Polynomial Multiplication of Encrypted Values
By generating masking polynomials in the Fourier domain and using number-theoretic transforms, the method addresses noise management challenges in homomorphic encryption, achieving secure and efficient polynomial multiplication and reduced storage requirements.
Patent Information
- Application Number
- JP2024535247
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-12-13
- Filing Date
- 2022-11-07
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-11-07
AI Technical Summary
Existing homomorphic encryption methods face challenges in efficiently managing noise levels during multiple operations, which can lead to decryption issues and security vulnerabilities.
The proposed method involves generating a representation of the masking polynomial in the Fourier domain using a pseudorandom number generator, allowing for efficient polynomial multiplication and reduced noise levels through the use of number-theoretic transforms.
This approach enables secure and compactly represented ciphertexts, facilitating efficient polynomial multiplication and reducing the memory footprint of bootstrapping keys, thereby enhancing the security and efficiency of homomorphic encryption operations.
Smart Images

Figure 0007699722000151 
Figure 0007699722000152 
Figure 0007699722000153
Abstract
Description
Technical Field
[0001] The subject matter of the present disclosure relates to computer-implemented encryption calculation methods, computer-implemented methods for calculating ciphertext representations, corresponding devices, and computer-readable media.
Background Art
[0002] Homomorphic encryption methods enable encryption calculations: calculations performed on data encrypted by a party on data that the party cannot decrypt, such as circuit evaluation. For example, input data and calculation results can be received and returned in encrypted form. Intermediate data, such as the internal state of the calculation, can also be in encrypted form.
[0003] Despite the calculation result being returned in encrypted form, the output upon decryption is expected to be the same or very close to that which would occur if the operation were performed on unencrypted data. Homomorphic encryption methods can be used for privacy-protecting outsourced storage and calculation. This enables data to be encrypted and, while encrypted, to be outsourced to a cloud environment for processing and / or storage.
[0004] For example, homomorphic encryption methods may be applied in fields such as healthcare where privacy regulations may make it difficult to share plain data, but calculations on encrypted medical data may be allowed. For example, a medical model deployed to classify medical data, for example, may be configured to receive medical data in an encrypted form from a third party, such as a hospital. The medical model may classify medical data, for example, as normal or abnormal, or as having some specific medical syndrome, disease, or other disorder. Using homomorphic encryption methods, the medical model may be applied to medical data received in encrypted form. This means that the party providing the medical model does not have access to the plain medical data corresponding to the encrypted medical data. The user of the service may decrypt the result of the medical model application.
[0005] In particular, there exist homomorphic encryption method technologies that can be used, at least in principle, to compute any function on encrypted data. Such technologies are referred to as "fully homomorphic encryption" (FHE) technologies.
[0006] Known embodiments of FHE use noisy ciphertexts for security reasons. For example, the encryption of a data item may include mapping the data item to a point within a key-dependent lattice, and noise is added to that point. In particular, many known embodiments of FHE use Generalized Learning With Errors (GLWE)-based ciphertexts, such as Ring Learning With Errors (RLWE) ciphertexts, and their security depends on the cryptographic hardness of the Generalized Learning With Errors problem, in particular, the RingLWE (RLWE) problem of RLWE-based ciphertexts. Such "GLWE-based" or "GLWE-type" ciphertexts may include a body polynomial that is derived from a mask polynomial and a plaintext and includes noise, in addition to one or more mask polynomials.
[0007] When a data item has just been encrypted, the noise is low and the encryption is fresh. For example, when the data item is decrypted, the amount of noise at a certain point in the decryption process can be small enough to be removed, e.g., by rounding. On the other hand, the noise should be high enough to make attacks on the system sufficiently difficult. For example, if there is no noise, many homomorphic encryption schemes may be attacked with linear algebra or other efficient algorithms, such as lattice reduction algorithms. When the data item is encrypted, noise is added that is selected such that homomorphic operations can still be performed while attacks are difficult.
[0008] Most homomorphic operations increase the noise inherent in the homomorphically encrypted data item. When many such operations are performed, the noise can reach a level where unique decryption is no longer possible. In general, it is known to use a technique called bootstrapping to reduce the noise of homomorphically encrypted values. Bootstrapping may use a public key called a bootstrapping key. By using bootstrapping to reduce the noise when necessary, it is possible in principle to compute any desired number of homomorphic operations.
[0009] A particular class of fully homomorphic encryption schemes is a homomorphic encryption scheme similar to TFHE. Such a scheme is described in I. Chillotti et al., "TFHE: Fast fully homomorphic encryption over the torus", J. Cryptol, 33(1): 34-91, 2020 (incorporated herein by reference). Schemes similar to TFHE are distinguished from other FHE schemes by supporting a relatively very efficient technique for bootstrapping. This bootstrapping technique can reduce the noise in the LWE-encrypted input values by homomorphically evaluating the LWE decryption of the exponent of a GLWE-encrypted monomial, resulting in an LWE-encrypted output value with a noise amount independent of the noise in the LWE-encrypted input values. TFHE bootstrapping is also programmable in the sense that the output value can be the result of applying a function to the input value. An example of such programmable bootstrapping is described in I. Chillotti et al., "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks", Cyber Security Cryptography and Machine Learning (CSCML 2021), vol. 12716 of Lecture Notes in Computer Science, pp. 1-19, Springer, 2021 (incorporated herein by reference).
[0010] TFHE programmable bootstrapping relies on the calculation of the so-called external product of a GGSW-type (generalized GSW-type, e.g., RGSW-type) ciphertext C using a GLWE-based ciphertext c. In general, for example, as described in "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks", the GGSW-type ciphertext C that encrypts a plaintext contains a plurality of GLWE-based ciphertexts c that encrypt respective values based on the plaintext. i The calculation of the external product involves multiplying each GLWE-based ciphertext c i by each multiplicand polynomial based on the GLWE-based ciphertext c (used to calculate the GGSW-type ciphertext). To perform these polynomial multiplications efficiently, TFHE employs a fast Fourier transform (FFT) for complex numbers using roots of unity ω j where
Number
[0011] The bootstrapping key used for programmable bootstrapping contains a large number of GGSW ciphertexts and itself contains a large number of GLWE-based ciphertexts, so the bootstrapping key is relatively large to store and transfer. For example, in the case of typical TFHE parameters, the bootstrapping key can be about 62 MB in size. However, this size can be reduced by defining the coefficients of the masking polynomial as the output of a pseudorandom function. Only the seed of the pseudorandom function then needs to be stored later. When using the key, the pseudorandom function is then evaluated to obtain the coefficients of the masking polynomial, and this representation is transformed into the complex evaluation of the masking polynomial with respect to the complex roots of unity where the FFT is performed. For example, when using RingLWE, the size of the bootstrapping key can be reduced to about 31 MB, which is about half, for typical parameters.
Prior Art Documents
Patent Documents
[0012]
Patent Document 1
Patent Document 2
Non-Patent Documents
[0013]
Non-Patent Document 1
Non-Patent Document 2
Summary of the Invention
Means for Solving the Problems
[0014] According to one aspect of the invention, a computer-implemented cryptographic calculation method is provided as defined by the claims. According to a further aspect of the invention, a computer-implemented method for calculating a representation of a ciphertext is provided as defined by the claims. According to a further aspect, a device for these computer-implemented methods is provided as defined by the claims. According to another aspect, a computer-readable medium is provided as defined by the claims.
[0015] The calculation method may involve, for example, polynomial multiplication of GLWE-based ciphertexts as part of the outer product of GGSW-type ciphertexts containing the ciphertext. The ciphertext may include one or more random mask polynomials and a body polynomial derived from the mask polynomial and the plaintext. The polynomial multiplication may involve multiplying the mask polynomial and the body polynomial of the ciphertext with respective multiplicand polynomials, for example, a common multiplicand polynomial.
[0016] The ciphertext can be stored in memory as data. For example, the data may be retrieved from persistent storage such as a hard drive, or the data may be received in advance from another party, such as the party that computed the ciphertext, and stored in volatile memory such as RAM. In any case, it is desirable for the stored data to be as small as possible. As described above, the ciphertext can be stored relatively efficiently when the party computing the ciphertext generates the coefficients of the masking polynomial using a pseudo-random number generator (PRNG); preferably a cryptographic PRNG. Instead of including the masking polynomial in the stored data, the seed can then be stored instead. However, in order to efficiently compute polynomial multiplication using the FFT, the coefficients of the masking polynomial need to be first transformed to the Fourier domain, i.e., the evaluation of these polynomials at the complex roots of unity.
[0017] The inventors recognized two important things. First, that it is also possible to define the stored data of the ciphertext such that the PRNG does not generate a masking polynomial in regular coefficient representation, but instead generates a representation of the masking polynomial in the Fourier domain, e.g., as the evaluation of a polynomial within a set of evaluation values. For this purpose, when encrypting the plaintext, the body polynomial can be computed such that the ciphertext is a correct encryption of the plaintext with respect to a masking polynomial generated in the Fourier domain according to the PRNG, as opposed to with respect to a masking polynomial whose coefficients are obtained from the PRNG.
[0018] In particular, for encryption, the PRNG can be applied according to a seed for generating a representation of the masking polynomial in the Fourier domain. These representations can be transformed to their regular coefficient representations. The coefficient representations may themselves be used to encrypt the plaintext based on a known random masking polynomial, resulting in a body polynomial in coefficient representation. The body polynomial may then be transformed back to the Fourier domain and output together with the seed as the representation of the ciphertext.
[0019] In order to perform the polynomial multiplication of the ciphertext represented in this way, it may be sufficient to expand the representation by directly generating the representation of the mask polynomial in the Fourier domain using a pseudorandom number generator according to the seed. The polynomial products of the mask polynomial and each multiplicand polynomial of the body polynomial can be efficiently calculated in the Fourier domain. The polynomial products can result in a Fourier domain representation of the calculated polynomial products. These representations may then be output in the Fourier domain representation or, if desired, inversely transformed into the coefficient representation. Interestingly, the conversion of the ciphertext in use to the Fourier domain is no longer essential, and it becomes more efficient to use the ciphertext. This conversion is efficiently performed here during the encryption of the ciphertext. The ciphertext can still be efficiently stored by remembering the seed. Once encrypted, such ciphertext can be reused many times, for example when used as a bootstrapping key and / or by a number of different parties, which is a valuable trade-off.
[0020] A second important insight made by the inventors is that, for security reasons, it is beneficial to use the Fourier domain of the number-theoretic transform instead of using the Fourier domain of the complex FFT as is currently done in a similar manner in TFHE. The number-theoretic transform is a technique known per se for performing efficient multiplication in polynomial rings. To perform polynomial multiplication using the NTT, the polynomial can be represented in the Fourier domain representation of the NTT. Typically, the Fourier domain representation of a polynomial includes several respective evaluations of the polynomial at several respective evaluation points. In the case of the Fourier domain representation, the polynomial can be efficiently multiplied, for example, by multiplication for each evaluation point. Furthermore, using the NTT, it is possible to efficiently calculate the Fourier domain representation of a polynomial from its coefficient representation (by applying the number-theoretic transform itself), and it is possible to efficiently calculate the coefficient representation from the Fourier domain representation (using the inverse number-theoretic transform).
[0021] The discrete Fourier transform (in standard form, defined for the quotient polynomial X n - 1 and prime power modulus q with n|q - 1), see, for example, J. von zur Gathen and J. Gerhard, "Modern Computer Algebra", Cambridge University Press, 3rd edition, 2013, Chapter 8 (incorporated herein by reference insofar as it describes the discrete Fourier transform), and the algorithms of Schonhage and Nussbaumer, see, for example, D. J. Bernstein, "Multidigit multiplication for mathematicians", Unpublished manuscript, available at https: / / cr.yp.to / papers.htmlsha - pum3, August 2001 (incorporated herein by reference insofar as it describes these two algorithms), and various number - theoretic transforms are known per se. Thus, performing polynomial multiplication "using a number - theoretic transform" may generally refer to performing polynomial multiplication in the Fourier domain of the number - theoretic transform, optionally combined with converting a polynomial to the Fourier domain and from this Fourier - domain representation to a polynomial using the NTT and / or its inverse.
[0022] The advantage of using a number - theoretic transform is that generating the Fourier - domain representation of the number - theoretic transform randomly and converting the Fourier - domain representation to a polynomial can lead to a polynomial that is about as random as a random polynomial, that is, when the coefficients are separately and randomly generated. This does not hold for the complex FFT, where the Fourier representation of a uniformly random polynomial is not uniformly distributed.
[0023] Therefore, using a PRNG to generate the representation of the mask polynomial in the Fourier domain of the number-theoretic transform can result in a ciphertext having the same probability distribution as a ciphertext constructed in the normal way with randomly generated coefficients, which does not apply to the complex FFT. Therefore, the problem that the distribution of the ciphertext may leak information about the underlying plaintext is avoided. In this way, a secure and compactly represented ciphertext is obtained, further enabling efficient polynomial multiplication.
[0024] Generalizing from GLWE, the provided technique is applied to ciphertexts that are "similar to GLWE", which means ciphertexts that include a random mask polynomial and a body polynomial. The technique can be applied to situations where the mask polynomial and the body polynomial of such GLWE-similar ciphertexts are each multiplied by a multiplicand polynomial. In particular, the provided technique is applied to an encryption calculation technique that uses stored key material, where the key material includes such ciphertexts, and the key material is used by multiplying the key material by each polynomial.
[0025] In an embodiment, the technique is applied to an encryption calculation “similar to TFHE”. Such an encryption calculation similar to TFHE is characterized by the use of a programmable bootstrapping operation based on evaluating a decryption in the exponent of an encrypted monomial. Specifically, programmable bootstrapping may include a blind rotation that results in an encrypted polynomial product of a test polynomial and a bootstrapping monomial, where the bootstrapping monomial represents a plaintext value as an exponent. This evaluation is calculated using an outer product of GGSW - type ciphertexts of a bootstrapping key. Such GGSW - type ciphertexts may include a plurality of ciphertexts similar to GLWE, and the calculation of the outer product may involve multiplying each ciphertext of the GGSW - type ciphertext with each polynomial. In such a TFHE - like setting, since the bootstrapping keys are relatively large, it is important that they can be stored and transmitted more efficiently. At the same time, since programmable bootstrapping is an important and relatively heavy operation, it is also important that it can be performed efficiently. Using the provided technique, the bootstrapping keys can be stored more efficiently and may enable an efficient application of programmable bootstrapping.
[0026] In an embodiment, the technique is used to obliviously select a first GLWE ciphertext or a second GLWE ciphertext based on a GGSW ciphertext. This oblivious selection can be done by calculating an outer product of the GGSW ciphertext and the difference between the first GLWE ciphertext and the second GLWE ciphertext. Then, the first GLWE ciphertext can be added to the calculated product. This operation is also known as a controlled selector gate or a controlled multiplexer CMux. The CMux operation may be part of programmable bootstrapping, or for example, may be used directly as a gate for homomorphic circuit evaluation.
[0027] In an embodiment, the coefficients of each multiplicand polynomial may be obtained, and the number-theoretic transform may be applied to transform the coefficients of each multiplicand polynomial into the Fourier domain. In this way, a GLWE-based ciphertext can be multiplied by a multiplicand polynomial available in coefficient form. Multiplication in the Fourier domain can typically be performed much more efficiently than in the coefficient domain, even when such a transformation is involved. Additional operations may exist intermediate to the transformation to the Fourier domain and the polynomial multiplication. For example, addition or multiplication (by a constant or a polynomial represented in another Fourier domain) may be applied in the Fourier domain to the multiplicand polynomial before the multiplication.
[0028] In an embodiment, the inverse number-theoretic transform may be applied to transform the Fourier domain representation of the computed polynomial product into the coefficients of the computed polynomial product. In this way, for example, a coefficient representation that can be used in subsequent computations such as sample extraction, key switching, etc. may be obtained. Again, it is possible to perform additional operations in the Fourier domain, such as addition or multiplication, intermediate to the computation of the product and the application of the inverse number-theoretic transform.
[0029] In an embodiment, the expanded stored data representing the GLWE-based ciphertext may be held in memory. The expanded stored data may be used to compute further polynomial products with additional multiplicand polynomials of the mask polynomial and the body polynomial. Thus, for these further polynomial products, it is not necessary to re-expand the stored data, leading to increased efficiency. Still, when the GLWE-based ciphertext needs to be stored again, or when it is desirable to reduce its memory footprint, this can be done by discarding the mask polynomials and storing only the seeds used to generate them.
[0030] In general, the polynomials described herein, for example, the body polynomial and the mask polynomial, may be defined as polynomials modulo a quotient polynomial p(X). For example, the polynomials may be defined as elements of the ring of polynomial quotients R[X] / (p(X)), by
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
[0031] In an embodiment, the quotient polynomial p(X) divides the polynomial X M -1 for a positive integer M, for example, is equal to X M -1, or X Mis a polynomial of lower degree than exactly dividing -1. The number of elements q of the set (e.g.,
Number
Number
Number
[0032] For example, the quotient polynomial can be any quotient polynomial p(X) that divides X M -1, and the Fourier representation of the polynomial can be defined as the set of evaluations of the polynomial within the set of powers of a primitive M-th root of unity. The Fourier representation can be multiplied by point-by-point multiplication at each evaluation point at each power of the primitive M-th root of unity. For the number-theoretic transform between the coefficient representation and the Fourier-domain representation to be efficient, it is advantageous if M contains one or more powers of 2 and / or one or more powers of 3, e.g., if M is a power of 2 or M is a power of 3.
[0033] In some cases, the Fourier representation of a polynomial may involve evaluation at each power of a primitive root of unity. However, this is not essential. In various cases, it is sufficient to use a subset of the powers, which leads to a more efficient Fourier domain representation. This is particularly the case when the quotient polynomial is equal to (X M -1) / (X d -1), where M = hd and d = M - N (and thus N = M - d = (h - 1)d). For example, the quotient polynomial may be (X 2d -1) / (X d -1)=(X d +1)=(X N +1) when h = 2, or (X 3d -1) / (X d -1)=(X 2d +X d +1)=(X N +X N / 2 +1) when h = 3. In such cases, the Fourier domain representation of the polynomial can be defined as the evaluation of the polynomial within only a subset of the powers of the primitive M-th root of unity ω, e.g., ω, ω 3 ,..., ω 2d-1 when h = 2, (ω, ω 2 ), (ω 4 , ω 5 ),..., (ω 3d-2 , ω 3d-1 ) when h = 3. To multiply polynomials, it is sufficient to evaluate only at this subset of the powers of the root of unity, which leads to more efficient polynomial multiplication. Nevertheless, efficient number theoretic transforms and inverses are possible.
[0034] For example, the quotient polynomial X N +1 may be used in combination with a primitive 2N-th root of unity. For example, the number of elements q is the number of elements of the prime field
Number
Number
[0035] The quotient polynomial X N + X N / 2 +1 can be used in combination with an even element q, such as a power of 2. This is beneficial because it enables efficient operations and because the use of a power of 2 is required for some applications.
[0036] In an embodiment, a plurality of GLWE-based ciphertexts can be generated to generate GGSW-type ciphertexts. For example, a plurality of such GGSW-type ciphertexts can be generated to generate a bootstrapping key for TFHE-type programmable bootstrapping, for example, by generating respective GGSW-type ciphertexts that encrypt respective parts of the decryption key. Generally, a GGSW-type ciphertext can be defined as a ciphertext that includes a plurality of GLWE-based ciphertexts that encrypt respective values based on a plaintext. In such a case, the plurality of GLWE-based ciphertexts may be based on the same seed. For example, the same seed may be used to generate respective different random mask polynomials for each ciphertext. Thus, it may be sufficient to store only a single seed for each GGSW-type ciphertext or even for each bootstrapping key, for example, thereby further reducing storage requirements.
[0037] Techniques provided for improved computations on encrypted data can be applied to a wide range of applications. Such applications include the evaluation of encrypted software programs without access to the plain data. For example, medical diagnostic software for medical data can be evaluated without actually accessing the medical data. The medical data can include medical images. The medical images can include, but are not limited to, multi-dimensional image data, such as two-dimensional (2D), three-dimensional (3D), or four-dimensional (4D) images, obtained by various acquisition modalities such as standard X-ray imaging, computed tomography (CT), magnetic resonance imaging (MRI), ultrasound (US), positron emission tomography (PET), single photon emission computed tomography (SPECT), and nuclear medicine (NM).
[0038] In embodiments, the techniques provided can be used to evaluate a neural network against encrypted inputs. Those evaluating the neural network may or may not have access to the plaintext of the trained parameters of the neural network, such as weights and biases. Generally, the techniques provided herein, such as improved polynomial multiplication, programmable bootstrapping, and outer products, improve the efficiency of neural network evaluation and / or reduce storage and transmission requirements for the ciphertexts or key material used.
[0039] Embodiments of the method can be implemented on a computer as a computer-implemented method, or in dedicated hardware, or in a combination of both. Executable code for embodiments of the method can be stored on a computer program product. Examples of computer program products include memory devices, optical storage devices, integrated circuits, servers, offline software, and the like. Preferably, the computer program product includes non-transitory program code stored on a computer-readable medium for performing embodiments of the method when the program product is executed on a computer. In an embodiment, the computer program includes computer program code adapted to perform all or part of the steps of embodiments of the method when the computer program is executed on a computer. Preferably, the computer program is embodied on a computer-readable medium.
[0040] Further details, aspects, and embodiments are described by way of example with reference to the drawings. Elements in the drawings are illustrated for simplicity and clarity and are not necessarily drawn to scale. In the drawings, elements corresponding to elements already described may have the same reference numerals.
Brief Description of the Drawings
[0041]
Figure 1a
Figure 1b
Figure 2
Figure 3a
Figure 3b
Figure 4a
Figure 4b
Figure 5a
Figure 5b
Figure 5c
Figure 5d
[0042] The subject matter of the present disclosure can have many different forms of embodiments. However, it should be understood that the present disclosure should be regarded as an exemplification of the principles of the subject matter of the present disclosure and is not intended to be limited to the specific embodiments shown in the drawings and described in detail herein. One or more specific embodiments will be shown in the drawings and described in detail herein under the understanding that the present disclosure is not intended to be limited to the specific embodiments shown in the drawings and described in detail herein.
[0043] Hereinafter, for the sake of understanding, the elements of the embodiment are described in terms of operations. However, it will become clear that each element is configured to perform the functions described as being performed by them.
[0044] Furthermore, the subject matter of the present disclosure is not limited to only the embodiments, but also includes the features described herein, or any other combination of features listed in different dependent claims.
[0045] The provided technique uses a ciphertext including one or more mask polynomials and body polynomials. The mask polynomial and the body polynomial may be defined, for example, as polynomials modulo a quotient polynomial p(X) over R[X] / (p(X)), where R may be a ring or associated with a ring, for example, **
Number
Number
[0046] As a specific example, the ciphertext is:
Number
Number
Number
Number
[0047] In the above example, s’ is a symmetric key, e.g., a key that can be used for both encryption and decryption. Throughout this specification, as an example, a symmetric secret key is used, in which case the secret key is used as both an encryption key and a decryption key. The ciphertext can be used, for example, in an asymmetric setting as well by using s’ as a private key, e.g., a decryption key, and providing encryption of zero as a public key, e.g., an encryption key, using the technology of, e.g., R. Rothblum, "Homomorphic encryption: From private-key to public-key", Theory of Cryptography (TCC 2011), vol. 6597 of Lecture Notes in Computer Science, pages 219 - 234, Springer, 2011. However, in such a case, typically the private decryption key s’ is used to compute a compressed representation of the ciphertext from the plaintext according to the provided technology.
[0048] For example, the ciphertext can be a GLWE - based ciphertext in the sense that their security is based on the cryptographic strength of the Learning with Generalized Errors (GLWE) problem. In the particular case where k = 1, e.g., one mask polynomial is used, it is also called the Ring - Learning with Errors (RLWE) problem. The dimension of the polynomial ring used is greater than 1, e.g., the GLWE - based ciphertexts used in this specification are not Learning with Errors (LWE) ciphertexts.
[0049] In particular, the polynomial is defined over a discretized torus, e.g., for a positive integer q
Number
Number
Number
Number
Number
Number
Number
[0050] Such polynomials on the discretized torus can be multiplied by a multiplicand polynomial from the corresponding polynomial quotient ring. More precisely,
Number
Number
Number
Number
Number
Number
Number
Number
[0051]
Number
Number
Number
Number
Number
Number
Number
Number
Number
Number
[0052] The discretized torus is frequently used in a manner similar to so-called TFHE, whereby the manner is meant to support programmable bootstrapping operations. In such a manner, encrypted calculations can be performed on LWE-based ciphertexts, for example, GLWE-based ciphertexts where the masked polynomial and the body polynomial are scalar values. As part of such calculations, programmable bootstrapping can be applied to such LWE-based ciphertexts, as described elsewhere. This programmable bootstrapping may involve GGSW-type ciphertexts encrypting digits, e.g., bits of an LWE secret key, and the ciphertexts can be defined, for example, on a discretized torus as described above.
[0053] Programmable bootstrap operations in a manner similar to TFHE make them an attractive choice for a wide range of applications. Since bootstrapping is relatively efficient compared to many other FHE methods, for example, it is even more suitable for performing relatively complex calculations having a depth of at least 10, at least 50, or at least 100 multiplications. In particular, the cryptographic parameters of a manner similar to TFHE can be selected based on the required accuracy and the resulting computational cost, independent of the amount of homomorphic operations and the depth of their circuits. In contrast, in other FHE methods, bootstrapping can be very inefficient, so in practice these methods are typically applied in a levelled manner, which means that their parameters are selected according to a given calculation so that it can be done without the need for bootstrapping. Such levelled techniques are not suitable for more complex calculations, so in such cases, a manner similar to TFHE is particularly beneficial.
[0054] For example, the bootstrapping key of an encryption method similar to TFHE may include n GGSW-type ciphertexts that encrypt the key digits of the LWE secret key. Typically, n is at most 1000 or at most 640. For example, n = 630. The GGSW-type ciphertext may include, for example, GLWE-based ciphertexts with l = 3, each containing k = 1 mask polynomial (e.g., RLWE may be used) and one body polynomial. The dimension of the polynomial ring may be selected as N = 1024, and the cardinality q associated with the polynomial may be, for example, q = 2 64 or the like.
[0055] However, other parameters are also possible as known per se. Generally, the security of GLWE-based ciphertexts is based on the distribution of the secret key and three main parameters: n = kN, where N is the dimension of the polynomial ring, k is the number of random elements of the ciphertext, and n is the length of the secret key; q is the cardinality of the set in which the polynomial is defined; and σ is the statistical parameter of the noise, e.g., its standard deviation. Given these parameters, the method for estimating the degree of security provided is known per se. See, for example, M. Albrecht et al., "On the concrete hardness of Learning with Errors", Journal of Mathematical Cryptology, 9(3): 169 - 203, 2015 (incorporated herein by reference).
[0056] In the embodiments of this specification, the parameters of LWE-based ciphertexts and GLWE-based ciphertexts similar to the TFHE used may be selected based on the desired security level, and the desired accuracy of operations such as linear combinations of LWE ciphertexts and / or the application of programmable bootstrapping, in other words, may be selected based on the noise level resulting from applying these operations. Interestingly, in the TFHE setting, the security parameter can be selected independently of the computational complexity, for example, independently of the depth of multiplication in the computation. This is not the case for non-TFHE-like schemes, where the security parameter is typically selected to limit or exclude bootstrapping.
[0057] In particular, the LWE-based ciphertexts and / or GLWE-based ciphertexts used in the TFHE setting of this specification may use a relatively small modulus, for example, at most 32 bits, at most 64 bits, or at most 128 bits. This modulus is typically selected independently of the computation to be performed, for example, according to the desired accuracy and / or efficiency. The parameters N, k, and / or σ can typically be selected to achieve the desired security level independently of the computation to be performed. For example, N may be set to at least 512, and / or at most 2048 or 4096, such as 1024. For example, in an embodiment, RLWE is used with N at least 512, and / or at most 2048 or 4096, such as 1024, and k = 1. Such values of N are not typically used in non-TFHE-like encryption schemes, such values severely limit the computations that can be done; instead, in non-TFHE-like schemes, q and N are typically both selected based on the desired security level such that q can be made much larger.
[0058] FIG. 1a schematically shows an example of an embodiment of a device 110 for use in encryption calculations, for example, for calculating the representation of a ciphertext, or for performing encryption calculations using such a ciphertext.
[0059] The device 110 may comprise a processor system 130, a storage 140, and a communication interface 150. The storage 140 may comprise local storage, for example, a local hard drive or electronic memory. The storage 140 may comprise non-local storage, for example, cloud storage. In the latter case, the storage 140 may comprise a storage interface to the non-local storage. For example, the storage 140 may be for storing data representing plaintext to be encrypted and / or ciphertext for encrypting the plaintext. Such a ciphertext may comprise one or more random mask polynomials and a body polynomial derived from the mask polynomial and the plaintext. The ciphertext may be stored in the storage 140 in the form of a seed of a pseudorandom number generator and a Fourier domain representation of the body polynomial, as will be described in more detail elsewhere.
[0060] The device 110 may communicate internally with other devices, external storage, input devices, output devices, and / or one or more sensors via a computer network. The computer network may be the Internet, an intranet, a LAN, a WLAN, etc. The computer network may be the Internet. The device may optionally comprise a connection interface 150, which is configured to communicate with other devices as required. For example, the connection interface may comprise a connector, for example, an Ethernet connector, an optical connector, etc., for example, a wired connector, or a wireless connector such as an antenna, for example, a Wi-Fi, 4G or 5G antenna. Communication, for example, internal communication, may use other communication protocols or media, for example, an internal data bus.
[0061] In device 110, communication interface 150 can be used to transmit or receive digital data. For example, device 110 can be configured to receive or transmit data representing ciphertext, such as a seed and a body polynomial represented in the Fourier domain. For example, the device can be configured to generate and transmit data or receive data and use the data in encryption calculations, for example, as part of a bootstrapping key.
[0062] The execution of device 110 may be implemented in a processor system 130, such as one or more processor circuits, such as a microprocessor, examples of which are shown herein. Device 110 may include multiple processors that can be distributed in different locations. For example, device 110 may use cloud computing.
[0063] Device 110 may be used to compute the representation of the ciphertext from the stored plaintext, in which case the processor system 130 may be configured to generate the ciphertext. For this purpose, the processor system 130 may be configured to obtain a seed for the pseudo-random number generator. The processor system 130 may be further configured to randomly generate a mask polynomial by using the pseudo-random number generator according to the seed to generate a representation of the mask polynomial in the Fourier domain of the number-theoretic transform. The processor system 130 may be further configured to apply the inverse of the number-theoretic transform to the evaluation of the mask polynomial to determine the coefficients of the mask polynomial. The processor system 130 may be further configured to use the plaintext and determine the coefficients of the body polynomial such that the ciphertext encrypts the plaintext. The processor subsystem 130 may be further configured to apply the number-theoretic transform to the coefficients of the body polynomial to determine the representation of the body polynomial in the Fourier domain. The processor system 130 may be further configured to output the representation of the ciphertext. The representation may include the seed and the representation of the body polynomial in the Fourier domain. For example, the representation may be output by storing the representation on the storage 130 and / or transmitting the representation to another party via the communication interface 150.
[0064] As an alternative to calculating the expression, device 110 may be used to perform cryptographic calculations using such an expression. In this case, processor system 130 may be configured to obtain, for example, each multiplicand polynomial for multiplying with the mask polynomial and the body polynomial as a result of operations prior to the cryptographic calculations being performed. Processor system 130 may be further configured to expand the stored data representing the ciphertext. The stored data may include the seed of the pseudorandom number generator and the representation of the body polynomial in the Fourier domain of the number theoretic transform. Expanding may include generating a representation of the mask polynomial in the Fourier domain using the pseudorandom number generator according to the seed. Processor system 130 may be further configured to calculate the polynomial product of the mask polynomial and the body polynomial with their respective multiplicand polynomials. The polynomial product may be calculated in the Fourier domain to yield a representation of the calculated polynomial product in the Fourier domain. Processor system 130 may be further configured to output the calculated polynomial product, for example, for use in the remainder of the cryptographic calculations.
[0065] Some of the figures show functional units that may be functional units of a processor system. For example, the figures may be used as a blueprint for a possible functional organization of a processor system. The processor circuitry is not typically shown separately from the units in most of the figures. For example, the functional units shown in FIGS. 2, 3a, 3b, 4a, and 4b (referred to below) may be implemented in whole or in part by computer instructions stored in an electronic memory of a device such as device 110 and executable by a microprocessor of device 110. In hybrid embodiments, the functional units are implemented partially in hardware, for example, as a coprocessor, such as an arithmetic and / or cryptographic coprocessor, and partially in software stored and performed on device 110.
[0066] For example, device 110 may be a device for performing encryption calculations. The encryption calculations may use a homomorphic encryption cryptographic method. For example, device 110 may be used to perform encryption calculations. For example, even though the device receives the data in an encrypted form from, for example, a data provider and device 110 cannot decrypt the data, it may still perform calculations. The calculations may involve, for example, multiplying a ciphertext and its respective polynomial as described herein as part of a programmable bootstrap.
[0067] For example, storage 140 may store encrypted data items received from, for example, one or more data providers or generated as intermediate or final results of calculations, such as outputs. Typically, most or all of the data items on which the calculations of device 110 are performed are encrypted with a key (keys) unknown to device 110. That is, device 110 may not be configured to obtain the plain data item corresponding to the encrypted data item, such as that stored in storage 140. The decryption key in plaintext form is secret to device 110, but the encryption key / decryption key may be available in an encrypted form. For example, the processor system may be configured to perform a sequence of homomorphic encryption operations, which may include arithmetic operations such as addition and multiplication on encrypted values, but may also include arithmetic operations on encrypted polynomials. The homomorphic operations may also include operations such as key switching, bootstrap, etc.
[0068] FIG. 1b schematically shows an example of an embodiment of an encryption calculation system 100. System 100 is configured to perform encryption calculations using homomorphic encryption, for example, fully homomorphic encryption.
[0069] The system 100 of this example includes a key generation device 111, a data provider device 160, and an encrypted computing device 112. The key generation device 111 and the data provider device 160 may be combined into a single device. The device 112 may be configured to receive encrypted data items from the data provider 160. At least one or more data items may be received in an encrypted form. One or more data items may be received in a plain format. Computations may be performed on the received data items and may also be performed on the stored data items. Interestingly, computations may be performed on the encrypted data without decrypting the data, for example, without converting the encrypted data items to plain format data.
[0070] The devices 111 and / or 112 of this example may each be based on the device 110 of FIG. 1a, and may include, for example, the processor system 130, the storage 140, and / or the communication interface 150 of FIG. 1a, respectively.
[0071] In this example, the device 111 includes, for example, a key generation unit 131 implemented by the processor system of the device 111. The key generation unit 131 is configured to generate a bootstrapping key 156 for use by the encrypted computing device 112. The bootstrapping key 156 may include a plurality of GLWE-type ciphertexts. The key generation unit 131 may be configured to generate these ciphertexts to determine the bootstrapping key 156 using the techniques provided herein. The device 111 may provide the bootstrapping key 156 to the device 112, for example, by transmitting the bootstrapping key 156 via the computer network 150, uploading the bootstrapping key 156 to shared storage, etc.
[0072] In this example, device 112 includes an encryption computing unit 132 implemented, for example, by a processor system of device 112. The encryption computing unit 132 can be configured to perform encryption calculations. The encryption calculations can involve bootstrapping of encrypted values, particularly programmable bootstrapping. To perform the bootstrapping, the encryption computing unit 132 can use a bootstrapping key 156 that the encryption computing unit 132 obtained from device 111, for example, received via network 150, or retrieved from shared storage. The bootstrapping can involve multiplying the mask polynomial and the body polynomial of the GLWE-based ciphertext of the bootstrapping key 156 with their respective multiplicand polynomials. The encryption computing unit can perform these multiplications described herein. The encryption calculations can also include many other operations as is known per se, for example, device 112 can be configured to evaluate an arithmetic circuit, evaluate a neural network against encrypted data, etc.
[0073] Although not shown in this figure, the encryption computing system 100 can comprise, for example, two, three, or more than three encryption computing devices. The encryption calculations can be distributed among the plurality of encryption computing devices. The encryption computing devices can typically exchange encrypted intermediate calculation results with each other. Each encryption multiplication device can be implemented like the encryption computing device 112 and can perform multiplication of ciphertexts by polynomials as described herein.
[0074] A homomorphic encryption scheme can be applied in many settings. For example, the encrypted computing device 112 can be operated by a cloud provider. The cloud provider can provide computing and storage services to its clients. By adopting homomorphic encryption, a data provider device 160 of FIG. 1b, e.g., a client of the cloud provider, can send their data in an encrypted form. The cloud provider can still perform the necessary computations and / or necessary storage, but cannot know what corresponds to the plain data. For example, the data provider device 160 may use a type of encryption key corresponding to a particular homomorphic encryption system used to encrypt data items. When the computation result is received by the data provider 160 from the encrypted computing device 112, the corresponding decryption key can be used to decrypt the encrypted data item. The encryption key and the decryption key may be the same, and typically are the same.
[0075] For example, the encrypted computing system 100 may be configured to train a machine learning model, such as an image classifier, e.g., a medical model, even if the encrypted computing device cannot access the plain data item. For example, linear regression can probably be performed on the input data without bootstrapping. For example, backpropagation can probably be performed on the input data with bootstrapping. The resulting model parameters can be returned to the entity owning the decryption key. This enables multiple providers of medical data to pool their data by sending it to a cloud provider. The cloud provider then returns the model parameters without being able to access the plain data. The encryption key may be equal to the decryption key.
[0076] After the model is trained, the encryption computing system 100 can be used, for example, to supply a model for use with medical data. This can be done using either plain model parameters or encrypted model parameters, and in both cases, it can be done using encrypted data, such as encrypted inputs, intermediate data, and output data. Using plain model parameters is usually much more efficient. In both cases, the effect of the system is that calculations, such as image classification, for example medical image classification, can be performed without the computer knowing the plain data items. For example, a mammogram can be evaluated for cancer even if the image is not even plain in the encrypted computing device 112 and without any encrypted computing device 112 or the cooperation of such devices knowing what the result of the cancer evaluation is. From a privacy perspective, it may be permissible to operate a plain model on encrypted privacy-sensitive data, but it may not be necessary to operate on plain privacy-sensitive data.
[0077] Other uses involve, for example, a database service for searching encrypted data within an encrypted database, and for example, the computation may be a comparison between an input item and a database item. For example, multiple computations may be combined to create a database index that matches an index. For example, the database may be a genomic database and the input may be a gene sequence. For example, system 100 may be used for protected control of a device. For example, a device, even a large-scale device such as a power plant, may send sensor values to the encrypted computing device 112 and receive the returned encrypted control signal. The control signal is computed from the sensor signal. An attacker of the system may be able to determine the content of data entering one or more encrypted computing devices 112 and the content of data coming from one or more encrypted computing devices 112, and may even be able to access the intermediate data of these devices, but since the data is encrypted, it will not help the attacker. Since the decryption key is not known to these devices, the data will not be revealed even if all of the encrypted computing devices 112 of system 100 are completely broken. Computing the control signal may involve mathematical operations such as linear algebra, averaging, matrix multiplication, polynomial evaluation, etc. All of that is possible to perform together with homomorphic encryption operations.
[0078] For example, a pool of encrypted data items may be maintained within an encryption computing system; subsets of these may be received, and other subsets may be, for example, intermediate results of encrypted computations. For example, an encryption computing device 112 may be configured to apply a homomorphic encryption operation to one, two, or more encrypted data items within a pool that is, for example, a collection of input values and / or intermediate values and / or output values. The result may be a new encrypted data item that can be stored in the pool. The pool may be stored in the storage of the encryption computing system. This may be local storage or distributed storage. In the latter case, it may happen that one or more encrypted data items are represented multiple times within the pool. Encrypted data items may be transmitted, for example, from one computing device to another when their values are needed somewhere. The pool may be realized in various ways, for example, as a register file, an array, various data structures, etc.
[0079] Encrypted data items can represent all kinds of data. For example, an encrypted data item may represent a number that needs to be averaged, or be used in linear regression, etc. For example, an encrypted data item can represent an image. For example, each pixel of an image can correspond to one or more encrypted data items. For example, a grayscale pixel may be represented by a gray level, which in turn may be represented by a single encrypted data item. For example, 256 gray levels may be encoded by a single encrypted data item. For example, a color pixel may be represented by a plurality of color levels, such as RGB levels, which in turn may be represented by a tuple of encrypted data items. For example, three 256-level colors may be encoded by three encrypted data items. How many encrypted data items are used to represent a certain type of data depends on the capabilities of the homomorphic encryption scheme. For example, a more restrictive homomorphic encryption scheme may be able to encode only 1 bit per encrypted data item. In that case, one color pixel may require 24 encrypted data items.
[0080] A set of homomorphic encryption operations may be defined for the computation. For example, from the homomorphic encryption operations, a network or circuit of operations that perform the computation together, for example, by an external compiler device or the computing device itself, may be constructed. For example, the operations may include Boolean operations. The way the homomorphic encryption operations are combined, for example, which operation is applied to which operand in the pool, determines the computation being performed. For example, the computation may be represented as a list of homomorphic encryption operations to be performed, along with an indication of the encrypted data items for which the operations are to be performed. The network or circuit may indicate to the encrypted computing device 112 when to perform programmable bootstrapping, or the encrypted computing device 112 may initiate programmable bootstrapping when it finds that the noise of the encrypted values is too large or will become too large.
[0081] FIG. 2 schematically shows an example of an embodiment of a method for calculating the polynomial product of two polynomials f(X) and g(X). The two polynomials in this example are defined with the quotient polynomial p(X) as the modulus. Some of the examples described in connection with this figure are known per se and are described, for example, in Chapter 8 of J. von zur Gathen and J. Gerhard, "Modern Computer Algebra", Cambridge University Press, 2003 (incorporated herein by reference). This figure shows the multiplication of polynomials in coefficient form, which results in the product of polynomials in coefficient form. This multiplication has several components: a number-theoretic transform, the inverse of the number-theoretic transform, and multiplication in the Fourier domain. The various embodiments of other figures have different configurations, but the components of this figure may be used.
[0082] The figure shows, for example, f(X)=Σ i f i X i mod p(X) coefficients f i and g(X)=Σ i g i X i mod p(X) coefficients g i by their respective values, showing two polynomials f241 and polynomial g243 represented in the coefficient domain.
[0083] To multiply polynomials, the number-theoretic transform NTT233 can be applied to transform the polynomials into the Fourier domain. The figure shows the Fourier domain representation 242 of polynomial 241 and the Fourier domain representation 244 of polynomial 243. Typically, the Fourier domain representations of polynomials 241, 243 include the evaluation of the polynomials at powers of a primitive root of unity from a finite ring, where the ring is, for example, the one from which the coefficients of polynomials 241, 243 are selected or to which those coefficients correspond. As demonstrated in the following examples, the Fourier domain representation may include all M powers of a primitive M-th root of unity, or, for example, only a strict subset of the powers. In some examples, there is a one-to-one correspondence between the coefficient representation 241 of polynomial mod p(X) and the Fourier representation 242, but this is not required. For example, NTT233 can map a set of coefficients to a subset of the possible Fourier representations 242.
[0084] Given the Fourier domain representations 242, 244, the polynomial product of the polynomials can be calculated in the Fourier domain in operation Mul238. This is typically performed as a point-by-point multiplication of the evaluations of the polynomials. The point-by-point multiplication can correspond to a multiplication for each value n corresponding to the quotient polynomial, as emphasized in the following examples, modulo X M -1. As a result, the Fourier domain representation 246 of the product of polynomials f and g can be obtained, for example, as the evaluation of the quotient polynomial within a set of powers of a primitive root of unity.
[0085] The inverse INTT234 of the number-theoretic transform 233 can be applied to the Fourier domain representation 246 of the product polynomial to obtain the representation 245 of the product polynomial in coefficient form h(X)=Σ i h i X i mod p(X). Interestingly, INNT234 can randomly generate the Fourier representation, for example, randomly generate each evaluation contained therein, and then apply the inverse number-theoretic transform 234, for example, for each coefficient h iIt may have the property of generating a random polynomial 245 having the same distribution as that randomly generated. This may apply, in particular, when there is a one-to-one mapping between the Fourier domain representation 246 and the coefficient representation 245, for example, when the Fourier domain representation contains the same number of elements as the number of coefficients of the polynomial, equal to the degree of the quotient polynomial, for example, and as shown in the following example, this may also apply when the Fourier domain representation is larger. For example, the number of Fourier domain representations 246 that map to a given polynomial 245 in the coefficient representation mod p(X) may be the same for each polynomial 245.
[0086] In general, various number-theoretic transforms are known per se and can be used in combination with the techniques described herein, for example, the discrete Fourier transform in its standard form; the algorithms of Schönhage and Nussbaumer.
[0087] Some specific examples of number-theoretic transforms and their corresponding Fourier domain representations are provided here. In general, these examples relate to polynomials over finite rings or tori. As illustrated below, there may be a correspondence between random polynomials and random Fourier domain representations. On the other hand, when using the classical Fourier transform instead of a number-theoretic transform such as the TFHE scheme like "TFHE: fast fully homomorphic encryption over the torus", an infinite-sized field of complex numbers
Number
[0088] Example 1: Quotient polynomial X M -1 In general, let R be a ring. Also, let ω ∈ R be a primitive M-th root of unity for an integer M > 1. Two polynomials f, g ∈ R[X] / (X MWhen (-1) is given, their product can be calculated by the number-theoretic transform, which is also known as the discrete Fourier transform. Details can be found in Chapter 8 of "Modern Computer Algebra".
[0089] When applying the number-theoretic transform, a polynomial f := f(X) = f0 + f1X + ··· + f M-1 X M-1 ∈ R[X] of degree < M can be identified with its coefficient vector (f0, f1,..., f M-1 ) ∈ R M . The number-theoretic transform 233 of the polynomial f regarded as a vector in R M can be calculated as the vector containing the evaluations of f at successive powers of ω:
Number
[0090] Now, consider polynomials f, g ∈ R[X] / (X M - 1) (and thus of degree < M). Since multiplication modulo X M - 1 is convolution (e.g., fg ≡ f * g (mod X M - 1)), the product h := fg ∈ [X] / (X M - 1) can be obtained as h = DFT ω -1 (DFT ω (f) · DFT ω (g)) where DFT ω -1 denotes the inverse number-theoretic transform 234, and DFT ω (f) · DFT ω(g) is the pointwise multiplication Mul238. Interestingly, the inverse DFT can be computed as [Number] for any polynomial h ∈ R[X] of degree < M. See Theorem 8.13 of "Modern Computer Algebra".
[0091] In this example, when the ring R is finite, there is a one-to-one correspondence between polynomials and their Fourier domain representations [Number] and thus a uniformly random polynomial can correspond to a uniformly random Fourier domain representation.
[0092] Example 2: Quotient polynomial p(X)|X M -1 In this example, the quotient polynomial p := p(X) can be any polynomial p(X) that divides X M - 1. Here again, ω ∈ R can be a primitive M-th root of unity. In this case, the product of two polynomials f, g ∈ R[X] / (p) is: - Perform NTT233 as in the above example, where f and g are considered as polynomials in R[X] / (X M - 1); - Perform Mul238 as in the above example and compute the Fourier representation of h’ := fg (mod X M - 1) as h’ = DFT ω -1 (DFT ω (f) · DFT ω (g)); - Perform INTT234 by computing the coefficient representation of h’ as above and return h = h’ mod p as the product of f and g in R[X] / (p) which can be obtained by.
[0093] In INNT234, it is not necessary to perform the reduction h = h’ mod p. For example, coefficients can be returned modulo the polynomial X M - 1. In this case, for security purposes, it may be desirable to randomize the returned coefficient representation by adding a random multiple r(X)p(X) of the quotient polynomial.
[0094] Furthermore, it should be noted that when performing NTT233 on polynomials f and g, it is possible to randomize the obtained Fourier domain representations 242, 243 by adding a random multiple of the quotient polynomial to f and / or g.
[0095] In this example, p(X) may be a strict divisor of X M - 1 and, for example, may have a degree smaller than M. However, p(X)=X M - 1 can also be considered as an example in this case.
[0096] Denoting the degree of p(X) as N, the coefficient representation of a polynomial can contain N elements, and the Fourier domain representation can contain M elements. When M = N, there is a one - to - one mapping between the Fourier domain representation of a polynomial modulo p(X) and its coefficient representation. When M > N, there is a one - to - one mapping between the Fourier domain representation and the polynomial mod (X M - 1), but not between the Fourier domain representation and the polynomial mod p(X). However, interestingly, the operation h = h’ mod p in INTT234 can guarantee that each coefficient representation 245 of the polynomial mod p(X) has an equal number of corresponding Fourier domain representations 246.
[0097] In the following example, (X M - 1) / (X dThe quotient polynomial of the form (-1) is described, where M = hd and d = M - N. As described above, in the following example, R may be finite and ω may be a primitive M-th root of unity. For such a quotient polynomial, the techniques of the above example can be used, but interestingly, more efficient polynomial multiplication is also possible by defining a Fourier representation that includes evaluation only at a subset of the powers of a primitive n-th root of unity. This is demonstrated below for the cases h = 2 and h = 3, but this example generalizes easily to higher values of h. However, the higher the reduction in the size of the Fourier representation, the smaller the value of h, which is why the cases h = 2 and h = 3, especially h = 2, are preferred.
[0098] Example 3: M = 2N, p(X) = X N +1 Given f, g ∈ R[X] / (X N +1), where f j ∈ R and
Number
Number
Number
Number
Number
[0099]
Number
Number
[0100] Thus, in this example, the NTT operation 233 can be implemented as the operation
Number
Number
Number
Number
[0101] In this example, there is a one-to-one correspondence between the coefficient expressions 241, 243, 245 and the Fourier domain expressions 242, 244, 246:
Number
[0102] Example 4: M = 3N / 2 (N is even), p(X) = X N +X N / 2 +1 Given f, g ∈ R[X] / (X N + X N / 2 + 1), then f j ∈ R and
Number
Number
Number
Number
[0103] Similarly, g3N / 2 = g(3N / 2 - 1)ω3N / 2 + g(3N / 2 - 2)ω(3N / 2 - 1) ∈ R 1,j * =g(3N / 2 - 1)ω3N / 2 + g(3N / 2 - 2)ω(3N / 2 - 1) ∈ R j ω3N / 2 j +g(3N / 2 - 1)ω(3N / 2 - 1) N / 2+j ω3N / 2 N / 2+j ∈R
Number
Number
[0104] Let η := ω3N / 2, which is a primitive (N / 2)-th root of unity. For i ∈ {1, 2}, let hi := figi mod (X3N / 2 3 and this is a primitive (N / 2)-th root of unity. For i ∈ {1, 2}, let hi := figi mod (X3N / 2 i * :=figi mod (X3N / 2 i * gi i * mod (X3N / 2N / 2 -1) can be calculated as. The polynomial h h i * = DFT η -1 (DFT η (f i * )·DFT η (g i * )) can be calculated as. The polynomial h i := f i g i mod ((ω 3-i X) N / 2 -1) for i ∈ {1, 2} is: h i,j = h i,j * (ω i ) -j ∈ R, and
Number
Number
[0105] Therefore, in this case, the number-theoretic transform operation 233
Number
Number
[0106] Also in this example, there is a one-to-one correspondence between the coefficient expressions 241, 243, 245 and the Fourier domain expressions 242, 244, 246: [Number] It should be noted that it is. In particular, a uniformly random Fourier domain expression corresponds to a uniformly random polynomial.
[0107] FIG. 3a schematically shows an example of an embodiment of the encryption unit 331 for calculating the encrypted text expressions 344 - 345 by encrypting a given plaintext. For example, the encryption unit 331 can be used in the key generation unit 131 of the key generation device 111 or another encryption calculation device 110.
[0108] The ciphertext may include one or more mask polynomials and body polynomials. For example, the ciphertext may be a GLWE-based ciphertext. The calculated expressions 344-345 may be for use in an encryption calculation method, as described, for example, with respect to FIGS. 1b, 3b, 4a, and 4b. As described elsewhere, such an encryption calculation method may involve multiplying the mask polynomial and the body polynomial by their respective multiplicand polynomials. As demonstrated in the example of FIG. 2, such polynomial multiplication can be performed efficiently when the mask polynomial and the body polynomial are represented in the Fourier domain of a number-theoretic transform. Thus, it is desirable to provide a representation of the ciphertext that can be efficiently expanded into such a Fourier domain representation while still guaranteeing that the compressed ciphertext follows the probability distribution of the encryption scheme. Such a representation may be provided by the encryption unit 331.
[0109] The figure shows the plaintext m347 to be encrypted. The plaintext may be a polynomial from the polynomial ring in which the mask polynomial and the body polynomial are defined. For example, the plaintext may be an encoding of one or more numbers, bits, characters, strings, etc. as a polynomial.
[0110] The figure also shows the encryption unit Enc336. The encryption unit may take as input the mask polynomials a1,..., a k 341 in coefficient form and the plaintext m347, and may determine the body polynomial b343. The encryption unit 336 may also take as input a secret key (not shown in this figure) for encrypting the plaintext 347. The encryption unit 336 may determine the coefficients 343 of the body polynomial such that the ciphertext formed by the mask polynomial 341 and the body polynomial 343 encrypts the plaintext 347. The encryption unit 336 may be a conventional encryption unit. For example, the unit may
Number
[0111] Furthermore, the seed S345 of the pseudo-random number generator is shown. The seed 345 may be included in the determined ciphertext representation. As shown in the figure, the seed may be randomly generated by a random number generator Rnd337, for example, a hardware random number generator or a pseudo-random number generator (preferably, a cryptographic PRNG). However, the seed may also be obtained differently. For example, the seed may be received from another device, or the seed may represent the state of the pseudo-random number generator, for example, after having been previously used to generate other random numbers.
[0112] A pseudo-random number generator (PRNG) Gen335 is also shown. The PRNG 335 can be configured to determine a sequence of random values when a seed 345 is provided. The PRNG is preferably a cryptographic pseudo-random number generator (CPRNG). The PRNG is used according to the seed 345 to randomly select a mask polynomial, for example, by generating a representation 342 of the mask polynomial in the Fourier domain of the number-theoretic transform from the Fourier domain in a uniformly random manner. For example, the representation of the mask polynomial can include evaluations of some mask polynomials within a set of evaluation values. The PRNG 335 can generate each evaluation sequentially. Examples of the Fourier domain representation of the number-theoretic transform are described, for example, with respect to FIG. 2. The PRNG can be used to sample the Fourier domain representation using techniques known per se, for example, by sampling bits from the PRNG and deriving random evaluations from those bits, for example, by rejection sampling. For example, any cryptographically secure pseudo-random number generator such as a stream cipher, a block cipher in counter mode, Yarrrow or Foruna PRNG can be used.
[0113] An INTT unit 334 is also shown. The INNT unit 334 can be configured to apply an inverse number-theoretic transform (INTT) to the evaluation 342 of the mask polynomial to determine the coefficients 341 of the mask polynomial, as described, for example, with respect to FIG. 2. Interestingly, the inverse number-theoretic transform can have the property of generating a uniformly random Fourier domain representation, and applying the INNT can lead to a uniformly random polynomial, in other words, a polynomial with uniformly random coefficients. For example, there can be a one-to-one mapping between the Fourier domain representation 342 of the polynomial and the coefficient representation 341. Therefore, generating the Fourier domain representation 335 and applying the INNT 334 can lead to a mask polynomial having the same random property as randomly generating each coefficient of the mask polynomial, which can be done conventionally.
[0114] The figure further shows the NTT unit 333. The NTT unit 333 can be configured to apply a number-theoretic transform (NTT) to the coefficients 343 of the body polynomial to determine a representation 344 of the body polynomial in the Fourier domain, as described, for example, with respect to FIG. 2. The Fourier domain representation 344 and the seed 345 can be used to represent the ciphertext. By storing the body polynomial in the Fourier domain, it can be directly used for Fourier domain multiplication. It is also possible to store the body polynomial in coefficient form, in which case the conversion to the Fourier domain can be performed at the point in time when multiplication is required thereafter.
[0115] By repeatedly using the encryption unit 331, a plurality of ciphertexts can be generated. For example, the encryption unit 331 can be used to generate a GGSW-type ciphertext including a plurality of generated ciphertexts, as also described with respect to FIG. 4a. In such a case where a plurality of ciphertexts are generated, these ciphertexts can be based on the same seed 345. For example, a random seed generated or obtained by the unit 337 may be used to initialize the PRNG 335 once, and then the PRNG can be used to generate the mask polynomial 342 for each ciphertext based on the same seed 345. Thereby, the representations of the plurality of ciphertexts in such a case share a common seed 345 that needs to be stored and / or transmitted only once when storing and / or transmitting a set of the plurality of ciphertexts, leading to a further reduction in storage and transmission bandwidth requirements.
[0116] Some detailed examples for determining the representations 344-345 are given here. The example describes the generation of an encryption representing a bootstrapping key, but can be easily adapted to the generation of an encryption representing any other value.
[0117] The first example: Quotient polynomial X N +1 This example is based on the corresponding example described with respect to FIG. 2. The polynomial represented is
Number
Number
Number
[0118] This example uses the primitive 2N-th root of unity ω. As described with respect to FIG. 2, in this case, particularly efficient multiplication based on number theory transformation is possible.
[0119] The modulus q
Number
Number
[0120] Below, it shows how the encryption unit 331 can be used to generate a bootstrapping key for TFHE programmable bootstrapping. Such a bootstrapping key may include a GGSW-type ciphertext of a part of the secret key. The GGSW-type ciphertext itself is indexed by (i, r), and each value [Number theory] It can be composed of GLWE - based encryption that encrypts . For details, please refer to Figure 4a. The bootstrapping key can be generated according to the following procedure:
[0121] 1. [Number theory] Generate a positive integer q such that has a primitive 2N - th root of 1, and select such a primitive 2N - th root ω modulo q;
[0122] 2. In the Rnd operation 337, uniformly and randomly draw a common seed σ345 from {0, 1} к . Here, κ is the security parameter;
[0123] 3. In the Gen operation 335, use the cryptographic pseudorandom number generator [Number theory] to obtain n·(k + 1)l vectors 342 [Number theory] as the output of CPRNG(σ) for 1 ≤ i ≤ n, 1 ≤ r ≤ (k + 1)l.
[0124] 4. For 1 ≤ i ≤ n, 1 ≤ r ≤ (k + 1)l: - Polynomial masking [Number theory] Apply the inverse number - theoretic transform 334 to construct 341. Here, for 1 ≤ j ≤ k [Number theory] is true. - The ciphertext is the plaintext [Number theory] A corresponding polynomial body to encrypt 347
Number
Number
Number
[0125] 5. Representation of the common seed σ345 and the body polynomial
Number
[0126] The second example: Quotient polynomial X N +X N / 2 +1 This example is based on the corresponding example described with respect to Figure 2. In this example, the body polynomial and the mask polynomial are
Number
Number
Number
[0127] The advantage of using this quotient polynomial is that it can be used in combination with even values of q, and in particular, q is a power of 2. This is advantageous for various cryptographic applications.
[0128] In this example, q is chosen such that 3 is a unit in R, and a primitive nth root of unity ω is chosen as a primitive (3N / 2)th root of unity, where for example N / 2 is a power of 3. As explained with respect to FIG. 2, in this case, particularly efficient multiplication of polynomials in R[X] / (X N +X N / 2 +1) is possible.
[0129] Using the notation of the previous example, the representation of the bootstrapping key can be generated as follows:
[0130] 1. Select a positive integer q such that R contains a primitive (3N / 2)th root of unity: N is even. Choose a (3N / 2)th primitive root of unity ω modulo q. For example, q may be chosen such that λ(q) ∝ 3N / 2, where λ is the Carmichael totient function; gcd(q, 3N / 2) = 1.
[0131] 2. In the Rnd operation 337, draw a seed σ345 uniformly at random from {0, 1} к in.
[0132] 3. Using the cryptographic pseudo-random number generator 335,
Number
Number
[0133] 4. For 1 ≤ i ≤ n, 1 ≤ r ≤ (k + 1)l, - By applying the inverse number theoretic transform 334, a polynomial mask [Number] Construct 341. Here, for 1 ≤ j ≤ k [Number] it is; - In the encryption operation 336, the ciphertext is the plaintext [Number] Encrypt 347 with a matching polynomial body [Number] Obtain 343. Here, e (i,j) is [Number] the Gaussian error above; - By applying the number-theoretic transform 333, [Number] Calculate 344;
[0134] 5. The representation of each ciphertext by the Fourier domain representation of the seed and the body polynomial all having the common seed σ344 [Number] (1 ≤ i ≤ n, 1 ≤ r ≤ (k + 1)l) The bootstrapping key including 344 - 345 [Number] is returned.
[0135] Example 3: Quotient polynomial p(X)|X M -1 In this example, the technology of the corresponding example in FIG. 2 can be used. When performing INNT334, the coefficient representation a iIt is possible to obtain (x)341 mod p(X) and calculate the encrypted Enc336 mod p(X). As described with respect to FIG. 2, when performing NTT333, it is possible to add a random multiple of p(X) to b(X) to randomize the Fourier domain representation 344, but this is not essential.
[0136] Alternatively, INTT334 can also avoid reduction modulo p(X). Thus, the polynomial 341 returned by INNT may be a polynomial modulo X M -1. This may be more computationally efficient in some cases. In this case, the encryption Enc336 may also be calculated modulo X M -1 to obtain the body polynomial b(X)343 mod X M -1, and NTT333 may be applied to this body polynomial. In this case, it is desirable to randomize the Fourier domain representation 344 obtained by adding a random multiple of p(X) to b(X) either in the coefficient domain before applying the NTT or in the Fourier domain after applying the NTT.
[0137] FIG. 3b schematically shows an example of an embodiment of the encrypted multiplication unit 332 for use in, for example, the encryption calculation device 110.
[0138] The encrypted multiplication unit 332 can operate on a ciphertext including one or more random mask polynomials and a body polynomial derived from the mask polynomial and the plaintext. For example, the ciphertext may be a GLWE-based ciphertext as described herein. The encrypted multiplication unit 332 can operate on a ciphertext represented in a compressed manner by the seed 345 of a pseudo-random number generator and by the representation 344 of the body polynomial in the Fourier domain of the number theoretic transform. For example, the representation 344-345 of the ciphertext may be determined in advance by a part of a device different from the encryption unit 331 of FIG. 3a, typically the encrypted multiplication unit 332.
[0139] The encrypted multiplication unit 332 can be for multiplying the mask polynomial and the body polynomial of the ciphertext by their respective multiplicand polynomials. For example, as will also be described in connection with FIG. 4a, the encrypted multiplication unit 332 may be used in an encrypted calculation to calculate an outer product or in various other operations of the encrypted calculation, such as multiplying a known polynomial by a ciphertext. The figure shows the respective multiplicand polynomials 351 for multiplying the mask polynomial and the body polynomial of the ciphertext. Each of the multiplicand polynomials 351 may all be distinct, or each of the multiplicand polynomials 351 may all be equal to, for example, one common multiplicand polynomial.
[0140] In the example shown in the figure, the multiplicand polynomials are obtained in coefficient representation 351, and the number-theoretic transform unit NTT 333 is used to apply a number-theoretic transform to convert the coefficients 351 of each multiplicand polynomial to Fourier domain representation 352. The NTT unit can be as described with respect to FIG. 2 or FIG. 3a. The unit 332 may not be required. For example, the multiplicand polynomials may already be available in Fourier domain representation, for example, as a previous output of the multiplication unit 332 or otherwise.
[0141] To obtain the representation of the ciphertexts 344 - 345 for which multiplication can be performed, the representations 344 - 345 can be expanded. For this purpose, the pseudo-random number generator (PRNG) Gen 335 can be used according to the seed 335 to generate the representation 342 of the mask polynomial in the Fourier domain. The PRNG can be as described with respect to FIG. 2 or FIG. 3a.
[0142] Given the Fourier domain representations of the mask polynomial 342, the body polynomial 344, and the multiplicand polynomial 352, the multiplication unit 338 can be used to compute the polynomial products of the mask polynomial 342 and the body polynomial 344 with their respective multiplicand polynomials 352 in the Fourier domain. As a result, the Fourier domain representation 354 of the computed polynomial product in the Fourier domain can be obtained. For example, the multiplication unit 338 may be the multiplication unit 238 of FIG. 2. Typically, the Fourier domain representation includes the evaluation of each polynomial within a set of evaluation values, and the multiplication 338 can be performed by point-by-point multiplication of polynomial evaluations, as is known per se.
[0143] The encrypted multiplication unit 332 can output the computed polynomial products in various formats as desired. For example, the polynomial products may be output in their Fourier domain representations 354, or as shown in the figure, the INNT unit 334 can be used to apply the inverse number theory transform to convert some or all of the Fourier domain representations 354 of the computed polynomial product into coefficient representations 353. The INNT unit 334 can be, for example, as described for FIG. 2 or FIG. 3a.
[0144] When there is no one-to-one correspondence between the Fourier domain representation 354 and the coefficient domain representation 353, in some cases, additional randomization can be performed as also described with respect to FIG. 2. In particular, when the encrypted multiplication unit 332 outputs the Fourier domain representation 354, the randomization can be performed such that a random Fourier domain representation 354 of the product is output. For example, when using the quotient polynomial p(X)|X M -1, this can be done by adding a random multiple r(X)p(X) of the quotient polynomial p(X) to the Fourier domain representation, for example, by generating that random multiple in the coefficient domain and using the FFT to transform that random multiple into the Fourier domain.
[0145] As described for the INTT234 of FIG. 2, the quotient polynomial p(X)|X MWhen -1 is used, p(X) is not reduced modulo the law, and thus X M It is also possible to output a coefficient domain representation 353 represented by a polynomial modulo -1. In this case, it is also desirable to randomize by adding a random multiple r(X)p(X) of the quotient polynomial to the output coefficient domain representation 353. The random multiple may be added in the Fourier domain before applying INTT334 or in the coefficient domain after applying INTT.
[0146] The encryption multiplication unit 332 can be used to repeatedly perform polynomial multiplication on the same encryption 344 - 345. In such a case, the expanded representations 342, 344 of the ciphertext may be held in memory and then used to compute further polynomial multiplications without the need to apply PRNG335 again at this point, thus improving the efficiency of further multiplications. However, to save memory, it is also possible to delete the Fourier domain representations 342 of the mask polynomials and, if necessary, regenerate them.
[0147] FIG. 4a schematically shows an example of an encryption multiplication unit 432 for use in, for example, an encryption computing device 110. The encryption multiplication unit 432 is used in this figure to compute the outer product of a GGSW - type ciphertext 456 and a GLWE - based multiplicand ciphertext 455.
[0148] Generally, a GGSW - type ciphertext 456 encrypting a plaintext M(X) may include a collection of GLWE - based ciphertexts each encrypting a respective value based on the plaintext. A GGSW - type ciphertext containing RLWE - based ciphertexts may also be called an RGSW ciphertext. A discretized torus, for example,
Number
[0149] For example, under a private key s’
Mathematics
Mathematics
[0150] Note that in the literature, GGSW ciphertexts are sometimes also described as being based on zero GLWE encryptions to which values based on the plaintext are added. Such GGSW ciphertexts can also be considered as GGSW ciphertexts that include GLWE-based ciphertexts. For example, the TGGSW ciphertext of "TFHE: fast fully homomorphic encryption over the torus" is a GGSW ciphertext that includes a GLWE ciphertext. That is, the TGGSW ciphertext is
Mathematics
Mathematics
Mathematics
[0151]
Number
Number
Number
Number
[0152] 1. When 1≦h≦k,
Number
Number
[0153] Thus, the TGGSW ciphertext C may be regarded as a series of (k + 1)l TGLWE ciphertexts, and a value that depends on the plaintext m to be encrypted:
Equation
[0154] The figure shows the representation 456 of the GGSW - type ciphertext. The GLWE - based ciphertext of the GGSW - type ciphertext can be represented by the respective seeds 445 of the pseudo - random number generator (RPNG) and the representation 444 of the body polynomial in the Fourier domain of the number - theoretic transform, as explained elsewhere. For example, the representation may be determined by the encryption unit 331 of FIG. 3a. As shown in the figure, the GLWE - based ciphertexts may share a common seed 445, e.g., the PRNG may be seeded by the seed 445.
[0155] To calculate the outer product, the representation 444 - 445 of the GLWE - based ciphertext of the GGSW - type ciphertext 456 may be expanded. For this, the pseudo - random number generator 435, e.g., the PRNG 335 of FIGS. 3a - 3b, may be used according to the common seed 445 or according to the respective seeds to generate the representation of the mask polynomial of the GLWE - based ciphertext 444 in the Fourier domain. This can be done as explained in connection with FIG. 3b. As shown in the figure, the expanded representation of the GGSW - type ciphertext in the Fourier domain can be obtained including the Fourier representation 442 of each mask polynomial and the Fourier representation 444 of each body polynomial.
[0156] As is known per se, the outer product of the GGSW - type ciphertext 456 by the GLWE - based multiplicand ciphertext 455 can be computed by multiplying the mask polynomial and the body polynomial of each GLWE - based ciphertext 444 with each multiplicand polynomial 451 based on the GLWE - based multiplicand ciphertext 455.
[0157] The determination of the multiplicand polynomial 451 is shown in detail in the figures for the case of the outer product described, for example, in "CONCRETE:Concrete Operates oN Ciphertexts Rapidly by Extending TfhE". In this case, the multiplicand polynomial is obtained by determining the so - called gadget decomposition GDec439 of the GLWE - based multiplicand ciphertext 455. Computing the gadget decomposition may include applying a radix decomposition for each coefficient to the polynomial of the ciphertext 455, thereby obtaining, for example, a multiplicand polynomial with small coefficients in the range [−B / 2,B / 2]. This is shown in the figures, where the mask polynomial a1 of the ciphertext 455 is radix - decomposed into polynomials a 1,1 ,..., a 1,l ; the body polynomial b is radix - decomposed into polynomials b1,..., b l and so on. In general, each multiplicand polynomial 451 can be obtained for each GLWE - encryption of the GGSW - type ciphertext 456.
[0158] As shown in FIGS. 2 and 3b, in order to perform the multiplication by the multiplicand polynomial 451, the multiplicand polynomial can be transformed by the NTT unit 433 into a Fourier - domain representation 452. The multiplication can then be performed in the Fourier domain by the multiplication unit 438. The multiplication unit 438 can be based on the multiplication units of FIGS. 2 and 3b, but in this case, it is configured to perform a matrix - vector multiplication of a 1×(k + 1)l - sized vector of the multiplicand polynomial 452 and a (k + 1)l×(k + 1) - sized matrix of the polynomials 442, 444 representing the GGSW - type ciphertext 456.
[0159] In this example, all the mask polynomials and body polynomials of a given GLWE-based encryption 444 are multiplied by a common multiplier polynomial of the multiplicand polynomials 452, but it is also possible to use different multiplicand polynomials for different polynomials of the GLWE-based encryptions 442, 444 as needed.
[0160] The multiplication 438 can yield a mask polynomial and a body polynomial of a GLWE-based ciphertext 454 represented in the Fourier domain. The ciphertext 454 can represent the encryption of the product of values encrypted by a GLWE-based ciphertext 455 and a GGSW-type ciphertext 456. This product is also called the outer product. Optionally, the encryption can be converted to the coefficient form 453 by the INTT unit 434 applying the inverse of the number-theoretic transform as shown in FIGS. 2, 3a, and 3b.
[0161] The outer product has various applications. For example, the outer product can be used in the evaluation of a GGSW encryption circuit for GLWE-encrypted values using circuit bootstrapping as described, for example, in "TFHE: Fast Fully Homomorphic Encryption over the Torus".
[0162] Another important application is to compute an encrypted CMux gate, also known as a controlled selector gate or a controlled multiplexer. The CMux gate computes the product of a GGSW-type ciphertext and the difference between a first GLWE ciphertext and a second GLWE ciphertext, and adds the first GLWE ciphertext to the computed product to select, based on the GGSW-type ciphertext, either the first GLWE-based ciphertext or the second GLWE-based ciphertext from an oblivious adversary. Mathematically, this can be described as
Number
Number
[0163] In particular, the outer product can be used in the programmable bootstrapping operation of a homomorphic encryption scheme similar to TFHE. Programmable bootstrapping can use a bootstrapping key that includes GGSW ciphertexts 456. Since the bootstrapping key typically includes many GGSW ciphertexts used in such outer products, the provided technique is particularly advantageous in this case. A specific example of programmable bootstrapping is described with respect to FIG. 4b.
[0164] Generally, a TFHE bootstrapping key can include a part of the secret key, for example, the TGGSW encryption of each bit. Programmable bootstrapping can evaluate a decryption function that uses this secret key under encryption by calculating the outer product of TGGSW encryptions. This is described, for example, in "Programmable Bootstrapping Enables Efficient Homomorphic Inference of Deep Neural Networks". As a detailed example,
Number
Number
Number
Number
Number
[0165] The improved storage and bandwidth requirements by the compressed representation 456 of the GGSW ciphertext are shown based on the above bootstrapping key. In the above example, the bootstrapping key [Number] reaches a total of nl(k + 1) 2 polynomials in, that is, [Number] of nl(k + 1) 2 reaches N elements. [Number] The elements of [Number] for [Number] are of the form, and thus, [Number] can be encoded using bits. As a result, the bootstrapping key in the above example requires [Number] Bits can be used. Typical parameters are n = 630, l = 3, k = 1, N = 1024, and q = 2 64 In this case, the bootstrapping key, as an example, has a total size of about 62 megabytes.
[0166] The compressed representation allows GLWE-based ciphertexts to be represented using less storage. GLWE-based ciphertexts consist of k + 1 elements: for example
Number
Number
Number
Number
Number
[0167] The pseudorandom number generator 435 can be used to recover the mask from the seed. For example,
Number
Number
Number
[0168] Therefore, to generate the Fourier domain representations of the n·(k + 1)l TGLWE ciphertexts that form the n bootstrapping keys, using the same seed σ445, they roughly divide the initial memory requirement by the factor (k + 1),
Number
[0169] FIG. 4b schematically shows an example of a bootstrapping unit 460 for use in, for example, the encryption computing device 110. The bootstrapping unit 460 can apply a programmable bootstrapping operation to the LWE encryption 461 to obtain an output LWE encryption 469. The output LWE encryption 459 can include an amount of noise independent of the noise in the input encryption 461. The unit 460 can therefore be used to reduce the noise in the input encryption 461. The output encryption 469 can encrypt the same value of the input encryption, but interestingly can also encrypt the result of applying a function to the input encryption 461. Such programmable bootstrapping is known, for example, from "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks" (the "Programmable Bootstrapping" section of that paper, which is incorporated herein by reference).
[0170] As shown in the figure, programmable bootstrapping may include a blind rotation operation 464. The blind rotation operation may evaluate LWE decryption in the exponents of a bootstrapping monomial and a GLWE-encrypted monomial called herein. In particular, the blind rotation may result in an encrypted polynomial product of a test polynomial and a bootstrapping monomial. The bootstrapping monomial may represent a plaintext value as an exponent. The blind rotation operation 464 may be performed with respect to an outer product that can be calculated as described herein, for example, by the encryption multiplication unit 432 of FIG. 4a. In particular, the blind rotation 464 may include calculating an outer product of one or more GGSW ciphertexts included in the bootstrapping key 456, such as an encryption of bits or other portions of the decryption key of the input encryption 461, and a GLWE-based multiplicand ciphertext based on the input encryption 461. By using the provided techniques, the calculation of the outer product may be improved as described herein. The outer product may be calculated, for example, as part of a controlled multiplexer of the blind rotation 464 to obliviously select a GLWE-based ciphertext for a zero bit of the LWE decryption key or a GLWE-based ciphertext for a one bit of the LWE decryption key using a GGSW encryption of the bits of the LWE decryption key of the bootstrapping key 456.
[0171] As shown in the figure, before the blind rotation 464, a modulus switching operation may be performed to scale the input encryption 461 to obtain a scaled input encryption 463. For example, as is known per se, scaling to the domain [0, 2N) may be applied using the quotient polynomial p(X) = X N + 1. For example, the components of the ciphertext may be scaled by 2N / q, and for example, each component may be in the form [Number] through the operation, and the input ciphertext 461 is defined modulo q. The result 463 may, in this case, be an LWE-type ciphertext modulo 2N. More generally, for a given M, X MWhen using other quotient polynomials that divide -1, the input ciphertext 461 can be scaled to the domain [0,M). As is known per se, the input ciphertext 461 may be made to take at most N possible values by ensuring that the scaled ciphertext 463 has, for example, the most significant bit of the input set to 0 or the like.
[0172] As is known per se, the blind rotation 464 can use a test polynomial. Essentially, the function evaluated by programmable bootstrapping can be identified as a lookup table with pairs (i,T[i]) for 0 ≤ i ≤ N - 1. The lookup table can be used to define a test polynomial, for example, ν i = T[i], where ν(X)=ν0 + ν1X+···+ν N-1 X N-1 can be used. The plaintext
Number
Number
[0173] The programmable bootstrapping described in "Programmable bootstrapping enables efficient homomorphic inference of deep neural networks" is for polynomials modulo the cyclotomic polynomial X N + 1, where N is a power of 2. Interestingly, the inventors noticed that programmable bootstrapping can also be used in combination with other quotient polynomials. For this purpose, the test polynomial can be used in the blind rotation 464, which is configured such that multiplying the test polynomial modulo the quotient polynomial by the bootstrapping monomial corresponding to the plaintext has the desired function output for that plaintext as its constant (or other fixed) coefficient.
[0174] In particular, to determine the test polynomial, the technique disclosed in European Patent Application EP21290080.7 filed on July 12, 2021 by Zama, SAS having the title "ENCRYPTED COMPUTATION COMPRISING A BLIND ROTATION" (incorporated herein by reference) can be used. As described therein, for example, general techniques can be used to determine the test polynomial given the quotient polynomial, as explained in the section "Example test polynomial 4. Other quotient polynomials / coefficient" of the reference (incorporated by reference). As also described in the reference, the test polynomial can be determined particularly efficiently when the fixed coefficient is the leading coefficient or the constant coefficient, and / or when the quotient polynomial is the trinomial X N ±εX N / 2 + 1.
[0175] In particular, to program the fixed coefficient, the coefficients of the test polynomial can be set to
Number
Number
[0176] When the quotient polynomial p(X) is a trinomial of the form p(X) = X N + εX N / 2 + 1 for an even N and ε ∈ {-1, 1}, the s-th coefficient for s < N / 2 is the following coefficient:
Number
[0177] Additional details and other examples of performing programmable bootstrapping where the quotient polynomial is not equal to X N + 1 are found in the above references and are incorporated by reference insofar as they relate to determining the quotient polynomial.
[0178] FIG. 5a schematically shows an example of an embodiment of a computer-implemented cryptographic calculation method 500.
[0179] Method 500 may include storing data representing a ciphertext. The ciphertext may include one or more random mask polynomials and a body polynomial derived from the mask polynomial and the plaintext. Method 500 may include 520 obtaining respective multiplicand polynomials for multiplying with the mask polynomial and the body polynomial. Method 500 may include 530 expanding the stored data representing the ciphertext. The stored data may include a seed of a pseudorandom number generator and a representation of the body polynomial in the Fourier domain of a number-theoretic transform. Expanding may include using a pseudorandom number generator according to the seed to generate a representation of the mask polynomial in the Fourier domain. Method 500 may include 540 calculating a polynomial product of the mask polynomial and the body polynomial with the respective multiplicand polynomials. The polynomial product may be calculated in the Fourier domain. The calculation may result in a representation of the calculated polynomial product in the Fourier domain. Method 500 may include 550 outputting the calculated polynomial product.
[0180] FIG. 5b schematically shows an example of an embodiment of a computer-implemented method 600 for calculating an encrypted text representation. The representation can be for use in an encryption calculation method as described in any one of the preceding claims. Method 600 may include obtaining 610 the plaintext to be encrypted. Method 600 may include generating 620 the encrypted text. The encrypted text may include one or more mask polynomials and a body polynomial. Generating 620 may include obtaining 621 a seed for a pseudorandom number generator. Generating 620 may include randomly selecting 622 a mask polynomial by generating a representation of the mask polynomial in the Fourier domain of a number-theoretic transform using the pseudorandom number generator according to the seed. Generating 620 may include applying the inverse of the number-theoretic transform to the evaluation of the mask polynomial to determine 623 the coefficients of the mask polynomial. Generating 620 may include using the plaintext and determining 624 the coefficients of the body polynomial such that the encrypted text encrypts the plaintext. Generating 620 may include applying the number-theoretic transform to the coefficients of the body polynomial to determine 625 a representation of the body polynomial in the Fourier domain. Method 600 may include outputting 630 the encrypted text representation, which includes the seed and the representation of the body polynomial in the Fourier domain.
[0181] As will be apparent to those skilled in the art, many different ways of executing methods 500, 600 are possible. For example, the steps may be performed in the order shown, but the order of the steps may vary, or some steps may be performed in parallel. Further, other method steps may be inserted between the steps. The inserted steps may represent an improvement of the method as described herein, or may be unrelated to the method. For example, some steps may be performed at least partially in parallel. Further, a given step need not be fully completed before the next step is started.
[0182] Embodiments of the method may be performed using software, which includes instructions to cause a processor system to perform method 500 or 600. The software may include only those steps performed by certain sub-entities of the system. The software may be stored on a suitable storage medium such as a hard disk, floppy disk, memory, optical disk, etc. The software may be transmitted as a signal along wired or wireless, or using a data network such as the Internet. The software may be made available for download and / or remote use on a server. Embodiments of the method may be performed using a bitstream configured to configure programmable logic, such as a field programmable gate array (FPGA), to perform the method.
[0183] The subject matter of the present disclosure is also to be understood to extend to a computer program adapted to practice the subject matter of the present disclosure, in particular a computer program on or in a carrier wave. The program may be in the form of object code, such as source code, object code, code intermediate source, and partially compiled forms, or in any other form suitable for use in the implementation of embodiments of the method. Embodiments related to computer program products include computer-executable instructions corresponding to each of at least one processing step of the described method. These instructions may be subdivided into subroutines and / or stored in one or more files that may be statically or dynamically linked. Another embodiment related to computer program products includes computer-executable instructions corresponding to each of at least one device, unit, and / or component of the described system and / or product.
[0184] Typically, the devices described herein, for example, in FIGS. 1a - 1c, include one or more microprocessors that execute appropriate software stored in the system. For example, the software may be downloaded and / or stored in a corresponding memory, such as volatile memory like RAM or non - volatile memory like flash. Alternatively, the system may be implemented, in whole or in part, in programmable logic, such as a field - programmable gate array (FPGA). The system may be implemented, in whole or in part, as a so - called application - specific integrated circuit (ASIC), for example, an integrated circuit (IC) customized for those specific applications. For example, the circuit may be implemented in CMOS using a hardware description language such as Verilog, VHDL, etc. In particular, the system may include a circuit for the evaluation of cryptographic primitives. The processor circuit may be implemented in a distributed manner, for example, as a plurality of sub - processor circuits. The storage may be distributed across a plurality of distributed sub - storages. Part or all of the memory may be electronic memory, magnetic memory, etc. For example, the storage may have volatile and non - volatile portions. Part of the storage may be read - only.
[0185] FIG. 5c shows a computer - readable medium 1000 having a writable portion 1010 and a computer - readable medium 1001 having a writable portion as well. Computer - readable medium 1000 is shown in the form of an optically readable medium. Computer - readable medium 1001 is shown in the form of electronic memory, in this case in the form of a memory card. Computer - readable media 1000 and 1001 may store data 1020, which, when performed by a processor system, may represent instructions for causing an embodiment of a method for performing calculations on values encrypted with LWE in accordance with an embodiment by the processor system.
[0186] Alternatively, or in addition, data 1020 may represent a ciphertext. The ciphertext may include one or more mask polynomials and a body polynomial derived from the mask polynomial and the plaintext. Data 1020 may include a seed of a pseudorandom number generator for generating a representation of the mask polynomial in the Fourier domain of the number theoretic transform and a representation of the body polynomial in the Fourier domain. In particular, data 1020 may represent a bootstrapping key for use in programmable bootstrapping, and the bootstrapping key may include a plurality of such ciphertexts that encrypt respective values based on, for example, the secret key of the programmable bootstrapping.
[0187] Data 1020 may be embodied on computer-readable medium 1000 as a physical mark or by magnetization of the computer-readable medium 1000. However, any other suitable implementation is also contemplated. Further, although computer-readable medium 1000 is shown here as an optical disk, it should be understood that computer-readable medium 1000 may be any suitable computer-readable medium such as a hard disk, solid state memory, flash memory, etc., and may be non-recordable or recordable. Computer program 1020 includes instructions that cause the processor system to perform the method of performing calculations on the LWE-encrypted values.
[0188] FIG. 5d shows a schematic representation of a processor system 1140 according to an embodiment of a device for performing an encryption calculation or for calculating a representation of a ciphertext. The processor system comprises one or more integrated circuits 1110. The architecture of the one or more integrated circuits 1110 is schematically shown in FIG. 6b. The circuit 1110 comprises a processing unit 1120, such as a CPU, for executing computer program components to perform the method according to the embodiment and / or for implementing its modules or units. The circuit 1110 comprises a memory 1122 for storing programming code, data, etc. A part of the memory 1122 may be read-only. The circuit 1110 may comprise a communication element 1126, such as an antenna, a connector, or both. The circuit 1110 may comprise a dedicated integrated circuit 1124 for performing some or all of the processing defined by the method. The processor 1120, the memory 1122, the dedicated IC 1124, and the communication element 1126 may be interconnected via an interconnection 1130, such as a bus. The processor system 1110 may be configured for contact and / or non-contact communication using an antenna and / or a connector, respectively.
[0189] For example, in an embodiment, the processor system 1140, such as a device for performing an encryption calculation or for calculating a representation, may comprise a processor circuit and a memory circuit, and the processor may be configured to execute software stored in the memory circuit. For example, the processor circuit may be an Intel Core i7 processor, an ARM Cortex-R8, etc. In an embodiment, the processor circuit may be an ARM Cortex M0. The memory circuit may be a ROM circuit or a non-volatile memory, such as a flash memory. The memory circuit may be a volatile memory, such as an SRAM memory. In the latter case, the device may comprise a non-volatile software interface configured to provide software, such as a hard drive, a network interface, etc.
[0190] Device 1110 is shown as including one of each of the components described, but various components may be replicated in various embodiments. For example, processor 1120 may be configured to independently execute the methods described herein, or multiple processors may be included and configured to perform steps or subroutines of the methods described herein to cooperate to achieve the functions described herein. Further, if device 1110 is implemented in a cloud computing system, various hardware components may belong to separate physical systems. For example, processor 1120 may include a first processor in a first server and a second processor in a second server.
[0191] Note that the above-described embodiments are illustrative rather than limiting the subject matter of the present disclosure, and those skilled in the art can design many alternative embodiments.
[0192] In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The use of the verb "comprise" and its conjugations does not exclude the presence of elements or steps other than those specified in the claim. The article "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. Expressions such as "at least one of" when preceding a list of elements represent a selection of all or any subset of the elements from the list. For example, the expression "at least one of A, B, and C" should be understood as including only A, only B, only C, both A and B, both A and C, both B and C, or all of A, B, and C. The subject matter of the present disclosure may be implemented by hardware including several distinct elements and by a suitably programmed computer. In device claims enumerating several parts, several of these parts may be embodied by one and the same item of hardware. The fact that certain means are recited in mutually different dependent claims does not indicate that a combination of these means cannot be used advantageously.
[0193] In the claims, the references in parentheses refer to the reference signs in the drawings of the exemplary embodiments or the formulas of the embodiments, and thus increase the clarity of the claims. These references shall not be construed as limiting the claims.
Claims
1. A computer-implemented encryption calculation method (500), comprising: - storing data representing a ciphertext (510), wherein the ciphertext includes one or more random mask polynomials, and a body polynomial derived from the mask polynomial and a plaintext (510); - obtaining respective multiplicand polynomials for multiplying with the mask polynomial and the body polynomial (520); - expanding the stored data representing the ciphertext (530), wherein the stored data includes a seed of a pseudo-random number generator and a representation of the body polynomial in the Fourier domain of a number-theoretic transform, and expanding includes generating a representation of the mask polynomial in the Fourier domain using the pseudo-random number generator according to the seed (530); - calculating a polynomial product of the mask polynomial and the body polynomial with the respective multiplicand polynomials (540), wherein the polynomial product is calculated in the Fourier domain to obtain a representation of the calculated polynomial product in the Fourier domain (540); - outputting the calculated polynomial product (550) and a method (500).
2. The method includes performing programmable bootstrapping according to a bootstrapping key, the bootstrapping key includes a GGSW-type ciphertext, and performing programmable bootstrapping includes calculating an outer product, according to the method (500) described in claim 1.
3. Performing programmable bootstrapping includes performing blind rotation according to a test polynomial, the blind rotation calculating a GLWE-type encryption of a monomial multiplied by the test polynomial modulo a quotient polynomial, the quotient polynomial being different from X N + 1, the method (500) according to claim 2.
4. The method includes calculating an outer product of a GGSW-type ciphertext and a GLWE-based multiplicand ciphertext, the GGSW-type ciphertext includes a plurality of GLWE-based ciphertexts, and the method includes multiplying the mask polynomial and the body polynomial of each GLWE-based ciphertext with the respective multiplicand polynomials based on the GLWE-based multiplicand ciphertext, according to the method (500) described in claim 1.
5. The method includes calculating an outer product of a GGSW-type ciphertext and a difference between a first GLWE-based ciphertext and a second GLWE-based ciphertext, and adding the first GLWE-based ciphertext to the calculated product to obliviously select the first GLWE-based ciphertext or the second GLWE-based ciphertext based on the GGSW-type ciphertext, according to the method (500) described in claim 4.
6. Obtaining the coefficients of each multiplicand polynomial, applying a number-theoretic transform to transform the coefficients of each multiplicand polynomial into the Fourier domain, and / or applying an inverse number-theoretic transform to transform the calculated polynomial product representation in the Fourier domain into the coefficients of the calculated polynomial product, the method (500) according to claim 1.
7. Further comprising holding in a memory the expanded stored data representing the ciphertext, and using the expanded stored data to calculate a further polynomial product of a mask polynomial and a body polynomial and a further multiplicand polynomial, the method (500) according to claim 1.
8. The polynomial is defined with the quotient polynomial as the divisor, and the quotient polynomial is divisible by X M The method (500) according to claim 1, wherein the quotient polynomial is divisible by X - 1.
9. The quotient polynomial is (X M - 1) / (X d - 1), M = hd and d = M - N, for example, the quotient polynomial is X N + 1 or X N+N/2+1 The method (500) according to claim 8, wherein the method is as described above.
10. The polynomial is defined on a set where the density is 2 64 -2 32 +1, or on a set where the density is equal to a power of 2, the method (500) according to claim 9.
11. A computer-implemented method (600) for calculating a representation of a ciphertext, the representation being for use in an encryption calculation method according to any one of claims 1 to 10, the method comprising - obtaining the plaintext to be encrypted (610), - generating a representation of the ciphertext (620), wherein the ciphertext includes one or more mask polynomials and a body polynomial, - obtaining a seed for a pseudorandom number generator (621), - randomly selecting a mask polynomial by using the pseudorandom number generator according to the seed to generate a representation of the mask polynomial in the Fourier domain of the number-theoretic transform (622), - applying the inverse of the number-theoretic transform to the evaluation of the mask polynomial to determine the coefficients of the mask polynomial (623), - using the plaintext to determine the coefficients of the body polynomial such that the ciphertext encrypts the plaintext (624), - applying the number-theoretic transform to the coefficients of the body polynomial to determine a representation of the body polynomial in the Fourier domain (625) to generate a representation of the ciphertext (620), - outputting the representation of the ciphertext (630), the representation including the seed and the representation of the body polynomial in the Fourier domain, (630) comprising a method (600).
12. Generating a GGSW-type ciphertext by generating a plurality of ciphertexts including one or more mask polynomials and a body polynomial, the plurality of ciphertexts optionally being based on the same seed, the method (600) according to claim 11.
13. A device (110, 112) for performing encryption calculations, - A storage (140) for storing data representing a ciphertext, the ciphertext including one or more random mask polynomials, a mask polynomial, and a body polynomial derived from a plaintext, the storage (140), - A processor system (130), - Obtaining respective multiplicand polynomials for multiplying with the mask polynomial and the body polynomial, - Expanding the stored data representing the ciphertext, the stored data including a seed of a pseudo-random number generator and a representation of the body polynomial in the Fourier domain of a number-theoretic transform, the expanding including using the pseudo-random number generator according to the seed to generate a representation of the mask polynomial in the Fourier domain, - Calculating a polynomial product of the mask polynomial and the body polynomial with the respective multiplicand polynomials, the polynomial product being calculated in the Fourier domain to obtain a representation of the calculated polynomial product in the Fourier domain, - Outputting the calculated polynomial product A processor system (130) configured as such. A device (110, 112) comprising the same.
14. A device (110, 111) for calculating a representation of a ciphertext, the representation being for use in the encryption calculation method according to any one of Claims 1 to 10, the device comprising: - A storage (140) for storing a plaintext to be encrypted, - A processor system (130), - Obtaining a seed for a pseudo-random number generator, - Randomly selecting a mask polynomial by using the pseudo-random number generator according to the seed to generate a representation of the mask polynomial in the Fourier domain of a number-theoretic transform, - Applying the inverse of the number-theoretic transform to the evaluation of the mask polynomial to determine the coefficients of the mask polynomial, - Using the plaintext to determine the coefficients of the body polynomial such that the ciphertext encrypts the plaintext, - Applying the number-theoretic transform to the coefficients of the body polynomial to determine a representation of the body polynomial in the Fourier domain - Thereby generating a representation of a ciphertext including one or more mask polynomials and a body polynomial, A processor system (130) configured to output a representation of the ciphertext including the seed and the representation of the body polynomial in the Fourier domain. A device (110, 111) comprising the same.
15. A computer-readable storage medium (1000), A computer-readable storage medium (1000) that, when executed by a processor system, includes instructions that cause the processor system to perform the method according to any one of claims 1 to 10. **Claim 16**: A computer-readable storage medium (1000), A computer-readable storage medium (1000) that, when executed by a processor system, includes instructions that cause the processor system to perform the method according to claim 11.
Citation Information
Patent Citations
EP21290025
Encrypted computation comprising a blind rotation
EP4195577A1
Medical Information Management Systems and Management Act
JP2005535360A
Homomorphic Processing Unit (HPU) for Accelerating Secure Computation under Homomorphic Encryption
JP2020537756A
Method and processing device for performing a lattice-based cryptographic operation
US20190312728A1