Homomorphic encryption-based ciphertext processing method and device
The method addresses the challenge of modulus reduction in homomorphic encryption by optimizing approximation polynomials using L2-norm minimization and Chebyshev polynomials, enhancing bootstrapping efficiency and reducing noise levels for secure and efficient data processing.
Patent Information
- Application Number
- JP2021067688
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-10-22
- Filing Date
- 2021-04-13
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2041-04-13
AI Technical Summary
Existing homomorphic encryption methods face challenges in efficiently approximating modulus reduction functions during bootstrapping, leading to increased noise levels and limitations in the number of operations without decryption.
A method and device for processing ciphertext using homomorphic encryption that determines an approximation polynomial based on a plurality of samples, optimizing it using L2-norm minimization and Chebyshev polynomials to reduce noise and enhance bootstrapping efficiency.
The proposed method reduces noise levels and minimizes the number of operations required for bootstrapping, allowing for more accurate and efficient processing of encrypted data without decryption, particularly in applications requiring high precision.
Smart Images

Figure 0007736246000046 
Figure 0007736246000047 
Figure 0007736246000048
Abstract
Description
[Technical Field]
[0001] The following embodiments relate to a ciphertext processing method and device based on homomorphic encryption. [Background technology]
[0002] Fully homomorphic encryption is an encryption method that allows any logical or mathematical operation to be performed on the encrypted data. Fully homomorphic encryption maintains security in data processing. Fully homomorphic encryption allows clients to receive many services while maintaining privacy. Summary of the Invention [Problem to be solved by the invention]
[0003] An object of the present invention is to provide a method and apparatus for processing ciphertext based on homomorphic encryption. [Means for solving the problem]
[0004] According to one embodiment, a method for processing a ciphertext based on homomorphic encryption includes determining an approximation polynomial corresponding to a modulus reduction for bootstrapping a ciphertext based on a plurality of samples extracted from the modulus reduction, and bootstrapping the ciphertext based on the approximation polynomial.
[0005] In one embodiment of the method for processing ciphertext based on homomorphic encryption, the step of determining the approximation polynomial may determine coefficients of the approximation polynomial such that a current difference between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial is smaller than a predetermined threshold.
[0006] In one embodiment of a homomorphic encryption-based ciphertext processing method, the step of determining the approximation polynomial may include determining whether a current difference between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial is smaller than a predetermined threshold, and if the current difference is equal to or larger than the predetermined threshold, increasing the number of the plurality of samples or the degree of the approximation polynomial based on a comparison between the current difference and a difference determined in a previous step.
[0007] In one embodiment of the method for processing a ciphertext based on homomorphic encryption, the step of determining the approximation polynomial includes increasing the number of the plurality of samples if a similarity between the current difference and a difference determined in a previous step is smaller than a predetermined threshold similarity; If the similarity is equal to or greater than a predetermined threshold similarity, the degree of the approximation polynomial may be increased.
[0008] In one embodiment of a homomorphic encryption-based ciphertext processing method, a difference between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial may be determined based on an L2-norm between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial.
[0009] In an embodiment of the homomorphic encryption-based ciphertext processing method, the determining of the approximation polynomial may determine the approximation polynomial composed of odd-order terms.
[0010] In one embodiment of the homomorphic encryption-based ciphertext processing method, the determining of the approximation polynomial may determine the approximation polynomial based on a Chebyshev polynomial.
[0011] In an embodiment of the method for processing a ciphertext based on homomorphic encryption, the samples may be extracted from a piecewise continuous section having a symmetric shape around a reference point of a function corresponding to the modulus reduction.
[0012] In an embodiment of the homomorphic encryption-based ciphertext processing method, the plurality of samples may be extracted from a portion of the piecewise continuous section divided by the reference point.
[0013] In one embodiment of the method for processing ciphertext based on homomorphic encryption, the step of bootstrapping the ciphertext may perform the bootstrap on the ciphertext by homomorphically evaluating the modulus reduction using the approximation polynomial.
[0014] According to one embodiment, a homomorphic encryption-based ciphertext processing device includes one or more processors, which determine an approximation polynomial corresponding to a modulus reduction for bootstrapping a ciphertext based on a plurality of samples extracted from the modulus reduction, and perform bootstrapping on the ciphertext based on the approximation polynomial.
[0015] One embodiment of a method includes determining an initial approximation polynomial corresponding to a modulus reduction for bootstrapping ciphertext based on an initial number of samples extracted from the modulus reduction; calculating an error between the initial approximation polynomial and a modulus reduction function; increasing one of the initial number of samples and the degree of the initial approximation polynomial based on the error; determining an updated approximation polynomial based on the increased number of samples or the increased degree of the initial approximation polynomial; and homomorphically evaluating the modulus reduction using the updated approximation polynomial.
[0016] In one embodiment of the method, calculating the error may include determining that a difference between the initial number of samples extracted from the modulus reduction and the value of the initial approximation polynomial is greater than or equal to a threshold. [Effects of the Invention]
[0017] According to the present invention, a method and apparatus for processing ciphertext based on homomorphic encryption can be provided. [Brief explanation of the drawings]
[0018] [Figure 1] 10 is a diagram illustrating the operation of a user terminal and a server for processing ciphertext encrypted based on homomorphic encryption according to an embodiment. FIG. [Figure 2] FIG. 10 is an exemplary illustration of a scaled modulus reduction function according to one embodiment. [Figure 3] FIG. 10 is a diagram illustrating a process of determining an approximate polynomial according to an embodiment. [Figure 4] FIG. 10 is a diagram illustrating bootstrap using an approximate polynomial determined according to an embodiment. [Figure 5] FIG. 1 illustrates a ciphertext processing method according to an embodiment. [Figure 6] 1 is a diagram illustrating a ciphertext processing device according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0019] The specific structural or functional descriptions of the embodiments are disclosed for illustrative purposes only and may be modified in various forms. Therefore, the embodiments are not limited to the specific disclosed forms, and the scope of the present specification includes modifications, equivalents, or alternatives within the technical spirit.
[0020] Although terms such as "first" or "second" may be used to describe multiple components, such terms should be construed only to distinguish one component from the other components. For example, a first component may be designated as a second component, and similarly, a second component may be designated as a first component.
[0021] The singular expression includes the plural expression unless the context clearly dictates otherwise. In this specification, the words "comprise" or "have" and the like indicate the presence of a feature, number, step, operation, component, part, or combination thereof described in the specification, and should be understood as not precluding the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.
[0022] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by a person of ordinary skill in the art to which the present invention pertains. Commonly used predefined terms should be interpreted as having a meaning consistent with the meaning they have in the context of the relevant art, and should not be interpreted as having an ideal or overly formal meaning unless expressly defined herein.
[0023] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. In the description of the embodiments, if a detailed description of related prior art is deemed to unnecessarily obscure the gist of the present invention, the detailed description will be omitted.
[0024] FIG. 1 is a diagram illustrating the operation of a user terminal and a server that process ciphertext encrypted based on homomorphic encryption according to an embodiment.
[0025] Referring to FIG. 1, a user terminal 110 and a server 120 are illustrated. The user terminal 110 is a device controlled by a user and may include, for example, various computer devices such as a smartphone, tablet, laptop, or personal computer, various wearable devices such as a smart watch or smart glasses, various home appliances such as a smart speaker, smart TV, or smart refrigerator, smart automobiles, smart kiosks, Internet of Things (IoT) devices, drones, robots, etc. The user terminal 110 may encrypt stored data based on homomorphic encryption and transmit the data to the server 120. The user terminal 110 may transmit data to the server 120 to use various services provided by the server 120, and the transmitted data may be encrypted for information protection. For processing of the encrypted data by the server 120, the user terminal 110 may encrypt the data based on homomorphic encryption.
[0026] Homomorphic encryption is an encryption method that allows operations on encrypted data without decryption. Homomorphic encryption is suitable for applications with a large amount of data that requires privacy because it can process encrypted data without decryption. For example, homomorphic encryption may be the Cheon-Kim-Kim-Song (CKKS) method, which will be described in detail later. In this specification, unencrypted data may be represented as plaintext, and encrypted data may be represented as ciphertext.
[0027] Homomorphic encryption includes noise, and the noise level can increase as operations are performed on the ciphertext. To prevent the noise from overwhelming the data, noise processing, or in other words, bootstrapping, which refreshes the noise, can be performed. Through bootstrapping, parameter size and computation overhead can be fixed regardless of circuit depth.
[0028] For a ciphertext encrypted with a somewhat homomorphic cipher, there is a maximum number of operations possible without bootstrapping, which may be expressed at level l (0 < l ≤ L). Bootstrapping is a process of refreshing a ciphertext at level 0 where no more operations can be performed and generating a ciphertext at level L with the same message.
[0029] Server 120 can perform various operations on the ciphertext via bootstrapping, where decryption of the ciphertext is not required and thus personal information protection is not violated. Depending on the embodiment, the ciphertext calculated by server 120 may be sent back to user terminal 110, and user terminal 110 may provide the data obtained by decrypting the corresponding ciphertext to the user or use it for subsequent operations.
[0030] In bootstrapping, homomorphic evaluation of modulus reduction is important. Only arithmetic operations may be evaluated as homomorphic, but modulus reduction is not an arithmetic operation, so polynomial approximation for modulus reduction is required. In this specification, homomorphic evaluation may be expressed as the calculation of homomorphic values or the execution of homomorphisms.
[0031] In this specification, the problem of obtaining an approximate polynomial for modulus reduction may be switched to an L2 - norm minimization problem where the optimal solution can be directly calculated. Therefore, the limitations due to polynomial approximation using trigonometric functions (such as the sine function) can be easily overcome. To obtain an approximate polynomial for modulus reduction, a discretized optimization method may be applied. By solving the modified discretized problem, it is possible to have a low error while reducing the degree of the approximate polynomial for modulus reduction. Also, the level loss of bootstrapping can be reduced, and a solution to the cast problem can be determined in an efficient manner without repeating.
[0032] FIG. 2 is an exemplary diagram of a scaled modulus reduction function according to one embodiment.
[0033] In this document, vectors are shown in bold, such as x, and are column vectors. Matrices may be shown in bold capital letters, such as A. The dot product of two vectors may be shown as <·,·> or simply ·. Matrix multiplication may be shown as ·, or may be omitted if not necessary. The Lp-norm of a vector is
[0034]
number
[0035] x←D denotes a sampling x from a distribution D. If a set is used instead of a distribution, then x denotes a random uniform sampling of the set elements.
[0036] Chebyshev Interpolation Chebyshev interpolation is a polynomial interpolation method that uses Chebyshev polynomials as the basis for the interpolating polynomials. Chebyshev polynomials of the first kind, i.e., Chebyshev polynomials, can be expressed by a recursive relation as follows:
[0037]
number
[0038]
number
[0039] In Chebyshev interpolation, the nth degree polynomial p n (x) may be expressed as a sum of Chebyshev polynomials of the form:
[0040]
number
[0041]
number
[0042] CKKS method For a positive constant M, Φ M (X) is called the Mth cyclotomic polynomial of degree N, where M is a power of 2, M=2N, Φ M (X)=X N It could be +1.
[0043]
number
[0044]
number
[0045]
number
[0046]
number
[0047]
number
[0048] Three types of distributions may be defined as follows: If γ>0, then
[0049]
number
[0050]
Number
[0051] The CKKS scheme is defined for key generation, encryption, decryption, and corresponding homomorphic operations as follows.
[0052] KeyGen(1 λ ). Given a security parameter λ, M which is a power of 2, constant h, constant P, real value γ, and the maximum ciphertext modulus Q ≥ q L is determined, and sampling is performed as follows.
[0053]
Number
[0054]
Number
[0055]
Number
[0056]
Number
[0057] Here, the supported basic operations may be similarly applied to the full-RNS variant of CKKS, and therefore the methods described herein may be applied to the CKKS scheme and its various variants.
[0058] Bootstrapping in the CKKS method Bootstrapping in the CKKS method may include four steps: ModRaise (Modulus Raising), CoeffToSlot (Putting Polynomial Coefficients in Plaintext Slots), EvalMod (Evaluation of the Approximated Modulus Reduction), and SlotToCoeff (Switching Back to the Coefficient Representation).
[0059] ModRaise is the process of changing the modulus of the ciphertext to a larger value.<ct,sk> ] q Assume that the ciphertext satisfies
[0060]
number
[0061] In connection with CoeffToSlot, approximate homomorphic operations may be performed on plaintext slots. Therefore, to handle t(X), polynomial coefficients are placed in plaintext slots. In the CoeffToSlot step, Ecd can be performed homomorphically using matrix multiplication, operations similar to FFT using the relationship of roots of unity, or hybrid methods of these. And
[0062]
Number
[0063] SlotToCoeff may be the inverse operation of CoeffToSlot.
[0064] Approximate polynomials corresponding to modulus reduction As described above, homomorphic evaluation of modulus reduction is important in the bootstrapping of the CKKS scheme.
[0065] As shown in the graph of Figure 2, the modulus reduction function is scaled by 1 / q, and [t]q can be defined as t - k (t ∈ I k ). Here, I k = [k - ε, k + ε], where k is a constant with |k| < K. Also, ε represents the ratio between the maximum coefficient of the message polynomial and the ciphertext modulus, in other words, |m| / q < ε. The domain of [t]q is
[0066]
Number
[0067]
number
[0068]
number
[0069] where t i ' is each I k It is uniformly sampled in the interval δ<<ε, for example, k-ε, k-ε+δ,..., k+ε-δ, k+ε. k There are (2ε / δ+1) samples in , so the total number of samples is
[0070]
number
[0071] In other words, the piecewise continuous interval I of the modulus reduction function shown in FIG. k = [k-ε, k+ε], (2ε / δ+1) samples may be extracted. As will be explained later, the modulus decreasing function k = [k-ε, k+ε] have a symmetrical form around a reference point (e.g., -2, -1, 0, 1, 2, etc.), and by utilizing this property, we can create a piecewise continuous interval I k The approximate polynomial can also be determined using only samples extracted from a portion of the k-ε k = [k-ε, k+ε] separated by a reference point (e.g., a portion having a modulus reduction function value greater than 0 or a portion having a modulus reduction function value less than 0).
[0072] The objective function to be minimized is given as follows:
[0073]
number
[0074]
number
[0075] Therefore, instead of a power basis, Chebyshev polynomials may be used on the polynomial basis.
[0076]
number
[0077] Then, the optimal coefficient vector c * is as follows:
[0078]
number
[0079]
number
[0080]
number
[0081]
number
[0082]
number
[0083]
number
[0084] Small interval [t i ,t i +δ), then we can consider |E(t)| for t in |E(t)|≦|E(t i )|+|E(t)-E(t i )| is determined, and |E(t)-E(t i )| may be restricted as follows:
[0085]
number
[0086]
number
[0087] 2) L2-norm instead of L-infinity norm We can constrain the L-infinity norm to the L2-norm as follows:
[0088]
number
[0089] 3)c * Time Complexity to find N tot Considering >n, matrix inversion (T T T) -1 may be the dominant computation. Therefore, when using the Coppersmith Winograd algorithm, the time complexity is O(N tot 2.37 ) which is c * is acceptable because it is pre-calculated and stored in the coefficients for the baby-step giant-step algorithm or the Paterson-Stockmeyer algorithm described below.
[0090] Efficient homomorphic evaluation of approximate polynomials The approximation polynomial can be optimized based on the Chebyshev polynomial. Therefore, for efficient homomorphic evaluation of the proposed polynomial, the baby-step giant-step algorithm and the modified Paterson-Stockmeyer algorithm can be applied. The baby-step giant-step algorithm can reduce the polynomial size to at most 2 while consuming a depth of m. l +2 m-l +ml-3 nonscalar multiplication p o (t) can be evaluated homomorphically, where 2 m may be greater than nth order.
[0091] Once the Chebyshev polynomials are evaluated via the baby-step giant-step algorithm, T 2n =2T n 2 -T0 and T 2n+1 =2T n T n+1 -T1 is used, and the multiplication by 2 is replaced by an addition, so one biscalar multiplication and two additions are required.
[0092] baby-step giant-step algorithm uses baby-step l -1 degree polynomials are evaluated, up to 2 m / 2 l However, there can be polynomials of 2 m If n+1 is greater than n, there may exist a polynomial whose coefficients are all 0. If we ignore this, the maximum degree of a polynomial is 2 in baby steps. l -1
[0093]
number
[0094]
number
[0095]
number
[0096]
number
[0097] Proposition: If f(t) is an odd function, then the nth degree polynomial with the best approximation is an odd function. P m denotes the subspace of polynomial functions of degree m at most, and f m (t) is the supreme norm and f(t) is the closest P m Indicates a unique element of
[0098]
number
[0099]
number
[0100] One of the advantages of the proposed method is that it takes advantage of the properties of odd functions. By utilizing the fact that odd functions are symmetric with respect to the origin, the L2-norm minimization can be solved only for samples whose values are greater than 0 (or smaller than 0). Therefore, the number of rows and columns of matrix T can be reduced by half. As a result, the time complexity of matrix inversion is reduced by approximately 1 / 8. In addition, some operations on even-order terms can be ignored during homomorphic evaluation.
[0101] Bootstrapping level reduction The proposed method allows for the selection of the most suitable parameters for reducing the level loss in the bootstrap. As mentioned above, the proposed method can obtain a more accurate approximation polynomial when the level loss is relatively large than the best method described above. The following describes how the parameters are selected based on these characteristics.
[0102] For noise estimation, the following lemmas may be used.
[0103]
number
[0104] In the EvalMod step, each component in the corresponding plain text slot is j |≦O(B rs ) small errors such as e j t for j +e j The approximate polynomial p o (t j ) is the scaling factor Δ bs evaluates to, so the approximate real number is:
[0105]
number
[0106]
number
[0107] In Lemma 2 above, the bootstrap error is independent of the scaling factor of the message Δ and may be bounded by O(N√h). Therefore, the precision of the plaintext is proportional to logΔ, where Δ can determine |m|. By the methods described previously, the level loss of the bootstrap is approximately O(m 3 / 2) is proportional to O(m). This is one of the advantages of the proposed method, which can overcome the limitations of existing methods and can provide greater effectiveness when more accurate calculations are required.
[0108] Various factors, such as the number of slots, affect the precision of the plain text. Therefore, the precision of the plain text is obtained using a numerical method and used to determine the parameters. Using the proposed method, a relatively small q is used, so more levels may remain after bootstrapping in some cases.
[0109] Through the above explanation, we can determine an approximate polynomial of the modulus reduction function for bootstrap. The problem of finding an approximate polynomial for modulus reduction can be replaced with the problem of minimizing the L2-norm, which can be found directly without using an intermediate function such as a sine function.
[0110] The approximation error of the proposed method is not affected by sine functions, allowing for highly accurate approximation of modulus reduction. Lower approximation errors can be achieved even with lower-order polynomials based on Chebyshev polynomials. The proposed polynomials may also utilize the baby-step giant-step algorithm and the Paterson-Stockmeyer algorithm. Based on the number of non-scalar multiplications, scalar multiplications, and additions required for the baby-step giant-step algorithm, it is confirmed that the proposed polynomials reduce the number of operations required for homomorphic approximation of modulus reduction.
[0111] The proposed method can provide bootstrap with less error, especially when choosing a large scaling factor. Therefore, the range of parameter selection can be expanded. Most importantly, the proposed method is essential for applications where accurate approximation is required. Conversely, the proposed method allows for better parameter selection due to the absence of such a lower bound. As a result, bootstrap can consume fewer levels when using the proposed method.
[0112] FIG. 3 is a diagram illustrating a process of determining an approximate polynomial according to an embodiment.
[0113] In step S301, the number of samples N, the degree of the approximation polynomial n, and the target error e target For example, the number of samples N may be set to 16. However, the embodiment is not limited thereto, and the number of initial samples may be set in various ways depending on the situation.
[0114] In step S302, for each section I k For each N samples t1,...,t N(2K-1) Here, Ik=[k-ε, k+ε] may be used.
[0115] In step S303, an approximation polynomial T based on the Chebyshev polynomial and a function value Y corresponding to the modulus reduction are determined, where:
[0116]
number
[0117] In step S304, the modulus reduction function value [t i ] q and the n-th degree polynomial value
[0118]
number
[0119] In step S305, the determined optimal coefficient vector c * Using the approximate polynomial p n (t) is determined.
[0120] In step S306, the determined approximate polynomial p n (t) and modulus reduction function [t] q The error between them is calculated.
[0121] In step S307, the calculated error is calculated as the target error e target If the calculated error is smaller than the target error e target If it is greater than or equal to, step S308 is continued.
[0122] In step S308, it is determined whether the similarity between the calculated error and the error calculated in the previous step is less than a predetermined threshold similarity. If the similarity is less than the predetermined threshold similarity, i.e., the error calculated in the current step is less than the error calculated in the previous step and are not similar to each other, step S309 is performed to increment the number of samples N. Conversely, if the similarity is greater than or equal to the predetermined threshold similarity, i.e., the error calculated in the current step is similar to the error calculated in the previous step, step S310 is performed to increment the degree n of the approximation polynomial. As such, if the number of samples is small, the approximation polynomial may not smoothly approximate the modulus reduction function, and therefore the number of samples N must be increased. If increasing the number of samples does not significantly improve the error, this indicates that the degree of the approximation polynomial is insufficient, and the degree n can be increased. As described above, since the approximation polynomial is composed of odd-order terms, the degree n is incremented by two.
[0123] The error calculated in step S307 is the target error e target If it is determined that the approximation polynomial p is smaller than the n (t) will be finalized and returned.
[0124] The approximate polynomial expressed as coefficients obtained by the above method can be used to bootstrap fully homomorphic encryption using various methods, including operations to reduce the number and depth of operations, such as the baby-step / giant-step algorithm and the Paterson-Stockmeyer algorithm.
[0125] Depending on the embodiment, for ease of calculation, only Chebysep polynomials of a certain degree may be used as the approximation polynomial. In addition to the Chebysep polynomials, Legendre polynomials or the power of x may be used as the basis.
[0126] FIG. 4 is a diagram for explaining bootstrap using an approximate polynomial determined according to an embodiment.
[0127] In step S410, the ciphertext that requires the modulus operation is identified during the bootstrap process. In step S420, the approximation polynomial p(t) for the modulus reduction function determined in Figure 3 is homomorphically evaluated, and in step S430, the approximation result of the modulus operation is obtained.
[0128] FIG. 5 is a diagram illustrating a ciphertext processing method according to an embodiment.
[0129] Referring to FIG. 5, there is shown a ciphertext processing method performed by a processor included in a ciphertext processing apparatus according to one embodiment.
[0130] In step S510, the ciphertext processing device determines an approximation polynomial corresponding to a modulus reduction for bootstrapping the ciphertext based on a plurality of samples extracted from the modulus reduction. The ciphertext processing device can determine coefficients of the approximation polynomial such that the difference between the values of the plurality of samples and the approximation polynomial is smaller than a predetermined threshold.
[0131] The ciphertext processing device may determine whether a difference between the plurality of samples and the value of the approximation polynomial is smaller than a predetermined threshold, and if the difference is equal to or greater than the predetermined threshold, may increase the number of the plurality of samples or the degree of the approximation polynomial based on a comparison between the difference and a difference determined in a previous step. For example, the ciphertext processing device may increase the number of the plurality of samples if a similarity between the difference and a difference determined in a previous step is smaller than a predetermined threshold similarity, or may increase the degree of the approximation polynomial if the similarity is equal to or greater than the predetermined threshold similarity. The difference between the plurality of samples and the value of the approximation polynomial may be determined based on an L2-norm between the plurality of samples and the value of the approximation polynomial.
[0132] The ciphertext processor may determine an approximation polynomial composed of odd-degree terms. The ciphertext processor may determine an approximation polynomial based on Chebyshev polynomials.
[0133] In step S520, the ciphertext processing device bootstraps the ciphertext based on the approximation polynomial. The ciphertext processing device can bootstrap the ciphertext by homomorphically evaluating modulus reduction using the approximation polynomial.
[0134] The steps shown in FIG. 5 are the same as those described above with reference to FIGS. 1 to 4, and therefore will not be described in detail.
[0135] FIG. 6 is a diagram illustrating a ciphertext processing apparatus according to an embodiment.
[0136] 6, a ciphertext processing device 600 according to one embodiment includes a memory 610 and a processor 620. The memory 610 and the processor 620 can communicate with each other via a bus 630 or the like.
[0137] The memory 610 may include computer-readable instructions. The processor 620 performs the above-described operations by executing the instructions stored in the memory 610. The memory 610 may be a volatile memory or a non-volatile memory.
[0138] The processor 620 executes instructions or programs and may include, for example, a central processing unit (CPU) or a graphic processing unit (GPU) as a device for controlling the ciphertext processing device 600. The processor 620 determines an approximation polynomial corresponding to modulus reduction for bootstrapping the ciphertext based on a plurality of samples extracted from the modulus reduction, and bootstraps the ciphertext based on the approximation polynomial.
[0139] The ciphertext processing device 600 may be used in a bootstrap process of a ciphertext in which a plaintext consisting of a real number or a complex number is encrypted in fully homomorphic encryption. When the degree of the approximation polynomial determined by the ciphertext processing device 600 is lowered, the number of operations is reduced, and therefore, the resources required for the ciphertext processing operation can be efficiently reduced.
[0140] In addition, the ciphertext processing device 600 can be applied to cloud computers, information protection machine learning, and other cryptographic / security technology fields such as the entire homomorphic cryptography application field, network security, system (terminal) security, cryptography / authentication, security management, content / information leakage prevention security, and authentication services.
[0141] In addition, the ciphertext processing device 600 can process the above-mentioned operations.
[0142] The above-described embodiments may be implemented using hardware components, software components, or a combination of hardware and software components. For example, the devices and components described herein may be implemented using one or more general-purpose or special-purpose computers, such as a processor, controller, arithmetic logic unit (ALU), digital signal processor, microcomputer, field programmable array (FPA), programmable logic unit (PLU), microprocessor, or other device that executes and responds to instructions.
[0143] Software includes computer programs, codes, instructions, or a combination of one or more thereof, which can configure a processing device to operate as desired and can independently or jointly instruct the processing device. The software and / or data can be permanently or temporarily embodied in any type of machine, component, physical device, virtual device, computer storage medium or device, or transmitted signal wave to be interpreted by the processing device and provide instructions or data to the processing device. The software can be distributed across computer systems coupled to a network and stored and executed in a distributed manner. The software and data can be stored on one or more computer-readable recording media.
[0144] The methods according to the present invention may be embodied in the form of program instructions that can be executed by various computer means and stored on a computer-readable storage medium. The storage medium may include program instructions, data files, data structures, and the like, alone or in combination. The storage medium and program instructions may be specially designed and constructed for the purposes of the present invention, or they may be well-known and available to those skilled in the art of computer software. Examples of computer-readable storage media include magnetic media such as hard disks, floppy disks, and magnetic tape, optical media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program instructions, such as ROM, RAM, flash memory, and the like. Examples of program instructions include not only machine code, such as produced by a compiler, but also high-level language code that is executed by a computer using an interpreter, for example. A hardware device may be configured to operate as one or more software modules to perform the operations described in the present invention, or vice versa.
[0145] Although the embodiments have been described above with reference to limited drawings, those skilled in the art may apply various technical modifications and variations based on the above description. For example, the described techniques may be performed in a different order than described, and / or the components of the described systems, structures, devices, circuits, etc. may be combined or combined in a different manner than described, or may be replaced or substituted with other components or equivalents, and still achieve suitable results.
Claims
1. A ciphertext processing method based on homomorphic encryption executed by a ciphertext processing device, an approximation polynomial determination step of determining an approximation polynomial corresponding to a modulus reduction for bootstrapping a ciphertext based on a plurality of samples extracted from the modulus reduction; bootstrap the ciphertext based on the approximation polynomial; The approximation polynomial determining step includes: determining whether a current difference between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial is less than a predetermined threshold; If the current difference is equal to or greater than a predetermined threshold, increasing the number of the plurality of samples if the similarity between the current difference and the difference determined in the previous step is smaller than a predetermined threshold similarity, and increasing the degree of the approximation polynomial if the similarity is equal to or greater than the predetermined threshold similarity; A ciphertext processing method comprising:
2. 2. The ciphertext processing method of claim 1, wherein a difference between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial is determined based on an L2-norm between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial.
3. 3. The ciphertext processing method according to claim 1, wherein the approximation polynomial determining step determines the approximation polynomial composed of odd-degree terms.
4. 4. The ciphertext processing method according to claim 1, wherein the approximation polynomial determining step determines the approximation polynomial based on a Chebyshev polynomial.
5. The method of claim 1, wherein the plurality of samples are extracted from piecewise continuous sections having a symmetrical shape around a reference point of a function corresponding to the modulus reduction.
6. The ciphertext processing method according to claim 5 , wherein the plurality of samples are extracted from a portion of the piecewise continuous section separated by the reference point.
7. The ciphertext processing method according to claim 1 , wherein the step of bootstrapping the ciphertext comprises bootstrapping the ciphertext by homomorphically evaluating the modulus reduction using the approximation polynomial.
8. A computer-readable storage medium on which a program for executing the ciphertext processing method according to any one of claims 1 to 7 is recorded.
9. In a homomorphic encryption-based ciphertext processing device, one or more processors; the one or more processors perform an approximation polynomial determination step of determining an approximation polynomial corresponding to a modulus reduction for bootstrapping a ciphertext based on a plurality of samples extracted from the modulus reduction; configured to bootstrap the ciphertext based on the approximation polynomial; The approximation polynomial determining step includes: determining whether a current difference between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial is less than a predetermined threshold; If the current difference is equal to or greater than a predetermined threshold, increasing the number of the plurality of samples if the similarity between the current difference and the difference determined in the previous step is smaller than a predetermined threshold similarity, and increasing the degree of the approximation polynomial if the similarity is equal to or greater than the predetermined threshold similarity; 1. A ciphertext processing device comprising:
10. 10. The ciphertext processing device according to claim 9, wherein a difference between the plurality of samples extracted from the modulus reduction and the value of the approximation polynomial is determined based on an L2-norm between the plurality of samples and the value of the approximation polynomial.
11. The ciphertext processing device according to claim 9 , wherein the one or more processors determine the approximation polynomial composed of odd-degree terms.
12. The cryptographic processing device according to any one of claims 9 to 11, wherein the one or more processors determine the approximation polynomial based on a Chebyshev polynomial.
13. The encryption / decryption processing device according to any one of claims 9 to 12, wherein the plurality of samples are extracted from piecewise continuous sections of a function corresponding to the modulus reduction, the section sections having a symmetrical form about a reference point.
14. The ciphertext processing device according to claim 13 , wherein the plurality of samples are extracted from a portion of the piecewise continuous section separated by the reference point.
Citation Information
Patent Citations
Scanning apparatus, drawing apparatus, and method of manufacturing article
KR1020130058615A
Multi-dimensional error definition, error measurement, error analysis, error function generation, error information optimization, and error correction for communications systems
US20080133982A1
Enabling constant plaintext space in bootstrapping in fully homomorphic encryption
US20190334694A1
Apparatus for approximately processing encrypted messages and methods thereof
US20200036511A1