Configurable Key-Switching Processing Method and System for CKKS-based Fully Homomorphic Encryption
Patent Information
- Application Number
- KR1020240136075
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-10-07
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2044-10-07
Smart Images

Figure R1020240136075_ABST
Abstract
Description
Technology Field
[0001] The present invention relates to a variable key exchange processing method and system for CKKS-based fully homomorphic encryption. Background Technology
[0002] Fully Homomorphic Encryption (FHE) has brought about a change in the paradigm of existing encryption systems by enabling operations on encrypted data without decryption and presenting a method to perform homomorphic operations such as addition, multiplication, and rotation while the data remains fully encrypted. Fully Homomorphic Encryption not only opens a new chapter in modern security technology but also presents innovations for the protection and processing of sensitive personal information in the digital age.
[0003] Currently, fully homomorphic encryption schemes can be broadly classified into three typical categories: BGV (Brakerski-Gentry-Vaikuntanathan), BFV (Brakerski / Fan-Vercauteren), and CKKS (Cheon-Kim-Kim-Song). All of the above fully homomorphic encryption schemes are based on RLWE (Ring-Learning With Error), which has the problem of increasing ciphertext noise as operations are performed. To solve this, techniques such as bootstrapping are used. Among these three schemes, CKKS represents the most recent research and is receiving attention in fields such as machine learning because it supports approximation operations on complex vectors.
[0004] The CKKS research team developed an open-source library called HEAAN (Homomorphic Encryption for Arithmetic of Approximate Numbers) to implement CKKS in software. HEAAN applies a method called approximation homomorphic encryption, which discards the decimal part without affecting the calculation results of CKKS. This offers advantages in terms of computational speed over existing fully homomorphic encryption systems and has the characteristic of being applicable to fields where specific approximation operations can be utilized. One of the most significant features of HEAAN is that it supports floating-point operations, enabling homomorphic operations within the complex number range. For example, the number represented as 3.14, the mantissa of 314 and 10 -2 It supports isomorphic operations in the complex range by splitting the complex vector by expressing it with an exponent and performing operations only on the mantissa while maintaining the exponent.
[0005] The ciphertext of the CKKS fully homomorphic cipher consists of L+1 different polynomials with bases of modulus. After a specific homomorphic operation, such as homomorphic multiplication, one basis of the polynomial is dropped, and after performing L homomorphic multiplications, only one polynomial remains. The number of polynomials currently remaining in the ciphertext is called the residual multiplication level of the ciphertext, and the level that is initialized after the bootstrapping operation is called L, the maximum multiplication level.
[0006] Key switching is an operation that re-linearizes ciphertext that cannot be decrypted after homomorphic operations so that it can be decrypted using the original key. It must be executed after homomorphic operations such as multiplication, rotation, and conjugation, and is executed dozens of times within algorithms such as rebooting. Therefore, key switching is the most resource-intensive and critical operation in fully homomorphic encryption systems, serving as a bottleneck for performance improvement. Due to its high computational complexity, frequent usage, and the vast amount of data it requires, the hardware structure must be designed efficiently by considering memory access patterns and the parallelization of submodules. Prior art literature
[0007] Korean Patent Publication No. 10-2023-0123418 (August 23, 2023) The problem to be solved
[0008] The technical problem to be solved by the present invention is to provide a hardware structure and method for a variable key exchange processing device for CKKS-based fully homomorphic encryption, which supports multiple applications using a single hardware structure, wherein three parameters excluding the polynomial length N—maximum multiplication level L, modulus length logPQ, and decomposition number dnum—provide variability according to the maximum multiplication level L. The objective of the present invention is to provide a hardware structure that enables variable key exchange processing in a CKKS-based fully homomorphic encryption system, thereby flexibly responding to various applications. means of solving the problem
[0009] In one aspect, the variable key exchange processing system for CKKS-based fully homomorphic encryption proposed in the present invention includes a configurable arithmetic core (CAC) that repeatedly performs variable operations a predetermined number of times to process key exchange operations that support a maximum multiplication level (L) in CKKS-based fully homomorphic encryption and support NTT (Number Theoretic Transform), INTT (Inverse Number Theoretic Transform), basis transformation, and key multiplication all in one module; a memory that stores an input / output vector and polynomial coefficients corresponding to said input / output vector; and a control unit that determines parameters received from a user to control the operation of said configurable arithmetic core to perform key exchange operations for CKKS-based fully homomorphic encryption and manages the address value of said memory to schedule key exchange operations between said memory and said configurable arithmetic core.
[0010] The above variable operation core arranges butterfly units in an 8x4 array and arranges twiddle factor generators and modular adder trees to process sub-operations including NTT, INTT, basis conversion, and key multiplication required for key exchange operations in a single module.
[0011] The above butterfly unit uses internal modular multipliers, modular adders, and modular subtractors to variably perform necessary operations according to sub-operations required for key exchange operations including NTT, INTT, basis conversion, and key multiplication.
[0012] The above modular adder tree is implemented in a tree form to perform the Multiply Accumulate (MAC) operation required when the variable operation core performs basis conversion or key multiplication operations.
[0013] The above modular adder performs a modular operation on the modulus that comes in as input after addition with the polynomial coefficients input to the butterfly unit, the above modular subtractor performs a modular operation on the modulus that comes in as input after subtraction with the polynomial coefficients input to the butterfly unit, and the above modular multiplier performs a modular operation on the modulus that comes in as input after multiplication with the polynomial coefficients input to the butterfly unit.
[0014] In another aspect, the variable key exchange processing method for CKKS-based fully homomorphic encryption proposed in the present invention includes the steps of: performing variable operations repeatedly a predetermined number of times to process key exchange operations that support a maximum multiplication level (L) in CKKS-based fully homomorphic encryption through a configurable arithmetic core (CAC) and support Number Theoretic Transform (NTT), Inverse Number Theoretic Transform (INTT), basis transformation, and key multiplication all in one module; storing an input / output vector and polynomial coefficients corresponding to the input / output vector in memory; and determining parameters received from a user through a control unit to control the operation of the configurable arithmetic core to perform key exchange operations for CKKS-based fully homomorphic encryption and managing the address value of the memory to schedule key exchange operations between the memory and the configurable arithmetic core. Effects of the invention
[0015] According to embodiments of the present invention, through a CKKS-based variable key exchange operating on various parameters (L, dnum, logPQ), hardware reusability can be increased and performance accelerated with low hardware complexity in a fully homomorphic encryption device operating in a Ring-LWE-based RNS (Residue Number System) number scheme. In addition, the variable operation core and butterfly unit according to an embodiment of the present invention consist of a modular adder, a modular subtractor, and a modular multiplier, and can support various moduli. During NTT and INTT operations, the variable operation core reconfigures the connections between 8x4, a total of 32 butterfly units, to 2 16 NTT and INTT operations for polynomials of length can be accelerated. Additionally, during basis transformation operations, two different MAC operations for 16 inputs can be accelerated. By repeating the above operations, key exchange operations for variable parameters can be performed and accelerated. Brief explanation of the drawing
[0016] FIG. 1 is a diagram illustrating the data flow of cloud computing based on CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 2 is a diagram illustrating the data flow of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention. FIG. 3 is a diagram showing a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 4 is a diagram illustrating the timing of key exchange operations in a variable key exchange architecture for a CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 5 is a diagram illustrating the timing of modular expansion and key multiplication operations in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 6 is a diagram illustrating the timing of modular reduction operations in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 7 is a diagram illustrating the timing of base transformation operations in a variable key exchange architecture for a CKKS-based fully homomorphic cipher according to an embodiment of the present invention. FIG. 8 is a diagram showing the structure of a Butterfly Unit in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 9 is a diagram illustrating the data flow when the Butterfly Unit operates for NTT in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 10 is a diagram illustrating the data flow when a Butterfly Unit operates for INTT in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 11 is a diagram illustrating the data flow when a variable operation core operates for NTT in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 12 is a diagram illustrating the data flow when a variable operation core operates for INTT in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 13 is a diagram illustrating the structure of a Twiddle Factor Generator in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 14 is a diagram showing a rotation factor generation algorithm according to an embodiment of the present invention. FIG. 15 is a diagram illustrating the data flow when a Butterfly Unit operates for MAC in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 16 is a diagram illustrating the data flow when a variable operation core operates for MAC in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. FIG. 17 is a flowchart illustrating the operation method of a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention. Specific details for implementing the invention
[0017] The present invention relates to a key exchange processing apparatus and method operating in variable parameters for a CKKS-based fully homomorphic cipher operating in an RNS number system, and more specifically, it is possible to support various lengths of ciphertext N, various modulus q and p of the RNS number system and their length logPQ, and a maximum multiplication level (L) which is the maximum number of homomorphic operations possible.
[0018] A variable key exchange processing device for CKKS-based fully homomorphic encryption according to an embodiment of the present invention is used to support variable parameters in CKKS-based fully homomorphic encryption operating in the RNS number system. Homomorphic encryption of the Ring-LWE technique in the RNS number system requires various maximum multiplication levels L depending on the application, and since it operates in the RNS number system, it requires various modulus parameters q and p of prime numbers. Depending on the various maximum multiplication levels L, the size of the decomposed number dnum and logPQ, which is the bit-width of the modulus, varies, and accordingly, it possesses security equivalent to 128-bit. Hereinafter, an embodiment of the present invention will be described in detail with reference to the attached drawings.
[0020] FIG. 1 is a diagram illustrating the data flow of cloud computing based on CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0021] FIG. 1 is a diagram illustrating cloud computing based on CKKS-based fully homomorphic encryption according to an embodiment. It is divided into a client (110) and a server (120) to perform operations required for a fully homomorphic encryption system.
[0022] Cloud computing based on CKKS-based fully homomorphic encryption according to an embodiment of the present invention can be broadly divided into a client (110) and a server (120). The client (110) encodes and encrypts plaintext and generates a key. When the generated key and ciphertext are transmitted to the server (120), the server (120) performs homomorphic operations for the service using the received ciphertext. The homomorphic operations at this time include not only addition, multiplication, rotation, and conjugation operations, but also key exchange and bootstrapping operations. After performing all given operations, the server (120) sends the resulting ciphertext back to the client (110), and the client (110) decrypts and decodes the ciphertext to verify the result.
[0023] A variable key exchange processing system for a CKKS-based fully homomorphic encryption according to an embodiment of the present invention includes a configurable arithmetic core (CAC) (121) that repeatedly performs variable operations a predetermined number of times to process key exchange operations that support a maximum multiplication level (L) in a CKKS-based fully homomorphic encryption and support NTT, INTT, basis transformation, and key multiplication all in one module; a memory (122) that stores an input / output vector and polynomial coefficients corresponding to the input / output vector; and a control unit (123) that determines a parameter received from a user, controls the operation of the configurable arithmetic core to perform key exchange operations for a CKKS-based fully homomorphic encryption, and manages the address value of the memory to schedule key exchange operations between the memory and the configurable arithmetic core.
[0025] FIG. 2 is a diagram illustrating the data flow of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention.
[0026] Since the CKKS-based fully homomorphic cipher according to the embodiment of the present invention encrypts plaintext using a polynomial, a process of encoding data into a polynomial and then decoding the polynomial back into data is required. Encoding is largely composed of Multiple Message Packing and Scaling Process.
[0027] The multi-message packing step of the CKKS-based fully homomorphic cipher according to an embodiment of the present invention is a process of replacing a plaintext vector consisting of multiple numbers with a single polynomial. By combining multiple data into a single polynomial, memory is utilized efficiently and computational efficiency is increased during the encryption process. Therefore, it helps to improve the speed and efficiency of encryption.
[0028] The digit adjustment of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention is a process of specifying the significant digits of the data for encryption. It refers to the process of selecting and adjusting a scaling factor to encrypt data while maintaining data accuracy. This is used to adjust the size of the data while maintaining the accuracy of the ciphertext. For example, n complex number data Given, a polynomial of degree 2n-1 Is It is expressed as follows.
[0029] In the decoding process of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention, the scaled value is restored and converted back to the original data of the ciphertext. To this end, the reciprocal of the scaling factor is calculated and used, and through the decoding process, the integer component of the original data, which is a plaintext polynomial, is obtained.
[0030] The CKKS-based fully homomorphic encryption according to an embodiment of the present invention differs slightly from conventional general homomorphic encryption because it is a homomorphic encryption system that supports approximation operations. Here, the key generation, encryption, and decryption algorithms of the CKKS algorithm are briefly explained.
[0031] The key generation algorithm for CKKS-based fully homomorphic encryption according to an embodiment of the present invention is a security level Given the maximum multiplication level L and scaling factor P , Set the integer P, and generate the key required for encryption, decryption, and operations. The formula for generating the secret key used in CKKS fully homomorphic encryption is It is similar to, and the formula for generating a public key is It is the same as, and the formula for generating the Evaluation Key is It is the same as.
[0032] The encryption algorithm of CKKS-based fully homomorphic encryption according to an embodiment of the present invention is a public key Using, polynomial All terms have a coefficient of -1, 0, or 1. There are n terms with a coefficient of 0, and n / 2 terms with coefficients of 1 and -1. Two errors The coefficient of each term is the standard deviation It follows a discrete Gaussian distribution. This property provides security for the encrypted data, and the structure of the polynomial makes it difficult for an attacker to recover or decrypt the data. The following equation represents the encryption mathematically.
[0033]
[0034] The decryption algorithm is the secret key It uses, and the ciphertext The inner product of the ciphertext and the secret key to decrypt Calculate the value. The following equation is the equation of the decoding algorithm.
[0035]
[0036] In the CKKS-based fully homomorphic encryption according to an embodiment of the present invention, homomorphic operations between ciphertexts are mostly performed on the server. Representative examples include addition, multiplication, key exchange, and rebooting. The equations representing homomorphic addition and homomorphic multiplication are as follows.
[0037]
[0038]
[0039] As can be seen from the equation above, the result of homomorphic multiplication involves the addition of the h(x) term, which causes a loss of linearity and renders the code unusable for decoding with the existing key. Therefore, a key exchange operation is required to re-linearize it.
[0040] In a CKKS-based fully homomorphic encryption-based cloud system according to an embodiment of the present invention, when a server performs homomorphic operations for a service using ciphertext received from a client, a key-exchange operation is performed for every multiplication. The key-exchange operation is homomorphic This is an operation that re-linearizes the ciphertext to resolve the problem where the ciphertext loses linearity after multiplication and can no longer be decrypted using the existing Secret Key. The Key Exchange operation consists of three detailed operations: Modulus Raise, Key Multiplication, and Modulus Down. Furthermore, each detailed operation is composed of sub-operations such as Number Theoretic Transform (NTT), Inverse Number Theoretic Transform (INTT), and Base Conversion.
[0041] The CKKS-based fully homomorphic cipher according to an embodiment of the present invention has several system parameters as follows: the polynomial length N of the polynomial representing the ciphertext, the maximum multiplicative level L, and the current multiplicative level of the ciphertext. l It appears as. And the system's security level λ , the decomposition number for the RNS (Residue Number System) is represented as dnum. The basis moduli Represented as, the product of the basis moduli Q It is represented as. Also, Special Moduli Represented as, and the product of the Special Moduli P It is represented as.
[0042] The system parameters of the CKKS-based fully homomorphic encryption according to the embodiment of the present invention have a significant impact on the system, and each is closely related. First, the polynomial length N is the security level, and the length of the moduli. logQ It has a correlation with... Therefore, to satisfy a high level of security, there are methods to increase the length of the polynomial or reduce the length of the total modulus. Also, the length of the modulus logQ It is related to the accuracy of isomorphic operations and the maximum multiplication level L. Therefore, to satisfy a high maximum multiplication level, one must either increase the length of the Moduli or sacrifice accuracy. The dnum parameter introduced for RNS is the size of the Special Moduli, as its value increases. logP The size becomes smaller and the maximum multiplication level L increases. However, as dnum increases, there is a disadvantage that the complexity of the key exchange module increases and the size of the key exchange key increases.
[0043] The NTT of the key exchange operation of the CKKS-based fully homomorphic encryption according to an embodiment of the present invention is a type of Fast Fourier Transform (FFT) that operates on a finite field (Finite Ring). The FFT is an algorithm for performing the Discrete Fourier Transform (DFT) at high speed, and among the core algorithms of the FFT, the Cooley-Tukey algorithm and the Gentleman-Sande algorithm can also be applied to the NTT. The CKKS fully homomorphic encryption is a polynomial ring NTT operates in this case. Here, NTT is implemented as Negative Wrapped Convolution. q 1 mod 2N satisfying q It works for.
[0044] The basis transformation of the CKKS-based fully homomorphic cipher according to an embodiment of the present invention is an operation that transforms the RNS-decomposed Modulus basis set, and is performed during the modular expansion and modular reduction processes. The basis transformation is mostly performed by a Multiply-Accumulate (MAC) operation that accumulates the product of the Modulus and the inverse of the Modulus to be transformed.
[0045] Key multiplication of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention is performed by MAC operation between an evaluation key generated at the client and a modularly expanded polynomial.
[0046] In the Ring-LWE cipher of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention, the polynomial is It is defined on a ring. Therefore, the ring R q The polynomial above a(x) and b(x ) It can be expressed by the following formula.
[0047]
[0048] Two polynomials a(x) and b(x) The result of polynomial multiplication c(x) It can be expressed by the following formula.
[0049]
[0050] Polynomial multiplication of the CKKS-based fully homomorphic cipher according to an embodiment of the present invention is performed as a convolution operation, and time Complexity is O(N 2 ) is. In the LWE technique, the longest-running operation is the part related to the polynomial ring, and using NTT, time complexity O(NlogN) It can be reduced to. The equation below is the definition of the NTT transform. At this time represents the Twiddle Factor of NTT.
[0051]
[0052] The definition of the INTT conversion is as follows.
[0053]
[0054] The convolutional product operation of the CKKS-based fully homomorphic cipher according to an embodiment of the present invention can be replaced with a point-wise multiplication (·) using NTT and INTT.
[0055]
[0056] hour The complexity is O(N 2 Unlike the convolution, the point-wise product is in time Complexity O(N) It is small. The NTT transform and INTT transform apply FFT algorithms such as the Cooley-Tukey algorithm and the Gentleman-Sande algorithm. O(NlogN) It has a complexity of . Therefore, the total time Complexity is O(N 2 ) at O(NlogN) It decreases to . The rotation factor of NTT is expressed as shown in the equation below.
[0057]
[0058] The CKKS-based fully homomorphic cipher according to an embodiment of the present invention is Since it uses negative wrapped convolution, q 1 mod 2N It is defined as Rotation factor based on the primitive root of the 2Nth unit W has
[0059] The Cooley-Tukey algorithm of the CKKS-based fully homomorphic encryption according to an embodiment of the present invention is mainly used at NTT and uses a divide-and-conquer method for the time of the DFT Reduces complexity. It recursively divides and conquers a DFT of size N into a DFT of size N / 2. It is generally used when N is a power of 2.
[0060] The DFT of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention is expressed by terms of odd and even degrees of the polynomial. The even terms , odd terms If so, it can be simplified as follows by utilizing the periodicity of the rotation factor.
[0061]
[0062]
[0063]
[0064] The Gentleman-Sande algorithm
[20] of the CKKS-based fully homomorphic cipher according to an embodiment of the present invention is mainly used in INTT and reduces the time complexity of INTT by a divide-and-conquer method, similar to the Cooley-Tukey algorithm of NTT. The following equation expresses the process of convolution divided into odd and even terms, just as in NTT.
[0065]
[0066]
[0067]
[0068] The Cooley-Tukey algorithm and the Gentleman-Sande algorithm of the CKKS-based fully homomorphic encryption according to an embodiment of the present invention each have the characteristic that the order of the input vectors is bit-reversed. That is, the order of the polynomial vectors input to NTT or INTT is bit-reversed at the output terminal after transformation.
[0069] The basis transformation of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention is a transformation for changing the basis set of a polynomial in a fully homomorphic cipher scheme that supports RNS. The basis set of the polynomial before the basis transformation B Let be the basis set after the basis transformation. C It is said to be and can be expressed by the following formula. l represents the current multiplication level of the ciphertext, and q and p represent the basis modulus, respectively.
[0070]
[0071] The polynomial a of the CKKS-based fully homomorphic cipher according to an embodiment of the present invention satisfies the following equation. [a] c The symbol represents a polynomial a expressed as a basis of the set C.
[0072]
[0073] The value obtained by multiplying all remaining basis primes, excluding only the j-th basis prime of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention It satisfies the following equation.
[0074]
[0075] The basis transformation from basis set C to B of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention can be expressed by the following equation. The inverse operation of the equation is replaced with a modular inverse operation.
[0076]
[0077] The modular expansion / reduction algorithm of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention includes a basis transformation internally. Modular expansion concatenates a polynomial that has undergone a basis transformation with an existing polynomial. The modular expansion algorithm is as follows.
[0078]
[0079] The modular reduction algorithm of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention is modularly expanded This is achieved by performing a basis transformation on the extended part of the existing polynomial back to the original basis set, followed by subtraction and inverse multiplication. The modular reduction algorithm is given by the following equation. Here, the inverse P is the product of all bases in basis set B, It can be represented as.
[0080]
[0081] Two ciphertexts of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention can be represented as follows.
[0082]
[0083] The multiplication of two ciphertexts is as follows.
[0084]
[0085] Non-linearized ciphertext after homomorphic multiplication of a CKKS-based fully homomorphic cipher according to an embodiment of the present invention d RNS decomposition and zero padding are performed on 2. At this time And, , . 0-insertion and RNS-decomposition are represented by the following equations.
[0086]
[0087]
[0088] When the RNS-decomposition of the CKKS-based fully homomorphic cipher according to an embodiment of the present invention is completed, each of the decomposed For this, proceed in the order of modular expansion → key multiplication → modular reduction. The processes of modular expansion, key multiplication, and modular reduction are each expressed by the following equations.
[0089]
[0090]
[0091]
[0092] After all processes of the CKKS-based fully homomorphic cipher according to an embodiment of the present invention are completed, the result of homomorphic multiplication can be re-linearized by adding the value obtained above to the result of multiplication. This is expressed by the following equation.
[0093]
[0095] FIG. 3 is a diagram showing a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0096] The present invention adopts a memory-based NTT architecture to efficiently manage memory and accelerate the execution speed of computations. . In addition, instead of receiving rotation factors for NTT externally, a Twiddle Factor Generator is introduced to generate them during computation, thereby minimizing the memory size for rotation factors.
[0097] The NTT and INTT structures of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention have very high hardware complexity because they include too many modular multipliers. Therefore, a method is needed to reuse them even while other operations are being performed, other than NTT and INTT. To this end, the present invention proposes a configurable arithmetic core (CAC) to design a single modular core that supports NTT, INTT, basis transformation, and key multiplication.
[0098] The structure of a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention proposes a variable key exchange architecture for CKKS-based fully homomorphic encryption that supports a maximum multiplication level L of 5≤L≤29.
[0099] In the structure of a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention, the variable operation core (CAC) of FIG. 3 is an 8-parallel structure. Table 1 is the homomorphic encryption system parameters supported by the proposed architecture.
[0100]
[0101]
[0102] The proposed architecture supports a total of five maximum multiplication levels L. The parameters in Table 1 are for security level 128 ≤ The length of the polynomial satisfying N=2 16 person logPQ This is a value obtained using Security Level Estimator software.
[0103] The polynomial coefficients serving as inputs to the structure of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention are filled into the POLY MEMORY of the block diagram. The operation is performed by modifying the values in the memory while the key exchange operation is in progress. In particular, since NTT and INTT are designed based on memory, the arrangement of this memory is very important. Since NTT is designed to repeat 24 NTTs, it must be able to read 16 data items at a time. Therefore, one POLY, C0, C1 MEMORY bank is 2 16 / 2 4 = Consists of 16 memories with 4096 addresses each. The proposed architecture requires 30 URAM memory banks for all multiplication levels. That is, POLY, C0, and C1 MEMORY each consist of a total of 48 x 2 16 It consists of x30 bit URAM MEMORY banks.
[0104] Among the three URAM MEMORY banks of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention, the POLY bank stores data to be received as input, and the C0 and C1 banks respectively store values after modular expansion and key multiplication. By considering the memory resources of the AMD (formerly Xilinx) ALVEO U250 FPGA board implementing the module, the values accumulated during the key multiplication (MAC) process are stored in the C0 and C1 banks, thereby efficiently processing a larger amount of data than the on-chip memory.
[0105] The parameter memory of a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention stores BASE values used in NTT's rotational factor generator and other parameter values required during key exchange operations. Other values of each modulus, the T value required for the Barrett Modular Multiplier, and pre-calculated values multiplied during basis transformation Stores the same values.
[0107] FIG. 4 is a diagram illustrating the timing of key exchange operations in a variable key exchange architecture for a CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0108] Referring to Fig. 4, Through modular expansion-key multiplication operations of that amount, the intermediate in C0 and C1 memory banks After accumulating values, the result is output through modular reduction operations.
[0110] FIG. 5 is a diagram illustrating the timing of modular expansion and key multiplication operations in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0111] Referring to Fig. 5, INTT and NTT are processed in parallel for each decomposed basis, and MAC operations are processed using all variable operation cores during basis transformation and key multiplication.
[0113] FIG. 6 is a diagram illustrating the timing of modular reduction operations in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0114] Referring to Fig. 6, similar to modular expansion, INTT, BCONV, and NTT operations are performed in sequence, followed by a subtraction operation.
[0116] FIG. 7 is a diagram illustrating the timing of base transformation operations in a variable key exchange architecture for a CKKS-based fully homomorphic cipher according to an embodiment of the present invention.
[0117] Referring to Fig. 7, the timing diagram shows the variable operation core processing parallel MAC operations during the basis transformation of the structure of a variable key exchange architecture for CKKS-based fully homomorphic encryption.
[0119] FIG. 8 is a diagram showing the structure of a Butterfly Unit in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0120] A variable computation core is proposed to prevent the NTT and INTT modules of the structure of a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention from being placed in an IDLE state and to enable them to be utilized for other operations. The variable computation core is basically 2 4 It consists of 32 Butterfly Units to support NTT / INTT. The 32 Butterfly Units are configured with a structure as shown in Fig. 3 to simultaneously support NTT, INTT, and MAC operations.
[0121] As can be seen in FIG. 8, the Butterfly Unit of the structure of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention consists of one modular multiplier, one modular adder, and one modular subtractor. Three input ports and three output ports perform different functions according to three operations: NTT, INTT, and MAC.
[0123] FIG. 9 is a diagram illustrating the data flow when the Butterfly Unit operates for NTT in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0124] FIG. 10 is a diagram illustrating the data flow when a Butterfly Unit operates for INTT in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0125] When performing an NTT / INTT operation of the structure of a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention, the coefficients of a polynomial are input to the A and B input ports of the Butterfly Unit, and a rotation factor is input to the C input port. When the Butterfly operation for NTT is completed, the result is output to the A and B output ports.
[0126] The difference between the NTT operation and the INTT operation of the structure of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention is the select signal applied to the multiplexer inside the Butterfly Unit. In FIGS. 9 and 10, the wires that are activated according to the select signal during NTT / INTT operation are shown in a darker color.
[0128] FIG. 11 is a diagram illustrating the data flow when a variable operation core operates for NTT in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0129] FIG. 12 is a diagram illustrating the data flow when a variable operation core operates for INTT in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0130] In the NTT / INTT operation of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention, 32 Butterfly Units form an array and are connected through a configurable wire connection. The configurable wire connections operate as shown in FIG. 11 when in NTT mode and as shown in FIG. 12 when in INTT mode.
[0132] FIG. 13 is a diagram illustrating the structure of a Twiddle Factor Generator in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0133] FIG. 14 is a diagram showing a rotation factor generation algorithm according to an embodiment of the present invention.
[0134] In order to conserve memory resources, a twiddle factor generator is added to the module of the structure of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention, which generates the twiddle factor used in NTT / INTT operations during the operation. Considering the latency of the modular multiplier, the twiddle factor base required for each stage is stored in the parameter memory. The algorithm for generating the twiddle factor is as shown in FIG. 14, and the block diagram of the twiddle factor generator is as shown in FIG. 13.
[0136] FIG. 15 is a diagram illustrating the data flow when a Butterfly Unit operates for MAC in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0137] In the variable operation core of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention, when MAC mode is selected, two Butterfly Units form a pair as shown in FIG. 15 and perform two modular multiplications and one modular addition. Both Butterfly Units perform two modular multiplications through B and C input ports, and one C output port is input through the A input port of the other Butterfly Unit to perform modular addition.
[0139] FIG. 16 is a diagram illustrating the data flow when a variable operation core operates for MAC in a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0140] The wire connection of the variable operation cores when selecting the MAC mode of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention is as shown in FIG. 16. Among the 32 BUs, 16 BUs are paired to accumulate the results of 16 parallel modular multiplications. Therefore, when one variable operation core operates in MAC mode, it performs 16 parallel modular multiplications twice and outputs two results.
[0141] The Butterfly Unit of the structure of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention includes a modular adder / subtractor. Input of the modular adder in1, in2 Since it exists within a finite field It must satisfy.
[0142] The modular multiplier inside the Butterfly Unit of the variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention is based on Barrett Modular Reduction and the equation It can be expressed as. It represents, and the modular multiplier is any having a length of w-bit or less Perform modular multiplication on it. This means that this T value is a pre-calculated value and must be input in pair with the Modulus when the Modulus is input.
[0143] The variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention proposes a hardware structure for a variable key exchange architecture for CKKS-based fully homomorphic encryption, which is attracting attention in the cloud and AI fields as a fourth-generation cipher. The high hardware complexity that is a problem in implementing the CKKS-based fully homomorphic encryption architecture is resolved by introducing a variable computation core architecture, and unlike other architectures that support only one maximum multiplication level L, it can support multiple L.
[0144] The variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention proposes a variable computation core architecture capable of processing NTT, INTT, basis transformation, and key multiplication, which are core components of the key exchange architecture, thereby maximizing resource utilization within the module. NTT / INTT can significantly reduce the time complexity of long-length polynomial multiplication in the Ring-LWE technique. The variable computation core enables hardware size savings by variably supporting NTT and INTT. Therefore, in key exchange algorithms where NTT, INTT, basis transformation, and key multiplication do not occur simultaneously, the variable computation core processes all operations of a single module, ensuring that it is never placed in an IDLE state. Furthermore, due to the characteristics of CKKS fully homomorphic encryption that supports RNS, the modulus of NTT and INTT changes continuously, and the required rotation factor changes accordingly; thus, a rotation factor generator is designed to enable computation to be performed without the need to read from external memory.
[0146] FIG. 17 is a flowchart illustrating the operation method of a variable key exchange architecture for CKKS-based fully homomorphic encryption according to an embodiment of the present invention.
[0147] A method of operation for a variable key exchange architecture for CKKS-based fully homomorphic encryption includes: a step of repeatedly performing variable operations a predetermined number of times to process key exchange operations that support a maximum multiplication level (L) in CKKS-based fully homomorphic encryption through a configurable arithmetic core (CAC) and support Number Theoretic Transform (NTT), Inverse Number Theoretic Transform (INTT), basis transformation, and key multiplication all in one module; a step of storing an input / output vector and polynomial coefficients corresponding to said input / output vector in memory; and a step of determining parameters received from a user through a control unit to control the operation of said configurable arithmetic core to perform key exchange operations for CKKS-based fully homomorphic encryption and managing the address value of said memory to schedule key exchange operations between said memory and said configurable arithmetic core.
[0148] Referring to FIG. 17, first, the maximum multiplication level L and the corresponding decomposition number (dnum) and modulus set are input (1710).
[0149] In the step of repeatedly performing variable operations a predetermined number of times to process key exchange operations, a Butterfly Unit is arranged in an 8x4 array and a Twiddle Factor Generator and a Modular Adder Tree are arranged to process sub-operations including NTT, INTT, basis transformation, and key multiplication required for key exchange operations in a single module. The Twiddle Factor Base required for the Twiddle Factor Generator is received as input (1720).
[0150] The input for the key exchange operation is received and modular expansion is performed (1730). Then, point-wise multiplication is performed on the modularly expanded value with the input key exchange key (1740).
[0151] After determining whether variable operations have been performed repeatedly a predetermined number of times (1750), if variable operations have been performed repeatedly a predetermined number of times, modulus down is performed on the accumulated value (1760, 1770). After performing modulus expansion, key multiplication, and modulus reduction processes, the result of the key exchange operation is finally output (1780).
[0153] The device described above may be implemented as a hardware component, a software component, and / or a combination of a hardware component and a software component. For example, the device and components described in the embodiments may be implemented using one or more general-purpose or special-purpose computers, such as, for example, a processor, a controller, an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable gate array (FPGA), a programmable logic unit (PLU), a microprocessor, or any other device capable of executing and responding to instructions. The processing unit may execute an operating system (OS) and one or more software applications executed on said operating system. Additionally, the processing unit may access, store, manipulate, process, and generate data in response to the execution of the software. For ease of understanding, the processing unit may be described as being used as a single unit, but those skilled in the art will understand that the processing unit may include a plurality of processing elements and / or a plurality of types of processing elements. For example, the processing unit may include multiple processors or one processor and one controller. Additionally, other processing configurations, such as parallel processors, are also possible.
[0154] Software may include computer programs, code, instructions, or a combination of one or more of these, and may configure a processing unit to operate as desired or instruct the processing unit independently or collectively. Software and / or data may be embodied in any type of machine, component, physical device, virtual equipment, computer storage medium, or device so as to be interpreted by the processing unit or to provide instructions or data to the processing unit. Software may be distributed over networked computer systems and may be stored or executed in a distributed manner. Software and data may be stored on one or more computer-readable recording media.
[0155] The method according to the embodiment may be implemented in the form of program instructions that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program instructions, data files, data structures, etc., either alone or in combination. The program instructions recorded on the medium may be those specifically designed and configured for the embodiment, or they may be those known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Examples of program instructions include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc.
[0156] Although the embodiments have been described above with reference to limited examples and drawings, those skilled in the art can make various modifications and variations from the description above. For example, suitable results can be achieved even if the described techniques are performed in a different order than described, and / or the components of the described system, structure, device, circuit, etc. are combined or assembled in a form different from described, or replaced or substituted by other components or equivalents.
[0157] Therefore, other implementations, other embodiments, and equivalents to the claims also fall within the scope of the claims set forth below.
Claims
Claim 1 A key exchange processing system comprising: a configurable arithmetic core (CAC) that repeatedly performs a configurable operation a predetermined number of times to process a key exchange operation that supports a maximum multiplication level (L) in a CKKS-based fully homomorphic encryption and supports Number Theoretic Transform (NTT), Inverse Number Theoretic Transform (INTT), basis transformation, and key multiplication all in one module; a memory that stores an input / output vector and polynomial coefficients corresponding to the input / output vector; and a control unit that determines a parameter received from a user, controls the operation of the configurable arithmetic core to perform a key exchange operation for CKKS-based fully homomorphic encryption, manages the address value of the memory, and schedules a key exchange operation between the memory and the configurable arithmetic core. Claim 2 In claim 1, the variable operation core is a key exchange processing system that arranges butterfly units in an 8x4 array and arranges a twiddle factor generator and a modular adder tree to process sub-operations including NTT, INTT, basis conversion, and key multiplication required for key exchange operations in a single module. Claim 3 In paragraph 2, the butterfly unit is a key exchange processing system that variably performs necessary operations according to sub-operations required for key exchange operations including NTT, INTT, basis conversion, and key multiplication using internal modular multipliers, modular adders, and modular subtractors. Claim 4 In paragraph 2, the modular adder tree is a key exchange processing system in which a modular adder is implemented in a tree form to perform a Multiply Accumulate (MAC) operation required when the variable operation core performs a basis conversion or key multiplication operation. Claim 5 A key exchange processing system according to claim 3, wherein the modular adder performs a modular operation on the input modulus after addition with the polynomial coefficient input to the butterfly unit, the modular subtractor performs a modular operation on the input modulus after subtraction with the polynomial coefficient input to the butterfly unit, and the modular multiplier performs a modular operation on the input modulus after multiplication with the polynomial coefficient input to the butterfly unit. Claim 6 A key exchange processing method comprising: a step of repeatedly performing variable operations a predetermined number of times to process key exchange operations that support a maximum multiplication level (L) in a CKKS-based fully homomorphic encryption through a configurable arithmetic core (CAC) and support Number Theoretic Transform (NTT), Inverse Number Theoretic Transform (INTT), basis transformation, and key multiplication all in one module; a step of storing an input / output vector and polynomial coefficients corresponding to the input / output vector in memory; and a step of determining parameters received from a user through a control unit to control the operation of the configurable arithmetic core and manage the address value of the memory to schedule key exchange operations between the memory and the configurable arithmetic core in order to perform key exchange operations for CKKS-based fully homomorphic encryption. Claim 7 In claim 6, the step of repeatedly performing variable operations a predetermined number of times to process the key exchange operation comprises arranging Butterfly Units in an 8x4 array and arranging Twiddle Factor Generators and Modular Adder Trees to process sub-operations including NTT, INTT, basis transformation, and key multiplication required for the key exchange operation in a single module; using Modular Multipliers, Modular Adders, and Modular Subtractors within the Butterfly Units to perform operations variably required according to the sub-operations required for the key exchange operation including NTT, INTT, basis transformation, and key multiplication; performing Multiply Accumulate (MAC) operations required when the variable operation core performs basis transformation or key multiplication operations through a Modular Adder Tree that implements the Modular Adder in a tree form; and regarding the modulus input after addition with the polynomial coefficients input to the Butterfly Unit through the Modular Adder, A key exchange processing method that performs an operation, performs a modular operation on the input modulus after subtraction with the polynomial coefficient input to the butterfly unit through the modular subtractor, and performs a modular operation on the input modulus after multiplication with the polynomial coefficient input to the butterfly unit through the modular multiplier.
Citation Information
Patent Citations
Apparatus and method for ring-LWE cryptoprocessor using MDF based ntt
KR1020220134159A
Appratus and method of homomorphic encryption operation using iterative array number theoretic transform
KR1020230078131A
Computing apparatus and method for integrating different homomorphic operations in homomorphic encryption
KR1020230087377A
Method and device based on homomorphic encryption for processing data
KR1020230123418A