Fully homomorphic encryption based on non-cyclotomic rings

Non-cyclotomic rings are used to enable fully homomorphic encryption, addressing the challenge of supporting both addition and multiplication operations on encrypted data, thereby enhancing data security and privacy in distributed computing environments.

WO2025154060A1PCT designated stage expired Publication Date: 2025-07-24DWALLET LABS LTD

Patent Information

Application Number
PCT/IL2025/050047
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-10-01
Filing Date
2025-01-14
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Conventional methods of fully homomorphic encryption face challenges in efficiently supporting both addition and multiplication operations on encrypted data, particularly in distributed computing environments where data security and privacy are crucial.

Method used

The method employs non-cyclotomic rings to encrypt and decrypt data using a processing circuitry-based approach, utilizing quotient rings and ideals to enable fully homomorphic encryption, allowing computations on encrypted data without decrypting it, and supports both addition and multiplication operations.

Benefits of technology

This approach enhances data security and privacy by enabling computations on encrypted data, facilitating secure operations in cloud computing and privacy-preserving applications like secure voting and confidential machine learning, while maintaining data confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IL2025050047_24072025_PF_FP_ABST
    Figure IL2025050047_24072025_PF_FP_ABST
Patent Text Reader

Abstract

A processor-based method of fully homomorphic encryption, comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:the third non-cyclotomic ring, and a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] FULLY HOMOMORPHIC ENCRYPTION BASED ON NON-CYCLOTOMIC

[0002] RINGS

[0003] TECHNICAL FIELD

[0004] The presently disclosed subject matter relates to data security, and in particular to methods of encryption and decryption.

[0005] BACKGROUND

[0006] Problems of performing fully homomorphic encryption and decryption have been recognized in the conventional art and various techniques have been developed to provide solutions.

[0007] SUMMARY

[0008] According to one aspect of the presently disclosed subject matter there is a processing circuitry (PC)-based method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

[0009] In addition to the above features, the method according to this aspect of the presently disclosed subject matter can comprise one or more of features (i) to (xxii) listed below, in any desired combination or permutation which is technically possible:

[0010] (i) the irreducible non-cyclotomic polynomial is one of: f(x) = xn+ x - b, or f(x) = xn- x + b; and the first ideal is: x-b wherein b is an integer.

[0011] (ii) the method further comprising, prior to the encrypting: encoding a given plaintext, of a given plaintext space, to the element of the first non-cyclotomic ring, the encoding being based on:

[0012] EncodedElement = wherein EncodedElement denotes the element of the first non-cyclotomic ring, Firstldeal denotes the first ideal, and wherein m denotes the given plaintext, and wherein mi is based on: m = and wherein f(b) is equivalent to a size of the given plaintext space.

[0013] (iii) the third non-cyclotomic ring is an order of a field, the field being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial.

[0014] (iv) the third non-cyclotomic ring is a final extension ring of a series of extension rings, the series of extension rings successively extending the fourth non-cyclotomic ring, the series of extension rings being of a given series length, wherein each successive extension ring is based on an equation:

[0015] CurrentNonCyclotomicExtensionRing = PredecessorNonCyclotomicRing[t] / MinimalPolynomial wherein PredecessorNonCyclotomicRing denotes a respective immediately preceding extension ring of the series, t is a respective additional algebraic element, and wherein MinimalPolynomial denotes a respective minimal polynomial, the respective minimal polynomial being based on an equation:

[0016] MinimalPolynomial = wherein Firstldeal denotes the first ideal, and wherein each aj is a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal, n is a respective given integer greater than 1 , and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing[t], and the minimal polynomial is irreducible in PredecessorNonCyclotomicRing.

[0017] (v) the given series length is 1 , and wherein the final extension ring of the series of final extensions rings is based on:

[0018] CurrentN onCyclotomicExtensionRing =

[0019] FourthNonCyclotomicRing[t] / MinimalPolynomial where FourthNonCyclotomicRing denotes the fourth non-cyclotomic ring.

[0020] (vi) the minimal polynomial defining the final extension ring is one of: a. tn + tn + x, or b. tn2- tn + x, or

[0021] C. tn2+ tn + x, or d. tn2- tn + x, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings.

[0022] (vii) the minimal polynomial defining the final extension ring is one of: a. tn2+ tn + btn-l, or b. tn2- tn + btn-l, Or

[0023] C. tn2+ tn - btn-l, Or d. tn2- tn - btn-l, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, and wherein tn-i denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring. (viii) the method further comprising, prior to the encrypting, encoding a given number of plaintexts to an element of the first non-cyclotomic ring, wherein the encoding comprises: a) generating, for each plaintext of the given number of plaintexts, a respective per- plaintext ring element of the first non-cyclotomic ring, the generating being based on:

[0024] PerPlaintextRingElement = wherein PerPlaintextRingElement denotes the element of the first non- cyclotomic ring, and wherein m denotes the given plaintext, and wherein mi is based on: m = and wherein f(b) is equivalent to a size of the given plaintext space; and b) calculating an encoded element based on the formula:

[0025] EncodedElementc0 = wherein EncodedElementc0 denotes the element of the first non-cyclotomic ring, n denotes the given number of plaintexts, PerPlaintextRingElementi denotes a respective per-plaintext ring element, and λidenotes a respective Lagrange coefficient. (ix) the given number of plaintexts is: wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring.

[0026] (x) the encrypting the element of a first non-cyclotomic ring comprises: calculating a linear combination, over the second non-cyclotomic ring of, at least: i. the element of the first non-cyclotomic ring, ii. a sum of, at least: a. a product of, at least, an encryption key and a randomizer, and b. a noise value, the calculating thereby resulting in an element of the second non-cyclotomic ring.

[0027] (xi) the encryption key is an element of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.

[0028] (xii) the encrypting is based on:

[0029] EncryptedElementc0 =

[0030] (PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (Thir dN onCy clotomicRing / S econdldeal) wherein Thir dNonCy clotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer. (xiii) the encrypting is based on:

[0031] EncryptedElementc0 =

[0032] (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

[0033] (xiv) the encrypting is based on:

[0034] EncryptedElementc0 =

[0035] (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue))

[0036] + Randomizer3) mod (ThirdNonCyclotomicRing / Secondldeal) wherein the first ideal and second ideal are principal ideals, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

[0037] (xv) the encrypting is based on:

[0038] EncryptedElementc0 =

[0039] ((PlaintextElement * Secondldeal) +

[0040] ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

[0041] (xvi) the encrypting is based on:

[0042] EncryptedElementc0 =

[0043] (PlaintextElement +

[0044] (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

[0045] (xvii) the encryption key is an element of a module derivative of the second non- cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm. (xviii) the encrypting is based on:

[0046] EncryptedElementc0 =

[0047] (PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (Thir dN onCy clotomicRing / S econdldeal) wherein Thir dNonCy clotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.

[0048] (xix) the encrypting is based on:

[0049] EncryptedElementc0 =

[0050] (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (Thir dNonCy clotomicRing / Secondldeal) wherein Thir dNonCy clotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. (xx) the encrypting is based on:

[0051] EncryptedElementc0 =

[0052] (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue))

[0053] + Randomizer3) mod (ThirdNonCyclotomicRing / Secondldeal) wherein the first ideal and second ideal are principal ideals, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

[0054] (xxi) the encrypting is based on:

[0055] EncryptedElementc0 =

[0056] ((PlaintextElement * Secondldeal) +

[0057] ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

[0058] (xxii) the encrypting is based on:

[0059] EncryptedElementc0 =

[0060] (PlaintextElement +

[0061] (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

[0062] According to another aspect of the presently disclosed subject matter there is provided a system of fully homomorphic encryption, the system comprising a processing circuitry (PC) configured to: encrypt an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

[0063] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xxii) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.

[0064] According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processing circuitry to perform a method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

[0065] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xxii) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.

[0066] (According to another aspect of the presently disclosed subject matter there is a processing circuitry (PC)-based method of decrypting fully homomorphically encrypted data, the method comprising: decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

[0067] In addition to the above features, the method according to this aspect of the presently disclosed subject matter can comprise one or more of features (i) to (xvi) listed below, in any desired combination or permutation which is technically possible:

[0068] (i) the irreducible non-cyclotomic polynomial is one of: f(x) = xn+ x - b, or f(x) = xn- x + b; and the first ideal is: x-b wherein b is an integer.

[0069] (ii) the method further comprising, subsequent to the decrypting: decoding the element of the first non-cyclotomic ring to a plaintext of a given plaintext space.

[0070] (iii) the decoding is based on calculating: felement(b) wherein felement() is a polynomial function corresponding to the element of the first non-cyclotomic ring.

[0071] (iv) the first non-cyclotomic ring is a quotient ring based on a final ring of a series of successive rings extending a fourth non-cyclotomic ring, and wherein the decoding comprises: a) determining one or more roots of a minimal polynomial associated with the first non-cyclotomic ring; b) for each determined root: calculating a result of substituting, in the element of the first non- cyclotomic ring, a respective extending algebraic element with the respective root, thereby generating one or more elements of a quotient ring derivative of a preceding ring of the series; c) responsive to the preceding ring being an extension ring of the fourth non- cyclotomic ring: for each generated element: repeating a) - b); and d) responsive to the preceding ring being the fourth non-cyclotomic ring: calculating, for each generated element felement(); thereby giving rise to one or more plaintexts.

[0072] (v) the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring: a value based on a product of a decryption key and a randomizing element, the decryption key and the randomizing element being elements of the second non-cyclotomic ring, thereby resulting in an element of the first non-cyclotomic ring.

[0073] (vi) the decrypting is based on:

[0074] DecryptedElement = EncryptedElementco - (DecryptionKey * EncryptedElementci) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementci denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.

[0075] (vii) the decryption key is a symmetric key.

[0076] (viii) the decryption key is a private key.

[0077] (ix) the randomizing element is derivative of at least one randomizer.

[0078] (x) the randomizing element is further derivative of at least one constant value. (xi) the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring: a value based on a product of a decryption key and a randomizing element, the decryption key and the randomizing element being elements of a module derivative of the second non-cyclotomic ring,

[0079] (xii) the decrypting is based on:

[0080] DecryptedElement = EncryptedElementco - (DecryptionKey * EncryptedElementci) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementci denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.

[0081] (xiii) the decryption key is a symmetric key.

[0082] (xiv) the decryption key is a private key.

[0083] (xv) The randomizing element is derivative of at least one randomizer.

[0084] (xvi) the randomizing element is further derivative of at least one constant value.

[0085] According to another aspect of the presently disclosed subject matter there is provided a system of decrypting fully homomorphically encrypted data, the system comprising a processing circuitry (PC) configured to: decrypt an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

[0086] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xvi) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.

[0087] According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processing circuitry to perform a method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

[0088] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xvi) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.

[0089] BRIEF DESCRIPTION OF THE DRAWINGS

[0090] In order to understand the invention and to see how it can be carried out in practice, embodiments will be described, by way of non-limiting examples, with reference to the accompanying drawings, in which:

[0091] Fig- 1 illustrates an example deployment of fully-homomorphic encryption / decry ption, in accordance with some embodiments of the presently disclosed subject matter;

[0092] Fig. 2A illustrates a logical block diagram of an example computer system enabled for performance of fully homomorphic encryption (FHE), in accordance with some embodiments of the presently disclosed subject matter;

[0093] Fig. 2B illustrates a logical block diagram of an example deployment of a computer system enabled for decryption of data encrypted using FHE, in accordance with some embodiments of the presently disclosed subject matter;

[0094] Fig. 3 illustrates a flow diagram of an example method of ring-based fully- homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter;

[0095] Fig. 4 illustrates a flow diagram of an example method of module-based fully- homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter; and

[0096] Fig. 5 illustrates a flow diagram of an example method of decrypting data that was encrypted using ring-based or module-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter. DETAILED DESCRIPTION

[0097] In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, it will be understood by those skilled in the art that the presently disclosed subject matter may be practiced without these specific details. In other instances, well-known methods, procedures, components and circuits have not been described in detail so as not to obscure the presently disclosed subject matter.

[0098] Unless specifically stated otherwise, as apparent from the following discussions, it is appreciated that throughout the specification discussions utilizing terms such as "processing", "computing", "comparing", "encrypting", “decrypting”, "determining", "calculating", “receiving”, “providing”, “obtaining”, “emulating” or the like, refer to the action(s) and / or process(es) of a computer that manipulate and / or transform data into other data, said data represented as physical, such as electronic, quantities and / or said data representing the physical objects. The term “computer” should be expansively construed to cover any kind of hardware-based electronic device with data processing capabilities including, by way of non-limiting example, the processor, mitigation unit, and inspection unit therein disclosed in the present application.

[0099] The terms "non-transitory memory" and “non-transitory storage medium” used herein should be expansively construed to cover any volatile or non-volatile computer memory suitable to the presently disclosed subject matter.

[0100] The operations in accordance with the teachings herein may be performed by a computer specially constructed for the desired purposes or by a general-purpose computer specially configured for the desired purpose by a computer program stored in a non- transitory computer-readable storage medium.

[0101] Embodiments of the presently disclosed subject matter are not described with reference to any particular programming language. It will be appreciated that a variety of programming languages may be used to implement the teachings of the presently disclosed subject matter as described herein. Homomorphic encryption is a form of encryption that allows computations to be performed on encrypted data. When mathematical operations are performed on a homomorphically encrypted ciphertext, the result is a ciphertext that, when decrypted, matches the result of identical operations performed on the original plaintext.

[0102] Certain homomorphic encryption schemes allow limited types of operations (e.g. addition or multiplication only). Fully Homomorphic Encryption (FHE) supports both addition and multiplication operations on ciphertexts, making it theoretically possible to perform any computation on encrypted data.

[0103] In distributed computing, homomorphic encryption can be valuable because it allows data to be processed by untrusted third parties without exposing sensitive information. For example, in cloud computing environments, users can offload computations to a cloud server without revealing the underlying data. This is useful in privacy-preserving applications such as secure voting systems, confidential machine learning, and secure data outsourcing. By ensuring that the data remains encrypted throughout the process, homomorphic encryption enhances security and privacy while enabling distributed systems to perform necessary computations.

[0104] Some embodiments of the presently disclosed subject matter are directed to methods of fully-homomorphic encryption and decryption based on non-cyclotomic rings. Some advantages of methods based on non-cyclotomic rings are presented in the additional disclosure section below.

[0105] Fig- 1 illustrates an example deployment of fully-homomorphic encryption / decry ption, in accordance with some embodiments of the presently disclosed subject matter.

[0106] Encryption system 105 can be a computer system adapted to perform encryption in a manner which enables FHE decryption. An example encryption system 105 is described below, with reference to Fig. 2A.

[0107] Communication network 110 can be any kind of suitable network for computer communications (Ethernet, Wi-Fi, 3G wireless network, 4G wireless network, 5G wireless network, Infiniband, etc.). In embodiments, communication network 110 includes a local area network (LAN), a wide area network (WAN), the Internet, and / or one or more Intranets. Communication network 110 can be operably attached to encryption system 105, encrypted calculation system 115, and decryption system 120.

[0108] Encryption calculation system 115 can be a computer system adapted to perform computation on FHE-encrypted data (i.e. without decrypting it first).

[0109] Decryption system 120 can be a computer system adapted to perform FHE decryption. An example encryption system 105 is described below, with reference to Fig. 2B

[0110] In some examples, encryption system 105 can encrypt data using homomorphic encryption in combination with e.g. a public key that is associated with a private key held by decryption system 120. Encryption system 105 can e.g. transmit the encrypted data to encrypted calculations system 115, which performs mathematical operations based on the encrypted data. Encrypted calculations system 115 can transmit the results of the mathematical operations to decryption system 120, which can then decrypt the encrypted results of the mathematical operations e.g. using its private key.

[0111] Fig. 2A illustrates a logical block diagram of an example computer system enabled for performance of fully homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.

[0112] Encryption system (processing circuitry) 200A can include processor 205A and memory 210 A.

[0113] Processor 205A can be a suitable hardware-based electronic device with data processing capabilities, such as, for example, a general purpose processor, digital signal processor (DSP), a specialized Application Specific Integrated Circuit (ASIC), one or more cores in a multicore processor, etc. Processor 205A can also consist, for example, of multiple processors, multiple ASICs, virtual processors, combinations thereof etc.

[0114] Memory 210A can be, for example, a suitable kind of volatile and / or non-volatile storage, and can include, for example, a single physical memory component or a plurality of physical memory components. Memory 210A can also include virtual memory. Memory 210A can be configured to, for example, store various data used in computation.

[0115] Encryption system (processing circuitry) 200A can be configured to execute several functional modules in accordance with computer-readable instructions implemented on a non-transitory computer-readable storage medium. Such functional modules are referred to hereinafter as comprised in the processing circuitry. These modules can include, for example, communications unit 215A, optional ring-based encryption unit 220A, optional module-based encryption unit 225A, and optional encoding unit 230A. The functional modules may include hardware modules, software modules, firmware modules, or combinations thereof. In some embodiments, the operations described with reference to one or more of the communications unit 215A, optional ring-based encryption unit 220A, optional module-based encryption unit 225A, and optional encoding unit 230A may be combined into fewer units. In some embodiments, the operations described with reference to one or more of the communications unit 215A, optional ring-based encryption unit 220A, optional module- based encryption unit 225A, and optional encoding unit 230A may be split up and handled by separate units.

[0116] Communications unit 215A can be any suitable component usable for communicating via communication network 110 (ethernet controller, wi-fi controller etc.). Communications unit 215A can facilitate e.g. reception of data for encryption and / or transmission of encrypted data.

[0117] Optional ring-based encryption unit 220A can encrypt data using a ring-based fully homomorphic encryption method as detailed herein.

[0118] Some embodiments of the presently disclosed subject matter utilize a plaintext ring which is a quotient ring of a non-cyclotomic ring (termed R) and an Ideal (termed I). Such a plaintext ring (herein termed “P”) can be described formally as:

[0119] P = R / I where R is a ring such that: R=Z[x] / f()

[0120] Where:

[0121] Z[x] denotes the set of all polynomials with integer coefficients (and for which the operations of addition and multiplication are defined as polynomial addition and multiplication), f() is an irreducible non-cyclotomic polynomial and the ideal I is a non-trivial ideal of the ring R (i.e. a proper subset of R satisfying additive closure and absorption, as known in the art).

[0122] Some embodiments of the presently disclosed subject matter utilize a ciphertext ring which is a quotient ring of the non-cyclotomic ring R and a second ideal herein termed Q (which is distinct from I). Such a ciphertext ring (herein termed “C”) can be described formally as:

[0123] C = R / Q

[0124] In some embodiments, the plaintext ring and ciphertext ring are based on the following definitions:

[0125] The irreducible non-cyclotomic polynomial from which the non- cyclotomic ring R is derived is: f(x) = xn + x - b for some degree n, and the Ideal of the non-cyclotomic ring is: x-b where b is an integer.

[0126] In some other embodiments, the plaintext ring and ciphertext ring are based on the following definitions: The irreducible non-cyclotomic polynomial from which the non- cycl otomic ring R is derived is: f(x) = xn + x + b for some degree n, and the Ideal of the non-cyclotomic ring is: x-b where b is an integer.

[0127] In some other embodiments, the plaintext ring and ciphertext ring are based on other specifications of f() and I.

[0128] Some embodiments of the presently disclosed subject matter are directed to methods of encrypting an element of a non-cyclotomic plaintext ring to an element of a non-cyclotomic ciphertext ring.

[0129] These methods can employ a e.g. symmetric encryption key or a public key / private key scheme. These methods can also employ one or more randomizers and / or constant values. These methods can also employ noise values.

[0130] To facilitate subsequent homomorphic mathematical operations as well as decryption / recons traction of plaintexts, some embodiments utilize a pair of ciphertext ring elements which can be transmitted together.

[0131] In some examples herein, this pair of elements making up a ciphertext are described as two elements in parentheses, e.g.

[0132] (co, Cl) where co identifies a ciphertext ring element that is derivative of an encryption operation utilizing e.g. a plaintext element, an encryption key and other parameters, and where ci is a ciphertext ring element that is derivative of e.g. randomizers and / or noise values and / or constant values and / or other parameters. In some examples herein, the pair of elements making up a ciphertext are described using the terms EncryptedElementc0 and EncryptedElementci to refer to the respective elements. In some cases herein, EncryptedElementci is referred to as a “randomizing element”.

[0133] Ring-based encryption unit 220A can, for example, utilize methods such as the methods described below with reference to Fig. 3.

[0134] Optional module-based encryption unit 225A can encrypt data using a module- based fully homomorphic encryption method.

[0135] A module over a ring R is a generalization of a vector space, where the scalars come from a ring rather than a field.

[0136] Some embodiments of the presently disclosed subject matter are directed to encryption / decry ption methods which utilize modules as randomizing elements.

[0137] In such embodiments, the second element (i.e. ci) of the (co, ci) ciphertext (i.e. EncryptedElementci) is a module.

[0138] Module-based encryption can have desirable security properties, as detailed below.

[0139] Module-based encryption unit 225A can, for example, utilize methods such as the methods described below with reference to Fig. 4.

[0140] Optional encoding unit 230A can encode data (e.g. integers, binary data) to elements of a plaintext ring to facilitate encryption. Optional encoding unit 230A can utilize encoding methods as described below with reference to Fig. 3.

[0141] It is noted that encryption system (processing circuitry) 200A can additionally implement some or all of the functions of encryption system (processing circuitry) 200B.

[0142] Fig. 2B illustrates a logical block diagram of an example deployment of a computer system enabled for decryption of data encrypted using FHE, in accordance with some embodiments of the presently disclosed subject matter. Decryption system (processing circuitry) 200B can include processor 205B and memory 210B.

[0143] Processor 205B can be a suitable hardware-based electronic device with data processing capabilities, such as, for example, a general purpose processor, digital signal processor (DSP), a specialized Application Specific Integrated Circuit (ASIC), one or more cores in a multicore processor, etc. Processor 205B can also consist, for example, of multiple processors, multiple ASICs, virtual processors, combinations thereof etc.

[0144] Memory 210B can be, for example, a suitable kind of volatile and / or non-volatile storage, and can include, for example, a single physical memory component or a plurality of physical memory components. Memory 210B can also include virtual memory. Memory 210B can be configured to, for example, store various data used in computation.

[0145] Decryption system (processing circuitry) 200B can be configured to execute several functional modules in accordance with computer-readable instructions implemented on a non-transitory computer-readable storage medium. Such functional modules are referred to hereinafter as comprised in the processing circuitry. These modules can include, for example, communications unit 215B, decryption unit 220B, and optional decoding unit 225B.

[0146] Decryption unit 220B can receive ciphertexts (e.g. ring-based or module-based) and can decrypt them to e.g. plaintext ring elements unit 220B can do this, for example, utilizing methods such as the methods described below with reference to Fig. 5.

[0147] Decoding unit 225B can then decode decrypted plaintext ring elements unit to e.g. integer or binary data. Decoding unit 225B can utilize, for example methods such as those described below with reference to Fig. 5.

[0148] Attention is directed to Fig. 3, which illustrates a flow diagram of an example method of ring-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter. Optionally: in some examples, it is desirable to perform fully homomorphic encryption (and possibly subsequent encrypted mathematical operations) upon plaintexts consisting of integers, binary data etc.

[0149] To accomplish this, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode (305) such a plaintext. More specifically: encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can map the plaintext to an element of a plaintext ring (e.g. a plaintext ring in accordance with the plaintext ring definition provided above), so as to facilitate performing fully homomorphic encryption on the plaintext ring element.

[0150] In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes a single plaintext to a single element of the plaintext ring. In some other examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes multiple plaintexts to a single plaintext ring element.

[0151] In some examples, a plaintext consists of a series of binary digits of a plaintext space of given size. For example: a binary plaintext can be of length 8 (i.e. the plaintext size is 256). In such embodiments, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode the plaintext to a polynomial element of the plaintext ring (the ring being defined by a polynomial f() ) based on the formula:

[0152] EncodedElement = wherein m denotes the given plaintext, and wherein mi is based on: m = and where f(b) is equivalent to the size of the plaintext space, and LogbQ denotes the logarithm in base b.

[0153] Accordingly, when the value of b is 2 (i.e. the first Ideal is x-2): where m denotes the given plaintext, and wherein mi is based on:

[0154] It is noted that in the formula above (i.e. with b = 2), the indexes of the polynomial terms are identical to the binary digits of the plaintext.

[0155] In some embodiments, multiple plaintexts can be encoded in a single plaintext ring element for encryption.

[0156] In such embodiments, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can utilize a special case of the non-cyclotomic ring R from which the plaintext ring and ciphertext ring are derived. Specifically, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can utilize a non-cyclotomic ring R that is an order of a field, the field in turn being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial.

[0157] In some such embodiments, this ring can be a final ring of a recursive series of extension rings of the fourth non-cyclotomic ring for which: the irreducible non-cyclotomic polynomial f(x) is either xn+ x - b or xn- x + b, and the first ideal (where the plaintext ring is derived by taking the quotient of the fourth non-cyclotomic ring R and the first ideal) is x-b where b is some integer.

[0158] For example, the first extension ring of the fourth non-cyclotomic ring can be based on:

[0159] FourthNonCyclotomicRing[t] / MinimalPolynomial where t is an algebraic element being added to the fourth non-cyclotomic ring, and where the minimal polynomial can be based on: and wherein c(t) and d(t) are polynomials in FourthNonCyclotomicRing[t], and the minimal polynomial is irreducible in the fourth non-cyclotomic ring. In some embodiments, n is an integer greater than one that defines the degree of the minimal polynomial (and determines the number of plaintext slots that will be available). Each aj can be a unique element of a ring that is a quotient of the fourth non-cyclotomic ring and the first ideal.

[0160] Similarly, subsequent extension rings can be based on:

[0161] PredecessorNonCyclotomicRing[ti] / MinimalPolynomial wherein PredecessorNonCyclotomicRing denotes the immediately preceding extension ring of the series, and ti is a respective additional algebraic element being added in this extension.

[0162] In this case, the minimal polynomial of the extension can again be based on: and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing [t], and the minimal polynomial is irreducible in the fourth non-cyclotomic ring, n is an integer greater than one that defines the degree of the minimal polynomial (and determines the number of plaintext slots that will be available). Each aj can be a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal. In some embodiments, n is an integer greater than one that defines the degree of this particular minimal polynomial.

[0163] The series of recursive extensions of the fourth non-cyclotomic ring can have a particular series length (e.g. 5).

[0164] The number of plaintext slots available in an element of the final extension ring of the series of extension rings can then be: wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring.

[0165] In some embodiments, the minimal polynomial defining the final extension ring of the series of extension rings is one of: a) tn2+ tn+ x, or b) tn2- tn + x, or c) tn2+ tn + x, or d) tn2- tn + x, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings.

[0166] In some embodiments, the minimal polynomial defining the final extension ring is one of: a) tn2+ tn + btn-1, or b) tn2- tn + btn-1, Or c) tn2+ tn - btn-1, Or d) tn2- tn - btn-1, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, and wherein tn-i denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring.

[0167] Encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode a given number of plaintexts to a single ring element of the plaintext ring that is the quotient of the final extension ring and the first ideal.

[0168] In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes a number of plaintexts that is equivalent to the number of plaintext slots available in each ring element (as given by the formula above). In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230 A) encodes a number of plaintexts that is less than the number of plaintext slots available, and utilizes other values (e.g. 0) in the unused slots.

[0169] Encryption system (processing circuitry) 200 A (e.g. encoding unit 230 A) can encode the plurality of plaintexts based on the following steps: a) generating, for each plaintext of the given number of plaintexts, a respective per- plaintext ring element of the plaintext ring, the generating being based on:

[0170] PerPlaintextRingElement = wherein PerPlaintextRingElement denotes the element of the plaintext ring, and wherein m denotes the given plaintext, and wherein mi is based on: m = and wherein f(b) is equivalent to a size of the given plaintext space; and b) calculating an encoded element based on the formula:

[0171] EncodedElementc0 = wherein EncodedElementc0 denotes the element of the plaintext ring, n denotes the given number of plaintexts, PerPlaintextRingElementi denotes a respective per- plaintext ring element, and λidenotes a respective Lagrange coefficient.

[0172] It is noted that this encoding method can be utilized to encode plaintexts to rings other than the rings defined herein. Similarly, it is noted that this encoding method can be utilized in the context of other applications (e.g. other encryption applications, non- encryption applications).

[0173] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can obtain (310) an encryption key. In some examples, the encryption key is received or derived from a secure key exchange mechanism. In some examples, the encryption key is an element of the ciphertext ring. . In some examples, the encryption key is an element of an algebraic structure (e.g. a module) that is derivative of the ciphertext ring.

[0174] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally obtain one or more randomizer. A randomizer can be a random value (with suitable distribution characteristics as described herein), that is used in the encryption to enhance security. In some examples, randomizers are obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use a randomizer. Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally obtain one or more noise values. Noise values can be a random value (with suitable distribution characteristics as described herein), that are used in homomorphic encryption to enhance security. In some examples, the noise values is obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use noise values.

[0175] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can next encrypt (315) an element of the plaintext ring to an element of the ciphertext ring.

[0176] In some embodiments, encryption system (processing circuitry) 200A (e.g. ring- based encryption unit 220A) performs the encryption by calculating a linear combination, over the ciphertext ring of, at least: the element of the plaintext ring to be encrypted, and a sum of, at least:

[0177] (i) a product of, at least, an encryption key and a randomizer, and

[0178] (ii) a noise value where the encryption key is an element of the ciphertext ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.

[0179] In some such embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a symmetric encryption key, e.g. in accordance with the formula:

[0180] EncryptedElementc0 =

[0181] (PlaintextElement + (Randomizer * EncryptionKey + NoiseValue)) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the plaintext ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the plaintext ring, EncryptionKey is the encryption key (i.e. an element of the ciphertext ring), NoiseValue is a noise value is sampled from the first ideal, and Randomizer is sampled from a distribution over a ring with a bounded expected norm.

[0182] In this case the associated randomizing element (e.g. for use in decryption) can be defined in accordance with the formula:

[0183] EncryptedElementc! =

[0184] (Randomizer) mod (ThirdNonCyclotomicRing / Secondldeal)

[0185] It is noted that in this case EncryptedElementco is a linear combination of the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.

[0186] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, e.g. in accordance with the formula:

[0187] EncryptedElementc0 =

[0188] (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / Secondldeal) where ConstantValue is a constant that is an element of the ciphertext ring, and Randomizer3 is sampled from distributions over respective rings with bounded expected norms.

[0189] In this case the associated randomizing element can be defined in accordance with the formula:

[0190] EncryptedElementci = ((Randomizer * ConstantValue)' + Randomizer2) mod (ThirdNonCyclotomicRing / Secondldeal) where Randomizer2 is sampled from a distribution over a ring with a bounded expected norm.

[0191] It is noted that here also EncryptedElementco is a linear combination of, at least, the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.

[0192] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal and second ideal are principal ideals, _in accordance the following formula:

[0193] EncryptedElementc0 =

[0194] In this case the associated randomizing element can be defined in accordance with the formula:

[0195] EncryptedElementci = ((Randomizerl * ConstantValue)' + Randomizer2) mod (ThirdNonCyclotomicRing / Secondldeal)

[0196] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal is not a principal ideal, and the second ideal is a principal ideal, _in accordance the following formula:

[0197] EncryptedElementc0 =

[0198] ( (PlaintextElement * Secondldeal) + ((Randomizerl * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )

[0199] In this case the associated randomizing element can be defined in accordance with the formula:

[0200] EncryptedElementci = ((Randomizerl * ConstantValue)' + Randomizer2) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )

[0201] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the element of the plaintext ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, _in accordance the following formula:

[0202] EncryptedElementc0 =

[0203] (PlaintextElement + ((Randomizerl * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )

[0204] In this case the associated randomizing element can be defined in accordance with the formula:

[0205] EncryptedElementci = ((Randomizerl * ConstantValue) + Randomizer2) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )

[0206] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally store (320) data derivative of the randomizer(s) and / or constant value, for use in decryption. For example: encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can compute EncryptedElementci according to formulas given above. Atention is directed to Fig. 4, which illustrates a flow diagram of an example method of module-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject mater.

[0207] As in the case of ring-based encryption, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode (405) a plaintext to the plaintext ring. Encryption system (processing circuitry) 200A (e.g. encoding unit 230 A) can optionally utilize encoding methods as described with reference to Fig. 3 above.

[0208] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can obtain (410) an encryption key. In some examples, the encryption key is received or derived from a secure key exchange mechanism. In some examples, the encryption key is an element of a module that is derivative of the ciphertext module.

[0209] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally obtain one or more randomizer. A randomizer can be a random value (with suitable distribution characteristics as described herein), that is used in the encryption to enhance security. In some examples, randomizers are obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use a randomizer.

[0210] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally obtain one or more noise values. Noise values can be a random value (with suitable distribution characteristics as described herein), that are used in homomorphic encryption to enhance security. In some examples, the noise values is obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use noise values.

[0211] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can then encrypt (415) an element of the plaintext ring to an element of the ciphertext ring, utilizing an encryption key that is an element of a module that is derivative of the ciphertext ring, as known in the art. In some embodiments, encryption system (processing circuitry) 200A (e.g. ring- based encryption unit 220A) performs the encryption by calculating a linear combination, over the ciphertext ring of, at least: the element of the plaintext ring to be encrypted, and a sum of, at least:

[0212] (i) a product of, at least, an encryption key and a randomizer, and

[0213] (ii) a noise value where the encryption key is an element of a module derived from the ciphertext ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm.

[0214] In some such embodiments, encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can perform encryption using a symmetric encryption key, e.g. in accordance with the formula:

[0215] EncryptedElementc0 =

[0216] (PlaintextElement + (Randomizer * EncryptionKey + NoiseValue)) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the plaintext ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the plaintext ring, EncryptionKey is the encryption key, NoiseValue is a noise value is sampled from the first ideal, and Randomizer is the randomizer.

[0217] In this case the associated randomizing element (e.g. for use in decryption) can be defined in accordance with the formula:

[0218] EncryptedElementc! =

[0219] (Randomizer) mod (ThirdNonCyclotomicRing / Secondldeal) It is noted that in this case EncryptedElementco is a linear combination of the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.

[0220] In some other embodiments, encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can perform encryption using a public / private encryption key pair, e.g. in accordance with the formula:

[0221] EncryptedElementc0 =

[0222] (PlaintextElement + ((Randomizer 1 * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / Secondldeal) where ConstantValue is a constant that is an element of a module derivative of the ciphertext ring, Randomizerl and Randomizer2 are sampled from distributions over respective modules with bounded expected norms, and Randomizer3 is sampled from a distribution over a ring with a bounded expected norm

[0223] In this case the associated randomizing element can be defined in accordance with the formula:

[0224] EncryptedElementci = ((Randomizerl * ConstantValue)' + Randomizer2) mod (ThirdNonCyclotomicRing / Secondldeal)

[0225] It is noted that here also EncryptedElementc0 is a linear combination of, at least, the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.

[0226] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal and second ideal are principal ideals, _in accordance the following formula:

[0227] EncryptedElementc0 =

[0228] In this case the associated randomizing element can be defined in accordance with the formula:

[0229] EncryptedElementci = ((Randomizerl * ConstantValue)' + Randomizer2) mod (ThirdNonCyclotomicRing / Secondldeal)

[0230] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal is not a principal ideal, and the second ideal is a principal ideal, in accordance the following formula:

[0231] EncryptedElementc0 =

[0232] ( (PlaintextElement * Secondldeal) + ((Randomizerl * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / (Secondldeal * FirstIdeal) )

[0233] In this case the associated randomizing element can be defined in accordance with the formula:

[0234] EncryptedElementci = ((Randomizerl * ConstantValue)' + Randomizer2) mod (ThirdNonCyclotomicRing / (Secondldeal * FirstIdeal) )

[0235] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the element of the plaintext ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, in accordance the following formula:

[0236] EncryptedElementc0 =

[0237] (PlaintextElement + ((Randomizerl * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )

[0238] In this case the associated randomizing element can be defined in accordance with the formula:

[0239] EncryptedElementci = ((Randomizerl * ConstantValue) + Randomizer2) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )

[0240] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally store (420) data derivative of the randomizer(s) and / or constant value, for use in decryption. For example: encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can compute EncryptedElementci according to formulas given above.

[0241] Attention is directed to Fig. 5, which illustrates a flow diagram of an example method of decrypting data that was encrypted using ring-based or module-based fully - homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.

[0242] Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain (505) a decryption key corresponding to the encryption key used to encrypt the ciphertext ring element to be decrypted. A decryption key can be e.g. a symmetric key, or a private key of a public / private key pair. In some examples, the decryption key can be received or derived as part of a key distribution protocol. The ecryption key can be, for example a ciphertext ring element, or an element of an algebraic structure (e.g. a module or other algebraic structure) that is derivative of the ciphertext ring. Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain data derivative of any randomizer s / constants used in encryption. In some examples, decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can simply obtain the randomizers and / or constants. In other examples, decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain a randomizing element that is derivative of the randomizers and / or constants (as described above with reference to encryption methods). Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can utilize the randomizing elements in decryption, as described below.

[0243] Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can decrypt (510) an element of the ciphertext ring to an element of the plaintext ring.

[0244] In some embodiments, decryption system (processing circuitry) 200B (e.g. encryption unit 220B) performs the decryption by a method comprising: subtracting, from the element of the second non-cyclotomic ring, a value based on a product of a decryption key and a randomizing element.

[0245] In some such embodiments, the decryption key and the randomizing element are elements of the ciphertext ring. In some other embodiments, the decryption key and the randomizing element are elements of the module derived from the ciphertext ring, as known in the art.

[0246] More formally: considering a case where an encryption procedure generated the encrypted element (EncryptedElementco, EncryptedElementci), the decrypting can be performed based on the following formula:

[0247] DecryptedElement = EncryptedElementc0 - (DecryptionKey * EncryptedElementci) mod (ThirdNonCyclotomicRing / Secondldeal) where ThirdNonCyclotomicRing denotes the non-cyclotomic ring R, Secondldeal denotes the second ideal of R (termed Q), DecryptedElement denotes the resulting element of the plaintext ring, and DecryptionKey denotes the decryption key. In some embodiments, the decryption key is symmetric (i.e. is the same as the encryption key). In some other embodiments, the decryption key is a private key i.e. a non-public key that corresponds to a public key that was utilized in the encryption operation that generated the element of the ciphertext ring.

[0248] In some embodiments, the randomizing element EncryptedElementci is identical with a randomizer that was multiplied by the encryption key in the encryption operation.

[0249] In some embodiments, the randomizing element EncryptedElementci is derivative of a randomizer that was multiplied by the encryption key in the encryption operation, and is further derivative of - for example - one or more additional randomizers and / or constant values and / or other parameters.

[0250] Decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can decode (515) the plaintext ring element to plaintext data (e.g. binary data).

[0251] In some embodiments, when parameter b is 2, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can map an element of the plaintext ring to a plaintext by calculating: felement(2) where feiement () is the plaintext ring element (i.e. a polynomial) resulting from the decoding. It is noted that this decoding method is the inverse of the encoding method which maps plaintext bits to coefficients of polynomial terms (as described above).

[0252] As described in detail above, a single plaintext ring element can, in some examples, be an encoding of multiple plaintexts.

[0253] Accordingly, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can perform decoding on the plaintext ring element, thereby generating multiple plaintexts.

[0254] In some examples, the plaintext ring element is a quotient ring of: a final ring of a series of extension rings, and a non-trivial ideal of the final ring.

[0255] It is noted that, as described in detail above each extension ring can be defined as: PredecessorNonCyclotomicRing[t] / MinimalPolynomial where t is an algebraic element being added to the predecessor ring (i.e. to extend it), and where the minimal polynomial can be:

[0256] To decode an element of a quotient ring derivative of an extended ring thus defined, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can generate, from the ring element, one or more ring elements of a quotient ring derivative of the immediately preceding extension ring in the series.

[0257] To generate the one or more ring elements of the quotient ring based on the immediately preceding ring, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can: a) determine the roots of the minimal polynomial associated with the ring of the encoded ring element. These can be identical with the aj values in the definition of the minimal polynomial. b) for each determined root aj: calculate a result of substituting, in the encoded ring element, the respective extending algebraic element (i.e. t) with the constant value aj, thereby generating one or more elements of a quotient ring based on the preceding ring of the series (i.e. generating a quotient ring element for each determined aj).

[0258] If the preceding ring is also an extension ring, then decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can then repeat steps a) -b) on this next ring.

[0259] If the preceding ring is a non-cyclotomic ring based on either xn+ x - b or xn- x + b, with the ideal being x-b (for some integer b) - i.e. not an extension of such a ring, then decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can calculate, for each generated element felement(); felement(b) thereby resulting in one or more plaintexts.

[0260] It is noted that this decoding method can be utilized to decode from rings other than the rings defined herein. It is similarly noted that this decoding method can be utilized in the context of other applications (e.g. other decryption applications, non- decryption applications).

[0261] It is noted that sections appearing hereinbelow describe addtional embodiments, and are part of the detailed description, and that any headings included therein are for ease of reference only.

[0262] We present a fully homomorphic encryption scheme which natively supports arithmetic and logical operations over “machine words” , namely plaintexts of the form W" (e.g. n = 64). Our scheme builds on the well-known BGV framework, but deviates in the selection of number field a nd i n t he e ncoding o f m essages. T his a Hows u s t o s upport large message spaces efficiently wi thout re sorting to ba telling. In deed, each ciphertext in our scheme efficiently en codes a si ngle me ssage fr om the message space.

[0263] Arithmetic operations (modulo 2n) are supported natively similarly to BGV-style FHE schemes, and we present an efficient bootstrapping pro- cedure for our scheme. Our bootstrapping algorithm has the feature that along the way it decomposes our machine word into bits, so that during bootstrapping it is possible to perform logical operations (essentially ad- dressing each bit in the message independently). This means that during a single bootstrapping cycle we can perform logical operations on n bits. For example, a “greater than” operation (if x > y output 1, otherwise output 0), only requires a single subtraction and a single bootstrapping cycle.

[0264] Along the way we present a number of new tools and techniques, such as a generalization of the BGV modulus switching to a setting where the plaintext and ciphertext moduli are ideals (and not numbers).

[0265] 1 Introduction

[0266] Fully homomorphic encryption (FHE) [RAD‘f78, Gen09a] allows us to compute on encrypted data without decrypting it first a nd w ithout a ny k nowledge of the secret key. This makes it a prominent privacy enhancing technology with numerous potential applications [GH19, CJP21], Whereas there is ample moti- vation for using FHE in the real world, its utilization in practice is hindered by the overhead it incurs in computation and in storage. More explicitly, the re- sources, say in running time, required to run a computation over encrypted data may be orders of magnitude longer than running the same computation in the clear. Narrowing this gap to a tolerable level has been a major research direction of the FHE community for over a decade, and indeed some success has recently been reported, notably the recent announcement of the integration of Swift FHE into Apple devices as a part of iOS 18 [BTR24] . However the overhead remains prohibitive (or at least quite restrictive) for many desirable applications.

[0267] There are two main paradigms in the literature for practically-oriented FHE candidates. Both rely on structure related to the Learning with Errors (LWE) [Reg05] and Ring Learning with Errors (RLWE) [LPR13a] , as put forth in [BV11b,BA11a,GS 13]. The first is a more direct extension [BV1 lb, B V11 a] and is utilized in the BGV, B / FV, CKKS schemes [BGV12, Bral2, FV12, CKKS17] and their successors, and is of a more arithmetic nature. We therefore refer to these as arithmetic schemes. Software libraries that take this approach in- clude [HS20, SEA11, CKKS16]. The second follows the paradigm of [GSW13, DM14, GGGI20] and is more native for boolean operations, and we therefore refer to them as boolean schemes. Software libraries that take this approach include [Zam21, tfh! 7]. Let us discuss these approaches in slightly more detail below.

[0268] Arithmetic Schemes. These schemes natively support arithmetic operations over some plaintext modulus p. In BGV and B / FV the operations are carried out exactly over a discrete ring, whereas in CKKS, they are real valued and noisy, but they are all natively arithmetic. When implemented naively, this approach leads to exorbitant information overhead. Namely to very large ciphertexts that encrypt a small amount of data. This is partly mitigated by the use of batching: the ability to encrypt multiple plaintexts in parallel “slots” in the same cipher- text, and apply operations on them in parallel. Batching reduces the amortized overhead, both in terms of storage and in terms of computation, since an oper- ation on the ciphertext corresponds to operations on many plaintexts.

[0269] Importantly, batching uses algebraic properties of the RLWE problem, and in particular requires a specific relation between p and the number field over which the scheme is defined. In particular this means that the strongest form of batching requires p which is an odd prime with some specific structure. There are techniques in the literature that allow to trade off the “amount of batching” with the form of the modulus [GHS12, HS21], These techniques use field extensions to produce plaintext spaces of the form GF(pd). Thus it is possible to batch finite- field elements of size, e.g., 264, but it is not possible to properly batch plaintexts from the ring We are not aware of solutions that allow batching for message spaces such as those targeted in this work, namely for a large p, specifically for p being a power of 2.

[0270] Either way, batching requires both aggregation of a large amount of data per ciphertext and the ability to split this large amount of data into small amounts (to fit in each slot) in such a way that per-slot homomorphic operations remain useful. This is simply not the case when we wish to work with large integers, which is how many modern computer systems operate.

[0271] As in all known approaches for FHE, if one wishes to compute functionali- ties with a-priori unbounded depth, then a bootstrapping operation needs to be executed periodically. Bootstrapping [Geo09b] reduces the “noise component” that exists in all known FHE candidates. The noise grows with every homo- morphic operation, and must be kept below a certain threshold to maintain the correctness of the scheme. Bootstrapping, therefore, is the process that allows to reduce the noise level so that additional homomorphic operations can be carried out. Bootstrapping essentially requires to apply the decryption algorithm ho- momorphically over the ciphertext. This requires applying operations that are not “natively” arithmetic, such as rounding or truncation of least significant bits. Therefore, whereas bootstrapping is heavy on resources in all known FHE instantiations, arithmetic schemes generally struggle with bootstrapping more than boolean ones. This is likewise the case for any non- arithmetic operation, in particular boolean operations like “greater than” are challenging to implement.

[0272] Boolean Schemes. In these schemes, each ciphertext essentially encrypts a single bit. It is possible to pack multiple ciphertexts into a more compact repre- sentation, and various optimizations have been introduced in [DM14, CGGI20], but homomorphic operations are still performed at the bit level. This allows to perform logical operations natively. A particularly successful approach is taken by the TFHE scheme [CGGI20]. This proposed a way to perform the bootstrap- ping operation very efficiently, and therefore elect to perform bootstrapping after (or rather, as a part of) every operation. This framework makes it harder to work with data types that are naturally composed of multiple bits, such as number modulo p. In boolean schemes, one needs to represent large numbers as a se- quence of bits and apply the appropriate boolean circuits to perform operations like addition and multiplication. This is possible, and indeed works naturally even for moduli of the form 2", but requires a large number of bootstrapping operations even for the simplest of operations (e.g. adding two n bit numbers as integers modulo n). We note that boolean schemes are very convenient for logical operations, e.g. “if” statements. For example, boolean comparison between two numbers, i.e. the predicate a > b, can be computed as easily as the difference a — b. Note that this is not the case for arithmetic schemes.

[0273] The Challenge: Arithmetic-Logic Unit for Machine Words. Our goal when using FHE is to be able to take existing code and covert it into running homomrophically with as little change as possible. Indeed, our algorithms and data types should remain oblivious to our choice of privacy preserving technique. We may therefore put forth the task of constructing a homomorphic framework that natively supports the “standard” operations of computer programs. In par- ticular, this includes arithmetics over integers modulo 2”, since integer data types in most architectures are of this form. At the same time we wish to be able to execute conditional statements, and apply logical operations on the bits of our numbers.1Indeed, the “slogan” for our goal is to implement an “Arith- metic Logic Unit” (ALU) inspired by such components that exist in CPUs. Such a unit would support arithmetics modulo 2", as well as logical operations at the bit level.

[0274] We note that both aforementioned approaches are universal (a.k.a Turing complete) and therefore allow in principle to implement an ALU. However, when concrete efficiency is concerned, if the native representation is only arithmetic or only boolean, then a change of representation will be required for some op- erations, which is usually prohibitive in terms of resources. This work therefore focuses on the following question.

[0275] Is it possible to design an FHE scheme that natively supports arithmetics modulo and supports boolean operations as well?

[0276] 1We are not considering float-point operations at this point. 1.1 Our Contribution — FHE for Arithmetic and Logical Operations

[0277] We present a number of novel ideas that allow us to break from the existing paradigm and present a fully homomorphic encryption scheme with new capa- bilities. We first show how to construct a BGV-style scheme with native support for arithmetics over while not incurring the penalty that is usually associ- ated with such plaintexts in “legacy” BGV. We then present a bootstrapping algorithm for our scheme which not only performs the “standard” bootstrap- ping features of reducing the noise in the ciphertext, but also, along them way, provides us access to the n individual bits in the binary representation of our message. This allows us, in the course of bootstrapping, to perform logical operations natively. Thus achieving both arithmetic and boolean logic without additional overhead.

[0278] For the first part, we construct an encryption scheme whose native plain- text space is Z2„ (where n is a parameter). We show that arithmetic homo- morphic operations (addition, multiplication) over this plaintext space can be performed essentially the same as in BGV-style FHE. However, the parameters of the scheme and noise scaling are comparable to BGV with plaintext {0, 1}. This is a crucial difference since prior to this work, a plaintext space of Z2„ meant an additional factor of 2ndin the noise, when evaluating a depth d arithmetic circuit. In contrast, in our scheme the growth would be roughly n()!di. which as explained above is comparable to binary plaintext. This has a cascading effect on all parameters of the scheme, since mild noise growth allows to reduce the so-called “noise ratio” of the underlying algebraic LWE problem, which in turn upgrades the security level of the scheme, which then allows to reduce the size of other parameters and maintain the same security level as previous schemes. As a result, we can instantiate our scheme with very large plaintext spaces that were previously prohibitive, with only minimal loss in performance. We note that we did not explore the possibility of batching in our scheme, so we only consider the setting of a single message per ciphertext. However, it may be possible to incorporate batching into our framework as well.

[0279] This is achieved by examining the properties of the BGV scheme in the algebraic setting (i.e. when it is based on structures stemming from the RLWE assumption and similar ones). We notice that, under the hood, BGV encryption can seemlessly be made to support any message space that is defined by an ideal in the ring where the scheme is defined (the ring of integers of some number field, or a subring thereof). This property was already noticed in the context of the NTRU scheme by Hoffstein and Silverman [HS00], and was used in the context of FHE in a number of works, e.g. [OLPX18, BGIV20]. However, these works fell short of achieving the goal of naturally supporting Z2„ since they insisted on sticking with the use of cyclotomic number fields which has indeed been prevailing in the FHE literature. We deviate from this paradigm and show that working with non-cyclotomic number fields opens the door for great versatility in the design of the message space. We view this as a major contribution of this work. Indeed, this modification requires us to use algebraic variants of LWE that are defined over such number fields. Whereas this is not as widely used in the literature, we notice that to the best of our knowledge there is no reason to speculate that cyclotomic number fields would lead to more secure constructions (in fact, some argue that the opposite is more likely). We provide a detailed discussion on the security of algebraic LWE in our context.

[0280] As an additional contribution, we discuss the possibility of creating “Double CRT” encoding of the ciphertexts in our scheme. Double CRT [ITS20] is a way to encode ciphertexts that relies on the decomposition of the ciphertext modulus into prime ideals of a cyclotomic ring. This implies a representation of a large ciphertext as an array of fairly-small numbers, where addition and multiplication in the ring translates into pointwise addition and multiplication of the elements of the array. Whereas on the face of it we may not use Double CRT in our scheme, since we do not know how to decompose ordinary integers into prime ideals in our ring, we show that it is possible to take the opposite approach and construct the ciphertext modulus as a product of “simple” ideals. This would indeed allow for decomposition, but would imply that the ciphertexts in our scheme can no longer be represented as vectors of polynomials, where each coefficient is in for some integer q, but instead are cosets of some ideal in our ring. We show that nevertheless it is possible to apply homomorphic evaluation in this case.

[0281] In the second part we wish to devise a bootstrapping algorithm for our scheme. The bootstrapping process is computationally labor-intensive since it requires evaluating a pretty complex function. Furthermore, the noise accu- mulation during bootstrapping directly reduces the homomorphic capacity of the scheme after bootstrapping. Therefore, there is a lot of effort in the lit- erature in order to reduce the complexity of bootstrapping in various FHE schemes [GHS12,HS21,DM14,CGGI20,KDE+24]. In particular, to come up with “decryption circuits” that require the least amount of resources and have the least noise accumulation.

[0282] In our scheme, we manage to introduce a decryption functionality which is both relatively mild in terms of resources, and allows us to extract the individual bits of the message in the course of bootstrapping. This means that during bootstrapping we can perform bit-level operations on the encrypted message, which we leverage to obtain logical / boolean evaluation capacity for our scheme.

[0283] Our starting point is the method of [KDE‘”24] who proposed to bootstrap BGV-style ciphertext by reducing the task to that of bootstrapping non-algebraic ciphertexts (i.e. ones that are not defined over a ring). In fact, this is quite straightforward in BGV-style encryption, since one can decompose an algebraic ciphertext into a collection of non-algebraic ciphertexts simply by thinking about ring elements as polynomials, and considering one coefficient at a time (see tech- nical overview below for additional details). They then use the [CGGI20, CJP21] bootstrapping approach which has been designed for non-algebraic ciphertexts, and use it essentially as a building block.

[0284] We cannot follow this blueprint as is, since our algebraic ciphertexts do not decompose well in terms of coefficients. That is, our use of a general ideal to define the ciphertext space means that noise in our ciphertext is not added per- coefficient as in previous FHE schemes. We therefore design a novel approach for recursive decomposition of our algebraic ciphertext into a collection of non- algebraic ciphertexts. Essentially this works by noticing that we can extract a non-algebraic ciphertext encrypting the least significant bit. We then bootstrap this ciphertext and show how to use the bootstrapped ciphertext in order to produce a non-algebraic encryption of the next bit of the message. At the end of the process, we have bootstrapped versions of non-algebraic encryptions of all bits of the message. This allows us to perform many logical operations “for free”: e.g. apply any permutation or shift on the bits, remove some of the bits or XOR them with each other. We can also apply more sophisticated operations such as bitwise AND using a bit more work.

[0285] We refer the reader to the technical overview below for a more detailed explanation on how our scheme works.

[0286] Finally, we consider concrete parameters for our scheme, with a plaintext space of n = 64 bits. We implemented our scheme and report implementation- specific details.

[0287] 1.2 Other Related Works

[0288] This work addresses FHE in the circuit model. This means that we consider computation that is represented in a combinatorial form as a circuit with boolean or arithmetic gates. Until recently, FHE was only known to be applicable in this model. Recently, Lin, Mook and Wichs [LMW23] introduced the first FHE scheme that operates in the RAM model (with suitable preprocessing). Whether our techniques have implications on RAM-FHE remains a subject for future inquiry.

[0289] 1.3 Paper Organization

[0290] Section 2 contains a technical overview of our scheme. Section 3 contains pre- liminaries and definitions. The basic scheme and basic arithmetic homomorphic evaluation are presented in Sections 4, 5. Our bootstrapping algorithm and the derived homomorphic logical operations are described in Section 6. In Section 7 we provide a detailed discussion on the security of algebraic-LWE in our ring. Im- plementation details are provided in Section 8. Our analysis for using algebraic modulus for the sake of double CRT is provided in Appendix A.

[0291] 2 Technical Overview

[0292] We start with a common blueprint for LWE-based encryption. The ciphertext is a (column) vector c, say in and the secret key s is a (row) vector of the same dimension, say in Z". The ciphertext is generated so that

[0293] We refer to q is the “ciphertext modulus” and p is the “plaintext modulus” , and we require that p, q are coprime. The encrypted message p can be interpreted integer, and taking it as an element of the ring as well. This means that for any q it is possible to find q' with the proper “volume” (the volume in this context is the index of the ideal in the ring) so that modulus switching has the desired properties. We notice that working with such algebraic ciphertext modulus may have additional advantages. For example, is “small” will allow to perform modulus switching as desired, and also provide a method for double-CRT encoding of the ciphertext, as explained above. We elaborate on this in Section A. Finally, going back to the first method, we notice that the scaling by a may be performed only “conceptually” without actually performing the multiplication. We can just “carry” the a factor throughout the computation and cancel it only at decryption (or at bootstrapping). ( f ( )) so its complex roots come in conjugate pairs). However, we will not require this real embedding here. In the canonical embedding, field addition and multiplication are done component-wise. 3.3 Homomorphic Encryption

[0294] We now define homomorphic encryption and its desired properties. Throughout this section (and this work) we use n to indicate the security parameter.

[0295] A homomorphic (public-key) encryption scheme

[0296]

[0297] We first replace the b vector in the public key to be sampled uniformly rather than being computed using MPLWE. By the MPLWE assumption with secret si, this hybrid is computationally indistinguishable from the original experiment.

[0298] Then we replace c by a uniform vector. This is computationally indistin- guishable from the previous hybrid again relying on MPLWE with secret r.

[0299] Finally, c is completely uniform and independent of p, which implies the security of the scheme.

[0300] In Section 7, we relate the hardness of MPLWE to that of more commonly used assumptions in lattice-based cryptography, such as RLWE, and discuss the proper choice of parameters. 5 Homomorphic Arithmetic Operations

[0301] In this section we present our algorithms for the homomorphic evaluation of arithmetic operations: addition, multiplication by a scalar and multiplication of ciphertexts. For the sake of the multiplication operations, we also introdce our versions of the key switching and modulus switching techniques.

[0302] Homomorphic evaluation of logical operations will be implemented as a part of our bootstrapping process, see Section ?? for details.

[0303] During this section there are addition and multiplication between elements that naturally live in different spaces, some of them are in 7lq(the ciphertexts),

[0304] 5.1 Addition

[0305] REFHE.Add takes two ciphertexts encrypted under the same secret key s. The addition is performed by adding the two ciphertexts (as vectors of ring elements).

[0306] 5.2 Scalar Multiplication

[0307] Same as with the message, we have to encode the scalar as a polynomial that equal to the scalar mod p. Then multiply each coordinate of the ciphertext by it. Notice that since the norm of the encoded scalar is small, when multiplying by it the noise grows roughly by the expansions factor, which is logarithmic in the size of the plaintext space. In BGV this factor is linear in the size of the plaintext space, so for large plaintext spaces we get a significant improvement in the noise growth.

[0308] 5.3 Key switching

[0309] 5.3.1 HElib inspired optimized keyswitch The following Key switching technique is based on the one presented in [HS20] , and is done in order to reduce the relative noise, in comparison to the standard approach in [BGV12]. This is indeed a generalization of the BGV keyswitching , which can be obtained as a

[0310]

[0311] Notice that since the ciphertext contains multiple elements from 71, the rounding is done on each element seperately.

[0312] We start with a lemma on the error rate of modulus switching for (rational) integer moduli. While this is the most efficient modulus switching we have for our scheme, it provides a good sense of the underlying concepts.

[0313] noise bound. As mentioned at the beginning of this section, it may not be ideal to choose integers q and q' that are congruent modulo p, as this could lead to very large ciphertext moduli values. Specifically, this condition implies q = q' (mod p), resulting in q > p. This would require a much larger ciphertext modulus than what is typically used in our implementations. For that we will have to choose w 7^ 1 and suffer from a multiplicative expansion factor in the resulting error. In order to overcome that we introduce the ideal modulus switching, which will result in working modulo q which is not a rational number.

[0314] 5.5 Multiplication

[0315]

[0316] Moduli ladder As in [BGV12], the setup phase of the scheme in algorithm 4.1 produces also a “ladder” of the cipher text moduli that will be used during the evaluation of the scheme. Notice that after each multiplication we perform key switch and then modulus switch, so the evaluation key should consist of a Public keyswitch matrix for each multiplication before the bootstrapping, and the relevant modulus.

[0317] 5.6 Optimizations

[0318] Notice that when performing a homomorphic evaluation, we generally work with layered circuits, where each cell corresponds to a layer that reflects the depth of multiplications required to reach that cell. Homomorphic operations have inputs only from the same layer, as the inputs must have the same key and modulus, which are determined by the depth of multiplications. Returning to our claim, we wish to show that all the cells in the same layer have the same scalar multiplier. Indeed, we need to explain that for multiplication, addition,

[0319] — The first and simplest way is to always use the modulus switching and key switching without the multiplication by scalar, and only in the last modswitch before bootstrapping multiply by a scalar w, that instead of be- ing chosen as equal to q' / q mod p it will be chosen such that the associated scalar with the new cell is 1.

[0320] — Another way is that the decryption algorithm will include also division by the relevant scalar mod p. The issue with this approach is that it can’t be used during binary operations during bootstrapping.

[0321] — We can also try to affect this factor during encryption, middle steps, or choosing of moduli ladder, in order for the final multiplier to have an inverse with small norm.

[0322] 6 Bootstrapping and Boolean Operations

[0323] We now present our bootstrapping algorithm. We start by introducing a generic notation that will be used throughout this section. In the course of the boot- strapping we switch between a number of forms of algebraic and non-algebraic LWE. All of these schemes have a very similar syntax, namely a linear decryption over some ring results in an encoding of a plaintext with some noise. To capture

[0324]

[0325] The rest of this section is organized as follows. In Section 6.1 we cover the subroutines in more depth, and in Section 6.2 we present our bootstrap algorithm in detail. The description above is provided mainly for intuition. In Section we show how logical operations can be preformed homomorphically during boot- strap.

[0326] 6.1 Subroutines of the Bootstrapping Algorithm

[0327] 6.1.1 Programmable Bootstrapping for B / FV This is the procedure from [KDET24] that allows to use the programmable bootstrapping of the TFHE scheme in order to bootstrap schemes that are based on the BGV and B / FV paradigms. MPLWE encryptions of powers of 2 multiplied by the secret key elements over the scheme’s ring under a different key denoted here as s, and so are of the form:

[0328] 6.2 Bootstrapping Procedure and Analysis

[0329] 6.2.1 Bootstrapping Setup The procedure REFHE. BS. Setup defines public parameters bspp, which include: a function D the function we evaluate during de- Q = om- ated hing s of 6.3 Boolean Operations

[0330] We now explain how to use our bootstrapping framework in order to perform boolean operations on the ciphertext in the course of bootstrapping. Our solution hinges on the property that the coefficients of the encoded plaintext fj, are the bits of the message m, and those are the values that are recovered in the course of our bootstrapping procedure. We start by considering boolean operations that permute ciphertext bits, and move on to logical operations. perform similar operations. It is also possible to output more than one output ciphertext, e.g. store the lower n / 2 bits in one ciphertext and the upper n / 2 bits in another.

[0331] All of these operations incur a minimal penalty in terms of noise and runtime compered to ordinary bootstrapping.

[0332] Comparisons. An additional class of logical operations is producing a boolean value which corresponds to the truth value of some numerical comparison. It

[0333] Multi-Bit Boolean Operations. Let us now consider operations that are performed over multiple bits. We note that using the above, equality to 0 can be tested by checking that both m > — 1 and m < 1, which can be done using two parallel bootstrapping sessions. Equality to 0 is also the n-bit NOR operation. Similarly other logical operators over the n bits can be implemented.

[0334] Fig. 1. Reduction relations between various relevant Algebraic LWE problems. The numbering refers to the different security issues 1, 2, 3 and 4 numbered below.

[0335] Known connections between the problems are summarized in Figure 1. The numbers on the arrows correspond to the following reductions.

[0336] 7.2 Security in Our Ring Compared to a Cyclotomic

[0337] It is a common choice to take K to be the cyclotomic field, this is done as many structural properties are known about them. This enables faster compu- tations [LPR13b] but also simplifies some of the security assumptions. Namely cyclotomic polynomials are monogenic, meaning that OK = T / i' / p')). Further- more as long as the defining cyclotomic number m does not admit a lot of distinct factors the transformation between the coefficient and canonical embeddings is asymptotically tame [BC22] . Lastly for power of two cyclotomic one can see that the dual ring is a scaling of the ring.

[0338] We also point out that some have argued that cyclotomic polynomials may be a worse choice in terms of security, compared to non-cyclotomics, since their structure may give raise to attacks. For example, in the context of the NTRU- Prime scheme, [BCLvV16] proposed to work with the non-cyclotomic xn— x + 1 (which is quite similar to ours). They claim that working with such polynomials can also be done quite efficiently, and is less risky in terms of security.

[0339] Lastly we want to address a line of attacks on polynomial LWE using poly- nomials of the form xn+ ax + b [EHL14,ELOS15,CIV16]. The general concept is to start with polynomials of the form xn+ b for a “large” b and show it behave similarly to xn+ ax + b for a “small” a. The first idea is that if b = q — 1 we get that f (1) = 0 mod q which in turns means that if there is a ring equation modulo both f and q it is possible to assign x = 1 and still obtain a valid equa- tion. This collapses the PLWE instance into a one-dimensional instance with small noise. Notice that this attack hinges on the coefficient embedding of the noise e(x) being small. Peikert [Pei16] surveys such “field dependent attacks” and concludes that they result from improper choice of noise parameters, that is enabled by pathological properties of the number field. Our interpretation of Peikert’s conclusion is that so long as we add the noise “properly”, i.e. in such a way that when looking at the respective dual instance, the noise is large enough, then no vulnerabilities are known. In essence this means that while we discuss the transformation between the canonical and coefficient embeddings for the se- curity reduction, this distinction may be void for practical attacks as long as we work in the dual ring.

[0340] 8 Performance and Implementation

[0341] We didn’t implement the optimized Key switch yet, and the algebraic modulus. We expect additional improvements from those.

[0342] Our parmeters y are for security x

[0343] 8.1 Parameter Estimations

[0344] We are going to estimate parameters generically i.e. for a plaintext of a certain size, a polynomial with certain parameters and varying security levels. In partic- ular for f we will denote by the singular values of the Vandermonde matrix Vf defined by the roots of f . We assume that s is sampled such that it has enough entropy but not anymore then necessary for the security parameter In particular assume that the RLWE problem is as hard as the LWE problem i.e. there are no better attacks on RLWE. Further we are going to assume that the hardness of a RLWE instance is determined by the smallest singular values of the co- variance matrix. Pictorially, the error is sampled from an ellipsoid and we assume instead the error is taken from the largest sphere contained in the ellipsoid. Lastly we are going to assume that modulus switching and re-linearization are preformed after each operation.

[0345] 8.1.1 Irreducibility of our polynomials

[0346] factorizes into the following primes:

[0347] 1399,

[0348] 315883,

[0349] 1054894487,

[0350] 1609025206302091,

[0351] 300524395301294803,

[0352] 102580173634571360137,

[0353] 8668017673543442201810164494961,

[0354] 1813131374962222709188812217190299

[0355] For k = 32: factorizes into the following primes:

[0356] 53,

[0357] 683,

[0358] 1189674929,

[0359] 72879316190189456125055364884319727806855527

[0360] So both of the polynomials are monogenic.

[0361]

[0362] Fig. 2. Logarithmic Fit for the square of the minimal and maximal singular values as a function of the degree 05.

[0363]

[0364] 8.2 Implementation

[0365] This section evaluates concrete runtime of our scheme encryption and decryption procedures, homomorphic arithmetic operations: addition and multiplication, as well as modulus switching and key switching, without algebraic ciphertext modulus and bootstrapping.

[0366] Parameters

[0367] We generated parameters for our scheme, such that correctness is achieved with high probability based on the somewhat naive bounds given in sections ?? and that the lattice problems are 128-bit secure according to the lattice estima- tor.

[0368] Setup The tests and results presented in the next section were obtained with a naive implementation in which no specific optimizations were applied to enhance performance. These results thus, reflect the raw computational costs associated with the building blocks of our scheme without the influence of advanced heuris- tics, algorithms or hardware-specific optimizations. The test bed for our results is as follows. We implemented our tests in Rust run on and bench-marked single-threaded speed for all procedures.

[0369] We use the Key Switching Algorithm for d = 2 and q = q' , And while the implementation supports working over modulus, for the concrete parameters we chose r = 1. While talking about depth of multiplications - Each plaintext goes through the following procedure:

[0370] 1. Encoding

[0371] 2. Encryption

[0372] 3. Modulus Switching

[0373] And then for each Multiplication:

[0374] — Tensor multiplication

[0375] — Key Switching

[0376] — Modulus Switching

[0377] In case of zero multiplications, after the third action (the modulus switch) ad- dition is performed. The ciphertext size is measured after the modulus switch, as this is the size required for transmission during communication.

[0378] Results Comparison with BGV We generated parameters to the original BGV [BGV 12] scheme, with similar to those we obtaines. We did that for plaintext spaces of sizes 216, 232, 264. Bellow you can see the comparison in the ciphertext sizes, when modulus switch is performed right after encryption to reduce the ciphertext size..

[0379] A Optimizing Performance Using Ideal Ciphertext Moduli

[0380] A.l Algebraic Number Theory facts

[0381] A.2 The difference in the scheme from rational q

[0382] The scheme remains structurally identical, where operations which previously performed modulo q are now conducted modulo q. The only aspect of the origi- nal scheme, as outlined in Algorithm 4.1, that requires further definition is the decryption algorithm. However, it is important to note that our modulus ladder ends with a rational integer. Consequently, decryption is only necessary when the modulus is a rational integer, which ensures that the scheme functions correctly without further modification.

[0383] Correctness and Security. Standard security assumptions talk about RLWE type problems with respect to a rational ciphertext modulus. Although there are assumptions with respect to alebraic ideals - as the GLWE security assumption in [PP19], we wish to talk about a simple reduction from M / P / R / O - LWE problems over an algebraic ciphertext modulus to a rational one. Working with an algebraic modulus q, we can perform modulus switch to the modulus a • q for a rational q and a a polynomial with 0,1 coefficients. Notice that (q) | (a • q) so in particular we get an MPLWE problem with the ciphertext modulus q - which is rational - where we lose roughly a factor of the expansion factor in the parameters.

[0384] We measure noise in in the coefficient embedding, the same as in definition 4.1. Note that the analysis of the noise growth after encryption, and the bounds needed for decyption stay the same.

[0385] Homomorphic Properties. Multiplication, Multiplication by scalar and Ad- dition are the same as in integer modulus, with q replaced by q in the algorithm. The analysis and bounds on the noise ηs(c, m) stay the same. There difference is a new gadget in the key switching and a new modulus switching.

[0386] A.3 Representing the Ciphertext mod (b2) and we can continue for the latter coefficients by taking mod b' every time. Notice it also proves that there is a unique way to write the element as a polynomial with coefficients in this range.

[0387]

[0388] A.5 Modulus Switching The following lemma summarizes the performance of the algorithm

[0389]

[0390] References

[0391] BC22. Ivan Blanco-Chacon. On the rlwe / plwe equivalence for cyclotomic number fields. Applicable Algebra in Engineering, Communication and Computing, 33(1):53-71, 2022. BCIV20. Carl Bootland, Wouter Castryck, Ilia Iliashenko, and Frederik Vercauteren. Efficiently processing complex-valued data in homomorphic encryption. J. Math. Cryptol., 14(l):55-65, 2020.

[0392] BCLvV16. Daniel J. Bernstein, Chitchanok Chuengsatiansup, Tanja Lange, and Chris- tine van Vredendaal. NTRU prime: reducing attack surface at low cost. Cryptology ePrint Archive, Paper 2016 / 461, 2016.

[0393] BGV12. Zvika Brakerski, Craig Gentry, and Vinod Vaikuntanathan. (leveled) fully homomorphic encryption without bootstrapping. In Shafi Goldwasser, ed- itor, Innovations in Theoretical Computer Science 2012, Cambridge, MA, USA, January 8-10, 2012, pages 309-325. ACM, 2012.

[0394] Bral2. Zvika Brakerski. Fully homomorphic encryption without modulus switching from classical gapsvp. In Reihaneh Safavi-Naini and Ran Canetti, editors, Advances in Cryptology - CRYPTO 2012 - 32nd Annual Cryptology Conference, Santa Barbara, CA, USA, August 19-23, 2012. Proceedings, volume 7417 of Lecture Notes in Computer Science, pages 868-886. Springer, 2012.

[0395] BTR24. Fabian Boemer, Karl Tarbe, and Rehan Rishi. Announcing swift homomorphic encryption, 2024. https : / / www. swift . org / blog / announcing-- swift - homomorphic - encryption / .

[0396] BVlla. Zvika Brakerski and Vinod Vaikuntanathan. Efficient fully homomorphic encryption from (standard) LWE. In Rafail Ostrovsky, editor, IEEE 52nd Annual Symposium on Foundations of Computer Science, FOCS 2011, Palm Springs, CA, USA, October 22-25, 2011, pages 97-106. IEEE Com- puter Society, 2011.

[0397] BVllb. Zvika Brakerski and Vinod Vaikuntanathan. Fully homomorphic encryp- tion from ring-lwe and security for key dependent messages. In Phillip Rogaway, editor, Advances in Cryptology - CRYPTO 2011 - 31st Annual Cryptology Conference, Santa Barbara, CA, USA, August lf-18, 2011. Proceedings, volume 6841 of Lecture Notes in Computer Science, pages SOS- 524. Springer, 2011.

[0398] CGGI20. Ilaria Chillotti, Nicolas Gama, Mariya Georgieva, and Malika Izabachene. TFHE: fast fully homomorphic encryption over the torus. J. Cryptol., 33(1):34-91, 2020.

[0399] CIV16. Wouter Castryck, Ilia Iliashenko, and Frederik Vercauteren. Provably weak instances of ring-LWE revisited. Cryptology ePrint Archive, Paper 2016 / 239, 2016.

[0400] CJP21. Ilaria Chillotti, Marc Joye, and Pascal Paillier. Programmable bootstrap- ping enables efficient homomorphic inference of deep neural networks. In Shlomi Dolev, Oded Margalit, Benny Pinkas, and Alexander A. Schwarz- mann, editors, Cyber Security Cryptography and Machine Learning - 5th International Symposium, CSCML 2021, Be ’er Sheva, Israel, July 8-9, 2021, Proceedings, volume 12716 of Lecture Notes in Computer Science, pages 1-19. Springer, 2021.

[0401] CKKS16. Jung Hee Cheon, Andrey Kim, Miran Kim, and Yongsoo Song. Homomor- phic encryption for arithmetic of approximate numbers. Cryptology ePrint Archive, Paper 2016 / 421, 2016.

[0402] CKKS17. Jung Hee Cheon, Andrey Kim, Miran Kim, and Yong Soo Song. Homomor- phic encryption for arithmetic of approximate numbers. In Tsuyoshi Takagi and Thomas Peyrin, editors, Advances in Cryptology - ASIACRYPT 2017 - 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3-7, 2017, Proceedings, Part I, volume 10624 of Lecture Notes in Computer Science, pages 409-437. Springer, 2017.

[0403] CLPX18. Hao Chen, Kim Laine, Rachel Player, and Yuhou Xia. High-precision arithmetic in homomorphic encryption. In Nigel P. Smart, editor, Topics in Cryptology - CT-RSA 2018 - The Cryptographers’ Track at the RS A Conference 2018, San Francisco, CA, USA, April 16-20, 2018, Proceedings, volume 10808 of Lecture Notes in Computer Science, pages 116-136. Springer, 2018.

[0404] Con09. Kieth Conrad. The different ideal. Expository papers / Lecture notes. Available at: http: / / www. math. uconn. edu / kcon- rad / blurbs / gradnumthy / different, pdf, 2009.

[0405] DM14. Leo Ducas and Daniele Micciancio. FHEW: Bootstrapping homomor- phic encryption in less than a second. Cryptology ePrint Archive, Paper 2014 / 816, 2014.

[0406] EHL14. Kirsten Eisentraeger, Sean Hallgren, and Kristin Lauter. Weak instances of PLWE. Cryptology ePrint Archive, Paper 2014 / 784, 2014.

[0407] ELOS15. Yara Elias, Kristin E. Lauter, Ekin Ozman, and Katherine E. Stange. Prov- ably weak instances of ring-lwe, 2015.

[0408] FV12. Junfeng Fan and Frederik Vercauteren. Somewhat practical fully homo- morphic encryption. IACR Cryptol. ePrint Arch., page 144, 2012.

[0409] GC14. Matthias Geihs and Daniel Cabarcas. Efficient integer encoding for ho- momorphic encryption via ring isomorphisms. In Diego F. Aranha and Alfred Menezes, editors, Progress in Cryptology - LATINCRYPT 2011 - Third International Conference on Cryptology and Information Security in Latin America, Florianopolis, Brazil, September 17-19, 2014, Revised Selected Papers, volume 8895 of Lecture Notes in Computer Science, pages 48-63. Springer, 2014.

[0410] GD84. Gary R. Greenfield and Daniel Drucker. On the discriminant of a trinomial. Linear Algebra and its Applications, 62:105-112, 1984.

[0411] Gen09a. Craig Gentry. Fully homomorphic encryption using ideal lattices. In Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing, STOC ’09, page 169-178, New York, NY, USA, 2009. Association for Computing Machinery.

[0412] Gen09b. Craig Gentry. Fully homomorphic encryption using ideal lattices. Symposium on the Theory of Computing, page 169-178, 2009.

[0413] GH19. Craig Gentry and Shai Halevi. Compressible FHE with applications to PIR. In Dennis Hofheinz and Alon Rosen, editors, Theory of Cryptography - 17th International Conference, TCC 2019, Nuremberg, Germany, December 1- 5, 2019, Proceedings, Part II, volume 11892 of Lecture Notes in Computer Science, pages 438-464. Springer, 2019.

[0414] GHS12. Craig Gentry, Shai Halevi, and Nigel P. Smart. Fully homomorphic en- cryption with polylog overhead. In David Pointcheval and Thomas Johans- son, editors, Advances in Cryptology - EUROCRYPT 2012, pages 465-482, Berlin, Heidelberg, 2012. Springer Berlin Heidelberg.

[0415] GSW13. Craig Gentry, Amit Sahai, and Brent Waters. Homomorphic encryp- tion from learning with errors: Conceptually-simpler, asymptotically-faster, attribute-based. Cryptology ePrint Archive, Paper 2013 / 340, 2013.

[0416] HS00. Jeffrey Hoffstein and Joseph H Silverman. Optimizations for ntru. In Proc, the Conf, on Public Key Cryptography and Computational Number Theory, Warsaw, pages 77-88, 2000. HS20. Shai Halevi and Victor Shoup. Design and implementation of HElib: a homomorphic encryption library. Cryptology ePrint Archive, Paper 2020 / 1481, 2020. https : / / sprint . iacr . org / 2020 / 1481.

[0417] HS21. Shai Halevi and Victor Shoup. Bootstrapping for helib. J. Cryptol., 34(1):7, 2021.

[0418] KDE+24. Andrey Kim, Maxim Deryabin, Jieun Eom, Rakyong Choi, Yongwoo Lee, Whan Ghang, and Donghoon Yoo. General bootstrapping approach for rlwe-based homomorphic encryption. IEEE Trans. Computers, 73(1):86- 96, 2024.

[0419] LMW23. Wei-Kai Lin, Ethan Mook, and Daniel Wichs. Doubly efficient private in- formation retrieval and fully homomorphic RAM computation from ring LWE. In Barna Saha and Rocco A. Servedio, editors, Proceedings of the 55th Annual ACM Symposium on Theory of Computing, STOC 2023, Orlando, FL, USA, June 20-23, 2023, pages 595-608. ACM, 2023.

[0420] LPR10. Vadim Lyubashevsky, Chris Peikert, and Oded Regev. On ideal lattices and learning with errors over rings. In Henri Gilbert, editor, Advances in Cryptology - EUROCRYPT 2010, 29th Annual International Conference on the Theory and Applications of Cryptographic Technigues, Monaco / French Riviera, May 30 - June 3, 2010. Proceedings, volume 6110 of Lecture Notes in Computer Science, pages 1-23. Springer, 2010.

[0421] LPR13a. Vadim Lyubashevsky, Chris Peikert, and Oded Regev. On ideal lattices and learning with errors over rings. J. ACM, 60(6):43:l-43:35, 2013.

[0422] LPR13b. Vadim Lyubashevsky, Chris Peikert, and Oded Regev. A toolkit for ring- Iwe cryptography. In Annual international conference on the theory and applications of cryptographic technigues, pages 35-54. Springer, 2013.

[0423] MP12. Daniele Micciancio and Chris Peikert. Trapdoors for lattices: Simpler, tighter, faster, smaller. In Annual International Conference on the Theory and Applications of Cryptographic Technigues, pages 700-718. Springer, 2012.

[0424] Peil6. Chris Peikert. How (not) to instantiate ring-LWE. Cryptology ePrint Archive, Paper 2016 / 351, 2016.

[0425] PP19. Chris Peikert and Zachary Pepin. Algebraically structured LWE, revis- ited. In Theory of Cryptography: 17th International Conference, TCC 2019, Nuremberg, Germany, December 1-5, 2019, Proceedings, Part I 17, pages 1-23. Springer, 2019.

[0426] PP24. Chris Peikert and Zachary Pepin. Algebraically structured Iwe, revisited. J. Cryptol., 37(3):28, 2024.

[0427] RAD+78. Ronald L Rivest, Len Adleman, Michael L Dertouzos, et al. On data banks and privacy homomorphisms. Foundations of secure computation, 4(ll):169-180, 1978.

[0428] Reg05. Oded Regev. On lattices, learning with errors, random linear codes, and cryptography. In Harold N. Gabow and Ronald Fagin, editors, Proceedings of the 37th Annual ACM Symposium on Theory of Computing, Baltimore, MD, USA, May 22-24, 2005, pages 84-93. ACM, 2005.

[0429] RSSS17. Miruna Rosea, Amin Sakzad, Damien Stehle, and Ron Steinfeld. Middle- product learning with errors. In Jonathan Katz and Hovav Shacham, edi- tors, Advances in Cryptology - CRYPTO 2017 - 37th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 20-24, 2017, Proceedings, Part III, volume 10403 of Lecture Notes in Computer Science, pages 283-297. Springer, 2017. RSW18. Miruna Rosea, Damien Stehle, and Alexandre Wallet. On the ring- LWE and polynomial- LWE problems. In Annual International Conference on the Theory and Applications of Cryptographic Techniques, pages 146-173. Springer, 2018.

[0430] SEA11. Microsoft SEAL. Microsoft seal is an easy-to-use and powerful homomor- phic encryption library., 2011. https : / / github . com / Microsoft / SEAL.

[0431] SS10. Damien Stehle and Ron Steinfeld. Faster fully homomorphic encryption. In Masayuki Abe, editor, Advances in Cryptology - ASIACRYPT 2010 - 16th International Conference on the Theory and Application of Cryptology and Information Security, Singapore, December 5-9, 2010. Proceedings, volume 6477 of Lecture Notes in Computer Science, pages 377-394. Springer, 2010. tfhl7. tfhe. Tfhe: Fast fully homomorphic encryption library over the torus, 2017. https : / / github . c.om / tfhe / tfh e.

[0432] Zam21. Zama. Concrete: Tfhe compiler that converts python programs into Hie equivalent, 2021. https : / / git.hub . com / zama~ai / concrete.

[0433] OVERVIEW

[0434] A homomorphic encryption scheme enables mathematical operations or computations to be performed on encrypted data without requiring its decryption. Therefore, the data remains confidential while being processed, even in an untrusted environment. As a result, useful operations may be performed on the encrypted data by a third party without requiring the third party to properly secure the data, as the original data cannot be identified without the decryption key. For example, a person or organization may apply standard encryption techniques to secure sensitive data on cloud platforms, but processing or validating the encrypted data in the cloud would require its decryption, which raises privacy issues and security vulnerabilities and may entail additional costs and resources. By utilizing homomorphic encryption, private data may be shared and evaluated securely in commercial cloud environments without endangering privacy. The cloud service provider only has access to the encrypted data (ciphertext) and can perform computations on the data without decryption. The results of the encrypted processing may be provided to the owner of the private data who can then decrypt the data (into plaintext) via the decryption key. In addition to cloud services, homomorphic encryption can be used by entities in a wide vary of businesses and industries, such as financial services, healthcare, retail, information technology and artificial intelligence systems, to allow access to encrypted data while protecting client or patient privacy

[0435] Homomorphic encryption schemes may be classified into several categories, including partially homomorphic encryption, somewhat homomorphic encryption, and fully homomorphic encryption. A partially homomorphic encryption allows only a single operation to be performed on the ciphertext, such as addition or multiplication. In contrast, fully homomorphic encryption (FHE) supports multiple operations indefinitely, such as both addition and multiplication, enabling a wider range of arbitrary computations to be performed on the ciphertext. However, FHE is characterized by certain limitations, particularly a very large computational overhead and high inefficiency due to protracted time for performing computations. Many FHE schemes are based on lattice mathematics, such as derived from the ring learning with errors (RLWE) problem, and are generally considered secure from breaches by quantum computing (i.e., post-quantum cryptography).

[0436] The present disclosure relates to a fully homomorphic encryption (FHE) scheme based on lattice problems which natively support a large plaintext space, such as a 256-bit value or higher. SUMMARY

[0437]

[0438] According to an aspect of the present disclosure, at least one of the FHE schemes is used by a client to encrypt private and / or sensitive data to be shared with a third party operative for performing computations or processing the encrypted data without decryption thereof.

[0439] According to an aspect of the present disclosure, the third party may include at least one of: a cloud service provider; a medical service provider; a financial service provider; or an information technology service provider.

[0440] According to an aspect of the present disclosure, the large plaintext space comprises an integer size of at least 256-bits. According to an aspect of the present disclosure, the method is applied in a decentralized network.

[0441] According to an aspect of the present disclosure, the method is applied in a blockchain system.

[0442] According to an aspect of the present disclosure, the method is applied in a large scale secret information sharing system.

[0443] DETAILED DESCRIPTION

[0444] The present disclosure relates to a fully homomorphic encryption (FHE) scheme based on lattice problems which natively support a large plaintext space, such as a 256-bit value or higher. Specifically, this may be achieved based on the Order-LWE problem, which is proven to be equivalent to known lattice problems [bolboceanu2019order].

[0445] The FHE scheme is detailed hereinbelow.

[0446] For all these variations, decryption may be performed by subtracting “as” and reducing modulo the lattice basis.

[0447] A construction similar to Brakerski, Gentry, Vaikuntanathan (BGV) [cryptoeprint:2011 / 277] encryption may be utilized to transform the aforementioned symmetric cryptosystems to a public key FHE.

[0448] Two alternative approaches may be considered.

[0449] In a first alternative approach, the plaintext m E [— p, p] is represented in a Chinese Remainder Theorem (CRT) representation. In other words, considering the message modulo

[0450]

[0451] The different variations and approaches presented herein may enable configurable, native plaintext space for a fully homomorphic encryption (FHE) scheme. The disclosed FHE scheme can allow for encrypting message in ZPand performing homomorphic operations on such messages in ZP. As opposed to the aforementioned alternative approaches (i.e., based on CRT or based on BGV), the size of the ciphertext is comparable and proportional to the size of the plaintext (and does not grow exponentially with “p” for example). The disclosed FHE scheme may be employed in various applications. One example relates to cloud computing services. A lightweight client (i.e., computationally or memory limited) may use third party cloud services while maintaining data privacy by sending private data encrypted to the cloud, which could homomorphically operate on the ciphertext and return an encrypted output. Only the client who holds the private key can restore the output into its original form. For example, such a client may be a smartphone application that performs real-time face recognition operations but cannot store and compute the required large complex neural network architectures. Additional exemplary applications involve sensitive data analysis, such as in the fields of medical or financial services. Such corporations or institutions may possess mass quantities of sensitive client information that can be kept encrypted under a carefully protected private key, while allowing third parties to perform requisite analyses over the encrypted sensitive data.

[0452] The disclosed fully homomorphic encryption (FHE) scheme may overcome certain disadvantages over existing FHE schemes having a limited size plaintext space. Firstly, for a sufficiently large plaintext space, the ciphertext consists of a single slot, in which the ciphertext bloat is constant (i.e., independent of security parameter). Other schemes may rely on packing technique, encrypting multiple plaintexts in a single ciphertext to obtain an amortized small ciphertext bloat. However, these extra slots cannot always be exploited, and in any case they increase the latency. Furthermore, supporting large plaintext space, such as 2128, is consistent with the operation of modem computers, processors and data registers. This may result not only in faster homomorphic computation, but also provide for a more natural, straightforward and more efficient translation between an ordinary computer program and one operating with encrypted data.

[0453] METHODS

[0454] 1. A method for a fully homomorphic encryption (FHE) scheme that natively supports a large plaintext space, the method comprising the steps of:

[0455] 2. The method of method 1, wherein a decryption of the encrypted data comprises subtracting “as” and reducing modulo the lattice basis.

[0456] 3. The method of method 1, further comprising the step of applying a Brakerski, Gentry, Vaikuntanathan (BGV) construction to transform the scheme into a public key FHE scheme. A method for a fully homomorphic encryption (FHE) scheme that natively supports a large plaintext space, the method comprising the steps of: applying a double Chinese Remainder Theorem (CRT) encryption process comprising the steps of: The method of method 4, further comprising applying a double CRT decoding process comprising the steps of: providing an output of a.

[0457] The method of method 4, further comprising the step of constructing a leveled FHE for an arbitrary plaintext space, the constructing comprising the steps of:

[0458] The method of either of methods 1 or 4, wherein the FHE scheme is used by a client to encrypt private and / or sensitive data to be shared with a third party operative for performing computations or processing the encrypted data without decryption thereof.

[0459] The method of method 7, wherein the third party is selected from the group consisting of: a cloud service provider; a medical service provider; a financial services provider; and an information technology service provider. The method of either of methods 1 or 4, wherein the large plaintext space comprises an integer size of at least 256-bits. The method as in any of the method 1 to 9, applied in a decentralized network. The method as in any of the method 1 to 10, applied in a blockchain system. The method as in any of the method 1 to 11, applied in a large scale secret information sharing system.

[0460] It is to be understood that the invention is not limited in its application to the details set forth in the description contained herein or illustrated in the drawings. The invention is capable of other embodiments and of being practiced and carried out in various ways. Hence, it is to be understood that the phraseology and terminology employed herein are for the purpose of description and should not be regarded as limiting. As such, those skilled in the art will appreciate that the conception upon which this disclosure is based may readily be utilized as a basis for designing other structures, methods, and systems for carrying out the several purposes of the presently disclosed subject matter. It will also be understood that the system according to the invention may be, at least partly, implemented on a suitably programmed computer. Likewise, the invention contemplates a computer program being readable by a computer for executing the method of the invention. The invention further contemplates a non-transitory computer-readable memory tangibly embodying a program of instructions executable by the computer for executing the method of the invention.

[0461] Those skilled in the art will readily appreciate that various modifications and changes can be applied to the embodiments of the invention as hereinbefore described without departing from its scope, defined in and by the appended claims.

Claims

CLAIMS1. A processing circuitry (PC)-based method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: c. the third non-cyclotomic ring, and d. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

2. The method of claim 1, wherein the irreducible non-cyclotomic polynomial is one of: f(x) = xn+ x - b, or f(x) = xn- x + b; and wherein the first ideal is: x-b wherein b is an integer.

3. The method of claim 2, the method further comprising, prior to the encrypting: encoding a given plaintext, of a given plaintext space, to the element of the first non-cyclotomic ring, the encoding being based on:EncodedElement =wherein EncodedElement denotes the element of the first non-cyclotomic ring, Firstldeal denotes the first ideal, and wherein m denotes the given plaintext, and wherein mi is based on: m =and wherein f(b) is equivalent to a size of the given plaintext space.

4. The method of claim 2, wherein the third non-cyclotomic ring is an order of a field, the field being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial.

5. The method of claim 4, wherein the third non-cyclotomic ring is a final extension ring of a series of extension rings, the series of extension rings successively extending the fourth non-cyclotomic ring, the series of extension rings being of a given series length, wherein each successive extension ring is based on an equation:CurrentNonCyclotomicExtensionRing = PredecessorNonCyclotomicRing[t] / MinimalPolynomial wherein PredecessorNonCyclotomicRing denotes a respective immediately preceding extension ring of the series, t is a respective additional algebraic element, and wherein MinimalPolynomial denotes a respective minimal polynomial, the respective minimal polynomial being based on an equation:MinimalPolynomial =wherein Firstldeal denotes the first ideal, and wherein each aj is a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal, n is a respective given integer greater than 1, and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing[t], and the minimal polynomial is irreducible in PredecessorNonCyclotomicRing.

6. The method of claim 5, wherein the given series length is 1, and wherein the final extension ring of the series of final extensions rings is based on:CurrentN onCyclotomicExtensionRing =FourthNonCyclotomicRing[t] / MinimalPolynomial where FourthNonCyclotomicRing denotes the fourth non-cyclotomic ring.

7. The method of claim 5, wherein the minimal polynomial defining the final extension ring is one of: a) tn2+ tn+ x, or b) tn2- tn + x, or c) tn2+ tn + x, or d) tn2- tn + x, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings.

8. The method of claim 5, wherein the minimal polynomial defining the final extension ring is one of: a) tn2+ tn + btn-1, or b) tn2- tn + btn-1, Or c) tn2+ tn - btn-1, Or d) tn2- tn - btn-1, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, and wherein tn-i denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring.

9. The method of claim 5, the method further comprising, prior to the encrypting, encoding a given number of plaintexts to an element of the first non- cyclotomic ring, wherein the encoding comprises: a) generating, for each plaintext of the given number of plaintexts, a respective per- plaintext ring element of the first non-cyclotomic ring, the generating being based on:PerPlaintextRingElement =wherein PerPlaintextRingElement denotes the element of the first non- cyclotomic ring, and wherein m denotes the given plaintext, and wherein mi is based on: m =and wherein f(b) is equivalent to a size of the given plaintext space; and b) calculating an encoded element based on the formula:EncodedElementc0 =wherein EncodedElementc0 denotes the element of the first non-cyclotomic ring, n denotes the given number of plaintexts, PerPlaintextRingElementi denotes a respective per-plaintext ring element, and λidenotes a respective Lagrange coefficient.

10. The method of claim 9, wherein the given number of plaintexts is:wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring.

11. The method of claim 1 , wherein the encrypting the element of a first non- cyclotomic ring comprises: calculating a linear combination, over the second non-cyclotomic ring of, at least: a. the element of the first non-cyclotomic ring, b. a sum of, at least:(i) a product of, at least, an encryption key and a randomizer, and(ii) a noise value, the calculating thereby resulting in an element of the second non-cyclotomic ring.

12. The method of claim 11 , wherein the encryption key is an element of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.

13. The method of claim 12, wherein the encrypting is based on:EncryptedElementc0 =(PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (Thir dN onCy clotomicRing / S econdldeal) wherein Thir dNonCy clotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.

14. The method of claim 12, wherein the encrypting is based on:EncryptedElementc0 =(PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

15. The method of claim 12, wherein the encrypting is based on:EncryptedElementc0 =(Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue))+ Randomizer3) mod (ThirdNonCyclotomicRing / Secondldeal) wherein the first ideal and second ideal are principal ideals, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

16. The method of claim 12, wherein the encrypting is based on:EncryptedElementc0 =((PlaintextElement * Secondldeal) +((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

17. The method of claim 12, wherein the encrypting is based on:EncryptedElementc0 =(PlaintextElement +(Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

18. The method of claim 11, wherein the encryption key is an element of a module derivative of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm.

19. The method of claim 18, wherein the encrypting is based on:EncryptedElementc0 =(PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (Thir dN onCy clotomicRing / S econdldeal) wherein Thir dNonCy clotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.

20. The method of claim 18, wherein the encrypting is based on:EncryptedElementc0 =(PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (Thir dNonCy clotomicRing / Secondldeal) wherein Thir dNonCy clotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

21. The method of claim 18, wherein the encrypting is based on:EncryptedElementc0 =(Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue))+ Randomizer3) mod (ThirdNonCyclotomicRing / Secondldeal) wherein the first ideal and second ideal are principal ideals, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

22. The method of claim 18, wherein the encrypting is based on:EncryptedElementc0 =((PlaintextElement * Secondldeal) +((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (Secondldeal * FirstIdeal) )wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring,EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

23. The method of claim 18, wherein the encrypting is based on:EncryptedElementc0 =(PlaintextElement +(Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.

24. A system of fully homomorphic encryption, the system comprising a processing circuitry (PC) configured to: encrypt an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

25. A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processor to perform a method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

26. A processing circuitry (PC)-based method of decrypting fully homomorphically encrypted data, the method comprising: decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

27. The method of claim 26, wherein the irreducible non-cyclotomic polynomial is one of: f(x) = xn+ x - b, or f(x) = xn- x + b; and wherein the first ideal is:x-b wherein b is an integer.

28. The method of claim 27, the method further comprising, subsequent to the decrypting: decoding the element of the first non-cyclotomic ring to a plaintext of a given plaintext space.

29. The method of claim 28 where the decoding is based on calculating: felement(b) wherein felement() is a polynomial function corresponding to the element of the first non-cyclotomic ring.

30. The method of claim 28 wherein the first non-cyclotomic ring is a quotient ring based on a final ring of a series of successive rings extending a fourth non-cyclotomic ring, and wherein the decoding comprises: a) determining one or more roots of a minimal polynomial associated with the first non-cyclotomic ring; b) for each determined root: calculating a result of substituting, in the element of the first non- cyclotomic ring, a respective extending algebraic element with the respective root, thereby generating one or more elements of a quotient ring derivative of a preceding ring of the series; c) responsive to the preceding ring being an extension ring of the fourth non- cyclotomic ring: for each generated element: repeating a) - b); and d) responsive to the preceding ring being the fourth non-cyclotomic ring: calculating, for each generated element felement(); felement(b) thereby giving rise to one or more plaintexts.

31. The method of claim 26, wherein the decrypting the element of a first non- cyclotomic ring comprises subtracting, from the element of the second non- cyclotomic ring:a value based on a product of a decryption key and a randomizing element, the decryption key and the randomizing element being elements of the second non-cyclotomic ring, thereby resulting in an element of the first non-cyclotomic ring.

32. The method of claim 31, wherein the decrypting is based on:DecryptedElement = EncryptedElementco - (DecryptionKey * EncryptedElementci) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementci denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.

33. The method of claim 31, wherein the decryption key is a symmetric key.

34. The method of claim 31, wherein the decryption key is a private key.

35. The method of claim 31, wherein the randomizing element is derivative of at least one randomizer.

36. The method of claim 35, wherein the randomizing element is further derivative of at least one constant value.

37. The method of claim 26, wherein the decrypting the element of a first non- cyclotomic ring comprises subtracting, from the element of the second non- cyclotomic ring: a value based on a product of a decryption key and a randomizing element,the decryption key and the randomizing element being elements of a module derivative of the second non-cyclotomic ring,38. The method of claim 37, wherein the decrypting is based on:DecryptedElement = EncryptedElementco - (DecryptionKey * EncryptedElementci) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementci denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.

39. The method of claim 37, wherein the decryption key is a symmetric key.

40. The method of claim 37, wherein the decryption key is a private key.

41. The method of claim 37, wherein the randomizing element is derivative of at least one randomizer.

42. The method of claim 41, wherein the randomizing element is further derivative of at least one constant value.

43. A system of decrypting fully homomorphically encrypted data, the system comprising a processing circuitry (PC) configured to: decrypt an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

44. A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processor to perform a method of decrypting fully homomorphically encrypted data, the method comprising: decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.

Citation Information

Patent Citations

  • Homomorphic encryption

    US20180212750A1

  • System and methods for validating and performing operations on homomorphically encrypted data

    US20220129892A1

Cited By

  • Electronic apparatus and control method thereof

    US20260180797A1