynomial obtained by circulating a coefficient of a plaintext polynomial of the third ciphertext in accordance with the second ciphertext which is a multiplicand, thereby calculating, as a fourth ciphertext of the operation result, a ciphertext corresponding to a result of a fused multiply-add operation between the plaintexts of the first ciphertext, the second ciphertext, and the fifth ciphertext; 13. A cryptographic processing method comprising:

16. A cryptographic processing program for causing a processor to execute a cryptographic processing method for processing a ciphertext, the ciphertext is a fully homomorphic ciphertext that has a value obtained by adding an error having a predetermined variance to a predetermined value as a plaintext associated with an integer and that enables a predetermined operation between integers without decryption, The processor, applying a function for obtaining a stepwise polynomial to a multiplier plaintext obtained when a first ciphertext, which is a multiplier, is decrypted, and applying the function for obtaining a ciphertext having as plaintext the first stepwise polynomial, the coefficient of which increases stepwise by the value of the multiplier plaintext, to the first ciphertext, thereby generating a third ciphertext having the first stepwise polynomial as plaintext; a constant term of a polynomial obtained by rotating the coefficients of the plaintext polynomial of the third ciphertext in accordance with the second ciphertext which is a multiplicand, thereby calculating, as a fourth ciphertext which is a calculation result, a ciphertext corresponding to a result of multiplication of the plaintexts of the first ciphertext and the second ciphertext; 4. A cryptographic processing program comprising:

17. A cryptographic processing program for causing a processor to execute a cryptographic processing method for processing a ciphertext, the ciphertext is a fully homomorphic ciphertext that has a value obtained by adding an error having a predetermined variance to a predetermined value as a plaintext associated with an integer and that enables a predetermined operation between integers without decryption, The processor, applying a function for obtaining a stepwise polynomial to a multiplier plaintext obtained when a first ciphertext, which is a multiplier, is decrypted, and applying the function for obtaining a ciphertext having as plaintext the first stepwise polynomial, the coefficient of which increases stepwise by the value of the multiplier plaintext, to the first ciphertext, thereby generating a third ciphertext having the first stepwise polynomial as plaintext; a fifth ciphertext is homomorphically added to a ciphertext calculated by extracting a constant term of a polynomial obtained by circulating a coefficient of a plaintext polynomial of the third ciphertext in accordance with the second ciphertext which is a multiplicand, thereby calculating, as a fourth ciphertext of the operation result, a ciphertext corresponding to a result of a fused multiply-add operation between the plaintexts of the first ciphertext, the second ciphertext, and the fifth ciphertext; 4. A cryptographic processing program comprising:

18. A cryptographic processing device for processing a ciphertext, comprising: the ciphertext is a fully homomorphic ciphertext that has a value obtained by adding an error having a predetermined variance to a predetermined value as a plaintext associated with an integer and that enables a predetermined operation between integers without decryption, calculating an eighth ciphertext having the polynomial as a plaintext by cycling through coefficients of a predetermined polynomial according to the first ciphertext, which is a multiplier; Multiplying each element of the eighth ciphertext by each element of the ciphertext based on the second ciphertext, which is the multiplicand, calculating a fourth ciphertext corresponding to a result of multiplication of the first ciphertext and the second ciphertext; 4. A cryptographic processing device comprising:

Citation Information

Patent Citations

  • Secure computation device, secure computation method, and secure computation program

    JP2021026082A

  • Secure computing device, secure computing method, and secure computing program

    JP2021113956A