Apparatus and method for performing reboot operations on isomorphic ciphertexts

The method for processing isomorphic ciphertexts addresses error amplification in conventional reboot methods by generating intermediate ciphertexts to expand the plaintext space, ensuring accurate and efficient calculations.

JP7839886B2Active Publication Date: 2026-04-02CRYPTO LAB INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-04-14
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Conventional reboot methods for homomorphic ciphertexts suffer from error amplification during the scaling factor reflection process, leading to a decrease in computational accuracy.

Method used

A method and apparatus for processing isomorphic ciphertexts that involves generating a first intermediate ciphertext by applying a preset reboot operation to the calculation result, followed by a subtraction operation with a second intermediate ciphertext to expand the plaintext space, ensuring errors are within an acceptable range.

Benefits of technology

This approach maintains higher computational accuracy by effectively expanding the plaintext space while minimizing error amplification, enabling continuous processing of isomorphic ciphertexts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007839886000045
    Figure 0007839886000045
  • Figure 0007839886000046
    Figure 0007839886000046
  • Figure 0007839886000047
    Figure 0007839886000047
Patent Text Reader

Abstract

A ciphertext processing method is disclosed, which includes the steps of performing an operation on a homomorphic ciphertext for an erroneous approximate message, and expanding a plaintext space of the operation result ciphertext when the approximate message weight in the operation result ciphertext obtained by the operation exceeds a threshold, and the step of expanding the plaintext space includes the steps of applying a preset reboot operation to the operation result ciphertext to generate a first intermediate ciphertext, applying a preset reboot operation to a subtraction operation result between the operation result ciphertext and the first intermediate ciphertext to generate a second intermediate ciphertext, and performing a subtraction operation of the second intermediate ciphertext on the first intermediate ciphertext to generate a homomorphic ciphertext with an expanded plaintext space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an apparatus and a method for efficiently performing a reboot method for a homomorphic ciphertext.

Background Art

[0002] As communication technologies have developed and the spread of electronic devices has become active, efforts have continued to maintain communication security between electronic devices. As a result, encryption / decryption technologies are used in many communication environments.

[0003] When a message encrypted by an encryption technology is sent to a recipient, the recipient needs to perform decryption in order to use the message. In this case, the recipient will generate wasted resources and time in the process of decrypting the encrypted data.

[0004] In addition, there is also a problem that if hacking is performed by a third party while the recipient temporarily decrypts the message for calculation, the message may easily leak to the third party.

[0005] To solve such problems, homomorphic encryption methods have been studied. According to homomorphic encryption, even if calculations are performed on the ciphertext itself without decrypting the encrypted information, after performing calculations on the plaintext, the same result as the encrypted value can be obtained. Therefore, various calculations can be performed without decrypting the ciphertext.

[0006] However, when performing homomorphic calculations such as homomorphic multiplication, the plaintext space within the homomorphic ciphertext decreases, and when the plaintext space becomes less than a certain size, further calculations cannot be performed. In this regard, in recent years, a reboot method that can expand the plaintext space of homomorphic ciphertexts has been used.

[0007] However, conventional reboot methods have a problem in that errors are amplified simultaneously during the scaling factor reflection process, potentially altering the accuracy of calculations. Therefore, there is a need for a reboot method that offers higher computational accuracy. [Overview of the Initiative] [Problems that the invention aims to solve]

[0008] Therefore, the present invention has been made in view of the above problems, and the object of the present invention is to provide an apparatus and method for efficiently performing a reboot operation on an isomorphic ciphertext. [Means for solving the problem]

[0009] To achieve the above objectives, the present invention provides a method for processing isomorphic ciphertexts according to one embodiment of the present invention, which includes the steps of: performing an operation on an isomorphic ciphertext with respect to an approximate message containing an error; and, if the weight of the approximate message in the calculation result ciphertext obtained by the operation exceeds a threshold, expanding the plaintext space of the calculation result ciphertext, wherein the step of expanding the plaintext space includes the steps of: generating a first intermediate ciphertext by applying a preset reboot operation to the calculation result ciphertext; generating a second intermediate ciphertext by applying the preset reboot operation to the result of a subtraction operation between the calculation result ciphertext and the first intermediate ciphertext; and generating an isomorphic ciphertext with an expanded plaintext space by performing a subtraction operation of the second intermediate ciphertext on the first intermediate ciphertext.

[0010] In this case, the step of generating the first intermediate ciphertext may involve reflecting a scaling factor so that the calculation result ciphertext has a predetermined range, applying a predetermined reboot operation to the calculation result ciphertext with the scaling factor reflected, reflecting the scaling factor in the result of applying the predetermined reboot operation, and generating the first intermediate ciphertext.

[0011] In this case, the aforementioned pre-set range may be [-1, 1].

[0012] On the other hand, the aforementioned preset range is

number

[0013] On the other hand, the pre-configured reboot operation may include the steps of: extending the modulus of the isomorphic ciphertext; linearly transforming the isomorphic ciphertext with the extended modulus into polynomial form; performing an approximate modulus operation on the isomorphic ciphertext transformed into polynomial form using a higher-order equation configured such that input values ​​within a pre-configured range approximate integer points; and linearly transforming the result of the approximate modulus operation back into the form of the isomorphic ciphertext.

[0014] On the other hand, the pre-configured reboot operation may include the steps of: linearly transforming the isomorphic ciphertext into polynomial form; extending the modulus of the isomorphic ciphertext linearly transformed into polynomial form; performing an approximate modulus operation on the extended result of the modulus; and linearly transforming the result of the approximate modulus operation back into the form of the isomorphic ciphertext.

[0015] On the other hand, an arithmetic device according to one embodiment of the present invention includes a memory for storing isomorphic ciphertexts for approximate messages including errors, and a processor for performing calculations on the isomorphic ciphertexts. The processor generates a first intermediate ciphertext by applying a preset reboot operation to the isomorphic ciphertext, generates a second intermediate ciphertext by applying the preset reboot operation to the result of a subtraction operation between the calculation result ciphertext and the first intermediate ciphertext, and generates an isomorphic ciphertext with an expanded plaintext space by performing a subtraction operation of the second intermediate ciphertext on the first intermediate ciphertext.

[0016] In this case, the processor may apply a scaling factor to the calculation result ciphertext so that it has a predetermined range, apply a predetermined reboot operation to the calculation result ciphertext to which the scaling factor has been applied, apply the scaling factor to the result to which the predetermined reboot operation has been applied, and generate the first intermediate ciphertext.

[0017] In this case, the aforementioned pre-set range may be [-1, 1].

[0018] On the other hand, the aforementioned preset range is

number

[0019] On the other hand, the processor may extend the modulus of the isomorphic ciphertext, linearly transform the isomorphic ciphertext with the extended modulus into polynomial form, perform an approximate modulus operation on the isomorphic ciphertext transformed into polynomial form using a higher-order equation set so that the input values ​​within a predetermined range approximate integer points, linearly transform the result of the approximate modulus operation back into the form of the isomorphic ciphertext, and perform the predetermined reboot operation.

[0020] On the other hand, the processor may linearly transform the isomorphic ciphertext into polynomial form, extend the modulus of the isomorphic ciphertext linearly transformed into polynomial form, perform an approximate modulus operation on the extended result of the modulus, linearly transform the result of the approximate modulus operation back into the form of an isomorphic ciphertext, and perform the pre-set reboot operation. [Effects of the Invention]

[0021] As described above, the present invention makes it possible to perform a reboot operation while maintaining higher accuracy than in the conventional method. [Brief explanation of the drawing]

[0022] [Figure 1] This is a diagram for explaining the structure of a network system according to an embodiment of the present invention. [Figure 2] This is a block diagram showing the configuration of an arithmetic unit according to an embodiment of the present invention. [Figure 3] This is a diagram for explaining the reboot operation of the present invention. [Figure 4] This is a diagram for explaining the reboot operation of the present invention. [Figure 5] This is a flowchart for explaining a method for processing homomorphic ciphertext according to the present invention. [Figure 6] This is a flowchart for explaining the reboot operation of the present invention. [Figure 7] This is a flowchart for explaining an operation of expanding the plaintext space of the present invention. [Figure 8] This is a diagram showing an algorithm for a reboot operation according to a first embodiment of the present invention. [Figure 9] This is a diagram showing an algorithm for a reboot operation according to a second embodiment of the present invention. [Figure 10] This is a diagram for explaining a change in accuracy due to a reboot operation. [Figure 11] This is a diagram for explaining a change in accuracy due to a reboot operation.

Modes for Carrying Out the Invention

[0023] Hereinafter, the present invention will be described in detail with reference to the accompanying drawings. In the present invention, in the process of transmitting information (data) to be processed, encryption / decryption may be applied as necessary, and expressions for explaining the information (data) transmission process in the present invention and the claims should be interpreted as including both cases of encryption / decryption even if not specifically mentioned. In the present invention, expressions such as "transmitted (transferred) from A to B" or "received by A from B" also include the case where transmission (transfer) or reception is performed through other intervening media, and do not necessarily represent only direct transmission (transfer) or reception from A to B.

[0024] In describing the present invention, the order of each step should be understood non-restrictively, unless the preceding step must logically and temporally precede the subsequent step. That is, except in the exceptional cases described above, even if a process described as a subsequent step is performed before a process described as a preceding step, it does not affect the essence of the disclosure, and the scope of rights should be defined regardless of the order of the steps. Furthermore, in this specification, the phrase "A or B" is defined to mean not only selectively referring to either A or B, but also including both A and B. In this invention, the term "including" also encompasses the inclusion of other components in addition to the elements listed as including.

[0025] In this invention, only the essential components necessary for describing the invention will be described, and components unrelated to the essence of the invention will not be mentioned. Furthermore, the terms used should not be interpreted as exclusive in meaning, including only the components mentioned, but rather as non-exclusive in meaning, potentially including other components.

[0026] In this invention, the term "value" is defined as a concept that includes not only scalar values ​​but also vectors. In this invention, expressions such as "calculate" or "compute" may be replaced with expressions that generate the result of the calculation or computation. Unless otherwise specified, operations on ciphertext described later mean isomorphic operations. For example, addition of isomorphic ciphertexts means isomorphic addition of two isomorphic ciphertexts.

[0027] The mathematical operations and calculations in each stage of the present invention, as described later, may be performed by computer computation using known coding methods and / or coding methods suitably devised for the present invention.

[0028] The specific mathematical formulas described below are, wherever possible, illustrative examples of multiple alternatives, and should not be interpreted as limiting the scope of the present invention to the formulas referenced herein.

[0029] For the sake of clarity, this specification will define the following conventions: a←D: Select element (a) according to the distribution (D). s1 and s2 ∈ R: S1 and S2 are elements belonging to the R set, respectively. mod(q): Modular operation with element q

number

[0030] Figure 1 is a diagram illustrating the structure of a network system according to one embodiment of the present invention.

[0031] Referring to Figure 1, the network system may include a plurality of electronic devices 100-1 to 100-n, a first server device 200, and a second server device 300, and each component may be interconnected via the network 10.

[0032] Network 10 may be implemented in various forms such as wired and wireless networks, broadcasting and communication networks, optical communication networks, and cloud networks, and each device may be connected without a separate intermediary using methods such as Wi-Fi, Bluetooth, and NFC (Near Field Communication).

[0033] In Figure 1, the electronic devices are shown as multiple devices 100-1 to 100-n, but it is not necessarily required that multiple electronic devices be used; one device may be used. For example, the electronic devices 100-1 to 100-n can be implemented using a variety of devices such as smartphones, tablets, game players, personal computers, laptops, home servers, and kiosk terminals, or they may be implemented using home appliances with IoT functionality.

[0034] Users may input various types of information through their own electronic devices 100-1 to 100-n. The input information may be stored on the electronic devices 100-1 to 100-n themselves, but for reasons such as storage capacity and security, it may also be transmitted to and stored on an external device. In Figure 1, the first server device 200 is responsible for storing such information, and the second server device 300 is responsible for using some or all of the information stored on the first server device 200.

[0035] Each electronic device 100-1 to 100-n may encrypt the input information in the same manner and transmit the same type of ciphertext to the first server device 200.

[0036] Each electronic device 100-1 to 100-n may include encryption noise, i.e., errors, calculated during the process of isomorphic encryption, in the ciphertext. Specifically, the isomorphic ciphertexts generated by each electronic device 100-1 to 100-n may be generated in such a way that when decrypted using a secret key, the resulting value including the message and error value is restored.

[0037] As an example, isomorphic ciphertexts generated from electronic devices 100-1 to 100-n may be generated in a form that satisfies the following properties when decrypted using a secret key. [Formula 1]

number

[0038] If the message size is too small or too large, a scaling factor can be used to adjust its size. Using a scaling factor allows for the encryption of not only integer messages but also real number messages, significantly increasing its usability. Furthermore, adjusting the message size using a scaling factor may also adjust the size of the area in the ciphertext where the message resides after the operation, i.e., the effective area.

[0039] Depending on the embodiment, the modulus q of the ciphertext may be set and used in various forms. For example, the modulus of the ciphertext is a power of the scaling factor Δ.

number

number

[0040] Furthermore, although the isomorphic ciphertext according to the present invention will be described assuming the use of fixed-point numbers, it may also be applicable when using floating-point numbers.

[0041] The first server device 200 may store the received ciphertext in its ciphertext state without decrypting it.

[0042] The second server device 300 may request the first server device 200 to provide a specific processing result for an isomorphic ciphertext. The first server device 200 may perform a specific operation in response to the request from the second server device 300 and then transmit the result to the second server device 300.

[0043] For example, if the ciphertexts ct1 and ct2 transmitted by two electronic devices 100-1 and 100-2 are stored in the first server device 200, the second server device 300 may request the first server device 200 to provide a sum of the information provided by both electronic devices 100-1 and 100-2. In response to the request, the first server device 200 may perform a calculation to add the two ciphertexts together and then transmit the resulting value (ct1 + ct2) to the second server device 300.

[0044] Due to the nature of isomorphic ciphertexts, the first server device 200 may perform calculations without decryption, and the resulting value may also be in the form of ciphertext. In this invention, the resulting value obtained by the calculation is called the calculation result ciphertext.

[0045] The first server device 200 may transmit the calculation result ciphertext to the second server device 300. The second server device 300 may decrypt the received calculation result ciphertext and obtain the calculation result value of the data contained in each isomorphic ciphertext.

[0046] The first server device 200 may perform calculations multiple times in response to user requests. In this case, the weight of the approximate message in the calculation result ciphertext obtained for each calculation will differ. If the weight of the approximate message exceeds a threshold, the first server device 200 may perform a reboot (bootstrapping) operation. Thus, since the first server device 200 can perform calculation operations, it may be called a calculation device.

[0047] Specifically, in the above equation 1, if q is less than M, M+e(mod q) will have a different value from M+e, making decryption impossible. Therefore, the value of q must always be kept greater than M. However, as the operation progresses, the value of q gradually decreases. Therefore, an operation is needed to change the value of q so that it is always greater than M, and this operation is called a reboot operation. By performing such a reboot operation, the ciphertext can become a state where it can be recalculated. Specific operations related to reboot will be described later with reference to Figures 3 and 4.

[0048] On the other hand, Figure 1 shows a case where encryption is performed by the first and second electronic devices and decryption is performed by the second server device, but it is not necessarily limited to this case.

[0049] Figure 2 is a block diagram showing the configuration of an electronic device according to one embodiment of the present invention.

[0050] Specifically, in the system shown in Figure 1, devices that perform isomorphic ciphertext processing, such as the first electronic device and the second electronic device, devices that perform calculations on isomorphic ciphertext, such as the first server device, and devices that decrypt isomorphic ciphertext, such as the second server device, may be referred to as computing devices. Such computing devices may be a variety of devices, such as PCs (personal computers), laptops, smartphones, tablets, and servers.

[0051] Referring to Figure 2, the arithmetic unit 400 may include a communication device 410, a memory 420, a display 430, an operation input device 440, and a processor 450.

[0052] The communication device 410 is formed to connect the computing unit 400 to an external device (not shown), and can be connected not only via a local area network (LAN) and the internet, but also via a USB (Universal Serial Bus) port or a wireless communication port (e.g., WiFi 802.11a / b / g / n, NFC, Bluetooth). Such a communication device 410 may be referred to as a transceiver.

[0053] The communication device 410 may receive a public key from an external device, and the arithmetic unit 400 may transmit a public key it has generated to an external device.

[0054] The communication device 410 may receive a message from an external device and transmit the generated identical ciphertext to the external device.

[0055] The communication device 410 may receive various parameters necessary for generating ciphertext from an external device. On the other hand, in implementation, these parameters may be directly input by the user via the operation input device 440, which will be described later.

[0056] Furthermore, the communication device 410 may receive a request from an external device to perform calculations on the same type of ciphertext, and may transmit the calculated result to the external device.

[0057] Memory 420 is a component for storing the OS for driving the arithmetic unit 400, various software, data, etc. Memory 420 can be implemented in a variety of forms, such as RAM, ROM, flash memory, HDD, external memory, or memory card, and is not limited to any one of them.

[0058] Memory 420 stores messages to be encrypted. Here, a message may be various credit information or personal information cited by the user, or it may be information related to usage history, such as location information or internet usage time information used by the computing unit 400.

[0059] Furthermore, the memory 420 may store the public key, and if the arithmetic unit 400 is a device that directly generates the public key, it may store not only the private key but also the public key and various parameters necessary for generating the private key.

[0060] Furthermore, memory 420 may store identical ciphertext generated in the process described later. Memory 420 may also store identical ciphertext transmitted from an external device. Additionally, memory 420 may store ciphertext resulting from calculations, which are the output of the calculation process described later.

[0061] The display 430 displays a user interface window for selecting functions supported by the arithmetic unit 400. Specifically, the display 430 may display a user interface window for selecting various functions provided by the arithmetic unit 400. Such a display 430 may be a monitor such as an LCD (liquid crystal display) or OLED (organic light-emitting diodes), and may be implemented as a touchscreen capable of simultaneously executing the functions of the operation input device 440 described later.

[0062] Display 430 may display a message requesting input of parameters necessary for generating a private key and a public key. Display 430 may also display a message allowing the user to select the message to be encrypted. In implementation, the message to be encrypted may be selected directly by the user or automatically. That is, personal information requiring encryption may be automatically set without the user having to directly select the message.

[0063] The operation input device 440 may receive input from the user regarding the selection of functions for the arithmetic unit 400 and control commands for those functions. Specifically, the operation input device 440 may receive input from the user regarding the parameters necessary for generating a private key and a public key. The operation input device 440 may also receive a message to be encrypted from the user.

[0064] The processor 450 controls each component within the arithmetic unit 400. Such a processor 450 may consist of a single device such as a CPU (central processing unit) or an ASIC (application-specific integrated circuit), or it may consist of multiple devices such as a CPU and a GPU (Graphics Processing Unit).

[0065] When a message to be transmitted is received by the processor 450, it is stored in memory 420. Then, the processor 450 uses the various settings and programs stored in memory 420 to isomorphically encrypt the message. In this case, a public key may be used.

[0066] The processor 450 may generate and use the public key necessary for encryption, or it may receive and use one from an external device. For example, the second server device 300, which performs decryption, may distribute the public key to another device.

[0067] When generating keys itself, processor 450 may generate a public key using the Ring-LWE technique. Specifically, processor 450 may first set various parameters and a ring and store them in memory 420. Examples of parameters may include the length of the plaintext message bits, and the sizes of the public and private keys.

[0068] The ring can be expressed by the following mathematical formula: [Formula 2]

number

[0069] A ring is a set of polynomials with predetermined coefficients, where addition and multiplication are defined between elements, and the set is closed under addition and multiplication. Such a ring may also be called a ring.

[0070] For example, the ring represents the set of n-th degree polynomials whose coefficient is Zq. Specifically, when n is Φ(N), it can represent an N-th degree cyclotomic polynomial. (f(x)) represents the ideal of Zq[x] generated as f(x). The Euler totient function Φ(N) represents a number of natural numbers smaller than N that are relatively prime to N. Φ N If we define (x) as a cyclotomic polynomial of degree N, the ring can also be expressed by equation 3 as follows: [Formula 3]

number

[0071] The private key (sk) can be expressed as follows:

[0072] On the other hand, the ring in equation 3 above contains complex numbers in the plaintext space. However, in order to improve the computation speed for isomorphic ciphertexts, only the set of rings above in which the plaintext space is real may be used.

[0073] Once such a ring is set up, processor 450 may calculate the secret key (sk) from the ring.

[0074] [Equation 4]

number

[0075] Then, processor 450 calculates a first random polynomial (a(x)) from the ring. The first random polynomial may be expressed as follows:

[0076] [Formula 5]

number

[0077] Furthermore, processor 450 may calculate errors. Specifically, processor 450 may extract errors from a discrete Gaussian distribution or a distribution statistically close thereto. Such errors may be expressed as follows:

[0078] [Formula 6]

number

[0079] Once the error has been calculated, processor 450 may perform a modular operation on the first random polynomial and the secret key to calculate a second random polynomial. The second random polynomial may be expressed as follows:

[0080] [Equation 7]

number

[0081] Ultimately, the public key (pk) is set in a form that includes a first random polynomial and a second random polynomial, as follows:

[0082] [Equation 8]

number

[0083] The key generation method described above is merely one example and is not necessarily the only way to generate public and private keys; it goes without saying that other methods can also be used to generate them.

[0084] On the other hand, the processor 450 may control the communication device 410 so that, once a public key is generated, it is transmitted to another device.

[0085] The processor 450 may then generate an isomorphic ciphertext for the message. Specifically, the processor 450 may generate an isomorphic ciphertext by applying the previously generated public key to the message. In this case, the processor 450 may generate the ciphertext so that its length corresponds to the size of the scaling factor.

[0086] Then, when an identical ciphertext is generated, the processor 450 may either store it in memory 420 or control the communication device 410 to transmit the identical ciphertext to another device in response to a user request or a pre-configured default command.

[0087] On the other hand, according to one embodiment of the present invention, packing may be performed. When packing is used in isomorphic encryption, it becomes possible to encrypt multiple messages with a single ciphertext. In this case, when the electronic device 100 performs operations between each ciphertext, the operations are processed in parallel for multiple messages, resulting in a significant reduction in the computational burden.

[0088] Specifically, if a message consists of multiple message vectors, the processor 450 may convert the multiple message vectors into a polynomial in a form that allows for parallel encryption, multiply that polynomial by a scaling factor, and then perform isomorphic encryption using a public key. This may generate a ciphertext by packing the multiple message vectors.

[0089] Furthermore, if decryption of an isomorphic ciphertext is required, the processor 450 may apply a secret key to the isomorphic ciphertext to generate a decrypted text in the form of a polynomial, and then decode the decrypted text in the form of a polynomial to generate a message. In this case, the generated message may contain errors, as mentioned in equation 1 above.

[0090] The processor 450 may perform operations on the ciphertext. Specifically, the processor 450 may perform operations such as addition or multiplication on isomorphic ciphertext while maintaining its encrypted state. Specifically, the processor 450 may perform a first function process on each of the isomorphic ciphertexts used in the operation, perform operations such as addition or multiplication between the first function-processed isomorphic ciphertexts, and then perform a second function process, which is the inverse function of the first function, on the isomorphic ciphertexts that have been processed. Such first and second function processes may utilize the linear transformation technique in the reboot process described later.

[0091] On the other hand, once the calculation is complete, the arithmetic unit 400 may detect the data in the valid area from the calculation result data. Specifically, the arithmetic unit 400 may perform a rounding process on the calculation result data to detect the data in the valid area. Rounding means rounding off the message while it is encrypted, and may also be called rescaling. Specifically, the arithmetic unit 400 applies the reciprocal of the scaling factor to each component of the ciphertext.

number

[0092] Furthermore, the arithmetic unit 400 may perform a reboot operation on the ciphertext if the weight of the approximate message in the calculated ciphertext exceeds a threshold. At this time, the arithmetic unit 400 may perform a reboot operation using the normal method or a reboot operation using the metabootstrap method according to the present invention. Specifically, the arithmetic unit 400 may decide on the reboot method considering the calculation speed and / or accuracy of the isomorphic ciphertext. For example, if the arithmetic unit 400 needs a fast reboot, it may perform a reboot using the normal method, and if high accuracy is required or if a large difference in values ​​between isomorphic ciphertexts is expected, it may decide to perform a reboot using the metabootstrap method.

[0093] When using the normal reboot method, the arithmetic unit 400 may perform a reboot operation by performing a pre-configured reboot operation. Specifically, the arithmetic unit 400 may extend the modulus of the isomorphic ciphertext, linearly transform the isomorphic ciphertext with the extended modulus into polynomial form, perform an approximate modulus operation on the isomorphic ciphertext transformed into polynomial form using a higher-order equation configured such that input values ​​within a pre-configured range approximate integer points, linearly transform the result of the approximate modulus operation back into the form of the isomorphic ciphertext, and then perform the reboot operation described above. In this case, the arithmetic unit 400 may perform the above-described modulus extension operation and linear transformation operation in a reversed order.

[0094] On the other hand, when using the metabootstrap method, the arithmetic unit 400 may generate a first intermediate ciphertext by applying a pre-set reboot operation to the isomorphic ciphertext, generate a second intermediate ciphertext by applying a pre-set reboot operation to the result of a subtraction operation between the calculation result ciphertext and the first intermediate ciphertext, and generate an isomorphic ciphertext with an expanded plaintext space by performing a subtraction operation of the second intermediate ciphertext on the first intermediate ciphertext. The metabootstrap method according to the present invention will be described in detail with reference to Figure 3.

[0095] As described above, the arithmetic unit 400 according to one embodiment of the present invention performs a reboot operation on isomorphic ciphertexts, thereby enabling more efficient isomorphic arithmetic. Furthermore, by using the metabootstrap method according to one embodiment of the present invention, it is possible to prevent a decrease in accuracy that may occur during the bootstrap process.

[0096] Figure 3 is a diagram illustrating the reboot operation. Specifically, Figure 3 shows the operations and reboot process for two isomorphic ciphertexts 10 and 20. This term reboot may also be expressed as bootstrap or plaintext space extension.

[0097] Each isomorphic ciphertext 10, 20 may include approximate message regions 11, 21, respectively. The approximate message regions 11, 21 contain both the message and errors (m1+e1, m2+e2).

[0098] The arithmetic unit 400 may take two identical ciphertexts 10 and 20 as input values ​​and perform a specific operation.

[0099] The resulting ciphertext 30 may include an approximate message area 31 that incorporates the calculation result (m3+e3) between each approximate message. As the calculation result becomes larger than the input value, the approximate message area also increases, thereby decreasing the remaining plaintext space 32. If such calculations are performed multiple times, eventually the remaining plaintext space 32 will run out or become smaller than the limit value, making calculations impossible. When this state is determined, the arithmetic unit 400 can perform a reboot operation.

[0100] In the rebooted ciphertext 40, it can be seen that the approximate message area 41 remains constant, while the plaintext space 42 expands.

[0101] Thus, the reboot method expands the plaintext space, enabling continuous processing of isomorphic ciphertexts. However, conventional reboot methods carried the risk of loss of precision (or amplification of errors) during the process. This will be explained in detail with reference to Figure 10.

[0102] There are two methods for representing numbers: fixed-point and floating-point. While floating-point is advantageous in terms of filling in significant figures, many isomorphic ciphertexts use fixed-point to prevent the possibility of data leakage within the ciphertext.

[0103] However, when using a fixed-point scheme and a wide range of data is used, the following problems arise. In the following explanation, for the sake of simplicity, we will support 30-bit precision for isomorphic ciphertexts and assign each of the two slots (slot[0], slot[1])

number

[0104] If the floating-point scheme (or the ideal method) satisfies a precision of 30, then slot [0]1010 guarantees 20 digits before the decimal point and 10 digits after the decimal point, for a total of 30 digits, and slot [1]1020 guarantees 30 digits after the decimal point.

[0105] However, in fixed-point arithmetic, 30-bit precision means that the 30 most significant digits are counted and stored as a single unit. Therefore, slot[0] is guaranteed 30 digits, consisting of 20 digits before the decimal point and 10 digits after the decimal point, similar to the floating-point arithmetic described above. However, slot[1] needs to have the same number of digits as slot[0], so it has 20 digits before the decimal point and 10 digits after the decimal point. Thus, in fixed-point arithmetic, only 10 digits after the decimal point are guaranteed for slot[0], resulting in an effective precision of 10 bits for that slot.

[0106] From the perspective of error amplification, given data

number

number

number

[0107] In other words, if we assume that the maximum absolute value of the data slots we normally handle is bound to 2^M and the minimum absolute value is bound to 2^N, then when a reboot occurs, there will be a difference of (MN) bits between the reboot precision and the floating-point precision.

[0108] Reflecting these points, we will now explain the normal reboot operation. A normal reboot involves the following steps in sequence: 1) changing the range of the isomorphic ciphertext to the range to which the approximation algorithm is applied, 2) applying the approximation algorithm, and 3) range recovery. For example, when rebooting CT3 = m3+e3 using an approximation algorithm with the range [-1, 1], the order (or scaling factor) is reflected for range adjustment.

number

number

number

[0109] Thus, when performing a normal reboot operation, a problem arises in which errors become larger during the scaling process for applying the approximation algorithm.

[0110] Therefore, in order to solve the problems in such conventional reboot processes, the present invention aims to ensure that the bootstrap result has only errors within the error range acceptable by the approximation algorithm.

[0111] To achieve this objective, it is necessary to: i) identify errors in the bootstrap results that exceed the error range acceptable by the approximation algorithm, and ii) remove the identified errors.

[0112] In the following section, with reference to Figure 4, we will describe one basic method for achieving the above-mentioned objective, but in practice, this method can be modified in various ways.

[0113] Figure 4 is a diagram illustrating the reboot operation of the present invention.

[0114] The new reboot operation according to the present invention utilizes the conventional reboot operation. It is also possible to modify the conventional reboot operation during use, or to use a modified version of the conventional reboot operation. For the sake of simplicity, the conventional reboot operation previously used according to the present invention will be referred to as the pre-set reboot operation, and the new reboot operation according to the present invention will be referred to as Meta Bootstrapping. (Hereafter,

number

[0115] Referring to Figure 4, when metabootstrapping is performed, a pre-configured reboot operation is performed on the first isomorphic ciphertext 50. Here, the pre-configured reboot operation may be a conventional reboot operation as described above, or it may be a modified version of the conventional reboot operation described later in the present invention. When such a reboot operation is performed, a first intermediate ciphertext (or rebooted isomorphic ciphertext) 60 may be generated. For example, the first isomorphic ciphertext is

number

number

number

number

number

[0116] Then, in order to check for errors included after the reboot that are "exceeding the error range allowed by the approximation algorithm," that is, to check for error values ​​other than the message, a subtractive isomorphic operation is performed on both the pre- and post-bootstrapping (or rebooting) isomorphic ciphertexts. This may generate a second intermediate ciphertext 70. For example, the second intermediate ciphertext is

number

[0117] Then, a pre-configured reboot operation is performed on the second intermediate ciphertext. This pre-configured reboot operation may be a conventional reboot operation that is generally known, or it may be a modified version of the conventional reboot operation described later in this invention. Here, the reboot process is performed on the first isomorphic ciphertext

number

number

[0118] Since this third intermediate ciphertext is an error that has passed through the approximation algorithm, it can be considered an "error greater than the error range allowed by the approximation algorithm." Therefore, ultimately, subtracting the third intermediate ciphertext from the first intermediate ciphertext will generate an isomorphic ciphertext containing only errors less than or equal to the error range allowed by the approximation algorithm. That is,

number

[0119] Thus, through the metabootstrap process, the rebooted isomorphic ciphertext will have only errors within the margin of error acceptable by the approximation algorithm.

[0120] Furthermore, the metabootstrap process according to the present invention has advantages not only in the accuracy mentioned above, but also in the following respects.

[0121] specifically,

number

[0122] To increase the total amount, the order of the ring must be increased. If the precision of each step of the reboot is increased, the amount of modulus consumed in each step will inevitably increase. The amount of modulus available after the reboot (or the number of possible multiplications) is the total modulus minus the amount of modulus consumed in the reboot. Therefore, the more modulus consumed in the reboot, the less modulus is available after the reboot, and the less efficient the reboot becomes. Increasing n to increase the modulus limit leads to yet another inefficiency, as any operation becomes slower in proportion to n.

[0123] In this respect, using the meta-reboot described herein results in multiple low-precision reboots, thus keeping the amount of modulus consumed by reboots low. Therefore, it has the following two advantages:

[0124] Firstly, at low n values, it is possible to achieve accuracy that is unattainable with conventional methods.

[0125] Next, fixing the precision means that the order can be lowered, allowing for the efficient design of high-precision reboots.

[0126] Figure 5 is a flowchart illustrating the method for processing isomorphic ciphertexts according to the present invention.

[0127] Referring to Figure 5, first, operations are performed on the isomorphic ciphertext of the approximate message containing the error (S510). For example, the operations may be set to basic operations such as multiplication, division, addition, and subtraction, but are not necessarily limited to these. Specifically, if the encrypted message is a complex number, a conjugate operation may be performed, and other operations such as statistics and sorting may also be performed.

[0128] Then, it is determined whether the approximate message weight in the ciphertext obtained through the calculation exceeds a threshold (S520). Figure 5 shows that the determination of whether the approximate message weight exceeds the threshold is made after the calculation, but it is not necessarily limited to that. In other words, it is also possible to make the determination before the calculation.

[0129] Then, when the approximate message weighting exceeds a threshold, the plaintext space of the calculated ciphertext is expanded. In other words, the metabootstrap according to the present invention may be performed. The detailed operation of the metabootstrap according to the present invention will be described below with reference to Figure 6.

[0130] Figure 6 is a flowchart illustrating the reboot operation of the present invention.

[0131] First, a pre-configured reboot operation is applied to the calculated ciphertext to generate a first intermediate ciphertext (S610). Specifically, a scaling factor may be applied to the calculated ciphertext so that it has a pre-configured range, a pre-configured reboot operation may be applied to the calculated ciphertext with the scaling factor applied, and the scaling factor may be applied to the result of the applied pre-configured reboot operation to generate the first intermediate ciphertext. Here, the pre-configured range is [-1, 1] or

number

[0132] Then, a pre-set reboot operation is applied to the result of the subtraction operation between the calculated ciphertext and the first intermediate ciphertext to generate a second intermediate ciphertext (S620). Specifically, the subtraction result between the calculated ciphertext and the first intermediate ciphertext indicates the difference in error change before and after bootstrapping, and the reboot result for the ciphertext indicates an error value greater than or equal to the error range of the approximation algorithm during that error.

[0133] Then, a subtraction operation is performed on the first intermediate ciphertext by the second intermediate ciphertext to generate an isomorphic ciphertext with an expanded plaintext space (S630). Specifically, when a subtraction isomorphic operation is performed by subtracting the second intermediate ciphertext from the first intermediate ciphertext, errors in the first intermediate ciphertext that are larger than the error range of the approximation algorithm are removed, meaning that the final ciphertext will have an error value within the error range of the message and the approximation algorithm.

[0134] On the other hand, the above explanation assumes that the reboot operation is performed in a single operation. However, in implementation, the above operation may be performed multiple times depending on the implementation method.

[0135] Figure 7 is a flowchart illustrating the operation of extending the plaintext space according to the present invention.

[0136] First, we extend the modulus of the isomorphic ciphertext. Specifically, we can extend the modulus for plaintext extension (S710).

[0137] Then, the modulus-extended isomorphic ciphertext is linearly transformed into polynomial form (S720). Specifically, the approximate modulus operation is performed using polynomials. Therefore, a linear transformation may be performed to convert the ciphertext into polynomial form. Such a linear transformation may be called SlotToCoeff. Specifically, since the polynomial of the isomorphic ciphertext is composed of complex numbers, a linear transformation may be performed using a predefined matrix to convert each coefficient of the polynomial into the form that fits into the slots. Here, the predefined matrix may be a DFT (discrete Fourier Transform) matrix. On the other hand, the present invention performs two pre-set reboot operations in the metabootstrap process, but the linear transformation may be performed in mutually different ways in the first reboot operation and the second reboot process. For example, since the first reboot operation is performed on the original message, a linear transformation with high precision may be performed, and since the second reboot operation is performed on errors in the ciphertext, it may be possible to use a linear transformation with lower precision than the first linear transformation.

[0138] An approximate modulus operation is performed on the isomorphic ciphertext transformed into a polynomial form using a higher-order equation set so that the input values ​​within a predetermined range approximate integer points (S730). Specifically, an approximate modulus operation may be performed on the linearly transformed isomorphic ciphertext using a higher-order equation set so that the input values ​​within a predetermined range approximate integer points.

[0139] Then, the result of the approximate modulo operation is linearly transformed into the form of an isomorphic ciphertext (S740). Specifically, the isomorphic ciphertext obtained by the approximate modulo operation may be transformed into a polynomial using the inverse matrix corresponding to the matrix used in the linear transformation of the isomorphic ciphertext above, and the transformed polynomial may be transformed into the form of a ciphertext.

[0140] On the other hand, while Figure 7 shows and explains the operation as performing a linear transformation to a polynomial after modulus extension, in practice, the linear transformation operation can be performed first, followed by the modulus extension operation. In this case, by reflecting the values ​​for modulus extension in the processing of the DFT matrix used during the linear transformation operation, the net number of calculations in the reboot process can be reduced.

[0141] In Figure 7, the conversion operation to a polynomial is shown and explained, but in implementation, the ciphertext may exist in the form of a polynomial. In such cases, the linear conversion operation to the polynomial described above may be omitted. That is, the linear conversion operation 720 in Figure 7 may be implemented in an omitted form.

[0142] Figure 8 shows the reboot operation algorithm according to the first embodiment of the present invention. The reboot operation algorithm according to the first embodiment assumes that the input range is [-1, 1] and that it has n-bit precision. In the table shown, x represents an isomorphic ciphertext and p represents a modulus greater than q.

[0143] Referring to Figure 8, first, the input range is transformed to reflect the precision of the isomorphic ciphertext.

number

number

[0144] If only this much is performed, it is the same as a general reboot process, so the explanation of the specific algorithms for each step of this process will be omitted.

[0145] Then, the difference between the isomorphic ciphertext before the reboot and the resulting ciphertext after the first reboot is calculated (tmp-op), and a second reboot is performed on the calculated result (BTS(temp2)).

[0146] Finally, the second reboot result (specifically, the reboot result relative to the difference between the reboot result and the error before the reboot) may be reflected in the first reboot result to generate the final isomorphic ciphertext.

[0147] Figure 9 is a diagram showing the reboot operation algorithm according to the second embodiment of the present invention. The reboot operation algorithm according to the second embodiment is:

number

[0148] Referring to Figure 9, first, the input range is transformed to reflect the precision of the isomorphic ciphertext.

number

number

number

[0149] Then, the difference between the isomorphic ciphertext before the reboot and the ciphertext resulting from the first reboot is calculated (temp-op), and a second reboot is performed on the calculated result (BTS(temp2)).

[0150] Finally, the second reboot result (specifically, the reboot result relative to the difference between the reboot result and the error before the reboot) may be reflected in the first reboot result to generate the final isomorphic ciphertext.

[0151] The following describes the case where a fixed-point isomorphic ciphertext is subjected to the metabootstrap method according to the present invention. First, we assume that x = (slot[0], slot[1]) and the level of x is 4.

[0152]

number

[0153]

number

[0154]

number

[0155]

number

[0156]

number

[0157] Thus, the final resulting isomorphic ciphertext contains e' as an error, but since e' is a reboot error, it is either less than or equal to 2^(-30). In other words, both slot[0] and slot[1] have a precision of 30 digits or more. This can be represented graphically as shown in Figure 11.

[0158] Referring to Figure 11, it can be seen that 30-bit precision is achieved even when using the fixed-point method. In fact, slot [0] achieves 50-bit precision, not 30-bit precision.

[0159] Thus, by using the metabootstrap method according to the present invention, it becomes possible to expand the plaintext space without loss of precision, even for fixed-point isomorphic ciphertexts.

[0160] On the other hand, the ciphertext processing methods according to the various embodiments described above may be implemented in the form of program code for each step, stored on a recording medium, and distributed. In this case, the device equipped with the recording medium may perform the above-mentioned encryption or encryption processing operations.

[0161] Such recording media may be a variety of computer-readable media such as ROM, RAM, memory chips, memory cards, external hard drives, hard drives, CDs, DVDs, magnetic disks, or magnetic tapes.

[0162] Although preferred embodiments of the present invention have been described in detail above with reference to the attached drawings, the present invention is not limited to these embodiments. It is clear to any person with ordinary skill in the art to which the present invention belongs that various modifications or alterations can be conceived within the scope of the technical intent described in the claims, and these are also understood to fall within the technical scope of the present invention.

Claims

1. A method for processing isomorphic ciphertexts in an arithmetic unit including a memory and a processor for storing isomorphic ciphertexts for approximate messages including errors, The processor performs operations on the isomorphic ciphertext, When the processor determines that the approximate message weight in the ciphertext obtained by the calculation exceeds a threshold, it takes the step of expanding the plaintext space of the ciphertext obtained by the calculation. Includes, The step of extending the plaintext space is: The processor applies a pre-configured reboot operation to the calculation result ciphertext to generate a first intermediate ciphertext, The processor generates a second intermediate ciphertext by applying the pre-set reboot operation to the result of a subtraction operation between the calculation result ciphertext and the first intermediate ciphertext. The processor performs a subtraction operation of the second intermediate ciphertext on the first intermediate ciphertext to generate an isomorphic ciphertext with an extended plaintext space. A method for processing isomorphic ciphertexts that include this type of text.

2. The step of generating the first intermediate ciphertext is: A method for processing an isomorphic ciphertext according to claim 1, comprising the steps of: the processor reflecting a scaling factor so that the calculation result ciphertext has a predetermined range; applying a predetermined reboot operation to the calculation result ciphertext with the scaling factor reflected; reflecting the scaling factor in the result of applying the predetermined reboot operation; and generating the first intermediate ciphertext.

3. The aforementioned preset range is A method for processing an isomorphic ciphertext according to claim 2, wherein the condition is [-1, 1].

4. The aforementioned preset range is [-2 (k-1)n , 2 (k-1)n The method for processing an isomorphic ciphertext according to claim 2, wherein k is the number of repetitions of the step of expanding the plaintext space and n is the precision.

5. The aforementioned preset reboot calculation is performed by The processor performs the steps of extending the modulus of the isomorphic ciphertext, The processor performs the step of linearly transforming the modulus-extended isomorphic ciphertext into polynomial form, The processor performs an approximate modulus operation on the isomorphic ciphertext, which has been converted into a polynomial form, using a higher-order equation set such that the input values ​​within a predetermined range approximate integer points. The processor performs the step of linearly transforming the result of the approximate modulus operation into the form of an isomorphic ciphertext. A method for processing an isomorphic ciphertext according to claim 1, including the following:

6. The aforementioned preset reboot calculation is performed by The processor performs the step of linearly transforming the isomorphic ciphertext into polynomial form, The processor extends the modulus of the isomorphic ciphertext that has been linearly transformed into the form of the polynomial, The processor performs an approximate modulus operation on the extended result of the modulus, The processor performs the step of linearly transforming the result of the approximate modulus operation into the form of an isomorphic ciphertext. A method for processing an isomorphic ciphertext according to claim 1, including the following:

7. Memory for storing isomorphic ciphertexts for approximate messages containing errors, The system includes a processor that performs operations on the aforementioned isomorphic ciphertext, The aforementioned processor, An arithmetic device that generates a first intermediate ciphertext by applying a pre-set reboot operation to the isomorphic ciphertext, generates a second intermediate ciphertext by applying the pre-set reboot operation to the result of a subtraction operation between the isomorphic ciphertext and the first intermediate ciphertext, and generates an isomorphic ciphertext with an expanded plaintext space by performing a subtraction operation of the second intermediate ciphertext on the first intermediate ciphertext.

8. The aforementioned processor, The arithmetic device according to claim 7, which reflects a scaling factor so that the isomorphic ciphertext has a predetermined range, applies a predetermined reboot operation to the isomorphic ciphertext to which the scaling factor has been applied, reflects the scaling factor in the result to which the predetermined reboot operation has been applied, and generates the first intermediate ciphertext.

9. The aforementioned preset range is The arithmetic device according to claim 8, wherein the values ​​are [-1, 1].

10. The aforementioned preset range is [-2 (k-1)n , 2 (k-1)n The arithmetic device according to claim 8, wherein k is the number of iterations of the step of extending the plaintext space, and n is the precision.

11. The aforementioned processor, The arithmetic device according to claim 7, which extends the modulus of an isomorphic ciphertext, linearly transforms the isomorphic ciphertext with the extended modulus into polynomial form, performs an approximate modulus operation on the isomorphic ciphertext transformed into polynomial form using a higher-order equation set such that input values ​​within a predetermined range approximate integer points, linearly transforms the result of the approximate modulus operation into the form of an isomorphic ciphertext, and performs the predetermined reboot operation.

12. The aforementioned processor, The arithmetic device according to claim 7, which linearly transforms the isomorphic ciphertext into polynomial form, extends the modulus of the isomorphic ciphertext linearly transformed into polynomial form, performs an approximate modulus operation on the extended result of the modulus, linearly transforms the result of the approximate modulus operation into the form of an isomorphic ciphertext, and performs the preset reboot operation.

Citation Information

Patent Citations

  • Device and method for sorting approximately encrypted ciphertext

    EP3982586A1

  • Apparatus and method for performing approximation operations on ciphertext

    JP2020530577A