Homomorphic encryption system having improved operation speed and method for generating ciphertext in same
The homomorphic encryption system addresses the challenge of maintaining computational speed by using a set polynomial matrix for bootstrapping multiple ciphertexts, reducing error sizes and enhancing operation speed through minimized multiplication operations.
Patent Information
- Application Number
- PCT/KR2024/012529
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-09
- Filing Date
- 2024-08-22
- Publication Date
- 2025-06-12
AI Technical Summary
Homomorphic encryption systems face challenges in maintaining computational speed due to increasing error sizes in ciphertexts when continuous calculations are performed, leading to a need for efficient methods to reduce error sizes while enhancing operation speed.
The implementation of a homomorphic encryption system that utilizes a computation unit to apply a set polynomial matrix for bootstrapping multiple ciphertexts simultaneously, reducing the number of multiplication operations and enhancing computational speed by using Tensor operations.
This approach effectively reduces the error size of multiple ciphertexts and improves the operational speed of the homomorphic encryption system by minimizing the number of multiplication operations required during the bootstrapping process.
Smart Images

Figure KR2024012529_12062025_PF_FP_ABST
Abstract
Description
Homomorphic encryption system with improved computational speed and ciphertext generation method therefor
[0001] The present invention relates to a homomorphic encryption system with improved computational speed and a method for generating ciphertext therein.
[0002] A homomorphic cryptosystem is a system capable of performing calculations on ciphertexts. However, if ciphertexts are continuously computed, the size of the errors within the ciphertexts can increase, rendering the computation impossible. Therefore, technologies are needed to address this issue, particularly a homomorphic cryptosystem that reduces the size of errors across multiple ciphertexts while simultaneously improving computational speed.
[0003] The present invention provides a homomorphic encryption system with improved computational speed and a method for generating ciphertext therein.
[0004] In order to achieve the above-described purpose, a homomorphic encryption system according to one embodiment of the present invention includes a computation unit that simultaneously computes a polynomial for an algorithm that reduces the size of an error for all ciphertexts, thereby converting a plurality of ciphertexts into new ciphertexts with a smaller error size. Here, the polynomial has elements corresponding to all of the ciphertexts.
[0005] A homomorphic encryption system according to another embodiment of the present invention includes a computation unit that uses a set polynomial matrix to apply an algorithm for reducing the error size of the ciphertexts to the ciphertexts in order to convert the plurality of ciphertexts into new ciphertexts with a smaller error size. Here, the number of columns of the set polynomial matrix is smaller than the number of ciphertexts, and the elements of the set polynomial matrix are composed only of "1", "0", and "-1".
[0006] A homomorphic encryption system according to another embodiment of the present invention includes a computation unit that uses a set polynomial matrix in a process of applying an algorithm for reducing the error size of the ciphertexts to the ciphertexts in order to convert the plurality of ciphertexts into new ciphertexts with a smaller error size. Here, the computation unit uses the set polynomial matrix so that the computation time corresponding to the multiplication and addition operations when the set polynomial matrix is used is smaller than the computation time corresponding to the multiplication and addition operations when the algorithm is operated in parallel for each of the ciphertexts.
[0007] A homomorphic encryption system according to another embodiment of the present invention includes a computation unit that uses a set polynomial matrix to apply an algorithm for reducing the error size of the ciphertexts to each of the ciphertexts in order to transform the plurality of ciphertexts into new ciphertexts having a smaller error size. Here, the number of multiplication operations when using the set polynomial matrix is smaller than the number of multiplication operations when applying the algorithm to the corresponding ciphertexts without using the set polynomial matrix.
[0008] A method for generating ciphertext in a homomorphic encryption system according to one embodiment of the present invention comprises the steps of preparing a set polynomial matrix; and the step of using the set polynomial matrix in a process of operating an algorithm for reducing an error size of a ciphertext with a plurality of ciphertexts. Here, the number of multiplication operations performed when operating the ciphertexts with the algorithm at once using the set polynomial matrix is smaller than the number of multiplication operations performed when operating the algorithm in parallel for each of the ciphertexts without using the set polynomial matrix.
[0009]
[0010] The homomorphic encryption system and the ciphertext generation method according to the present invention can generate ciphertexts with small error sizes by gathering and bootstrapping the ciphertexts at once using a bootstrapping algorithm. In particular, the homomorphic encryption system can improve the operation speed of the homomorphic encryption system by applying a set polynomial matrix that can reduce the number of multiplication operations when bootstrapping the ciphertexts.
[0011] FIG. 1 is a block diagram illustrating a homomorphic encryption system according to one embodiment of the present invention.
[0012] FIG. 2 is a diagram illustrating a process for generating ciphertexts with small error sizes in a homomorphic encryption system according to the first embodiment of the present invention.
[0013] FIG. 3 is a diagram illustrating a process for generating ciphertexts with small error sizes in a homomorphic encryption system according to a second embodiment of the present invention.
[0014] FIG. 4 is a diagram illustrating a process for generating ciphertexts with small error sizes in a homomorphic encryption system according to a third embodiment of the present invention.
[0015] As used herein, singular expressions include plural expressions unless the context clearly dictates otherwise. In this specification, terms such as "consist of" or "include" should not be construed to necessarily include all components or steps described in the specification, and should be construed to mean that some of the components or steps may not be included, or that additional components or steps may be included. In addition, terms such as "part" and "module" described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware or software, or by a combination of hardware and software.
[0016]
[0017] The present invention can reduce the computation time by applying a set polynomial matrix, for example, a Tensor operation, that satisfies a specific condition when generating new ciphertexts with a small error size by applying a specific algorithm to a plurality of ciphertexts in a TFHE / FHEW homomorphic encryption system, for example, by bootstrapping the ciphertexts.
[0018] This homomorphic encryption system refers to a cryptosystem that can perform operations on ciphertexts, and can perform arbitrary logical operations (gate operations) or addition / multiplication operations homomorphically. Homomorphic ciphertexts used in this homomorphic encryption system may include the LWE (Learning with errors) ciphertext of the following mathematical formula 1, the MLWE (Module LWE) ciphertext of the following mathematical formula 2, and the RLWE (Ring LWE) ciphertext. Of course, the above homomorphic ciphertexts are not limited to the above ciphertexts.
[0019]
[0020] Here, q, n, and △ represent natural numbers, is homogeneously random represents a vector of n elements selected from , e represents an error with a small value (usually e ranges from -3 to 3), m represents the message to be sent, refers to a secret key that only the user has.
[0021]
[0022] Here, the elements of the LWE ciphertext are If the elements of , the elements of the MLWE ciphertext are These are the elements (polynomials) of the ring called A collection of polynomials whose coefficients are the elements In the degree direction, modulo It refers to a structure that performs operations. That is, the total number of elements is becomes a dog. At this time, K is a parameter corresponding to n in the LWE ciphertext.
[0023] Meanwhile, in the MLWE ciphertext of mathematical expression 2, the case where K = 1 is an RLWE ciphertext.
[0024] In the homomorphic encryption system, if the ciphertext is continuously computed, the error size within the ciphertext increases, resulting in a state where the ciphertext can no longer be computed. Therefore, the homomorphic encryption system needs to convert the ciphertext into a new ciphertext with a smaller error size, and a specific algorithm can be used for this purpose.
[0025] In one embodiment, the homomorphic encryption system can generate new ciphertexts with smaller error sizes by bootstrapping ciphertexts. Therefore, if multiple ciphertexts exist, each ciphertext must be bootstrapped. Specifically, a polynomial for the bootstrapping algorithm can be computed for each ciphertext, as in Algorithm 1 below.
[0026] [Correction pursuant to Rule 91, October 25, 2024]
[0027] Looking at Algorithm 1 above, we can see that when L LWE ciphertexts are given, lines 2 through 7 are sequentially executed according to the index of line 1. Consequently, if the time to bootstrap each ciphertext is t, the time to compute L ciphertexts is Lt. In other words, the computation time increases linearly with the number of ciphertexts. Therefore, there is no computational time benefit when performing bootstrapping on L ciphertexts.
[0028] The homomorphic encryption system of the present invention proposes a technique for reducing computational time when generating multiple ciphertexts with small errors. In the following, a bootstrapping algorithm (operation) is used to generate ciphertexts with small errors. However, various algorithms can be used, as long as they can generate ciphertexts with small errors, and are not limited to the bootstrapping algorithm.
[0029] According to one embodiment, the homomorphic encryption system can perform bootstrapping operations on multiple ciphertexts at once without performing bootstrapping operations on the ciphertexts in parallel to reduce computation time.
[0030] According to one embodiment, the homomorphic encryption system may use a set polynomial matrix when performing a bootstrapping operation by gathering the ciphertexts at once. Here, the number of columns of the set polynomial matrix is smaller than the total number of ciphertexts, and the set polynomial matrix may only be composed of "1", "0", and "-1".
[0031] In another embodiment, the homomorphic encryption system may utilize a set polynomial matrix that can reduce the number of multiplication operations compared to performing bootstrapping operations on the ciphertexts in parallel. Multiplication operations require hundreds of times more logic circuits than addition operations, significantly slowing down the computational speed. Therefore, the homomorphic encryption system utilizes a set polynomial matrix that can reduce the number of multiplication operations.
[0032] Preferably, the homomorphic encryption system can reduce the number of multiplication operations under the condition that the operation speed according to addition and multiplication operations when using the set polynomial matrix is faster than the operation speed according to addition and multiplication operations when bootstrapping the ciphertexts in parallel.
[0033] For example, the homomorphic encryption system can use tensor operations to reduce the number of multiplication operations. Let's examine how computational speed improves when performing these tensor operations.
[0034]
[0035] The matrix product of A and B is At this time, 8 multiplication operations are performed.
[0036] To perform tensor operations, a set of polynomial matrices can be used, as follows:
[0037]
[0038] The operation when using this set polynomial matrix is as follows:
[0039]
[0040]
[0041] Looking at the results of the above operation, when performing a Tensor operation, the result is the same as when performing the matrix multiplication of A and B (C 11 =19, C 12 =22, C 21 =43, C 22 =50) is obtained. In comparison in terms of operation speed, when performing matrix multiplication of A and B, 8 multiplication operations were performed, but when performing Tensor operation, addition operations relatively increased, but multiplication operations were performed only 7 times. In other words, the number of addition operations increased, but the number of multiplication operations decreased. Since the speed of multiplication operation is considerably slower than that of addition operation, the operation speed when performing Tensor operation can be faster than when performing matrix multiplication operation of A and B. As a result, the operation time when performing Tensor operation can be reduced compared to when performing matrix multiplication operation of A and B.
[0042] The above homomorphic encryption system uses a set polynomial matrix having a smaller number of columns than the number of ciphertexts in the bootstrapping operation process in order to reduce the number of multiplication operations, and only "1", "0", and "-1" can be used as elements of the set polynomial matrix.
[0043] Although (2×2) matrix operations were mentioned above, set polynomial matrices can be used for various matrix operations, such as (3×3) matrix operations.
[0044] Meanwhile, the above-mentioned set polynomial matrix is not an arbitrary matrix, but a matrix that satisfies the condition of producing the same result as the result of a matrix multiplication operation. This set polynomial matrix can be determined in advance before performing the bootstrapping operation.
[0045]
[0046] Below, we will examine the structure of a homomorphic encryption system that performs these operations.
[0047] FIG. 1 is a block diagram illustrating a homomorphic encryption system according to one embodiment of the present invention.
[0048] Referring to FIG. 1, the homomorphic encryption system of the present embodiment may include a polynomial generation unit (100) and a calculation unit (102).
[0049] The polynomial generation unit (100) can generate a set polynomial matrix that can reduce the number of multiplication operations when bootstrapping multiple ciphertexts at once. This set polynomial matrix will be prepared before performing the bootstrapping operation.
[0050] The computation unit (102) can perform a bootstrapping operation by gathering multiple ciphertexts at once to generate new ciphertexts with a small error size. In other words, the computation unit (102) does not perform parallel computations on the ciphertexts.
[0051] However, since a method of operating the above ciphertexts in parallel and applying a tensor operation to the bootstrapping operation process of each ciphertext improves the actual operation speed, the present invention may also include such a method.
[0052] Hereinafter, for the convenience of explanation, the algorithm for reducing the error size will be assumed to be a bootstrapping algorithm, and the above set polynomial matrix will be assumed to be a tensor operation.
[0053] FIG. 2 is a diagram illustrating a process for generating ciphertexts with small error sizes in a homomorphic encryption system according to the first embodiment of the present invention.
[0054] Referring to FIG. 2, the computation unit (102) of the homomorphic encryption system of the present embodiment generates a plurality of ciphertexts (C1 to C L ) When performing a bootstrapping operation by applying a polynomial (dotted line) to each, new ciphertexts can be generated by applying a tensor operation. In this case, although the ciphertexts are bootstrapped in parallel, the operation speed can be improved because a tensor operation, not a simple matrix multiplication operation, is applied during the bootstrapping operation.
[0055] FIG. 3 is a diagram illustrating a process for generating ciphertexts with small error sizes in a homomorphic encryption system according to a second embodiment of the present invention.
[0056] Referring to FIG. 3, the operation unit (102) of the homomorphic encryption system of the present embodiment can perform a bootstrapping operation by gathering L (an integer greater than or equal to 2) ciphertexts at once. To this end, bootstrapping polynomials (a polynomial composed of c and a polynomial composed of b) for the L ciphertexts are used as Tensor operations ( ) can be performed. At this time, the polynomial consisting of b can include information about the secret key, and the set polynomial matrix for the above tensor operation is prepared in advance.
[0057] Figure 3 uses the GINX bootstrapping operation.
[0058] The alphabet of the secret key (a collection of numbers used as elements of the secret key) In other words, in the LWE homomorphic encryption system, the secret key is When you say that, the bootstrapping key is doggy It consists of dogs. Each message is When I said, bk i,j is a ciphertext that encrypts 1 only when j=k, and encrypts 0 for the rest. At this time, the algorithm for applying a set polynomial matrix for tensor operations when bootstrapping L ciphertexts for which bootstrapping is to be performed is as follows.
[0059] [Correction pursuant to Rule 91, October 25, 2024]
[0060] FIG. 4 is a diagram illustrating a process for generating ciphertexts with small error sizes in a homomorphic encryption system according to a third embodiment of the present invention.
[0061] Referring to FIG. 4, the operation unit (102) of the homomorphic encryption system of the present embodiment can perform a bootstrapping operation by gathering L ciphertexts at once. To this end, bootstrapping polynomials (a polynomial composed of c and a polynomial composed of b) for L ciphertexts are used as Tensor operations ( ) can be performed. At this time, the polynomial consisting of b can include information about the secret key, and the set polynomial matrix for the above tensor operation is prepared in advance.
[0062] Figure 4 uses AP bootstrapping operation (Lee's method).
[0063] In the bootstrapping key of the AP bootstrapping series is given as many dimensions as the LWE ciphertext, and each is a message. is being encrypted. In particular, this technique is Lee's bootstrapping technique. From algebra, for N, which is a power of 2, Group for multiplication by collecting only odd numbers inside This becomes the same as the mathematical formula 3 below.
[0064]
[0065] Likewise from algebra middle and There exists an element that satisfies both. Now, any element among such elements Select and define the function in mathematical formula 4 below.
[0066]
[0067] At this time is a discrete logarithm. Now, by utilizing this, we can find the RLWE ciphertext and automorphism key for m(X) using the automorphism algorithm aut. By using It can be defined as an operation that outputs a ciphertext for .
[0068] The algorithm for applying a set polynomial matrix for tensor operations when bootstrapping L ciphertexts is as follows.
[0069] [Correction pursuant to Rule 91, October 25, 2024]
[0070]
[0071] Meanwhile, the components of the aforementioned embodiments can be easily understood from a process perspective. That is, each component can be understood as a separate process. Furthermore, the processes of the aforementioned embodiments can be easily understood from the perspective of the device components.
[0072] In addition, the technical contents described above may be implemented in the form of program commands that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program commands, data files, data structures, etc., alone or in combination. The program commands recorded on the medium may be those specially designed and configured for the embodiments or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. The hardware devices may be configured to operate as one or more software modules to perform the operations of the embodiments, and vice versa.
[0073] The above-described embodiments of the present invention are disclosed for the purpose of illustration, and those skilled in the art with common knowledge of the present invention will be able to make various modifications, changes, and additions within the spirit and scope of the present invention, and such modifications, changes, and additions should be considered to fall within the scope of the following patent claims.
Claims
1. In order to convert multiple ciphertexts into new ciphertexts with a smaller error size, a computation unit is included that performs a polynomial operation on all of the ciphertexts at once for an algorithm that reduces the error size. A homomorphic encryption system, characterized in that the above polynomial has elements corresponding to all of the above ciphertexts.
2. In the first paragraph, the operation unit uses a set polynomial matrix when operating the ciphertexts with the polynomial. A homomorphic encryption system, characterized in that the number of columns of the above set polynomial matrix is smaller than the number of the above ciphertexts, and the elements of the above set polynomial matrix consist only of "1", "0", and "-1".
3. A homomorphic encryption system according to claim 2, wherein the algorithm is a bootstrapping algorithm and the set polynomial matrix is a tensor operation.
4. In the first paragraph, the operation unit uses a set polynomial matrix when operating the ciphertexts with the polynomial. A homomorphic encryption system characterized in that the above calculation unit uses the above set polynomial matrix so that the number of multiplication operations when calculating the above ciphertexts with the above polynomial at once is smaller than the number of multiplication operations when calculating the above algorithm in parallel for each of the above ciphertexts.
5. In the first paragraph, the operation unit uses a set polynomial matrix when operating the ciphertexts with the polynomial. A homomorphic encryption system characterized in that the above calculation unit uses the above set polynomial matrix so that the calculation time corresponding to the multiplication operation and the addition operation when calculating the above ciphertexts with the above polynomial at once using the above set polynomial matrix is smaller than the calculation time corresponding to the multiplication operation and the addition operation when calculating the above algorithm in parallel for each of the above ciphertexts without using the above set polynomial matrix.
6. A homomorphic encryption system according to claim 1, characterized in that the ciphertext is an LWE (Learning with errors) ciphertext, an MLWE (Module LWE) ciphertext, or an RLWE (Ring LWE) ciphertext.
7. Including a computational unit that uses a set of polynomial matrices to apply an algorithm that reduces the error size of the ciphertexts to the ciphertexts in order to convert multiple ciphertexts into new ciphertexts with a smaller error size, A homomorphic encryption system, characterized in that the number of columns of the above set polynomial matrix is smaller than the number of the above ciphertexts, and the elements of the above set polynomial matrix consist only of "1", "0", and "-1".
8. In the 7th paragraph, the operation unit uses the set polynomial matrix so that the number of multiplication operations when using the set polynomial matrix is smaller than the number of multiplication operations when performing the algorithm in parallel for each of the ciphertexts without using the set polynomial matrix. A homomorphic encryption system characterized in that the result obtained by using the above set of polynomial matrices is identical to the result obtained by performing parallel operations on the above algorithm for each of the above ciphertexts.
9. Including a computational unit that uses a set polynomial matrix to apply an algorithm that reduces the error size of the ciphertexts to the ciphertexts in order to convert multiple ciphertexts into new ciphertexts with a smaller error size, A homomorphic encryption system characterized in that the above operation unit uses the above set polynomial matrix so that the operation time corresponding to the multiplication operation and the addition operation when the above set polynomial matrix is used is smaller than the operation time corresponding to the multiplication operation and the addition operation when the above algorithm is operated in parallel for each of the above ciphertexts.
10. A homomorphic encryption system, characterized in that in the 9th paragraph, the number of multiplication operations when the set polynomial matrix is used is smaller than the number of multiplication operations when the algorithm is operated in parallel for each of the ciphertexts without using the set polynomial matrix.
11. Including a computational unit that uses a set of polynomial matrices to apply an algorithm that reduces the error size of the ciphertexts to each of the ciphertexts in order to convert multiple ciphertexts into new ciphertexts with a smaller error size, A homomorphic encryption system characterized in that the number of multiplication operations when using the above set polynomial matrix is smaller than the number of multiplication operations when applying the above algorithm to the corresponding ciphertext without using the above set polynomial matrix.
12. A homomorphic encryption system according to claim 11, wherein the algorithm is a bootstrapping algorithm, and the set polynomial matrix is a polynomial matrix for tensor operation.
13. Step of preparing a set polynomial matrix; and Including a step of using the above set of polynomial matrices in a process of operating an algorithm that reduces the error size of a ciphertext with a plurality of ciphertexts, A method for generating ciphertexts in a homomorphic encryption system, characterized in that the number of multiplication operations performed when the ciphertexts are operated with the algorithm at once using the above set polynomial matrix is smaller than the number of multiplication operations performed when the algorithm is operated in parallel for each of the ciphertexts without using the above set polynomial matrix.
Citation Information
Patent Citations
Beverage water-proof cup holder
KR1020230042172A
Hologram fan for data transmission and management through remote control
KR1020240026555A
Method for transmitting message in a multi-broker environment, apparatus and computer program for performing the method
KR1020250075260A
Apparatus and Method of Cryptographic Processing for Homomorphic Encryption
KR102451633B1