Publicly verifiable pseudorandom function under fully homomorphic encryption
The optimized method for generating homomorphic encryption of pseudorandom nonces in FHE systems addresses inefficiencies by using hash and mapping functions with bootstrapping, reducing processing time and noise in ciphertext.
Patent Information
- Application Number
- PCT/IL2025/050352
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-21
- Filing Date
- 2025-04-21
- Publication Date
- 2025-10-30
AI Technical Summary
Conventional cryptographic protocols using fully homomorphic encryption (FHE) face inefficiencies and increased noise in ciphertext due to the homomorphic performance of complex pseudorandom functions, which are time-consuming and resource-intensive.
An optimized method generates a homomorphic encryption of a pseudorandom nonce by applying a hash function and a mapping function to an input value, followed by a bootstrapping procedure using an evaluation key, avoiding the need for homomorphic performance of complex pseudorandom functions.
This approach reduces processing time and resource usage while maintaining cryptographic security, and minimizes noise accumulation in the ciphertext.
Smart Images

Figure IL2025050352_30102025_PF_FP_ABST
Abstract
Description
[0001] PUBLICLY VERIFIABLE PSEUDORANDOM FUNCTION
[0002] UNDER FULLY HOMOMORPHIC ENCRYPTION
[0003] TECHNICAL FIELD
[0004] The presently disclosed subject matter relates to use of cryptographic systems, and in particular to implementation of pseudorandom functions under homomorphic encryptions.
[0005] BACKGROUND
[0006] Problems of implementation of cryptographic pseudorandom functions have been recognized in the conventional art and various techniques have been developed to provide solutions.
[0007] SUMMARY
[0008] According to one aspect of the presently disclosed subject matter there is provided a processor-based method of generating, from an input value, a homomorphic encryption of a nonce, the nonce being pseudorandomly derivative of the input value, the method comprising: applying a hash function to the input value, thereby resulting in a hash result; applying a mapping function to the hash result, application of the mapping function resulting in a first ciphertext space element; and utilizing an evaluation key associated with an encryption key, performing a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element, the second ciphertext space element being a homomorphic encryption, under the encryption key, of a value pseudorandomly derivative of the input value. In addition to the above features, the method according to this aspect of the presently disclosed subject matter can comprise one or more of features (i) to (iv) listed below, in any desired combination or permutation which is technically possible:
[0009] (i) the method additionally comprising performing a homomorphic calculation based on the second ciphertext space element;
[0010] (ii) the hash result being a bit series of a given length;
[0011] (iii) the hash function being SHA-2;
[0012] (iv) the mapping function being a one-to-one mapping function.
[0013] According to another aspect of the presently disclosed subject matter there is provided a system of generating, from an input value, a homomorphic encryption of a nonce, the nonce being pseudorandomly derivative of the input value, the system comprising a processing circuitry configured to: apply a hash function to the input value, thereby resulting in a hash result; apply a mapping function to the hash result, application of the mapping function resulting in a first ciphertext space element; and utilize an evaluation key associated with an encryption key, to perform a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element, the second ciphertext space element being a homomorphic encryption, under the encryption key, of a value pseudorandomly derivative of the input value.
[0014] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (iv) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.
[0015] According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer readable non-transitory storage medium containing program instructions which, when read by processing circuitry, cause the processing circuitry to perform a method of generating, from an input value, a homomorphic encryption of a nonce, the nonce being pseudorandomly derivative of the input value, the method comprising: applying a hash function to the input value, thereby resulting in a hash result; applying a mapping function to the hash result, the mapping function resulting in a first ciphertext space element; and utilizing an evaluation key associated with an encryption key, performing a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element, the second ciphertext space element being a homomorphic encryption, under the encryption key, of a value pseudorandomly derivative of the input value.
[0016] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (iv) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.
[0017] According to one aspect of the presently disclosed subject matter there is provided a processor-based method of threshold validation of a signature, the signature being a signature of a message, the method comprising: a) receiving a fully homomorphic encryption of a signature key, under an encryption key; b) utilizing the fully homomorphic encryption of the signature key to perform a homomorphic signature computation based on, at least, the signature key, the message, and a nonce, wherein the nonce is derivative of a process comprising: i. applying a hash function to an input value that is derivative of, at least, the message, thereby resulting in a hash result; ii. applying a mapping function to the hash result, the mapping function resulting in a first ciphertext space element; and iii. utilizing an evaluation key associated with the encryption key to perform a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element.
[0018] In addition to the above features, the method according to this aspect of the presently disclosed subject matter can further comprise feature (i) listed below:
[0019] (i) receiving a threshold share of a fully homomorphic decryption key that corresponds to the encryption key; utilizing the received threshold share to perform threshold decryption of the homomorphically -encrypted signature, thereby resulting in a decryption share of the homomorphically -encrypted signature; and merging the resulting decryption share with one or more additional decryption shares, thereby resulting in the signature.
[0020] According to another aspect of the presently disclosed subject matter there is provided a system of threshold validation of a signature, the signature being a signature of a message, the system comprising a processing circuitry configured to: a) receive a fully homomorphic encryption of a signature key, under an encryption key; b) utilize the fully homomorphic encryption of the signature key to perform a homomorphic signature computation based on, at least, the signature key, the message, and a nonce, thereby signing the message; wherein the processing circuitry is further configured to: i. apply a hash function to an input value that is derivative of, at least, the message, thereby resulting in a hash result; ii. apply a mapping function to the hash result, the mapping function resulting in a first ciphertext space element; and iii. utilize an evaluation key associated with the encryption key to perform a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element, and wherein the nonce is based on the second ciphertext space element.
[0021] This aspect of the disclosed subject matter can further optionally comprise feature (i) listed above with respect to the method, mutatis mutandis. According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer-readable non-transitory storage medium containing program instructions which, when read by processing circuitry, cause the processing circuitry to perform a method of threshold validation of a signature, the signature being a signature of a message, the method comprising: a) receiving a fully homomorphic encryption of a signature key, under an encryption key; b) utilizing the fully homomorphic encryption of the signature key to perform a homomorphic signature computation based on, at least, the signature key, the message, and a nonce, wherein the nonce is derivative of a process comprising: i. applying a hash function to an input value that is derivative of, at least, the message, thereby resulting in a hash result; ii. applying a mapping function to the hash result, the mapping function resulting in a first ciphertext space element; and iii. utilizing an evaluation key associated with the encryption key to perform a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element.
[0022] This aspect of the disclosed subject matter can further optionally comprise feature (i) listed above with respect to the method, mutatis mutandis.
[0023] BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to understand the invention and to see how it can be carried out in practice, embodiments will be described, by way of non-limiting examples, with reference to the accompanying drawings, in which: Fig. 1 illustrates an example system configured to perform pseudorandom number generation in accordance with some embodiments of the presently disclosed subject matter;
[0025] Fig. 2 illustrates a flow diagram of an example method generating, from an input value, a homomorphic encryption of a random value (herein termed a nonce), the nonce being pseudorandomly derivative of the input value, in accordance with some of embodiments of the presently disclosed subject matter;
[0026] Fig- 3 illustrates an example system configuration for performance of a threshold signature protocol based on a pseudorandom number generation nonce, in accordance with some embodiments of the presently disclosed subject matter; and
[0027] Fig. 4 illustrates a flow diagram of an example method of threshold signature verification based on an optimized pseudorandom function, in accordance with some embodiments of the presently disclosed subject matter.
[0028] DETAILED DESCRIPTION
[0029] Certain cryptographic protocols and methods utilize pseudorandom number generation. For example, many cryptographic protocols and methods employ a random or pseudorandom number as a “nonce” to provide security (e.g. by preventing an attacker from being able to “replay” an old message of a previous protocol exchange).
[0030] Fully homomorphic encryption (FHE) is an advanced form of encryption that allows computations to be performed directly on encrypted data without needing to decrypt it first. This means that sensitive data can remain encrypted and secure while being processed, enabling privacy-preserving operations in scenarios like cloud computing or secure data analysis. The result of any computation using FHE remains encrypted, and only the data owner with the correct decryption key can access the final result in plaintext.
[0031] An evaluation key in fully homomorphic encryption is a special kind of auxiliary key that enables computations on encrypted data without revealing the secret key. When a user encrypts data with their public key, the system also uses the evaluation key to perform homomorphic operations — like addition or multiplication — on that ciphertext. The evaluation key typically includes encrypted forms of secret key bits or other structured information that allow the FHE scheme to handle complex operations such as bootstrapping or key switching.
[0032] Bootstrapping in fully homomorphic encryption is a technique used to reduce the noise that accumulates during computations on encrypted data, which, if left unchecked, can eventually render the ciphertext undecipherable. Since each homomorphic operation slightly increases this noise, bootstrapping refreshes the ciphertext by homomorphically evaluating the decryption circuit on itself — essentially decrypting and re-encrypting the data while it remains encrypted. This process restores the ciphertext to a lower-noise state, allowing for an unlimited number of operations.
[0033] In some embodiments of the presently disclosed subject matter, cryptographic methods or protocols operate on values (e.g. keys, signatures) which are fully- homomorphically encrypted. More specifically, the methods and protocols can perform mathematical and cryptographic operations on the FHE-encrypted values, thereby increasing security.
[0034] Some such protocols (e.g. some threshold signature systems) require utilization of pseudorandom values that are a deterministically derivative of particular input values.
[0035] In some such systems - in order to keep the pseudorandom value (nonce) secret - it is frequently necessary to encrypt the input value (using FHE) and homomorphically perform a complex pseudorandom function (e.g. Secure Hash Algorithms (SHA)-2) upon the FHE-encrypted input value. This operation can be expensive in terms of time and processor cycles, and can significantly increase noise in the ciphertext.
[0036] Some embodiments of the presently disclosed subject matter utilize an optimized method of generation - based on a given input value - of FHE-encrypted pseudorandom numbers. Among the advantages of the optimized method is - in some embodiments - avoiding homomorphic performance of the complex pseudorandom function, and thereby saving time and processor cycles, and avoiding increase of noise in the ciphertext. In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, it will be understood by those skilled in the art that the presently disclosed subject matter may be practiced without these specific details. In other instances, well-known methods, procedures, components and circuits have not been described in detail so as not to obscure the presently disclosed subject matter.
[0037] Unless specifically stated otherwise, as apparent from the following discussions, it is appreciated that throughout the specification discussions utilizing terms such as "processing", "computing", "comparing", "encrypting", “decrypting”, "determining", "calculating", “receiving”, “providing”, “obtaining”, “emulating” or the like, refer to the action(s) and / or process(es) of a computer that manipulate and / or transform data into other data, said data represented as physical, such as electronic, quantities and / or said data representing the physical objects. The term “computer” should be expansively construed to cover any kind of hardware-based electronic device with data processing capabilities including, by way of non-limiting example, the processor, mitigation unit, and inspection unit therein disclosed in the present application.
[0038] The terms "non-transitory memory" and “non-transitory storage medium” used herein should be expansively construed to cover any volatile or non-volatile computer memory suitable to the presently disclosed subject matter.
[0039] The operations in accordance with the teachings herein may be performed by a computer specially constructed for the desired purposes or by a general-purpose computer specially configured for the desired purpose by a computer program stored in a non- transitory computer-readable storage medium.
[0040] Embodiments of the presently disclosed subject matter are not described with reference to any particular programming language. It will be appreciated that a variety of programming languages may be used to implement the teachings of the presently disclosed subject matter as described herein. Fig. 1 illustrates an example system configured to perform pseudorandom number generation in accordance with some embodiments of the presently disclosed subject matter.
[0041] Processing circuitry 100 can include processor 105 and memory 110.
[0042] Processor 105 can be a suitable hardware-based electronic device with data processing capabilities, such as, for example, a general-purpose processor, digital signal processor (DSP), a specialized Application Specific Integrated Circuit (ASIC), one or more cores in a multicore processor, etc. Processor 105 can also consist, for example, of multiple processors, multiple ASICs, virtual processors, combinations thereof etc.
[0043] Memory 110 can be, for example, a suitable kind of volatile and / or non-volatile storage, and can include, for example, a single physical memory component or a plurality of physical memory components. Memory 110 can also include virtual memory. Memory 110 can be configured to, for example, store various data used in computation.
[0044] Processing circuitry 100 can be configured to execute several functional modules in accordance with computer-readable instructions implemented on a non-transitory computer-readable storage medium. Such functional modules are referred to hereinafter as comprised in the processing circuitry. These modules can include, for example, pseudorandom number generation unit (PNGU) 120, optional threshold signature unit 125 and communication unit 115.
[0045] Processing circuitry 100 can include communication unit 115. Communication unit 115 can be a suitable type of communication interface for sending or receiving data, exchanging data with other systems. Communication unit 115 can receive, for example, encrypted signature keys and can perform key distribution to receive threshold decryption keys.
[0046] Pseudorandom number generation unit 120 can perform pseudorandom number generation, for example, as part of cryptographic protocols.
[0047] In some embodiments, pseudorandom number generation unit 120 performs a method of generating a homomorphically encrypted pseudorandom value that is derivative of a seed value. Such pseudorandom values can be utilized in various cryptographic applications and protocols (such as threshold signature verification mechanisms, as will be described below).
[0048] In some such embodiments, an efficient and optimized method of pseudorandom number generation is utilized - increasing speed, reducing processing requirements, and reducing noise - by avoiding homomorphic evaluation of complex hash functions, as will be described in detail below with reference to Fig. 2.
[0049] Optional threshold signature unit 125 can e.g. perform a threshold signature verification application utilizing a homomorphically encrypted pseudorandom value generated by pseudorandom number generation unit 120, as described below with reference to Fig. 4.
[0050] It is noted that the teachings of the presently disclosed subject matter are not bound by the systems described with reference to Fig. 1 or Fig. 3. Equivalent and / or modified functionality can be consolidated or divided in another manner and can be implemented in any appropriate combination of software with firmware and / or hardware and executed on a suitable device. The systems can each be a standalone entity, or integrated, fully or partly, with other entities - via a network or other means.
[0051] Fig- 2 illustrates a flow diagram of an example method of generating, from an input value, a homomorphic encryption of a random value (herein termed a nonce), the nonce being pseudorandomly derivative of the input value, in accordance with some of embodiments of the presently disclosed subject matter.
[0052] Some embodiments of the presently disclosed subject matter utilize an optimized method of generation of an FHE-encrypted pseudorandom number- based on a given input value. Among the advantages of the optimized method are - in some embodiments - avoiding homomorphic performance of the complex pseudorandom function, and thereby saving time and processor cycles, and avoiding increase of noise in the ciphertext. More formally, the generation can be characterized by: Output = PRF (Input) where Input is a series of bits, and Output is a homomorphic encryption of a plaintext value (under a particular FHE encryption key).
[0053] Processing circuitry 100 (for example: pseudorandom number generation unit 120) can obtain 205 an input value.
[0054] By way of non-limiting example, some Elliptic Curve Digital Signature Algorithm (ECDSA) signature schemes utilize a signing key for signing, and also specify a particular input value for the derivation of the nonce i.e. from a concatenation of a message and its signing key. This example is further described hereinbelow, with reference to Fig. 4.
[0055] Processing circuitry 100 (for example, pseudorandom number generation unit 120) can next perform a hash function on the input value. For example, processing circuitry 100 (for example, pseudorandom number generation unit 120) can perform the SHA-2 hash on the input value. The output of the hash function can be a bit series of a particular length (e.g. 256 bits) - and can be interpreted e.g. as a positive integer.
[0056] It is noted that processing circuitry 100 (for example, pseudorandom number generation unit 120) can - in some embodiments - apply a function other than SHA-2, provided that the function’s characteristics match application-specific requirements of a pseudorandom number generator (such as determinism, collision resistance etc.). As used herein, the term “hash function” is interpreted to include all such functions.
[0057] Next, processing circuitry 100 (for example, pseudorandom number generation unit 120) can, utilizing a suitable mapping function, map 215 the hash result (e.g. the integer) to an element of the ciphertext space.
[0058] For example - processing circuitry 100 (for example, pseudorandom number generation unit 120) can perform the mapping by creating a ciphertext element bit-by-bit from the integer hash function result, where each bit of the ciphertext element is assigned a representation from a corresponding integer bit. In some embodiments, this mapping function can be a one-to-one function i.e.: a mapping f : X — > Y such that for every pair of distinct inputs xi and X2 in X, their images are distinct; that is, x, X2 f(xi) f(x2). In other words, each different x yields a different y.
[0059] It is noted that that this resulting ciphertext element may or may not be a homomorphic encryption of some plaintext value, under a particular encryption key.
[0060] Processing circuitry 100 (for example, pseudorandom number generation unit 120) can then utilize the evaluation key that is associated with a particular decryption key, and can bootstrap 220 the ciphertext space element that resulted from applying the mapping function to the hash result. The result will then be a second ciphertext element, which is a homomorphic encryption, under the particular encryption key, of some plaintext value (this plaintext value can then constitute the nonce).
[0061] It is noted that the result of the method described in Fig. 2 matches - for many applications / contexts - requirements of cryptographic pseudorandom function.
[0062] It is further noted that the nonce resulting from the method described in Fig. 2 is secret, and is deterministically derivative of the input value. Consequently, when multiple parties employ the method of Fig. 2, each will derive the same result. This property can be important in some applications (e.g. the threshold signature method described below, with reference to Fig. 4).
[0063] It is further noted that the nonce resulting from the method described in Fig. 2 can match requirements of pseudorandom functions (e.g. collision resistance, one-wayness, secondary preimage resistance etc.)
[0064] It is further noted that the method of Fig. 2 avoids homomorphic performance of a complex pseudorandom function, and thus can be more cost-effective in terms of time and processor cycles, and thus can avoid concomitant increase of noise in the ciphertext.
[0065] Following the derivation of the encrypted nonce (i.e. the second ciphertext space element), processing circuitry 100 (for example, threshold signature unit 125 can perform a homomorphic evaluation (i.e. calculation) based on the encrypted nonce (e.g. in a use case such as the one described with reference to Fig. 4). It is noted that the teachings of the presently disclosed subject matter are not bound by the flow diagrams illustrated in Fig. 2 and Fig. 4, the illustrated operations can occur out of the illustrated order. It is also noted that whilst the flow chart is described with reference to elements of the systems of Figs. 1 and 3, this is by no means binding, and the operations can be performed by elements other than those described herein.
[0066] Fig- 3 illustrates an example system configuration for performance of a threshold signature protocol based on a pseudorandom number generation nonce, in accordance with some embodiments of the presently disclosed subject matter.
[0067] A first party 305A, a second party 305B, and up to an nth party 305N can be computer systems which are operably connected to a network 310. First party 305A, second party 305B, and up to the nth party 305N can each receive a threshold share of a fully homomorphic decryption key. First party 305 A, second party 305B, through nth party 305N can further receive a homomorphic encryption of a private signature key based on a threshold signature scheme such as ECDSA.
[0068] First party 305A, second party 305B, through nth party 305N can then perform a threshold signature mechanism protocol in which each party utilizes a pseudorandomly generated nonce. By performing pseudorandom nonce generation, each party can utilize the same nonce in its signature, thereby providing necessary nonce-based security protections while enabling group signing.
[0069] Details of the cryptographic method are described below with reference to Fig. 4.
[0070] Fig. 4 illustrates a flow diagram of an example method of threshold signature verification based on an optimized pseudorandom function, in accordance with some embodiments of the presently disclosed subject matter.
[0071] A threshold decryption key share can be a component of a cryptographic system where the secret decryption key is divided among multiple parties, such that only a subset of them — meeting a predefined threshold — must collaborate to successfully decrypt a message. This approach, known as threshold cryptography, enhances security and fault tolerance by ensuring that no single party holds the entire decryption key, reducing the risk of compromise. Each party holds a "share" of the key, and when the threshold number of shares (e.g., 3 out of 5) are combined, they can jointly reconstruct the decryption operation without revealing the full key to any individual.
[0072] The method illustrated in Fig. 4 can use FHE to perform an algorithm of threshold signature validation. Specifically, after a threshold number of validators have signed a message (e.g. a cryptocurrency transaction) using an encrypted signature key, the validators (for example) can then joint decrypted the resulting encrypted signature, so that the actual signature of the transaction becomes available.
[0073] Processing circuitry 100 (for example, threshold signature unit 125) can receive 405 a threshold share of a fully-homomorphic decryption key. Processing circuitry 100 (for example, threshold signature unit 125) can receive the share via - for example - a key distribution mechanism conducted together with a number of other systems.
[0074] Processing circuitry 100 (for example, threshold signature unit 125) can also receive 410 a fully homomorphic encryption of a signature key (for example, a key suitable for a signature method such as ECDSA). The signature key can be fully homomorphically encrypted of under the encryption key corresponding to the received decryption key share.
[0075] Processing circuitry 100 (for example, threshold signature unit 125) can 415 sign a message in accordance with the particular signature method being employed (e.g. ECDSA).
[0076] It is noted that some signature methods specify combining (e.g. concatenating) a pseudorandomly-generated nonce to the message to be signed.
[0077] In some embodiments of the presently disclosed matter, processing circuitry 100 (for example, threshold signature unit 125) performs the signing operation homomorphically (i.e. the operations of the signing are performed using homomorphic mathematical operations), in conjunction with the homomorphically-encrypted signature key, the message, and the nonce. Thus the result of the signing is similarly homomorphically-encrypted. Processing circuitry 100 (for example, threshold signature unit 125) can - in principle - generate the nonce by e.g. homomorphically encrypting a concatenation of the encrypted signature key and the message to be signed. Processing circuitry 100 (for example, threshold signature unit 125) can then homomorphically apply a hash function to the homomorphically-encrypted concatenation, resulting in a pseudorandom homomorphically-encrypted nonce. As noted above, applying a hash function homomorphically in this manner can be expensive in terms of processing power, and can be slow and can increase ciphertext noise.
[0078] Accordingly, processing circuitry 100 (for example, threshold signature unit 125) can - in some embodiments of the presently disclosed subject matter - generate the nonce in accordance with the method described above with reference to Fig. 2, thereby reducing delay, use of processing resources, and ciphertext noise increase.
[0079] Processing circuitry 100 (for example, pseudorandom number generation unit 120) can next - utilizing its threshold share of the decryption key - perform threshold decryption 420 of the homomorphically encrypted signature, thereby resulting in a decryption share of the message signature that is based on the pseudorandom nonce.
[0080] Processing circuitry 100 (e.g., pseudorandom number threshold signature unit) can merge 430 the resulting decryption share with one or more additional decryption shares, (e.g. received from other participating systems) thereby resulting in the signature that is based on the pseudorandom nonce. Processing circuitry 100 (for example, threshold signature unit 125) can then validate the signature.
[0081] It is to be understood that the invention is not limited in its application to the details set forth in the description contained herein or illustrated in the drawings. The invention is capable of other embodiments and of being practiced and carried out in various ways. Hence, it is to be understood that the phraseology and terminology employed herein are for the purpose of description and should not be regarded as limiting. As such, those skilled in the art will appreciate that the conception upon which this disclosure is based may readily be utilized as a basis for designing other structures, methods, and systems for carrying out the several purposes of the presently disclosed subject matter. It will also be understood that the system according to the invention may be, at least partly, implemented on a suitably programmed computer. Likewise, the invention contemplates a computer program being readable by a computer for executing the method of the invention. The invention further contemplates a non-transitory computer-readable memory tangibly embodying a program of instructions executable by the computer for executing the method of the invention.
[0082] Those skilled in the art will readily appreciate that various modifications and changes can be applied to the embodiments of the invention as hereinbefore described without departing from its scope, defined in and by the appended claims.
Claims
CLAIMS1. A processor-based method of generating, from an input value, a homomorphic encryption of a nonce, the nonce being pseudorandomly derivative of the input value, the method comprising: applying a hash function to the input value, thereby resulting in a hash result; applying a mapping function to the hash result, application of the mapping function resulting in a first ciphertext space element; and utilizing an evaluation key associated with an encryption key, performing a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element, the second ciphertext space element being a homomorphic encryption, under the encryption key, of a value pseudorandomly derivative of the input value.
2. The method of claim 1, additionally comprising: performing a homomorphic calculation based on the second ciphertext space element.
3. The method of claim 1, wherein the hash result is a bit series of a given length.
4. The method of claim 3, wherein the hash function is SHA-2.
5. The method of claim 1, wherein the mapping function is a one-to-one mapping function.
6. A system of generating, from an input value, a homomorphic encryption of a nonce, the nonce being pseudorandomly derivative of the input value, the system comprising a processing circuitry configured to: apply a hash function to the input value, thereby resulting in a hash result; apply a mapping function to the hash result, application of the mapping function resulting in a first ciphertext space element; utilize an evaluation key associated with an encryption key, to perform a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element, the second ciphertext space element being a homomorphic encryption, under the encryption key, of a value pseudorandomly derivative of the input value.
7. A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processing circuitry, cause the processing circuitry to perform a method of generating, from an input value, a homomorphic encryption of a nonce, the nonce being pseudorandomly derivative of the input value, the method comprising: applying a hash function to the input value, thereby resulting in a hash result; applying a first mapping function to the hash result, the mapping function resulting in a first ciphertext space element; utilizing an evaluation key associated with an encryption key, performing a bootstrapping procedure upon the first ciphertext ring element, thereby resulting in a second ciphertext space element,the second ciphertext space element being a homomorphic encryption, under the encryption key, of a value pseudorandomly derivative of the input value.
8. A method of threshold validation of a signature, the signature being a signature of a message, the method comprising: a) receiving a fully homomorphic encryption of a signature key, under an encryption key; b) utilizing the fully homomorphic encryption of the signature key, performing a homomorphic signature computation based on, at least: the signature key, the message, and a nonce, thereby signing the message; wherein the nonce is a derivative of a method comprising: i. applying a hash function to an input value that is derivative of, at least, the message, thereby resulting in a hash result, ii. applying a mapping function to the hash result, the mapping function resulting in a first ciphertext space element, and iii. utilizing an evaluation key associated with the encryption key, performing a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element.
9. The method of claim 8, further comprising: receiving a threshold share of a fully homomorphic decryption key, wherein the decryption key corresponds to the received encryption key;utilizing the received threshold share to perform threshold decryption of the homomorphically-encrypted signature, thereby resulting in a decryption share of the homomorphically-encrypted signature; and merging the resulting decryption share with one or more additional decryption shares, thereby resulting in the signature.
10. A system of threshold validation of a signature, the signature being a signature of a message, the system comprising a processing circuitry (PC) configured to: a) receive a fully homomorphic encryption of a signature key, under an encryption key; b) utilizing the fully homomorphic encryption of the signature key, performing a homomorphic signature computation based on, at least: the signature key, the message, and a nonce, thereby signing the message; wherein the PC is further configured to: i. apply a hash function to an input value that is derivative of, at least, the message, thereby resulting in a hash result, ii. apply a mapping function to the hash result, the mapping function resulting in a first ciphertext space element, iii. utilize an evaluation key associated with the fully homomorphic decryption key to perform a bootstrapping procedure upon the firstciphertext space element, thereby resulting in a second ciphertext space element, and wherein the nonce is based on the second ciphertext space element.
11. A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processing circuitry, cause the processing circuitry to perform a method of threshold validation of a signature, the signature being a signature of a message, the method comprising: a) receiving a fully homomorphic encryption of a signature key, under an encryption key; b) utilizing the fully homomorphic encryption of the signature key, performing a homomorphic signature computation based on, at least: the signature key, the message, and a nonce, thereby signing the message; wherein the nonce is a derivative of a method comprising: i. applying a hash function to an input value that is derivative of, at least, the message, thereby resulting in a hash result, ii. applying a mapping function to the hash result, the mapping function resulting in a first ciphertext space element, andiii. utilizing an evaluation key associated with the encryption key, performing a bootstrapping procedure upon the first ciphertext space element, thereby resulting in a second ciphertext space element.
Citation Information
Patent Citations
Method, apparatus, and system for providing a homomorphic cryptosystem
US20210099308A1
Method for Generating a Digital Signature of an Input Message
US20220173914A1
Apparatus for generating blind signature and method thereof
US20230291573A1
Cited By
Safe remote control and cut-off method for electric energy meter
CN121567336A