Encryption device, encryption method, and encryption program
By excluding random and noise components from the master public key and adding symmetric key-type noise to public key ciphertexts, the encryption device reduces ciphertext size in fully homomorphic encryption systems, addressing the inefficiency of larger noise in public-key ciphers.
Patent Information
- Application Number
- JP2022154468
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-09-28
- Publication Date
- 2025-06-11
- Estimated Expiration
- 2042-09-28
AI Technical Summary
In fully homomorphic encryption systems using lattice cryptography with multiple distributed keys, the larger noise in public-key ciphers results in larger ciphertext sizes, which is inefficient compared to symmetric-key ciphers.
An encryption device generates an encryption key by excluding the random and noise components corresponding to its distributed secret key from the master public key, and then adds a symmetric key-type random and noise component to a public key ciphertext to reduce noise and ciphertext size.
This approach reduces the size of the ciphertext in fully homomorphic operation systems, especially as the number of users decreases, allowing for more efficient data transmission and processing.
Smart Images

Figure 0007691400000017 
Figure 0007691400000018 
Figure 0007691400000019
Abstract
Description
Technical Field
[0001] The present invention relates to a fully homomorphic operation system using lattice cryptography with a plurality of distributed keys.
Background Art
[0002] The threshold fully homomorphic encryption (ThFHE) is a fully homomorphic encryption (FHE) extended for use by a plurality of users. The configuration of ThFHE is shown in Non-Patent Documents 1 and 2 and the like. Here, the LWE cryptography is a cryptography serving as a basis for constructing ThFHE, and can be configured as both symmetric-key cryptography and public-key cryptography.
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Non-Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] The LWE cipher can be configured as either a symmetric-key cipher or a public-key cipher. However, since the noise of the ciphertext is larger in the public-key cipher than in the symmetric-key cipher, it was necessary to set the ciphertext size (modulus q) relatively large. For this reason, in FHE, since the user on the data transmission side holds the secret key, it is common to use a lighter symmetric-key cipher type encryption algorithm. On the other hand, in ThFHE, due to its structure, only a public-key cipher type encryption algorithm can be used, so there was a problem that the ciphertext size becomes larger compared to the symmetric-key cipher type encryption algorithm.
[0005] An object of the present invention is to provide an encryption device, an encryption method, and an encryption program capable of reducing the size of a ciphertext in a fully homomorphic operation system using lattice ciphers with a plurality of distributed keys.
Means for Solving the Problems
[0006] The encryption device according to the present invention generates an encryption key by excluding a random component and a noise component corresponding to the distributed secret key held by the device itself from the master public key in the lattice encryption corresponding to a plurality of distributed secret keys. The encryption device includes a key generation unit and a ciphertext generation unit. The ciphertext generation unit generates a ciphertext obtained by adding a random component and a noise component of a symmetric key type based on the distributed secret key held by the device itself to a public key ciphertext based on the encryption key.
[0007] The lattice encryption may be a threshold fully homomorphic encryption scheme.
[0008] The encryption method according to the present invention includes a key generation step and a ciphertext generation step. In the key generation step, an encryption device generates an encryption key by excluding a random component and a noise component corresponding to the distributed secret key held by the device itself from the master public key in the lattice encryption corresponding to a plurality of distributed secret keys. In the ciphertext generation step, the encryption device generates a ciphertext obtained by adding a random component and a noise component of a symmetric key type based on the distributed secret key held by the device itself to a public key ciphertext based on the encryption key.
[0009] The encryption program according to the present invention is for causing a computer to function as the encryption device.
Advantages of the Invention
[0010] According to the present invention, in a fully homomorphic operation system using lattice encryption with a plurality of distributed keys, the size of the ciphertext can be reduced.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Embodiment for Carrying Out the Invention
[0012] Hereinafter, an example of an embodiment of the present invention will be described. In the encryption method of this embodiment, as an example of the fully homomorphic encryption method, ThFHE will be improved, but it is not limited to this, and it is also applicable to other encryption algorithms using lattice encryption that constitute a fully homomorphic operation system.
[0013] [ThFHE Algorithm] First, for comparison with this embodiment, the configuration of a secret calculation system using ThFHE will be described.
[0014] FIG. 3 is a diagram showing the configuration of a secret calculation system in which a plurality of users participate, using conventional ThFHE. In ThFHE, it is possible to set various decryption methods. For example, it is also possible to set a configuration that enables decryption only with a distributed secret key of t out of N people (threshold) (t-out-of-N). Here, a configuration of N-out-of-N will be exemplified.
[0015] Each user (party 1 to N) has its own secret key (distributed secret key) sk i and encrypts the data m i (including sensitive information) using the public key pk i corresponding to the secret keys sk of all users, i to calculate the master public key jpk := (pk 1 +... + pk N ) (1).
[0016] The operator (Evaluator) performs a homomorphic operation f(m 1 +... + m N ) using the operation key evk generated by all users and the master public key jpk, with the ciphertext received from all users as the input (2). The operator sends the ciphertext ct after the operation to all users (3).
[0017] Each user uses its own secret key ski Perform partial decryption (PartDec) using it and send the partially decrypted text to all users (4). Each user integrates the partially decrypted texts of all users obtained and obtains the plaintext of the calculation result (FinDec) (5).
[0018] Here, the cryptographic system LWE that is the basis of ThFHE is defined as follows. ·params=(1 λ ,q,m,n,χ LWE ,χ rand ): params is a group of parameters that are implicitly used in all the following cryptographic algorithms. 1 λ is the security parameter, q = q(λ) is the modulus, m = m(λ), n = n(λ) are the dimensions, χ LWE =χ LWE (λ), χ rand =χ rand (λ) is a probability distribution over Z q . Note that Gaussian noise is often used for χ LWE , and for the noise χ rand used for public-key encryption, U({0,1}) or the same Gaussian noise as χ LWE is often used.
[0019] ·A←U(Z q m×n ): It is a fixed random public matrix in the scheme and is generated and fixed before key generation.
[0020] ·sk←LWE.SymKeyGen(1 λ ): Generate a uniformly random secret key sk := s ← U(Z q n ).
[0021] ·pk←LWE.PubKeyGen(sk): Sample noise e ← χ LWE m and calculate t = As + e, and output the public key pk := (A, t).
[0022] ·ct ← LWE.SymEnc(sk, m ∈ {0, 1}): a ← U(Z q n ), e ← χ LWE Sample the following and output the ciphertext of the common key cryptosystem type.
Number
[0023] ·ct ← LWE.PubEnc(pk, m ∈ {0, 1}): r ← χ rand m Sample the following and output the ciphertext of the public key cryptosystem type.
Number
[0024] ·m ← LWE.Dec(sk, ct): Output the following plaintext.
Number
[0025] Based on such LWE encryption, the key generation, encryption, and decryption algorithms of ThFHE can be described as follows. Here, the number of users is N, and each user is represented as (P 1 , …, P N ).
[0026] ·(Key Generation) (sk 1 , …, sk N , jpk) ← ThFHE.KeyGen(1 λ ): Each user P i generates its own unique secret key sk i . sk i ← LWE.SymKeyGen(1 λ ) Next, each user P iis e i ←χ LWE m is sampled, and sk i is used to generate the "partial" public key pk i as follows. pk i :=(A, t i :=As i +e i )←LWE.PubKeyGen(sk i ) And the master public key jpk (joint public key) is generated as follows.
Number
[0027] ·(Encryption) ct:=(a, b)←ThFHE.Enc(jpk:=(A, t * ), m∈{0, 1}): This algorithm is the same as the aforementioned LWE.PubEnc(jpk, m∈{0, 1}). That is, r←χ rand m is sampled and the following public key encryption ciphertext is output.
Number
Number
[0028] ·(Decryption) m←ThFHE.Dec(ct:=(a, b), sk 1 , …, sk N ): (PartDec): Each user P i broadcasts the partial decryption text p i =a T s i +e i ’ to all users. Here, e i ’←χ LWE is. (FinDec): Partial decryption text p of all obtained users 1 ,…,p N From [Number] Calculate and output. Note that [Number] Holds.
[0029] [Improved encryption algorithm] In this embodiment, by replacing the encryption algorithm ThFHE.Enc in the conventional ThFHE with the following ThFHE.HybridEnc, the magnitude of the noise in the ciphertext is made smaller than before, and as a result, the size of the ciphertext is also reduced.
[0030] Note that the user with the secret key sk with subscript j∈[N] is denoted as P j j And denoted as. Also, assume that P j holds the "partial" public key pk that is an intermediate product of ThFHE.KeyGen j .
[0031] ·ct←ThFHE.HybridEnc(jpk:=(A,t * ),pk j :=(A,t j ),sk j :=s j ,m∈{0,1}): Preparation: User P j uses, as its own encryption key instead of the master public key, [Number] To generate. Note that by generating and holding this encryption key by P j during key generation etc., this step can be omitted during the encryption process.
[0032] Encryption: User P j samples r←χ LWE m , e  ̄ ←χ LWE and outputs them as ciphertexts, where [Number] holds. Here, [Number] is satisfied. Note that the decryption algorithm does not need to be changed and can be executed by ThFHE.Dec.
[0033] FIG. 1 is a diagram showing the functional configuration of the encryption device 1 in the present embodiment. The encryption device 1 is a terminal used by each of a plurality of users who encrypt and provide data including sensitive information in a secure computing system and entrust homomorphic operations to an operator, and is an information processing device (computer) provided with various input / output and communication interfaces in addition to a control unit 10 and a storage unit 20.
[0034] The control unit 10 is a part that controls the entire encryption device 1, and realizes each function in the present embodiment by appropriately reading and executing various programs stored in the storage unit 20. The control unit 10 may be a CPU.
[0035] The storage unit 20 is a storage area for various programs and various data for causing the hardware group to function as the encryption device 1, and may be a ROM, a RAM, a flash memory, a hard disk drive (HDD), or the like. Specifically, the storage unit 20 stores, in addition to a program (encryption program) for causing the control unit 10 to execute each function of the present embodiment, user data to be encrypted, various key data for encryption and decryption, and the like.
[0036] The control unit 10 includes a key generation unit 11 and a ciphertext generation unit 12. The key generation unit 11 generates an encryption key jpk by excluding the random component (As j ) and the noise component (e j ) corresponding to the distributed secret key sk held by the local terminal from the master public key jpk in a lattice cryptosystem (e.g., ThFHE) corresponding to a plurality of distributed secret keys. j ) for the encryption key jpk  ̄ j .
[0037] The ciphertext generation unit 12 generates a ciphertext by adding the common key cryptography type random component (as
Number
[0038]
Number
[0039] As a result,
Number
Number
[0040] FIG. 2 is a diagram showing the magnitude of the noise on the ciphertext in the present embodiment in comparison with the conventional method. Here, as a general setting, Var(χ LWE ):=σ 2 ,Var(χ rand) When set to \(O(1)\), the results of comparing the noise magnitude on the ciphertext between the conventional ThFHE.Enc and the ThFHE.HybridEnc of this embodiment are illustrated. When \(m\) is sufficiently large, the obtained noise reduction effect ratio is
Number
[0041] According to this embodiment, the encryption device 1 generates an encryption key excluding the random component and the noise component corresponding to the distributed secret key held by its own terminal from the master public key in the lattice encryption corresponding to a plurality of distributed secret keys, and generates a ciphertext obtained by adding the common key type random component and the noise component based on its own distributed secret key to the public key type ciphertext based on this encryption key. Therefore, when the \(m\)-dimensional noise in the public key encryption algorithm becomes large due to further accumulation according to the number of users, the encryption device 1 replaces the noise component corresponding to its own secret key with the scalar noise component in the common key encryption algorithm, thereby reducing the overall noise magnitude. As a result, the encryption device 1 can reduce the size of the ciphertext in a fully homomorphic operation system using lattice encryption with a plurality of distributed keys.
[0042] For example, in a secret calculation system using a fully homomorphic encryption method using multiple keys such as ThFHE, by applying the encryption algorithm of this embodiment that fuses the common key encryption algorithm and the public key encryption algorithm, the size of the ciphertext can be reduced especially as the number of users decreases.
[0043] Note that, as a result, for example, a user on the data transmission side can use a lighter encryption algorithm than before, which makes it possible to contribute to Goal 9 of the United Nations Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization, and foster innovation."
[0044] As described above, the embodiments of the present invention have been explained. However, the present invention is not limited to the above-described embodiments. Also, the effects described in the above-described embodiments are merely an enumeration of the most suitable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0045] The encryption method by the encryption device 1 is realized by software or a hardware circuit. When realized by software, the program constituting this software is installed in an information processing device (computer). Also, these programs may be recorded on a removable medium such as a CD-ROM and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Further, these programs may be provided to the user's computer as a web service via a network without being downloaded.
Explanation of Reference Numerals
[0046] 1 Encryption device 10 Control unit 11 Key generation unit 12 Ciphertext generation unit 20 Storage unit
Claims
1. A key generation unit that generates an encryption key by excluding a random component and a noise component corresponding to the distributed secret key held by the own device from the master public key in a lattice cryptography corresponding to a plurality of distributed secret keys; An encryption device comprising: an encrypted text generation unit that generates an encrypted text obtained by adding a random component and a noise component of a symmetric key type based on the distributed secret key held by the own device to an encrypted text of a public key cryptography type based on the encryption key.
2. The encryption device according to claim 1, wherein the lattice cryptography is a threshold fully homomorphic encryption method.
3. An encryption method in which an encryption device executes a key generation step of generating an encryption key by excluding a random component and a noise component corresponding to the distributed secret key held by the own device from the master public key in a lattice cryptography corresponding to a plurality of distributed secret keys; and an encrypted text generation step of generating an encrypted text obtained by adding a random component and a noise component of a symmetric key type based on the distributed secret key held by the own device to an encrypted text of a public key cryptography type based on the encryption key.
4. An encryption program for causing a computer to function as the encryption device according to claim 1 or claim 2.
Citation Information
Patent Citations
Apparatus for performing threshold design on secret key and method thereof
US20200266974A1
Secure distributed key generation for multiparty homomorphic encryption
US20210399874A1
Decentralized multi-authority attribute-based encryption
WO2022076327A1