Multi-key homomorphic encryption method and calculation method, storage medium and computer device
By using the security parameter λ and the key generation method MKHE_KG(1λ) in the multi-key fully homomorphic encryption scheme to generate the evaluation key and encryption private key, and encrypt the message polynomial m, the problem of lack of security and non-supporting superconstant participants in the existing solution is solved, and efficient multi-key fully homomorphic encryption calculation is achieved.
Patent Information
- Application Number
- PCT/CN2023/131857
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-15
- Publication Date
- 2025-05-22
AI Technical Summary
Existing multi-key fully homomorphic encryption schemes lack security and do not support hyperconstant parties, especially in NTRU-based schemes.
The security parameter λ and key generation method MKHE_KG(1λ) are used to generate the evaluation key evk and the encryption private key F, and the message polynomial m is encrypted through the encryption method MKHE_Enc(m,F), and the encrypted ciphertext c is generated. Then the evaluation key evk and the encrypted ciphertext c are sent to the server to realize the homomorphic calculation of the encrypted ciphertext by the server.
A multi-key full-homomorphic encryption scheme based on NTRU is provided, which improves the computing efficiency of the multi-key full-homomorphic encryption scheme and solves the problem of lack of secure and supporting superconstant parties.
Smart Images

Figure CN2023131857_22052025_PF_FP_ABST
Abstract
Description
Multi-key homomorphic encryption method, calculation method, storage medium and computer equipment Technical Field
[0001] The present invention relates to the field of cryptography, and in particular to a multi-key homomorphic encryption method, a calculation method, a storage medium, and a computer device. Background Art
[0002] Fully homomorphic encryption (FHE) allows direct computation on encrypted data, making it possible to securely outsource computations on sensitive information to untrusted environments (such as cloud computing). Since Gentry proposed the first FHE scheme in 2009, a series of research efforts have significantly improved FHE's security, functionality, and performance. Existing fully homomorphic encryption schemes are primarily based on the Learning with Errors (LWE) problem, its ring variants RLWE, and the NTRU problem. These difficult lattice-based mathematical problems are simple in structure and resistant to quantum computer attacks.
[0003] However, in many application scenarios, data provided by different parties needs to be collaboratively computed without compromising data privacy. For example, each participant holds their own private data that cannot be disclosed. However, they hope to jointly compute a function, such as making predictions on a machine learning model using data from all parties. Traditional FHE schemes require that all data be encrypted using the same public-private key pair, which is inconsistent with real-world application scenarios. To address the problem of joint computation of multi-user ciphertext data, López-Alt et al. introduced the concept of multi-key fully homomorphic encryption (MKFHE). Unlike traditional single-key fully homomorphic encryption (FHE), MKFHE allows arbitrary homomorphic operations to be performed on ciphertext from different users (i.e., with different keys), and requires all users participating in the computation to jointly decrypt the computation results. This approach can effectively address the challenges of joint computation of multi-user ciphertext.
[0004] Currently, multi-key fully homomorphic encryption schemes can be divided into four major categories: BGV, GSW, TFHE, and NTRU. BGV-type MKFHE schemes offer relatively simple ciphertext expansion and easy multi-hop functionality, but suffer from the complexity of the key exchange process and the high computational complexity of generating the computational key. GSW-type MKFHE schemes have the advantages of simple homomorphic operations and the absence of pre-generated computational keys, but the implementation of ciphertext expansion and multi-hop functionality is quite complex. TFHE-type MKFHE schemes offer fast encryption and decryption and bootstrapping, but the extended ciphertext length grows linearly with the number of users, and the supported plaintext space is relatively small. NTRU-type MKFHE offers advantages such as fast encryption and decryption and small ciphertext size, but these schemes require a pre-defined number of participants and lack multi-hop functionality. Furthermore, existing NTRU-type MKFHE schemes require an exponential ciphertext modulus and support a constant number of participants at most. In summary, all types of MKFHE schemes require further improvement, making the development of new and efficient multi-key fully homomorphic encryption schemes of great significance.
[0005] To address the above-mentioned problems, no effective solutions have been proposed so far.
[0006] Summary of the Invention
[0007] Embodiments of the present invention provide a multi-key homomorphic encryption method, a calculation method, a storage medium, and a computer device to at least solve the technical problem of the lack of a secure NTRU-based multi-key fully homomorphic encryption scheme that supports super-constant participants.
[0008] According to one aspect of an embodiment of the present invention, a multi-key homomorphic encryption method is provided, comprising: obtaining a message polynomial m, wherein the message polynomial m is used to represent a message uploaded by a participant to a server for homomorphic computation; generating a multi-key homomorphic encryption method MKHE_KG(1 λ ), generate an evaluation key evk corresponding to the participant and an encryption private key F corresponding to the participant; based on the encryption method MKHE_Enc(m,F), use the encryption private key F to encrypt the message polynomial m to obtain the encrypted ciphertext c corresponding to the participant; send the evaluation key evk and the encrypted ciphertext c to the server, wherein the server is used to perform homomorphic calculation on the encrypted ciphertext and other encrypted ciphertexts, and the other encrypted ciphertexts are sent to the server by other participants, and the other encrypted ciphertexts are ciphertexts obtained after the other participants use their respective encryption private keys to encrypt their respective message polynomials.
[0009] Optionally, the method according to the security parameter λ and the key generation method MKHE_KG(1 λ), generating the evaluation key evk corresponding to the participant and the encrypted private key F corresponding to the participant, including: randomly sampling the encrypted private key F←χ from the distribution χ according to the security parameter λ n×n , and the inverse element of the encrypted private key F Exists; randomly sample vector e←χ from distribution χ n ,calculate The evaluation key evk is generated, where “·” represents a rounding function.
[0010] Optionally, the encryption method MKHE_Enc(m,F) is used to encrypt the message polynomial m using the encryption private key F to obtain the encrypted ciphertext c corresponding to the participant, including: randomly sampling a vector e'←χ from the distribution χ n According to the vector e', the inverse element of the encrypted private key F and parameter q, encrypt the message polynomial m∈{0,1} according to the following formula to generate the encrypted ciphertext c: Where Δ = "q / 4".
[0011] Optionally, the method further comprises: receiving the joint encrypted ciphertext sent by the server Wherein, the joint encrypted ciphertext The server generates the ciphertext after performing homomorphic calculation based on the encrypted ciphertext c; the joint encrypted ciphertext is calculated based on the encrypted private key F. Decryption is performed to obtain the decrypted ciphertext m' corresponding to the participant, where
[0012] Optionally, the method further comprises: generating a key according to a key generation method MS_KG(1 λ ) and the security parameter λ, generate the bootstrapped private key s and bootstrapped public key b of the participant; according to the encryption method MS_UniEnc(μ,s), use the bootstrapped private key s as the auxiliary message μ∈R Q Encryption is performed to obtain the auxiliary message ciphertext (d, f) of the participant; the auxiliary message ciphertext (d, f) and the bootstrap public key b are sent to the server, wherein the server is used to bootstrap refresh the joint encrypted ciphertext obtained after homomorphic calculation based on the auxiliary message ciphertext (d, f) and the bootstrap public key b.
[0013] Optionally, the method further comprises: generating a relinearization key rlk corresponding to the participant according to a key generation method ExtProdKGen(s,f), the bootstrap private key s and the bootstrap private key f; generating a vector NTRU ciphertext NTRU′ according to the auxiliary message μ and f. Q,fi (μ / f i);The relinearization key rlk and the vector NTRU ciphertext NTRU′ Q,fi (μ / f i ) is sent to the server, wherein the server is used to generate a ciphertext NTRU′ according to the relinearization key rlk and the vector NTRU Q,fi (μ / f i ) performs bootstrapping refresh on the joint encrypted ciphertext obtained after homomorphic computation.
[0014] According to another aspect of an embodiment of the present invention, a multi-key homomorphic computing method is provided, comprising: obtaining a first ciphertext Second ciphertext and the evaluation key evk of the i-th participant among all participants i , wherein the first ciphertext is a homomorphic ciphertext corresponding to k1 participants, the second ciphertext is a homomorphic ciphertext corresponding to k2 participants, and the total number of participants includes the k1 participants and the k2 participants; for the first ciphertext Expand and obtain the first extended ciphertext corresponding to the private key group And the second ciphertext Expand to obtain the second extended ciphertext corresponding to the private key group The private key group is composed of the private keys of the k1 participants and the k2 participants, According to the evaluation key evk of the i-th participant i , for the first extended ciphertext and the second extended ciphertext Perform homomorphic calculation with the NAND gate to obtain the ciphertext of the calculation result in, 01 represents a 0 vector with dimension i, and 02 represents a 0 vector with dimension ki.
[0015] Optionally, the method further comprises: receiving the bootstrapping public key b sent by the i-th participant i , bootstrap key {brk i,j} j∈[k] , relinear key rlk i and key switching key ksk i ; According to the bootstrap calculation method and the rotation polynomial r, the ciphertext of the calculation result Perform self-bootstrapping to obtain the refreshed calculation result ciphertext.
[0016] Optionally, the bootstrap public key b i , the bootstrap key {brk i,j} j∈[k], the relinear key rlk i and the key switching key ksk i The i-th participant generates the following: according to the i-th participant's encrypted private key F i , using the key generation method MS_KG(1 λ ) and the security parameter λ, generate the bootstrapped private key s of the i-th participant i and the bootstrapped public key b i For participant 1, the bootstrap key is generated as follows:
[0017] For participants 2≤i≤k, the bootstrap key is generated as follows:
[0018] The relinearization key rlk i According to the encryption method MS_UniEnc(f i ,s i )generate;
[0019] The key switching key ksk i According to the key switching key generation method KSKG(s i ,F i ,q,B)generated;
[0020] The bootstrap calculation method and the rotation polynomial r, the ciphertext of the calculation result Perform self-bootstrapping to obtain the refreshed calculation result ciphertext, including:
[0021] calculate
[0022] For 1≤i≤k, initialize
[0023] For 0≤j<n, iteratively execute the following loop
[0024] initialization For 1≤i≤k, the iterative calculation
[0025] Will The modulus is switched from Q back to q, and we get
[0026] right Perform key switching to obtain the refreshed calculation result ciphertext Among them, the refreshed calculation result ciphertext
[0027] Optionally, the method further comprises: receiving the bootstrapping public key b sent by the i-th participant i , bootstrap key {brk i,j} j∈[0,n-1] and key switching key ksk i ; According to the bootstrap calculation method and the rotation polynomial r, the ciphertext of the calculation result Perform self-bootstrapping to obtain the refreshed calculation result ciphertext.
[0028] Optionally, the bootstrap public key b i , the bootstrap key {brk i,j} j∈[0,n-1] and the key switching key ksk i The i-th participant generates the following: according to the i-th participant's encrypted private key F i , using the key generation method MS_KG(1 λ ) and the security parameter λ, generate the bootstrapped private key s of the i-th participant i and the bootstrapped public key b i For participant 1, the bootstrap key is generated as follows:
[0029] brk 1,0 =MS_UniEnc(z 1,0 / s i ,s1);brk 1,j =MS_UniEnc(z 1,j ,s1) for 2≤j≤n-1;
[0030] For participants 2≤i≤k, the bootstrap key is generated as follows:
[0031] brk i,j =MS_UniEnc(z i,j )1≤j≤n-1;
[0032] The key switching key ksk i According to the key switching key generation method KSKG(s i ,F i ,q,B)generated;
[0033] The bootstrap calculation method and the rotation polynomial r, the ciphertext of the calculation result Perform self-bootstrapping to obtain the refreshed calculation result ciphertext, including:
[0034] calculate
[0035] 2) Initialize the accumulator
[0036] 3) For 1≤i≤k, execute the following loop for 0≤j<n iterations
[0037] Switch the modulus of ACC from Q back to q to obtain ACC'; switch the key of ACC' to obtain the refreshed calculation result ciphertext Among them, the refreshed calculation result ciphertext
[0038] Optionally, the key switching key ksk i Through the key switching key generation method KSKG(s i ,F i ,q,B), the key switching key generation method KSKG(s i ,F i ,q,B) includes the following steps: input the bootstrapping private key s of the i-th participant i ∈R, encrypted private key Integer B,q; calculation And order Represents an identity matrix I of rank N N The result of the tensor operation with the gadget vector g; let It is a matrix where all positions are 0 except E[0][0]=1, and the sampling matrix G i ←χ (N·d)×n ; Output When it is necessary to use the key switching key ksk i In the case of key switching, the key switching method The switching steps include: Enter MK-NTRU ciphertext and the key switching key {ksk i} i∈[k] ; Let (c i,0 ,…,c i,N-1 ) means c i The coefficient of calculate Output the ciphertext obtained after key switching
[0039] According to another aspect of an embodiment of the present invention, a non-volatile storage medium is also provided, which includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute any one of the multi-key homomorphic encryption methods described above or any one of the multi-key homomorphic computing methods described above.
[0040] According to another aspect of an embodiment of the present invention, a computer device is further provided, comprising a memory and a processor, wherein the memory is used to store programs, and the processor is used to run the programs stored in the memory, wherein when the program is run, any one of the multi-key homomorphic encryption methods described above or any one of the multi-key homomorphic computing methods described above is executed.
[0041] In the embodiment of the present invention, the security parameter λ and the key generation method MKHE_KG (1 λ ) is used to encrypt the message polynomial m, generate the evaluation key evk and the encryption private key F corresponding to the participant, and then based on the encryption method MKHE_Enc(m,F), use the encryption private key F to encrypt the message polynomial m to obtain the encrypted ciphertext c corresponding to the participant; the evaluation key evk and the encrypted ciphertext c are sent to the server, so that the server can perform homomorphic calculations on the encrypted ciphertext and other encrypted ciphertexts, achieving the purpose of providing an NTRU-based multi-key fully homomorphic encryption scheme to achieve fully homomorphic calculations, thereby achieving the technical effect of improving the computational efficiency of the multi-key fully homomorphic encryption scheme, and then solving the technical problem of the lack of a secure NTRU-based multi-key fully homomorphic encryption scheme that supports super-constant participants. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0043] FIG1 shows a hardware structure block diagram of a computer terminal for implementing a multi-key homomorphic encryption method;
[0044] FIG2 is a schematic diagram of a process of a multi-key homomorphic encryption method according to an embodiment of the present invention;
[0045] FIG3 is a schematic diagram of a flow chart of a multi-key homomorphic computation method according to an embodiment of the present invention;
[0046] FIG4 is a structural block diagram of a multi-key homomorphic encryption device provided according to an embodiment of the present invention;
[0047] FIG5 is a structural block diagram of a multi-key homomorphic computing device provided according to an embodiment of the present invention. DETAILED DESCRIPTION
[0048] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0049] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0050] According to an embodiment of the present invention, a method embodiment of multi-key homomorphic encryption is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0051] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 shows a hardware structure block diagram of a computer terminal for implementing a multi-key homomorphic encryption method. As shown in Figure 1, the computer terminal 10 may include one or more (processors 102a, 102b, ..., processor 102n are used in the figure to illustrate) processors (the processor may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that the structure shown in Figure 1 is only for illustration and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may also include more or fewer components than those shown in Figure 1, or have a configuration different from that shown in Figure 1.
[0052] It should be noted that the one or more processors and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10. As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0053] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the multi-key homomorphic encryption method in the embodiment of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implementing the multi-key homomorphic encryption method of the above-mentioned application. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0054] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 .
[0055] First, some nouns or terms that appear in the description of the embodiments of this application are subject to the following interpretations:
[0056] Homomorphic encryption, a computationally complex cryptographic technique based on difficult mathematical problems, ensures that operations on homomorphically encrypted data produce the same results as those on unencrypted data. In 2009, Craig Gentry of IBM first proposed a fully homomorphic algorithm based on an ideal lattice, an encryption algorithm capable of protecting data privacy.
[0057] Automorphism refers to the isomorphism process from a mathematical object to itself, that is, a way to map this mathematical object to itself while maintaining the overall structure of the mathematical object.
[0058] The LWE ciphertext represents the ciphertext encrypted based on the learning with errors problem, where the learning with errors (LWE) problem is a problem of solving a system of linear equations with noise.
[0059] RLWE ciphertext refers to the ciphertext encrypted based on the ring learning with errors problem (RLWE).
[0060] NTRU ciphertext is encrypted using a public-key system invented by three mathematics professors at Brown University in 1996. NTRU (Number Theory Research Unit) is a public-key system. Because NTRU generates keys more easily, encryption and decryption speeds are much faster than those of well-known algorithms like RSA.
[0061] Bootstrapping, a ciphertext refresh technique, uses homomorphic decryption to reduce ciphertext noise.
[0062] represents a set of integers, i.e. represents the set of residue classes modulo q, that is, Where q is a positive integer; for any positive integer n, Indicates n The direct product of represents the set of residue classes modulo Q, that is, Where Q is a positive integer; Indicates n The direct product of .
[0063] Let n,N,q, is a positive integer, R is defined in The polynomial ring of degree N-1, R q It is defined in The polynomial ring of degree N-1 on R Q It is defined in The polynomial ring of degree N-1 over ; It is defined in The polynomial ring of degree n-1, It is defined in The polynomial ring of degree n-1 over , It is defined in The ring of polynomials of degree n-1 over .
[0064] For distribution D, x←D means randomly selecting x according to distribution D; for a finite set S, x←S means uniformly randomly selecting x from set S.
[0065] For real numbers "x" represents the integer closest to x.
[0066] The symbol := indicates assignment, that is, for any two values a and b, a:=b means assigning a to b.
[0067] The present invention provides a practical new multi-key fully homomorphic encryption method. Specifically, the present invention designs a multi-key fully homomorphic encryption scheme that supports NAND gate operations based on the matrix NTRU difficulty problem. A fast outer product method of multi-key ciphertext and single-key ciphertext based on NTRU is designed; an efficient outer product method of vector NTRU ciphertext and multi-key NTRU ciphertext extended ciphertext is designed; and two fast bootstrapping methods are proposed based on the multi-key fully homomorphic encryption scheme. The multi-key fully homomorphic encryption scheme designed by the present invention does not require the number of participants to be set and meets the multi-hop function. Compared with the same type of TFHE-type multi-key fully homomorphic encryption scheme, it has high computational efficiency and smaller evaluation keys.
[0068] Figure 2 is a flow chart of a multi-key homomorphic encryption method according to an embodiment of the present invention. This method can be applied to any participant. Optionally, any participant can encrypt the message polynomial that it wants to perform fully homomorphic calculations on and upload it to a server that performs multi-key fully homomorphic calculations. The server will complete the calculations and return the calculation results to the corresponding participant. As shown in Figure 2, the method includes the following steps:
[0069] Step S201: Obtain a message polynomial m, where the message polynomial m is used to represent the message uploaded by the participant to the server for homomorphic computation.
[0070] Step S202: Based on the security parameter λ and the key generation method MKHE_KG (1 λ ), generate the evaluation key evk corresponding to the participant and the encryption private key F corresponding to the participant.
[0071] The encryption private key F in this step is the private key used to encrypt the message polynomial m, and the private key will not be transmitted to the outside of the participants. As an optional embodiment, according to the security parameter λ and the key generation method MKHE_KG (1 λ ), generating the evaluation key evk and the encrypted private key F corresponding to the participant, may include the following steps: randomly sampling the encrypted private key F←χ from the distribution χ according to the security parameter λ n×n , and the inverse element of the encrypted private key F Exists; randomly sample vector e←χ from distribution χ n ,calculate Generate an evaluation key evk, where “·” represents a rounding function.
[0072] Step S203: Based on the encryption method MKHE_Enc(m,F), the encryption private key F is used to encrypt the message polynomial m to obtain the encrypted ciphertext c corresponding to the participant.
[0073] As an optional embodiment, based on the encryption method MKHE_Enc(m,F), the encryption private key F is used to encrypt the message polynomial m to obtain the encrypted ciphertext c corresponding to the participant, including the following process: randomly sampling vector e'←χ from the distribution χ n ; According to the vector e', the inverse element of the encrypted private key F And parameter q, encrypt the message polynomial m∈{0,1} according to the following formula to generate the encrypted ciphertext c: Where Δ = "q / 4".
[0074] In step S204, the evaluation key evk and the encrypted ciphertext c are sent to the server, where the server is used to perform homomorphic calculations on the encrypted ciphertext and other encrypted ciphertexts. The other encrypted ciphertexts are sent to the server by other participants, and the other encrypted ciphertexts are ciphertexts obtained by other participants using their respective encryption private keys to encrypt their respective message polynomials.
[0075] Through the above steps, the security parameter λ and the key generation method MKHE_KG(1 λ ) is used to encrypt the message polynomial m, generate the evaluation key evk and the encryption private key F corresponding to the participant, and then based on the encryption method MKHE_Enc(m,F), use the encryption private key F to encrypt the message polynomial m to obtain the encrypted ciphertext c corresponding to the participant; the evaluation key evk and the encrypted ciphertext c are sent to the server, so that the server can perform homomorphic calculations on the encrypted ciphertext and other encrypted ciphertexts, achieving the purpose of providing an NTRU-based multi-key fully homomorphic encryption scheme to achieve fully homomorphic calculations, thereby achieving the technical effect of improving the computational efficiency of the multi-key fully homomorphic encryption scheme, and then solving the technical problem of the lack of a secure NTRU-based multi-key fully homomorphic encryption scheme that supports super-constant participants.
[0076] As an optional embodiment, the above method may further include a decryption process: receiving the joint encrypted ciphertext sent by the server Among them, the joint encrypted ciphertext The ciphertext generated by the server after homomorphic calculation based on the encrypted ciphertext c; the joint encrypted ciphertext is encrypted according to the encryption private key F Decrypt and obtain the decrypted ciphertext m' corresponding to the participant, where
[0077] Optionally, jointly encrypt the ciphertext It can also be the ciphertext generated by the homomorphic computing server after the homomorphic computing and bootstrapping steps. The F in the formula i Indicates that this encrypted private key is the encrypted private key of the i-th participant.
[0078] As an optional embodiment, the method can also realize the ciphertext bootstrapping on the server side in the following manner: according to the key generation method MS_KG(1 λ ) and security parameter λ, generate the participant's bootstrapped private key s and bootstrapped public key b; according to the encryption method MS_UniEnc(μ,s), the bootstrapped private key s is used as the auxiliary message μ∈R Q Encryption is performed to obtain the auxiliary message ciphertext (d, f) of the participant; the auxiliary message ciphertext (d, f) and the bootstrap public key b are sent to the server, where the server is used to bootstrap refresh the joint encrypted ciphertext obtained after homomorphic calculation based on the auxiliary message ciphertext (d, f) and the bootstrap public key b.
[0079] As an optional embodiment, the above bootstrapping method may further include the following steps: generating a relinearization key rlk corresponding to the participant according to the key generation method ExtProdKGen(s,f), the bootstrapping private key s and the bootstrapping private key f; generating a vector NTRU ciphertext according to the auxiliary message μ and the bootstrapping private key f The relinearization key rlk and the vector NTRU ciphertext Sent to the server, where the server is used to ciphertext based on the relinearization key rlk and vector NTRU The joint encrypted ciphertext obtained after homomorphic computation is bootstrapped and refreshed.
[0080] Figure 3 is a flow chart of a multi-key homomorphic computation method according to an embodiment of the present invention. This multi-key homomorphic computation method can be applied to a homomorphic computation server. The homomorphic computation server can obtain encrypted ciphertext from multiple participants. The encrypted ciphertext is the ciphertext obtained by each participant using their own encryption private key to encrypt the message they transmit. The server then performs multi-key homomorphic computation on the encrypted ciphertext to obtain a homomorphic computation result. As shown in Figure 3, the method includes the following steps:
[0081] Step S301: Obtain the first ciphertext Second ciphertext and the evaluation key evk of the i-th participant among all participants i , where the first ciphertext is the homomorphic ciphertext corresponding to k1 participants, and the second ciphertext is the homomorphic ciphertext corresponding to k2 participants, and all participants include k1 participants and k2 participants.
[0082] Step S302: the first ciphertext Expand and obtain the first extended ciphertext corresponding to the private key group And the second ciphertext Expand and obtain the second extended ciphertext corresponding to the private key group Among them, the private key group is composed of the private keys of k1 participants and k2 participants.
[0083] Step S303: Based on the evaluation key evk of the i-th participant i , for the first extended ciphertext and the second extended ciphertext Perform homomorphic calculation with the NAND gate to obtain the ciphertext of the calculation result in, 01 represents a 0 vector of dimension i, and 02 represents a 0 vector of dimension ki. The present invention uses a NAND gate to perform homomorphic calculations because the NAND gate is complete.
[0084] As an optional embodiment, the above method further includes: receiving the bootstrapping public key b sent by the i-th participant i , bootstrap key {brk i,j} j∈[k] , relinear key rlk i and key switching key ksk i ; According to the bootstrap calculation method And the rotation polynomial r, the calculation result ciphertext Perform self-bootstrapping to obtain the refreshed calculation result ciphertext.
[0085] As an optional embodiment, the bootstrap public key b i , bootstrap key {brk i,j} j∈[k] , relinear key rlk i and key switching key ksk i Generated by the i-th participant in the following way: Based on the i-th participant's encrypted private key F i , using the key generation method MS_KG(1 λ ) and security parameter λ, generate the bootstrapped private key s of the i-th participant i and the bootstrapped public key b i ; For participant 1, the bootstrap key is generated as follows:
[0086] For participants 2≤i≤k, the bootstrap key is generated as follows:
[0087] Relinearization key rlk iAccording to the encryption method MS_UniEnc(f i ,s i )generate;
[0088] Key switching key ksk i According to the key switching key generation method KSKG(s i ,F i ,q,B)generated;
[0089] According to the bootstrap calculation method And the rotation polynomial r, the calculation result ciphertext Perform self-bootstrapping to obtain the refreshed calculation result ciphertext, including:
[0090] calculate
[0091] For 1≤i≤k, initialize
[0092] For 0≤j<n, iteratively execute the following loop
[0093] initialization For 1≤i≤k, the iterative calculation
[0094] Will The modulus is switched from Q back to q, and we get
[0095] right Perform key switching to obtain the refreshed calculation result ciphertext Among them, the refreshed calculation result ciphertext
[0096] As an optional embodiment, the method further includes: receiving the bootstrapping public key b sent by the i-th participant i , bootstrap key {brk i,j} j∈[0,n-1] and key switching key ksk i ; According to the bootstrap calculation method And the rotation polynomial r, the calculation result ciphertext Perform self-bootstrapping to obtain the refreshed calculation result ciphertext.
[0097] As an optional embodiment, the bootstrap public key b i , bootstrap key {brk i,j} j∈[0,n-1] and key switching key ksk i Generated by the i-th participant in the following way: Based on the i-th participant's encrypted private key F i, using the key generation method MS_KG(1 λ ) and security parameter λ, generate the bootstrapped private key s of the i-th participant i and the bootstrapped public key b i ; For participant 1, the bootstrap key is generated as follows:
[0098] brk 1,0 =MS_UniEnc(z 1,0 / s i ,s1);brk 1,j =MS_UniEnc(z 1,j ,s1) for 2≤j≤n-1;
[0099] For participants 2≤i≤k, the bootstrap key is generated as follows:
[0100] brk i,j =MS_UniEnc(z i,j )1≤j≤n-1;
[0101] Key switching key ksk i According to the key switching key generation method KSKG(s i ,F i ,q,B)generated;
[0102] According to the bootstrap calculation method And the rotation polynomial r, the calculation result ciphertext Perform self-bootstrapping to obtain the refreshed calculation result ciphertext, including:
[0103] 1) Calculation
[0104] 2) Initialize the accumulator
[0105] 3) For 1≤i≤k, execute the following loop for 0≤j<n iterations:
[0106] Switch the modulus of ACC from Q back to q to obtain ACC'; switch the key of ACC' to obtain the refreshed calculation result ciphertext Among them, the refreshed calculation result ciphertext
[0107] As an optional embodiment, the key switching key ksk i Through the key switching key generation method KSKG(s i ,F i ,q,B), key switching key generation method KSKG(s i ,F i,q,B) includes the following steps: input the bootstrapping private key s of the i-th participant i ∈R, encrypted private key Integer B,q; calculation And order Represents an identity matrix I of rank N N The result of the tensor operation with the gadget vector g; let It is a matrix where all positions are 0 except E[0][0]=1, and the sampling matrix G i ←χ (N·d)×n ; Output When you need to use the key switch key ksk i In the case of key switching, the key switching method The switching steps include: Enter MK-NTRU ciphertext and key switch key {ksk i} i∈[k] ; Let (c i,0 ,…,c i,N-1 ) means c i The coefficient of calculate Output the ciphertext obtained after key switching
[0108] Based on the above embodiment and optional embodiment, the present invention proposes a multi-key fully homomorphic encryption method based on M-NTRU. The following steps are optional implementations of the method, which may include the following sub-methods:
[0109] Key generation method MKHE_KG(1 λ ): Input security parameter λ to generate evaluation key evk and private key F.
[0110] Encryption method MKHE_Enc(m,F): Input the message to be encrypted m∈{0,1} and the encryption private key F, and output the ciphertext c.
[0111] Decryption method The input consists of the joint ciphertext and private key {F i} i∈[k] , output decrypted m.
[0112] Homomorphic computing NAND gate method Input two joint ciphertexts and the evaluation key evk of participant i i Output homomorphic computation results Participant i is any participant in the two joint ciphertexts. Each NAND gate only supports operations between two data, so complex operations can be broken down into multiple NAND gates.
[0113] The multi-key fully homomorphic encryption method based on M-NTRU described in this embodiment is instantiated by five positive integer parameters n, q, k, k1, and k2. The multi-key fully homomorphic encryption method based on the M-NTRU mathematical problem proposed in this invention is described as follows:
[0114] Key generation method MKHE_KG(1 λ ): Enter the security parameter λ and execute as follows:
[0115] 1) Randomly sample the matrix F←χ from the distribution χ n×n , so that the inverse element F of the matrix F -1 exist exists in
[0116] 2) Randomly sample vector e←χ from distribution χ n ,calculate
[0117] 3) Output the evaluation key evk and the encrypted private key F.
[0118] Encryption method MKHE_Enc(m,F): Input the message polynomial m∈{0,1} to be encrypted and the encryption private key F, and execute as follows:
[0119] 1) Randomly sample vector e'←χ from distribution χ n ; Calculate Δ = "q / 4";
[0120] 2) Calculate and output encrypted ciphertext
[0121] Decryption method Input the joint private key of k participants (the private key group corresponding to k participants) Encrypted ciphertext Calculate and output:
[0122] Homomorphic computing NAND gate method Assume evk i is the evaluation key of party i, The corresponding homomorphic ciphertexts are for participants k1 and k2 respectively. Let k represent the number of all participants and execute as follows:
[0123] 1) Extension Get the private key Ciphertext
[0124] 2) Let 01 represent the zero vector of dimension i and 02 represent the zero vector of dimension ki. Calculate and output the joint encrypted ciphertext:
[0125] The present invention also proposes an efficient extended ciphertext outer product method based on NTRU. The ciphertext outer product refers to the result obtained by multiplying two ciphertexts. In encryption algorithms, some mathematical operations such as addition, subtraction, multiplication, etc. are often required. However, it is not feasible to perform these operations directly in the ciphertext state because the ciphertext is encrypted and the value of the plaintext cannot be directly obtained. In order to be able to perform mathematical operations in the ciphertext state, the concept of ciphertext outer product is introduced. The ciphertext outer product allows multiplication operations to be performed in the ciphertext state without exposing the value of the plaintext, which helps to enhance the security of the encryption algorithm and protect the user's data privacy.
[0126] The efficient NTRU-based ciphertext outer product method proposed in this invention includes the following sub-methods:
[0127] Key generation method MS_KG(1 λ ): Input security parameter λ, output bootstrapped public key b and bootstrapped private key s.
[0128] Encryption method MS_UniEnc(μ,s): input auxiliary message μ∈R Q And the bootstrapped private key s, output the auxiliary message ciphertext (d,f).
[0129] Extended Outer Product Method Input multi-key NTRU ciphertext Public key set {b j} j∈[k] And the UniEnc ciphertext of party i (d i ,f i ), output the ciphertext after the outer product operation
[0130] The ciphertext outer product method based on the NTRU mathematical problem described in this embodiment will be instantiated by five positive integer parameters N, Q, d, k, and B. This embodiment involves using the method defined in For a polynomial ring R of degree N-1, let represents a gadget vector of dimension d, represents the gadget decomposition in the lattice code, and <·,·> represents the inner product operation.
[0131] The specific steps of the ciphertext outer product method based on the NTRU mathematical problem proposed in this invention are described as follows:
[0132] Key generation method MS_KG(1 λ): Input security parameter λ, public random string a∈R d , execute as follows:
[0133] 1) Uniformly randomly sample s∈R from the private key distribution χ Q , and s is in R Q Medium reversible;
[0134] 2) Randomly sample from the error distribution D Calculate b = -a·s + e;
[0135] 3) Output the bootstrapped public key b and the bootstrapped private key s.
[0136] Encryption method MS_UniEnc(μ,s): input auxiliary message μ∈R Q And the bootstrap private key s, execute as follows:
[0137] 1) Uniformly randomly sample r∈R from the private key distribution χ Q , and r is in R Q medium reversible;
[0138] 2) Randomly sample from the error distribution D calculate
[0139] 3) Randomly sample from the error distribution D Calculate f = (e² + rg) / s;
[0140] 4) Output ciphertext
[0141] Extended Outer Product Method Input multi-key NTRU ciphertext The public key set corresponding to k participants {b j} j∈[k] And the UniEnc ciphertext of party i (d i ,f i ), execute as follows:
[0142] 1) For 1≤i≤k, calculate u j = <g -1 (c j ),d i >,
[0143] 2) Calculation
[0144] 3) Output
[0145] In addition, the present invention also proposes an efficient method for extending the outer product of vector NTRU ciphertext and MK-NTRU ciphertext. The efficient extended outer product method based on NTRU proposed in the present invention includes the following sub-methods:
[0146] Key generation method ExtProdKGen(s i ,f i ): Enter the private key s of party i i and f i , output relinearization key rlk i ;
[0147] Extended Outer Product Method Enter MK-NTRU ciphertext Public key set {b j} j∈[k] , vector NTRU ciphertext and the relinearization key rlk i , output the calculation result of the expanded outer product
[0148] The ciphertext outer product method based on the NTRU mathematical problem described in this embodiment will be instantiated by four positive integer parameters N, Q, d, and k. This embodiment involves using the method defined in The polynomial ring R of degree N-1 Q The form of the vector NTRU ciphertext used in this embodiment is Where e represents the noise vector, is the gadget vector.
[0149] The specific implementation steps of the NTRU-based extended ciphertext outer product method proposed in this invention are described as follows:
[0150] Key generation method ExtProdKGen(s i ,f i ): Input the private key s of party i i and f i , calculate and output the relinearization key rlk i =MS_UniEnc(f i ,s i ).
[0151] Extended Outer Product Method Input a bootstrapped private key s=(s1,…,s k ) encrypted MK-NTRU ciphertext And the public key set {b j} j∈[k] , vector NTRU ciphertext and the reproducibility key rlk i, execute as follows:
[0152] 1) For j∈[k], calculate make
[0153] 2) Calculate and output
[0154] The key switching method from MK-NTRU ciphertext to MK-FHE ciphertext includes the following sub-methods:
[0155] Key switching key generation method KSKG(s i ,F i ,q,B):Enter the private key Integer q, B, output key switching key ksk i .
[0156] Key switching method Input multi-key NTRU ciphertext Key switch key {ksk i} i∈[k] , output ciphertext
[0157] Each participant can independently run the following key generation algorithm:
[0158] Key switching key generation KSKG(s i ,F i ,q,B):Enter the private key Integer B,q. Calculation make Represents an identity matrix I of rank N N The result of the tensor operation with the gadget vector g. It is a matrix where all positions are 0 except E[0][0]=1. The sampling matrix G i ←χ (N·d)×n Output
[0159] Key switching method Input multi-key NTRU ciphertext Key switch key {ksk i} i∈[k] , execute as follows:
[0160] 1) Let (c i,0 ,…,c i,N-1 ) means c i The coefficient of
[0161] 2) Calculation Output
[0162] The optional embodiment of the present invention further provides two bootstrapping algorithms. The bootstrapping algorithm based on NTRU ciphertext proposed by the present invention includes the following sub-methods:
[0163] Bootstrap key generation method BSKGen(F i ,f i ): Input the private key F of participant i i ,f i , generate public and private keys (s i ,b i ), bootstrap key {brk i,j} j∈[k] , re-linear key rlk i , key switching key ksk i .
[0164] Bootstrap calculation method Enter multi-key ciphertext Four-tuple public key pair {(b i ,brk i ,rlk i ,ksk i )} i∈[k] And rotate the polynomial r, output the refreshed ciphertext
[0165] The specific steps of the NTRU ciphertext-based bootstrapping algorithm 1 proposed in the present invention are described as follows:
[0166] Each participant independently runs the following key generation algorithm (taking participant i as an example);
[0167] Bootstrap key generation method BSKGen(F i ,f i ): Enter the private key F of participant i i ,f i , matrix F i The first column vector is col0(F i )=(z0,…,z n-1 ) indicates that the execution is as follows:
[0168] 1) Generate public and private keys (s i ,b i ) = MS_KG;
[0169] 2) Party 1 generates the bootstrap key as follows:
[0170] For 1≤j≤n-2
[0171] Participant 2≤i≤k generates the bootstrap key as follows:
[0172] For 1≤j≤n-1
[0173] 3) Relinearization key generation rlk i =MS_UniEnc(f i ,s i );
[0174] 4)Key switching key generation ksk i =KSKG(s i ,F i ,q,B).
[0175] Bootstrap calculation method Enter multi-key ciphertext Four-tuple public key pair {(b i ,brk i ,rlk i ,ksk i )} i∈[k] And the rotation polynomial r, performed as follows:
[0176] 1) Calculation
[0177] 2) For 1≤i≤k, initialize
[0178] 3) For 0≤j<n iterations, execute the following loop
[0179] 4) Initialization For 1≤i≤k, the iterative calculation is:
[0180] 5) Mode switching. Use mode switching technology to The modulus is switched from Q back to q to obtain
[0181] 6) Key switching. Calculation
[0182] The bootstrapping algorithm 2 based on NTRU ciphertext proposed in this invention includes the following sub-methods:
[0183] Bootstrap key generation method BSKGen(F i ): Input the private key F of participant i i , generate public and private keys (s i ,b i ), output bootstrap key {brk i,j} j∈[0,n-1], key switching key ksk i .
[0184] Bootstrap calculation method Enter multi-key ciphertext The public key pair of three elements {(b i ,brk i ,ksk i )} i∈[k] And rotate the polynomial r, output the refreshed ciphertext
[0185] The second bootstrapping algorithm based on NTRU ciphertext proposed in this invention is described as follows:
[0186] Each participant independently runs the following key generation algorithm (taking participant i as an example)
[0187] Bootstrap key generation method BSKGen(F i ): Input the private key F of participant i i , matrix F i The first column vector is col0(F i )=(z i,0 ,…,z i,n-1 ) indicates that the execution is as follows:
[0188] 1) Generate public and private keys (s i ,b i )=MS_KG(1 λ );
[0189] 2) Party 1 generates the bootstrap key as follows:
[0190] brk 1,0 =MS_UniEnc(z 1,0 / s i ,s1);brk 1,j =MS_UniEnc(z 1,j ,s1) for 2≤j≤n-1;
[0191] Participant 2≤i≤k generates the bootstrap key as follows:
[0192] brk i,j =MS_UniEnc(z i,j )1≤j≤n-1
[0193] 3)Key switching key generation ksk i =KSKG(s i ,F i ,q,B).
[0194] Bootstrap calculation method Enter multi-key ciphertext The public key pair of three elements {(b i ,brk i ,ksk i )} i∈[k] And the rotation polynomial r, performed as follows:
[0195] 1) Calculation
[0196] 2) Initialize the accumulator
[0197] 3) For 1≤i≤k, execute the following loop for 0≤j<n iterations:
[0198] 4) Mode switching: Use mode switching technology to switch the mode of ACC from Q back to q to obtain ACC'.
[0199] 5) Key switching. Calculation
[0200] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the present invention is not limited by the order of the actions described, because according to the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and components involved are not necessarily required for the present invention.
[0201] Through the description of the above implementation methods, those skilled in the art can clearly understand that the multi-key homomorphic encryption method and the multi-key homomorphic computing method according to the above embodiments can be implemented by means of software plus the necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0202] According to an embodiment of the present invention, a multi-key homomorphic encryption device for implementing the above-mentioned multi-key homomorphic encryption method is also provided. Figure 4 is a structural block diagram of the multi-key homomorphic encryption device provided according to an embodiment of the present invention. As shown in Figure 4, the multi-key homomorphic encryption device includes: a first acquisition component 41, a generation component 42, an encryption component 43 and a sending component 44. The multi-key homomorphic encryption device is described below.
[0203] A first acquisition component 41 is used to obtain a message polynomial m, wherein the message polynomial m is used to represent the message uploaded by the participant to the server for homomorphic computation;
[0204] The generating component 42 is connected to the first acquiring component 41 and is used to generate a key according to the security parameter λ and the key generating method MKHE_KG (1 λ ), generating the evaluation key evk corresponding to the participant and the encryption private key F corresponding to the participant;
[0205] An encryption component 43, connected to the generation component 42, is configured to encrypt the message polynomial m using the encryption private key F based on the encryption method MKHE_Enc(m,F) to obtain the encrypted ciphertext c corresponding to the participant;
[0206] The sending component 44 is connected to the encryption component 43 and is used to send the evaluation key evk and the encrypted ciphertext c to the server, wherein the server is used to perform homomorphic calculations on the encrypted ciphertext and other encrypted ciphertexts. The other encrypted ciphertexts are sent to the server by other participants, and the other encrypted ciphertexts are ciphertexts obtained by the other participants using their respective encryption private keys to encrypt their respective message polynomials.
[0207] It should be noted that the first acquisition component 41, generation component 42, encryption component 43, and sending component 44 described above correspond to steps S201 to S204 in the embodiment. The examples and application scenarios implemented by these three components and the corresponding steps are the same, but are not limited to the contents disclosed in the above embodiment. It should be noted that the above components, as part of the device, can be run in the computer terminal 10 provided in the embodiment.
[0208] According to an embodiment of the present invention, a multi-key homomorphic encryption device for implementing the above-mentioned multi-key homomorphic computing method is also provided. Figure 5 is a structural block diagram of the multi-key homomorphic computing device provided according to an embodiment of the present invention. As shown in Figure 5, the multi-key homomorphic computing device includes: a second acquisition component 51, a ciphertext expansion component 52 and a homomorphic computing component 53. The multi-key homomorphic computing is explained below.
[0209] The second acquisition component 51 is used to obtain the first ciphertext Second ciphertext and the evaluation key evk of the i-th participant among all participants i , wherein the first ciphertext is a homomorphic ciphertext corresponding to k1 participants, the second ciphertext is a homomorphic ciphertext corresponding to k2 participants, and the total number of participants includes the k1 participants and the k2 participants;
[0210] The ciphertext expansion component 52 is connected to the second acquisition component 51 and is used to Expand and obtain the first extended ciphertext corresponding to the private key group And the second ciphertext Expand to obtain the second extended ciphertext corresponding to the private key group The private key group is composed of the private keys of the k1 participants and the k2 participants,
[0211] The homomorphic computing component 53 is connected to the ciphertext expansion component 52 and is used to calculate the evaluation key evk of the i-th participant according to the evaluation key evk of the i-th participant. i , for the first extended ciphertext and the second extended ciphertext Perform homomorphic calculation with the NAND gate to obtain the ciphertext of the calculation result in, 01 represents a 0 vector with dimension i, and 02 represents a 0 vector with dimension ki.
[0212] It should be noted that the second acquisition component 51, the ciphertext expansion component 52, and the homomorphic computation component 53 correspond to steps S301 to S303 in the embodiment. The three components and the corresponding steps implement the same examples and application scenarios, but are not limited to the contents disclosed in the above embodiment. It should be noted that the above components, as part of the device, can be run in the computer terminal 10 provided in the embodiment.
[0213] An embodiment of the present invention may provide a computer device. Optionally, in this embodiment, the computer device may be located in at least one of a plurality of network devices in a computer network. The computer device includes a memory and a processor.
[0214] Among them, the memory can be used to store software programs and components, such as the program instructions / components corresponding to the multi-key homomorphic encryption method and multi-key homomorphic calculation method and device in the embodiments of the present invention. The processor executes various functional applications and data processing by running the software programs and components stored in the memory, that is, realizing the above-mentioned multi-key homomorphic encryption method and multi-key homomorphic calculation method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the computer terminal via a network. Examples of the above-mentioned network include but are not limited to the Internet, corporate intranet, local area network, mobile communication network and combinations thereof.
[0215] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: obtaining a message polynomial m, wherein the message polynomial m is used to represent the message uploaded by the participant to the server for homomorphic calculation; according to the security parameter λ and the key generation method MKHE_KG (1 λ ), generate an evaluation key evk corresponding to the participant and an encryption private key F corresponding to the participant; based on the encryption method MKHE_Enc(m,F), use the encryption private key F to encrypt the message polynomial m to obtain the encrypted ciphertext c corresponding to the participant; send the evaluation key evk and the encrypted ciphertext c to the server, wherein the server is used to perform homomorphic calculation on the encrypted ciphertext and other encrypted ciphertexts, and the other encrypted ciphertexts are sent to the server by other participants, and the other encrypted ciphertexts are ciphertexts obtained after the other participants use their respective encryption private keys to encrypt their respective message polynomials.
[0216] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: obtain the first ciphertext Second ciphertext and the evaluation key evk of the i-th participant among all participants i , wherein the first ciphertext is a homomorphic ciphertext corresponding to k1 participants, the second ciphertext is a homomorphic ciphertext corresponding to k2 participants, and the total number of participants includes the k1 participants and the k2 participants; for the first ciphertext Expand and obtain the first extended ciphertext corresponding to the private key group And the second ciphertext Expand to obtain the second extended ciphertext corresponding to the private key group The private key group is composed of the private keys of the k1 participants and the k2 participants, According to the evaluation key evk of the i-th participant i , for the first extended ciphertext and the second extended ciphertext Perform homomorphic calculation with the NAND gate to obtain the ciphertext of the calculation result in, 01 represents a 0 vector with dimension i, and 02 represents a 0 vector with dimension ki.
[0217] A person skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a non-volatile storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0218] An embodiment of the present invention further provides a non-volatile storage medium. Optionally, in this embodiment, the non-volatile storage medium can be used to store program codes executed by the multi-key homomorphic encryption method and the multi-key homomorphic computing method provided in the above embodiment.
[0219] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0220] Optionally, in this embodiment, the non-volatile storage medium is configured to store program codes for executing the following steps: obtaining a message polynomial m, wherein the message polynomial m is used to represent a message uploaded by a participant to a server for homomorphic computation; generating a key according to a security parameter λ and a key generation method MKHE_KG(1 λ ), generate an evaluation key evk corresponding to the participant and an encryption private key F corresponding to the participant; based on the encryption method MKHE_Enc(m,F), use the encryption private key F to encrypt the message polynomial m to obtain the encrypted ciphertext c corresponding to the participant; send the evaluation key evk and the encrypted ciphertext c to the server, wherein the server is used to perform homomorphic calculation on the encrypted ciphertext and other encrypted ciphertexts, and the other encrypted ciphertexts are sent to the server by other participants, and the other encrypted ciphertexts are ciphertexts obtained after the other participants use their respective encryption private keys to encrypt their respective message polynomials.
[0221] Optionally, in this embodiment, the non-volatile storage medium is configured to store program codes for executing the following steps: obtaining the first ciphertext Second ciphertext and the evaluation key evk of the i-th participant among all participants i , wherein the first ciphertext is a homomorphic ciphertext corresponding to k1 participants, the second ciphertext is a homomorphic ciphertext corresponding to k2 participants, and the total number of participants includes the k1 participants and the k2 participants; for the first ciphertext Expand and obtain the first extended ciphertext corresponding to the private key group And the second ciphertext Expand to obtain the second extended ciphertext corresponding to the private key group The private key group is composed of the private keys of the k1 participants and the k2 participants, According to the evaluation key evk of the i-th participant i , for the first extended ciphertext and the second extended ciphertext Perform homomorphic calculation with the NAND gate to obtain the ciphertext of the calculation result in, 01 represents a 0 vector with dimension i, and 02 represents a 0 vector with dimension ki.
[0222] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0223] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0224] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or components, which can be electrical or other forms.
[0225] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0226] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0227] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, and other media that can store program code.
[0228] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention. Industrial Applicability
[0229] The solution provided in the embodiment of the present application can be applied to the field of cryptography. In the embodiment of the present application, the security parameter λ and the key generation method MKHE_KG (1 λ ) is used to encrypt the message polynomial m, generate the evaluation key evk and the encryption private key F corresponding to the participant, and then based on the encryption method MKHE_Enc(m,F), the encryption private key F is used to encrypt the message polynomial m to obtain the encrypted ciphertext c corresponding to the participant; the evaluation key evk and the encrypted ciphertext c are sent to the server, so that the server can perform homomorphic calculations on the encrypted ciphertext and other encrypted ciphertexts, thereby achieving the purpose of providing a multi-key fully homomorphic encryption scheme based on NTRU to realize fully homomorphic calculations, thereby achieving the technical effect of improving the computational efficiency of the multi-key fully homomorphic encryption scheme.
Claims
1. A multi-key homomorphic encryption method, include: Obtain a message polynomial m, wherein the message polynomial m is used to represent the message uploaded by the participant to the server for homomorphic computing; According to the security parameter λ and the key generation method MKHE_KG(1 λ ), generate an evaluation key evk corresponding to the participant and an encryption private key F corresponding to the participant; Based on the encryption method MKHE_Enc(m, F), the message polynomial m is encrypted using the encryption private key F to obtain the encrypted ciphertext c corresponding to the participant; The evaluation key evk and the encrypted ciphertext c are sent to a server, wherein the server is used to perform homomorphic calculation on the encrypted ciphertext and other encrypted ciphertexts, and the other encrypted ciphertexts are sent to the server by other participants, and the other encrypted ciphertexts are ciphertexts obtained by the other participants encrypting their respective message polynomials using their respective encryption private keys.
2. The method according to claim 1, in, The method according to the security parameter λ and the key generation method MKHE_KG (1 λ ), generating an evaluation key evk corresponding to the participant and an encryption private key F corresponding to the participant, including: According to the security parameter λ, the encrypted private key F←χ is randomly sampled from the distribution χ n×n , and the inverse element of the encrypted private key F exist; Randomly sample a vector e←χ from the distribution χ n ,calculate Generate the evaluation key evk, where "·" represents a rounding function.
3. The method according to claim 2, in, The method based on the encryption method MKHE_Enc(m, F), using the encryption private key F to encrypt the message polynomial m, to obtain the encrypted ciphertext c corresponding to the participant, includes: Randomly sample a vector e′←χ from distribution χ n ; According to the vector e′, the inverse element of the encrypted private key F and parameter q, encrypt the message polynomial m∈{0,1} according to the following formula to generate the encrypted ciphertext c:
4. The method according to claim 3, in, The method further comprises: Receive the joint encrypted ciphertext sent by the server Among them, the combined Secret text The ciphertext generated by the server after performing homomorphic calculation based on the encrypted ciphertext c; The joint encryption ciphertext is encrypted according to the encryption private key F. Decryption is performed to obtain the decrypted ciphertext m′ corresponding to the participant, where 5. The method according to any one of claims 1 to 4, in, The method further comprises: According to the key generation method MS_KG(1 λ ) and the security parameter λ, generating the bootstrapped private key s and the bootstrapped public key b of the participant; According to the encryption method MS_UniEnc(μ, s), the bootstrapped private key s is used as the auxiliary message μ∈R Q Encryption is performed to obtain the auxiliary message ciphertext (d, f) of the participant; The auxiliary message ciphertext (d, f) and the bootstrap public key b are sent to the server, wherein the server is used to bootstrap refresh the joint encrypted ciphertext obtained after homomorphic calculation according to the auxiliary message ciphertext (d, f) and the bootstrap public key b.
6. The method according to claim 5, in, The method further comprises: Generate the relinearization key rlk corresponding to the participant according to the key generation method ExtProdKGen(s, f), the bootstrap private key s and the bootstrap private key f; Generate the vector NTRU ciphertext according to the auxiliary message μ and the bootstrap private key f The relinearization key rlk and the vector NTRU ciphertext Sent to the server, wherein the server is used to generate a ciphertext according to the relinearization key rlk and the vector NTRU The joint encrypted ciphertext obtained after homomorphic computation is bootstrapped and refreshed.
7. A multi-key homomorphic computing method, include: Get the first ciphertext Second ciphertext and the evaluation key evk of the i-th participant among all participants i , wherein the first ciphertext corresponds to k 1 The second ciphertext is the homomorphic ciphertext corresponding to k participants. 2 The homomorphic ciphertext of k participants, all of whom include the k 1 The k participants and the 2 Participants For the first ciphertext Expand and obtain the first extended ciphertext corresponding to the private key group And for the second ciphertext Expand to obtain a second extended ciphertext corresponding to the private key group Wherein, the private key group is composed of the k 1 The k participants and the 2 Each participant has their own private key. According to the evaluation key evk of the i-th participant i , for the first extended ciphertext and the second extended ciphertext Perform homomorphic calculation with the NAND gate to obtain the ciphertext of the calculation result in, 0 1 represents a 0 vector of dimension i, 0 2 Represents a zero vector of dimension ki.
8. The method according to claim 7, in, The method further comprises: Receive the bootstrap public key b sent by the i-th participant i , bootstrap key {brk i,j } j∈[k] , re-linear key rlk i and key switching key ksk i ; According to the bootstrap calculation method and the rotation polynomial r, the ciphertext of the calculation result Perform bootstrapping to obtain the refreshed ciphertext of the calculation result.
9. The method according to claim 8, in, The bootstrapped public key b i , the bootstrap key {brk i,j } j∈[k] , the re-linear key rlk i and the key switching key ksk i Generated by the i-th participant in the following manner: According to the encrypted private key F of the i-th participant i , using the key generation method MS_KG(1 λ ) and the security parameter λ, generate the bootstrapped private key s of the i-th participant i and the bootstrapped public key b i ; For Party 1, the bootstrap key is generated as follows: For 1≤j≤n-2 For participants 2≤i≤k, the bootstrap key is generated as follows: For 1≤j≤n-1 The relinearization key rlk i According to the encryption method MS_UniEnc(f i ,s i )generate; The key switching key ksk i According to the key switching key generation method KSKG(s i , F i ,q,B)generated; The bootstrap calculation method and the rotation polynomial r, the ciphertext of the calculation result Perform self-bootstrapping to obtain the refreshed calculation result ciphertext, including: calculate For 1≤i≤k, initialize For 0≤j<n, iteratively execute the following loop initialization For 1≤i≤k, the iterative calculation Will The modulus is switched from Q back to q, giving right Switch the key to get the refreshed calculation result ciphertext Among them, the refreshed calculation result ciphertext 10. The method according to claim 7, in, The method further comprises: Receive the bootstrap public key b sent by the i-th participant i , bootstrap key {brk i,j } j∈[0,n-1] and key switching key ksk i ; According to the bootstrap calculation method and the rotation polynomial r, the ciphertext of the calculation result Perform bootstrapping to obtain the refreshed ciphertext of the calculation result.
11. The method according to claim 10, in, The bootstrapped public key b i , the bootstrap key {brk i,j } j∈[0,n-1] and the key switching key ksk i Generated by the i-th participant in the following manner: According to the encrypted private key F of the i-th participant i , using the key generation method MS_KG(1 λ ) and the security parameter λ, generate the bootstrapped private key s of the i-th participant i and the bootstrapped public key b i ; For Party 1, the bootstrap key is generated as follows: brk 1,0 =MS_UniEnc(z 1,0 / s i ,s 1 );brk 1,j =MS_UniEnc(z 1,j ,s 1 ) for 2≤j≤n-1; For participants 2≤i≤k, the bootstrap key is generated as follows: brk i,j =MS_UniEnc(from i,j )1≤j≤n-1; The key switching key ksk i According to the key switching key generation method KSKG(s i , F i ,q,B)generated; The bootstrap calculation method and the rotation polynomial r, the ciphertext of the calculation result Perform self-bootstrapping to obtain the refreshed calculation result ciphertext, including: calculate 2) Initialize the accumulator 3) For 1≤i≤k, for 0≤j<n iterations, execute the following loop Switch the modulus of ACC from Q back to q to obtain ACC′; Switch the key of ACC′ to get the refreshed calculation result ciphertext Among them, the refreshed calculation result ciphertext 12. The method according to any one of claims 8 to 11, in, The key switching key ksk i By key switching key generation method KSKG(s i , F i , q, B), the key switching key generation method KSKG(s i , F i , q, B) comprises the following steps: Input the bootstrap private key s of the i-th participant i ∈R, encrypted private key integer B,q; calculate And order Represents an identity matrix I of rank N N The result of tensor operation with gadget vector g; make It is a matrix where all positions are 0 except E[0][0]=1. The sampling matrix G i ←χ (N·d)×n ; Output When it is necessary to use the key switching key ksk i When performing key switching, the key switching method The switching steps include the following: Enter MK-NTRU ciphertext and the key switching key {ksk i } i∈[k] ; Let (c i,0 , …, c i,N-1 ) means c i The coefficient of calculate Output the ciphertext obtained after key switching 13. A non-volatile storage medium, the non-volatile storage medium comprising a stored program, in, When the program is running, the device where the non-volatile storage medium is located is controlled to execute the multi-key homomorphic encryption method described in any one of claims 1 to 6 or the multi-key homomorphic computing method described in any one of claims 7 to 12.
14. A computer device, comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to run the program stored in the memory. in, When the program is running, it executes the multi-key homomorphic encryption method described in any one of claims 1 to 6 or the multi-key homomorphic computing method described in any one of claims 7 to 12.
Citation Information
Patent Citations
Multi-key fully homomorphic encryption method on ring surface
CN116707752A
File travel data privacy calculation method and system based on multi-key homomorphic encryption
CN116896439A
Cited By
Voiceprint verification method and device based on fully homomorphic encryption, equipment and medium
CN120582907A