Compression of the BGV evaluation key

The method of using a single KSK for homomorphic encryption key-switching in homomorphic encryption systems addresses noise control and modulus switching inefficiencies, enhancing key management and reducing complexity in resource-constrained settings.

WO2025248516A1PCT designated stage Publication Date: 2025-12-04DWALLET LABS LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/IL2025/050444
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-26
Filing Date
2025-05-25
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

Conventional homomorphic encryption systems face challenges with noise control, modulus switching, and key-switching, leading to inefficiencies in key management and computational complexity.

Method used

A method and system for switching encryption keys in homomorphic encryption using a single key-switching key (KSK) based on a fractional decomposition, allowing for modulus-switching without a 'ladder' of keys, and a computer program product to implement this process.

Benefits of technology

This approach simplifies key establishment protocols, reduces key length, and decreases communication and computational complexity while maintaining encryption integrity, particularly beneficial in resource-constrained environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IL2025050444_04122025_PF_FP_ABST
    Figure IL2025050444_04122025_PF_FP_ABST
Patent Text Reader

Abstract

A processor-based method of switching encryption keys of a homomorphically- encrypted ciphertext, the ciphertext being of a first ciphertext modulus, the method comprising: obtaining a key-switching key (KSK), the KSK being based on an encryption, under a first encryption key, of a fractional decomposition of a second encryption key, the first and second encryption keys being of a second ciphertext modulus that is greater than the first ciphertext modulus; computing a fractional decomposition of a value derivative of: the ciphertext, and the first ciphertext modulus; deriving, from the KSK, a modulus- switched KSK that is of the first ciphertext modulus; and deriving, based on the modulus-switched KSK and the fractional decomposition of the value, a key- switched ciphertext, the ciphertext modulus of the key-switched ciphertext being of the first ciphertext modulus.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] COMPRESSION OF THE BGV EVALUATION KEY

[0002] TECHNICAL FIELD

[0003] The presently disclosed subject matter relates to use of homomorphic encryption, and in particular to implementation of encryption key management for homomorphic encryption.

[0004] BACKGROUND

[0005] Problems of noise control, modulus switching, and key-switching in homomorphic encryption systems have been recognized in the conventional art.

[0006] SUMMARY

[0007] According to one aspect of the presently disclosed subject matter there is provided a processor-based method of switching encryption keys of a homomorphically-encrypted ciphertext, the ciphertext being of a first ciphertext modulus, the method comprising: obtaining a key-switching key (KSK), the KSK being based on an encryption, under a first encryption key, of a fractional decomposition of a second encryption key, the first and second encryption keys being of a second ciphertext modulus that is greater than the first ciphertext modulus; computing a fractional decomposition of a value derivative of: the ciphertext, and the first ciphertext modulus; deriving, from the KSK, a modulus-switched KSK that is of the first ciphertext modulus; and deriving, based on the modulus-switched KSK and the fractional decomposition of the value, a key-switched ciphertext, the ciphertext modulus of the key-switched ciphertext being of the first ciphertext modulus. In addition to the above features, the method according to this aspect of the presently disclosed subject matter can further comprise one or more of features (i) to (iv) listed below, in any desired combination or permutation which is technically possible:

[0008] (i) each fractional decomposition being a binary fractional decomposition;

[0009] (ii) the fractional decomposition being based on: where f \x) outputs the 1 most significant base-b digits of x, Ciphertext denotes the ciphertext, CiphertextModulus denotes the first ciphertext modulus, 1 denotes a dimension, and b denotes a base of the decomposition;

[0010] (iii) the obtained KSK is based on a sequence of ciphertext elements d-| k lwherein the sequence is in accordance with: where: n denotes a number of components in the first encryption key, p denotes a plaintext modulus associated with the first and second encryption key, q denotes the second ciphertext modulus, b denotes a decomposition base,

[0011] 1 denotes a dimension of the fractional decomposition of the second encryption key, s[j] denotes a j-th component of the first encryption key, s’ denotes the second encryption key, ej,k denotes a noise term, and

[0012] E|.k denotes a number of ciphertext modulo reductions performed upon decryption of

[0013] (iv) the key-switched ciphertext is based on where DecomposedCiphertext{j,k} denotes a k-th digit of a j-th entry of the fractional decomposition of the ciphertext.

[0014] According to another aspect of the presently disclosed subject matter there is provided a system of switching encryption keys of a homomorphically-encrypted ciphertext, the ciphertext being of a first ciphertext modulus, the system comprising a processing circuitry configured to: obtain a key-switching key (KSK), the KSK being based on an encryption, under a first encryption key, of a fractional decomposition of a second encryption key, the first and second encryption keys being of a second ciphertext modulus that is greater than the first ciphertext modulus; compute a fractional decomposition of a value derivative of: the ciphertext, and the first ciphertext modulus; derive, from the KSK, a modulus-switched KSK that is of the first ciphertext modulus; and derive, based on the modulus-switched KSK and the fractional decomposition of the value, a key-switched ciphertext, the ciphertext modulus of the key-switched ciphertext being of the first ciphertext modulus. This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (iv) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.

[0015] According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer-readable non-transitory storage medium containing program instructions which, when read by processing circuitry, cause the processing circuitry to perform a method of switching encryption keys of a homomorphically-encrypted ciphertext, the ciphertext being of a first ciphertext modulus, the method comprising: obtaining a key-switching key (KSK), the KSK being based on an encryption, under a first encryption key, of a fractional decomposition of a second encryption key, the first and second encryption keys being of a second ciphertext modulus that is greater than the first ciphertext modulus; computing a fractional decomposition of a value derivative of: the ciphertext, and the first ciphertext modulus; deriving, from the KSK, a modulus-switched KSK that is of the first ciphertext modulus; and deriving, based on the modulus-switched KSK and the fractional decomposition of the value, a key-switched ciphertext, the ciphertext modulus of the key-switched ciphertext being of the first ciphertext modulus.

[0016] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (iv) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.

[0017] BRIEF DESCRIPTION OF THE DRAWINGS In order to understand the invention and to see how it can be carried out in practice, embodiments will be described, by way of non-limiting examples, with reference to the accompanying drawings, in which:

[0018] Fig- 1 is a block diagram of an example encryption / decryption supporting ladderless homomorphic encryption key switching, in accordance with some embodiments of the presently disclosed subject matter;

[0019] Fig- 2 illustrates a flow diagram of an example prior art method of key-switching, utilizing a “ladder” of key-switching-keys;

[0020] Fig- 3 illustrates a flow diagram of an example method of scale- free key switching, in accordance with some embodiments of the presently disclosed subject matter; and

[0021] Fig. 4 illustrates a block diagram of an example computing device, in accordance with embodiments of the present disclosure.

[0022] DETAILED DESCRIPTION

[0023] In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, it will be understood by those skilled in the art that the presently disclosed subject matter may be practiced without these specific details. In other instances, well-known methods, procedures, components and circuits have not been described in detail so as not to obscure the presently disclosed subject matter.

[0024] Unless specifically stated otherwise, as apparent from the following discussions, it is appreciated that throughout the specification discussions utilizing terms such as "processing", "computing", "comparing", "encrypting", “decrypting”, "determining", "calculating", “receiving”, “providing”, “obtaining”, “emulating” or the like, refer to the action(s) and / or process(es) of a computer that manipulate and / or transform data into other data, said data represented as physical, such as electronic, quantities and / or said data representing the physical objects. The term “computer” should be expansively construed to cover any kind of hardware-based electronic device with data processing capabilities including, by way of non-limiting example, the processor, mitigation unit, and inspection unit therein disclosed in the present application.

[0025] The terms "non-transitory memory" and “non-transitory storage medium” used herein should be expansively construed to cover any volatile or non-volatile computer memory suitable to the presently disclosed subject matter.

[0026] The operations in accordance with the teachings herein may be performed by a computer specially constructed for the desired purposes or by a general-purpose computer specially configured for the desired purpose by a computer program stored in a non- transitory computer-readable storage medium.

[0027] Embodiments of the presently disclosed subject matter are not described with reference to any particular programming language. It will be appreciated that a variety of programming languages may be used to implement the teachings of the presently disclosed subject matter as described herein.

[0028] Fig- 1 is a block diagram of an example encryption / decryption supporting ladderless homomorphic encryption key switching, in accordance with some embodiments of the presently disclosed subject matter.

[0029] Encryption / decryption system (processing circuitry) 100 can be a system adapted to encrypt and / or decrypt data using homomorphic encryption techniques - for example: the BGV (Brakerski-Gentry-Vaikuntanathan) scheme or similar schemes (such as Brakerski-Fan-Vercauteren (BFV) or Cheon-Kim-Kim-Song (CKKS)) - and / or to perform operations (e.g. mathematical computations) upon such data.

[0030] Processor 105 can be a suitable hardware-based electronic device with data processing capabilities, such as, for example, a general purpose processor, digital signal processor (DSP), a specialized Application Specific Integrated Circuit (ASIC), one or more cores in a multicore processor, etc. Processor 105 can also consist, for example, of multiple processors, multiple ASICs, virtual processors, combinations thereof etc.

[0031] Memory 110 can be, for example, a suitable kind of volatile and / or non-volatile storage, and can include, for example, a single physical memory component or a plurality of physical memory components. Memory 110 can also include virtual memory. Memory 110 can be configured to, for example, store various data used in computation.

[0032] Encryption / decryption system (processing circuitry) 100 can be configured to execute several functional modules in accordance with computer-readable instructions implemented on a non-transitory computer-readable storage medium. Such functional modules are referred to hereinafter as comprised in the processing circuitry. These modules can include, for example, encryption / decryption unit 125, key establishment unit 130, key switching unit 135, modulus switching unit 140, homomorphic operations unit 145, and communications unit 115.

[0033] Encryption / decryption unit 125 can perform e.g. BGV encryption and decryption operations. For example: encryption / decryption unit 125 can obtain a plaintext, and utilize e.g. a BGV encryption key (e.g. as received from key establishment unit 130) to encrypt the plaintext to a ciphertext (e.g. or a particular ciphertext space associated with the encryption key).

[0034] Encryption / decryption unit 125 can also utilize an encryption key that is derivative of a key establishment process.

[0035] Key establishment unit 130 can, for example, perform (or participate in) secure generation and distribution of various cryptographic keys. For example: key establishment unit 130 can participate in a key establishment protocol with one or more peer systems. Key establishment methods / protocols can result in e.g.: encryption / decryption keys (asymmetric or symmetric); one or more key switching keys (KSKs); and / or relinearization keys etc. It is noted that a key establishment protocol / method can generate a “ladder” of KSKs (i.e., a sequence of KSKs where each KSK enables key-switching of a ciphertext of a particular modulus).

[0036] Some embodiments of the presently disclosed subject matter can receive a single “ladderless” KSK (as will be described below), which can then be utilized in keyswitching of ciphertexts with any modulus higher than the KSK modulus, as will be described below.

[0037] Among the advantages of some embodiments of the presently disclosed subject matter is: utilization of the single KSK rather than the ladder can simplify the key establishment protocol. For example, a protocol which uses zero-knowledge proofs for validation of generated keys can benefit from shorter key length.

[0038] Key switching unit 135 can perform key switching, a process that transforms a ciphertext encrypted under one secret key into a functionally equivalent ciphertext under a different secret key.

[0039] Key-switching is a technique used in homomorphic encryption to convert a ciphertext encrypted under one secret key into a ciphertext under another key, without decrypting the message. In the BGV scheme, this can be essential for supporting advanced operations like bootstrapping, modulus switching, and efficient multi-party computation.

[0040] For example, key switching unit 135 can accomplish this transformation by using a special key-switching key, often generated from the original and target secret keys. Prior art methods of key-switching, and well as a ’’ladderless” key-switching method, and how the present technique differs from those prior art methods are described in detail below.

[0041] Modulus switching unit 140 can perform modulus switching on a ciphertext. Modulus switching is a technique in lattice-based homomorphic encryption schemes, like BGV, used to reduce the ciphertext modulus while preserving the underlying plaintext. It helps manage noise growth during homomorphic operations by scaling down both the ciphertext and its associated noise. The ciphertext components are rescaled proportionally to a smaller modulus, ensuring continued correctness of decryption.

[0042] Homomorphic operations unit 145 can perform arithmetic operations such as multiplication or addition upon ciphertexts.

[0043] Communications unit 115 facilitates the transmission and reception of encrypted or unencrypted data (and key establishment protocols) to / from external systems. Communications unit can 115 utilize a wired or wireless communication technique, e.g. thernet, Infiniband, e3G, 4G, 5G wireless, Wi-Fi, etc.

[0044] It is noted that the teachings of the presently disclosed subject matter are not bound by the systems described with reference to Fig. 1. Equivalent and / or modified functionality can be consolidated or divided in another manner and can be implemented in any appropriate combination of software with firmware and / or hardware and executed on a suitable device. The systems can each be a standalone entity, or integrated, fully or partly, with other entities - via a network or other means.

[0045] Fig- 2 illustrates a flow diagram of an example prior art method of key-switching, utilizing a “ladder” of KSKs.

[0046] For simplicity of description, the prior art method is described with reference to the encryption system of Fig. 1.

[0047] Processing circuitry 100 (for example: key establishment unit 130) can receive a “ladder” (e.g. sequential array) of Key- Switching Keys (KSKs). Each KSK of the ladder can be a matrix or vector of ciphertext space elements of a particular modulus. Each ciphertext space element of a KSK can be a ciphertext under the new key (s') that encrypts a component of the old key (s).

[0048] More formally: where di(s) denotes the i-th digit (in a chosen base, e.g., base b) in the decomposition of s, and EncQ denotes encryption under the subscripted key.

[0049] A ladder can be indexed by modulus or level in a data structure, thereby enabling access to a suitable KSK for accommodation of changes in modulus during computation.

[0050] Processing circuitry 100 (for example: key switching unit 135) can next receive 210 a ciphertext for key-switching and then decompose the ciphertext.

[0051] A ciphertext c in BGV under secret key s can be a vector (co, ci). Decryption can be performed as: m = co+ ci* s mod q

[0052] To facilitate key-switching, processing circuitry 100 (for example: key switching unit 135) can decompose ci into coefficients ci(1)in base b i.e.:

[0053] This decomposition facilitates the re-encryption of the result under a new key.

[0054] Processing circuitry 100 (for example: key switching unit 135) can next select 215 a KSK from the ladder.

[0055] Because BGV uses modulus switching, the modulus q of the ciphertext determines which KSK should be used. Using the correct KSK ensures the decomposition matches the ciphertext's modulus and secret key structure.

[0056] Processing circuitry 100 (for example: key switching unit 135) can then perform key switching via 220 KSK multiplication and summation.

[0057] For example: each digit from the decomposition can be multiplied with the corresponding KSK ciphertext, i.e.: The final key-switched ciphertext can be computed as:

[0058] This results in a ciphertext under the new key s' that decrypts to the same plaintext.

[0059] Fig- 3 illustrates a flow diagram of an example method of scale- free key switching, in accordance with some embodiments of the presently disclosed subject matter.

[0060] The method of Fig. 3 can enable key-switching of ciphertexts under multiple moduli, based on a single KSK.

[0061] Processing circuitry 100 (e.g. key establishment unit 130) can receive 305 a KSK that is based on an encryption (under a new secret key) of a fractional decomposition of an initial secret key. For example, processing circuitry 100 (e.g. key establishment unit 130) can obtain the KSK as part of a key establishment protocol.

[0062] In some examples, the initial key is the square of the new key.

[0063] The new secret key and initial secret key can both be associated with a particular ciphertext modulus i.e. the ciphertext modulus of the new secret key can be identical with the ciphertext modulus of the initial secret key.

[0064] It is noted that the term “initial secret key” refers to a key under which a particular ciphertext is encrypted before a key-switch operation. A ciphertext may have its key switched multiple times, and in each key switch the current secret key can be termed the “initial” secret key. It is further noted that in some examples, the current key can be identical with the initial key.

[0065] The term “fractional decomposition” is herein interpreted to include (for a given value (termed v) that is less than the ciphertext modulus (termed q) ) a series of coefficients [co, ci ... ci-i] such that, for a given integer base b and dimension 1:

[0066] Put differently: the summation (of a particular dimension 1) can approximate v within a rounding error. The rounding error can be less than b4.

[0067] A binary fractional decomposition is a fractional decomposition in which b is 2.

[0068] A function fx(x / q) can then generate a finite decomposition of 1 / x into a series of coefficients of inverses of b1. Essentially, f \) outputs the most significant 1 base-b digits of x / q.

[0069] More formally, defining f as a vector containing successive negative powers of a base integer b (truncated at dimension 1) , f \x) can be defined as: a mapping [0,1) -> {0,1 J1such that |f * f \x) - x| <= b4

[0070] In some embodiments, the received KSK can be based on a sequence of ciphertext elements d*J’k), wherein the sequence is in accordance with: where: n denotes a number of components in the new encryption key, p denotes a plaintext modulus associated with the encryption keys, q denotes the ciphertext modulus associated with the encryption keys, b denotes a decomposition base,

[0071] 1 denotes a dimension of the fractal decomposition of the initial encryption key, s[j] denotes a j-th component of the initial encryption key, s’ denotes the new encryption key, ej,k denotes a noise term, and Ej,k denotes the number of ciphertext modulo reductions performed upon decryption of d^,k^ using s'

[0072] Processing circuitry 100 (e.g. key switching unit 135) can next receive a ciphertext for key-switching, and can compute 310 a fractional base-b decomposition of this ciphertext. The ciphertext can be - for example - a vector of ciphertext space elements. In some embodiments, processing circuitry 100 (e.g. key establishment unit 130) can compute a fractional base-b decomposition of a value based on a ciphertext space element of the ciphertext - in combination with the modulus of the ciphertext space to which the ciphertext belongs. In some embodiments, processing circuitry 100 (e.g. key establishment unit 130) can compute the decomposition on a value further derivative of other additional values (e.g., the modulus of the plaintext space of the plaintext that the ciphertext encrypts). In some embodiments, processing circuitry 100 (e.g. key establishment unit 130) can compute the decomposition for each ciphertext space element of the j entries of the ciphertext vector.

[0073] More specifically, processing circuitry 100 can compute - for example:

[0074] DecomposedCiphertext = f1(Ciphertext / CiphertextModulus)

[0075] Processing circuitry 100 (e.g. key switching unit 135) can next, modulus switch 315 the KSK, resulting in a modulus-switched KSK with the same modulus of ciphertext to be key-switched.

[0076] By way of non-limiting example: given a KSK associated with a ciphertext modulus q, and a ciphertext for key-switching associated with a ciphertext space with modulus q', where q' < q, such that q' =pq (p being the modulus of the plaintext space of the plaintext corresponding to the ciphertext), the modulus-switched KSK can be derived based on: where r(j,k^ is the smallest norm vector for which d^’® = d(j,k^ . Processing circuitry 100 (e.g. key switching unit 135) can next, based on the fractional decomposition and on the KSK, compute a new ciphertext that is encrypted under the new secret key.

[0077] For example, processing circuitry 100 (e.g. key switching unit 135) can multiply 320 each coefficient of the decomposition result by a corresponding element of the KSK, and sum the resulting products, resulting in the key-switched ciphertext. It is noted that proof of the correctness of this method appears hereinbelow.

[0078] More formally: processing circuitry 100 (e.g. key switching unit 135) can compute:

[0079] NewCiphertext = where DecomposedCiphertext{j,k} is the k-th digit of the j-th entry of DecomposedCiphertext (as defined above).

[0080] It is noted that the teachings of the presently disclosed subject matter are not bound by the flow diagrams illustrated in Fig. 3, the illustrated operations can occur out of the illustrated order. It is also noted that whilst the flow chart is described with reference to elements of the systems of Fig. 1, this is by no means binding, and the operations can be performed by elements other than those described herein.

[0081] Fig- 4 illustrates a diagrammatic representation of a machine in the example form of a computing device 400 within which a set of instructions, for causing the machine to perform any one or more of the methodologies discussed herein, may be executed. In alternative embodiments, the machine may be connected (e.g., networked) to other machines in a Local Area Network (LAN), an intranet, an extranet, or the Internet. The computing device 400 may correspond to or include, for example, processing circuitry 100 of Fig. 1. The machine may operate in the capacity of a server or a client machine in a client-server network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine may be a personal computer (PC), a tablet computer, a set-top box (STB), a Personal Digital Assistant (PDA), a cellular telephone, a web appliance, a server, a network router, switch or bridge, or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while only a single machine is illustrated, the term “machine” shall also be taken to include any collection of machines (e.g., computers) that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.

[0082] The example computing device 400 includes a processing device 402, a main memory 404 (e.g., read-only memory (ROM), flash memory, dynamic random access memory (DRAM) such as synchronous DRAM (SDRAM), etc.), a static memory 406 (e.g., flash memory, static random access memory (SRAM), etc.), and a secondary memory (e.g., a data storage device 428), which communicate with each other via a bus 408.

[0083] Processing device 402 represents one or more general-purpose processors such as a microprocessor, central processing unit, or the like. More particularly, the processing device 402 may be a complex instruction set computing (CISC) microprocessor, reduced instruction set computing (RISC) microprocessor, very long instruction word (VLIW) microprocessor, processor implementing other instruction sets, or processors implementing a combination of instruction sets. Processing device 402 may also be one or more special-purpose processing devices such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), network processor, or the like. Processing device 402 is configured to execute the processing logic (instructions 426) for performing operations and steps discussed herein.

[0084] The computing device 400 may further include a network interface device 422 for communicating with a network 464. The computing device 400 also may include a video display unit 410 (e.g., a liquid crystal display (LCD) or a cathode ray tube (CRT)), an alphanumeric input device 412 (e.g., a keyboard), a cursor control device 414 (e.g., a mouse), and a signal generation device 420 (e.g., a speaker).

[0085] The data storage device 428 may include a machine-readable storage medium (or more specifically a non-transitory computer-readable storage medium) 424 on which is stored one or more sets of instructions 426 embodying any one or more of the methodologies or functions described herein, such as instructions for encryption / decryption unit 125, key establishment unit 130, key switching unit 135, modulus switching unit 140 and / or homomorphic operations unit 145 of Fig. 1. A non- transitory storage medium refers to a storage medium other than a carrier wave. The instructions 426 may also reside, completely or at least partially, within the main memory 404 and / or within the processing device 402 during execution thereof by the computer device 400, the main memory 404 and the processing device 402 also constituting computer-readable storage media.

[0086] While the computer-readable storage medium 424 is shown in an example embodiment to be a single medium, the term “computer-readable storage medium” should be taken to include a single medium or multiple media (e.g., a centralized or distributed database, and / or associated caches and servers) that store the one or more sets of instructions. The term “computer-readable storage medium” shall also be taken to include any medium other than a carrier wave that is capable of storing or encoding a set of instructions for execution by the machine and that cause the machine to perform any one or more of the methodologies of the present disclosure. The term “computer-readable storage medium” shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media.

[0087] In some embodiments, additional hardware and / or firmware may also be included in computing device 400 that corresponds to encryption / decryption unit 125, key establishment unit 130, key switching unit 135, modulus switching unit 140 and / or homomorphic operations unit 145 of Fig. 1.

[0088] Text of the provisional disclosure (containing proofs and additional relevant information) appears hereinbelow:

[0089] On Compressing The BGV Evaluation Key

[0090] Abstract. This note is concerned with the key generation process for the BGV FHE scheme (Brakerski, Gentry, Vaikuntanathan, ITCS 12). In the textbook key-generation for this scheme, one has to generate and publish a fresh set of so-called “key-switching parameters” for every modulus in a “ladder of moduli” . We show that this step can be avoided, so that key-switching parameters are only generated for the “top” modulus. The per-modulus parameters are generated on-the-fly during the evaluation process. We discuss the advantages and limitations of this approach.

[0091] 1 Introduction

[0092] The BGV Fully Homomorphic Encryption (FIIE) scheme [BGV 12] uses two techniques when homomorphically evaluating a multiplication operation: keyswitching and modulus-switching. Key-switching requires a public evaluation key, while modulus-switching does not. Alas, modulus-switching changes the modulus of its output ciphertext. The key- switching parameters, per the textbook implementation, depend on the modulus. Therefore, the evaluation key for the textbook BGV scheme requires generating modulus-switching parameters for each modulus in the “ladder of moduli” that will be generated by modulus switching during homomorphic evaluation. If this ladder has L levels, then the evaluation key contains L “copies” of the evaluation key. Indeed, each copy is with respect to a smaller modulus and is therefore somewhat shorter than the top level, but only by an additive term, so the total size of all key-switching parameters scales linearly with 71. This can be a burden from various aspects. The goal of this note is to examine whether this can be removed.

[0093] Our approach is to generate a single copy of the key-switching parameters, only for the top level of the modulus ladder. We then show how to apply modulus switching to the key switching parameters themselves in order to convert them from the top-level modulus to any other modulus in the ladder. Therefore, the modulus-switching parameters can become L times shorter

[0094] Our technique requires to modify the way key-switching is performed. In particular, in textbook key switching, one creates “pseudo-ciphertexts” Cjj, for any element 2ls [y] which is a product of a power of two with a secret-key element. In our solution, the pseudo-ciphertext will encode < / 2 ' .s [7] instead. That is, instead of positive powers of two, we consider negative powers of two, multiplied by the top-level modulus q. This means that whereas in textbook key-switching, we consider a decomposition of the input ciphertext into bits, in our key-switching we decompose the input ciphertext divided by q into negative powers of 2 (since the 2 number is smaller than one). We call this new technique “scale- free binary decomposition” . This may change the computational complexity of key-switching, which needs to be taken into account.

[0095] The above brings to mind the B / FV approach of “scale invariant FHE” [Bral2, FV12] which indeed proposes to view the ciphertext divided by q as more fundamental than an ordinary ciphertext. B / FV- style FHE does not require modulus switching at all, so it does not suffer from the above drawbacks. However, one may still wish to perform modulus switching even in B / FV in order to improve efficiency. Again, the textbook method for doing this will require key-switching parameters for each modulus. Indeed, our method here could apply in the same way (and perhaps even more naturally) to B / FV.

[0096] It is important to point out that while our approach “compresses” the evaluation key for the BGV scheme, it does not seem to lead to improvement in the computational complexity. Indeed, a user will still need to use the “compressed” key to derive the “uncompressed” key in order to perform the homomorphic evaluation. Our approach might offer an advantage in a setting where storage is particularly scarce, by allowing to generate the modulus-switching parameters “on the fly” : whenever a certain level of modulus-switching is required, the respective parameters are generated, and there is no need to keep the entire “uncompressed” key in memory. However, this approach would be costly in terms of computational complexity, and we are not sure that it will find much use. However, we do believe that our approach may find applications in the distributed setting, where parties wish to come together to generate parameters for an FHE scheme. In this setting, the key that is generated must be validated, which may be done by parties providing zero-knowledge proofs for the messages that they send. Tn such a case, a reduction in the size of the key that needs to be generated can be directly translated to a factor- L reduction in the communication complexity and the computational complexity of proof generation.

[0097] 2 Preliminaries

[0098] As usual in lattice-based cryptography literature, for x C ZQ, we define |rc| = min / jgz |x + kq\. This is simply the absolute value of the (only) representative of x (mod q) that lies between [— g / 2, g / 2).

[0099] We recall the gadget vector for binary decomposition modulo eg (formally introduced in [MP 12]). We define the “gadget vector” g = [1, . . . , 2€], where t = (log — 1, and derive the binary decomposition operator g1: Zf / ;• {0, 1}A so that g • g1f.r j = x for all x t ZQ.

[0100] 2.1 BGV-Style FHE

[0101] We consider the properties of the BGV scheme [BGV 12] that are relevant for this work. For the sake of simplicity, we consider the LWE-based version of the scheme, and not the more commonly used RLWE-based versions. Our methods work equally well for all versions, and the LWE version is easier to describe. The On Compressing The BGV Evaluation Key 3 scheme has quite a few parameters, but we only discuss those that are relevant for this work. In particular, we consider the ciphertext modulus q, which means that ciphertexts are vectors over Zq, and the plaintext modulus p, which means that encrypted messages are over Zp. We note that in BGV, p, q need to be coprime (otherwise the scheme is trivially not secure).

[0102] Ciphertexts in BGV-style schemes are of the form c G ZJ, and secret keys are of the form s G Z”. It is useful to consider the elements of c as integers in the range [— Q / 2, q / 2) and express the inner product c • s G Z as c • s = m + pe + qE , (1) where m, e, E are integers so that m G [— p / 2,p / 2) and m + pe G [—q / 2, q / 2). Note that under these constraints, m, e, E arc uniquely determined by the value of c • s. The above implies that c • s =qm + pe and therefore that m = (c • s (mod q)) (mod p). For the sake of correctness of homomrphic evaluation, it is often required that + pe\ C q. We therefore denote the invariant noise of the ciphertext c with respect to s as

[0103] Likewise we can refer to the implicit message in c with respect to s as jus(c) = m . (3)

[0104] We omit the subscript s when it is clear from the context.

[0105] In terms of security, the only feature that we require is that it is possible to generate, during the key generation process,

[0106] 2.2 Key-Switching

[0107] Key-Switching [BVi 1,BGV12] is a procedure that translates a ciphertext c with ciphertext modulus q and dimension n respective to a secret key s, into c' with the same modulus and dimension n’ respective to s'. The required properties are: (4) (nlog Q) , (5) where v is some fixed polynomial. We note that in practical settings the actual value of v may be important and one attempts to analyze it as tightly as possible given all properties and parameters of the scheme. In this work, however, we are interested in presenting a solution for a broad a class of parameters as possible, so it suffices for us to require that v is some polynomial.

[0108] The key-switching parameters takes as additional input the key switching parameters ksp, which are public parameters that are generated during the key generation of the scheme. In particular, knowledge of s is required in or deer to generate ksp. 4

[0109] The BGV key-switching mechanism is as follows. The key-switching parameters are generated as ksp where d^,k) are pseudo-ciphertexts under the key s' with the property that where we have a bound < ft for some global bound ft.

[0110] To use ksp for key switching c into c' we do the following. We compute y = g1fcj G {0, I}"10®?, the binary decomposition of c using the gadget g, so that is the fc-th bit of the y-th entry in c. We then set namely to be the subset sum of the entries with respect to y. A straightforward calculation (done many times in the literature) shows that

[0111] 2.3 Modulus- Switching

[0112] Modulus switching [BGV 12] is a procedure that translates a ciphertext c with dimension n and modulus q. encrypted with respect to a secret key s, into a ciphertext c' encrypted with respect to the same s, but with modulus q' < q. It is required that q' =pq (and of course q, q' are coprime to p). The requirements are syntactically similar to those of key switching: ps / (c') = ps(c) (11)

[0113] <5s(c') < 5s(c) + ! / (nlog p) , (12) however notice that the secret key s is the same for c, c', and that <5s(c') is defined with respect to q' whereas Js(c) is with respect to q.

[0114] Textbook modulus-switching does not require any special parameters, and is simply done by setting c' = ^-c + r, where r is chosen to be the minimum-norm vector s.t. c =pc' . The vector r is therefore chosen by rounding each clement in ^-c[j] into the nearest element in c[j] +pZ. Therefore it holds that 11 r|| < p / 2.

[0115] Claim 2.1 (Textbook Modulus Switching). If c • s = m + pe + qE then

[0116] Proof. We have that c' • s = (q' / q)c • s + r ■ s (13)

[0117] = E pe + qE) + r • s (14)

[0118] = iq' / q)(rn + pe) + r ■ s + q'E . (15) On Compressing The BGV Evaluation Key 5

[0119] Therefore

[0120] It remains to show that m remains the same. Since c =pc' and q =pq' , we have: and the claim follows.

[0121] 3 Our New Key-Switching and Modulus-Switching

[0122] 3.1 Scale- Free Binary Decomposition

[0123] Our scale free binary decomposition is defined as follows. We define a “scale- free gadget” (alternatively “fractional gadget”) f by considering f = [21. . . . , 2; l], We note that we may think of f as an infinitely long vector containing all negative powers of 2, which we truncate at dimension £ for convenience. We can now define f1: [0, 1) -P- {0, 1}€, so that for all x it holds that |f • f1 < 2 ' . Essentially, f1outputs the most significant t bits in the (potentially infinite, fractional) binary representation of x.

[0124] We extend the domain of f1to all of R by taking the input modulo 1. For the scale invariant binary decomposition is f1(a / q).

[0125] 3.2 Scale-Free Key-Switching

[0126] We now present our scale-free notion of key-switching for BGV. We generate the ksp as follows. ksp are pseudo-ciphertexts under the key s' with the property that where we have a bound IfhvLLTk < p for someglobal bound fi. Note that the bound includes an additional additive factor of 0.5 compared to the textbook version of key switching. Essentially this is because we want (3 to also account for the effect of the rounding error of q2fes[j]. We denote the rounding error in the above as

[0127] To use ksp for key switching c into c' we do the following. Let p denote the inverse of p modulo q. We use our new gadget to compute y = f1(pc / r / J G {0, l}n£, the fractional binary decomposition of pc, so that y^ is the fc-th bit of the y-th entry in c. We then set namely to be the subset sum of the d^*-1entries with respect to y.

[0128] Claim 3.1. It holds that c' • s' =qc • s + pe, where |e| / q < nlog q • j3 + 2 ' s]^ .

[0129] Proof. Let us denote {p / q) p / q , ( ) and recall that by the properties of f we have that HfH^

[0130] We have that:

[0131] That is, we have c' • s' =qc • s + pe, where e is an integer. Let us now bound e.

[0132] < |r • s| + nlog q ■ / 3 (32)

[0133] < 2~€||S|| I + nlog Q - / 3 , (33) which concludes the proof of the claim. On Compressing The BGV Evaluation Key 7

[0134] We note that by taking the value of the parameter £ large enough, we can eliminate the effect of the norm of the secret key on the performance. With the “standard” choice of I « log y we already achieve 2-f||s||1< n, even if s contains arbitrarily large values. Taking I logy + log n will make the contribution constant. If we know that s is small, as is often the case in FHE implementations (due to the role played by the key in modulus switching), then it is possible to choose a smaller t and improve the efficiency of key switching, with very little effect on the noise accumulation.

[0135] 3.3 Key-Switching Parameters for Any Modulus

[0136] We now show that if we have key-switching parameters ksp with respect to s, s' and modulus q, and we are given a modulus q' < q s.t. q' =pq, then it is possible to derive ksp' that works with respect to the same s, s', but modulus q' . Specifically, our transformation is simply textbook modulus switching. For all dChfc) jnksp, define the smallest norm vector for which did’k)' =pd^’E . Indeed, ||r<JF) ||^ < p / 2.

[0137] Lemma 3.2. It holds that ksp' is a valid set of key switching parameters modulo q’ with a new relative noise value

[0138] Proof. We know by definition that

[0139] We furthermore have ■ s' — qEpk, and since dC’F) . s' q1Epk—p(h mod p) and d^,fc) .s' qEj,k—p0, we have that h =p0. So we can write h = p • ( [< / '2- / cs[j]J + e'k).

[0140] It remains to bound the magnitude of e'fe. We denote r'k= \q'2fcs[j]J — y'2-fes[j] (and \rj'k| < 1 / 2), so and the lemma follows.

[0141] References

[0142] BGV12. Zvika Brakerski, Craig Gentry, and Vinod Vaikuntanathan. (leveled) fully homomorphic encryption without bootstrapping. In Shafi Goldwasser, editor, Innovations in Theoretical Computer Science 2012, Cambridge, MA, USA, January 8-10, 2012, pages 309-325. ACM, 2012.

[0143] Bral2. Zvika Brakerski. Fully homomorphic encryption without modulus switching from classical gapsvp. In Reihaneh Safavi-Naini and Ran Canetti, editors, Advances in Cryptology - CRYPTO 2012 - 32nd Annual Cryptology Conference, Santa Barbara, CA, USA, August 19-23, 2012. Proceedings, volume 7417 of Lecture Notes in Computer Science, pages 868—886. Springer, 2012.

[0144] BV11. Zvika Brakerski and Vinod Vaikuntanathan. Efficient fully homomorphic encryption from (standard) LWE. In Rafail Ostrovsky, editor, IEEE 52nd Annual Symposium on Foundations of Computer Science, FOCS 2011, Palm Springs, CA, USA, October 22-25, 2011, pages 97 106. IEEE Computer Society, 2011.

[0145] FV12. Junfeng Fan and Frederik Vercauteren. Somewhat practical fully homomorphic encryption. IACR Cryptol. ePrint Arch., page 144, 2012.

[0146] MP12. Daniele Micciancio and Chris Peikert. Trapdoors for lattices: Simpler, tighter, faster, smaller. In David Pointcheval and Thomas Johansson, editors, Advances in Cryptology - EUROCRYPT 2012 - 31st Annual International Conference on the Theory and Applications of Cryptographic Techniques, Cambridge, UK, April 15-19, 2012. Proceedings, volume 7237 of Lecture Notes in Computer Science, pages 700-718. Springer, 2012.

[0147] It is to be understood that the invention is not limited in its application to the details set forth in the description contained herein or illustrated in the drawings. The invention is capable of other embodiments and of being practiced and carried out in various ways. Hence, it is to be understood that the phraseology and terminology employed herein are for the purpose of description and should not be regarded as limiting. As such, those skilled in the art will appreciate that the conception upon which this disclosure is based may readily be utilized as a basis for designing other structures, methods, and systems for carrying out the several purposes of the presently disclosed subject matter.

[0148] It will also be understood that the system according to the invention may be, at least partly, implemented on a suitably programmed computer. Likewise, the invention contemplates a computer program being readable by a computer for executing the method of the invention. The invention further contemplates a non-transitory computer-readable memory tangibly embodying a program of instructions executable by the computer for executing the method of the invention.

[0149] Those skilled in the art will readily appreciate that various modifications and changes can be applied to the embodiments of the invention as hereinbefore described without departing from its scope, defined in and by the appended claims.

Claims

CLAIMS1. A processor-based method of switching encryption keys of a homomorphically- encrypted ciphertext, the ciphertext being of a first ciphertext modulus, the method comprising: obtaining a key-switching key (KSK), the KSK being based on an encryption, under a first encryption key, of a fractional decomposition of a second encryption key, the first and second encryption keys being of a second ciphertext modulus that is greater than the first ciphertext modulus; computing a fractional decomposition of a value derivative of: the ciphertext, and the first ciphertext modulus; deriving, from the KSK, a modulus-switched KSK that is of the first ciphertext modulus; and deriving, based on the modulus-switched KSK and the fractional decomposition of the value, a key-switched ciphertext, the ciphertext modulus of the key- switched ciphertext being of the first ciphertext modulus.

2. The method of claim 1, wherein each fractional decomposition is a binary fractional decomposition.

3. The method of claim 1 wherein the fractional decomposition is based on: f1(Ciphertext / CiphertextModulus) wherein f1(x) is a function which outputs the 1 most significant base-b digits of its input, where:Ciphertext denotes the ciphertext,CiphertextModulus denotes the first ciphertext modulus, 1 denotes a dimension, and b denotes a base of the decomposition. '4. The method of claim 1, wherein the obtained KSK is based on a sequence of ciphertext elements d*Jk), wherein the sequence is in accordance with:where:n denotes a number of components in the first encryption key, p denotes a plaintext modulus associated with the first and second encryption key, q denotes the second ciphertext modulus, b denotes a decomposition base,1 denotes a dimension of the fractional decomposition of the second encryption key, s[j] denotes a j-th component of the first encryption key, s’ denotes the second encryption key, ej,k denotes a noise term, andEj,k denotes a number of ciphertext modulo reductions performed upon decryption using s'.

5. The method of claim 1, wherein the key-switched ciphertext is based on:where DecomposedCiphertext{j,k} denotes a k-th digit of a j-th entry of the fractional decomposition of the ciphertext.

6. A system of switching encryption keys of a homomorphically-encrypted ciphertext, the ciphertext being of a first ciphertext modulus, the system comprising a processing circuitry configured to: obtain a key-switching key (KSK), the KSK being based on an encryption, under a first encryption key, of a fractional decomposition of a second encryption key, the first and second encryption keys being of a second ciphertext modulus that is greater than the first ciphertext modulus; compute a fractional decomposition of a value derivative of: the ciphertext, and the first ciphertext modulus; derive, from the KSK, a modulus-switched KSK that is of the first ciphertext modulus; and derive, based on the modulus-switched KSK and the fractional decomposition of the value, a key-switched ciphertext, the ciphertext modulus of the key-switched ciphertext being of the first ciphertext modulus.

7. The system of claim 6, wherein each fractional decomposition is a binary fractional decomposition.

8. The system of claim 6, wherein the fractional decomposition is based on: f1(Ciphertext / CiphertextModulus) wherein f1(x) is a function which outputs the 1 most significant base-b digits of its input, where:Ciphertext denotes the ciphertext,CiphertextModulus denotes the first ciphertext modulus,1 denotes a dimension, and b denotes a base of the decomposition. '9. The system of claim 6, wherein the obtained KSK is based on a sequence of ciphertext elements d*J’k), wherein the sequence is in accordance with:where:n denotes a number of components in the first encryption key, p denotes a plaintext modulus associated with the first and second encryption key, q denotes the second ciphertext modulus, b denotes a decomposition base,1 denotes a dimension of the fractional decomposition of the second encryption key, s[j] denotes a j-th component of the first encryption key, s’ denotes the second encryption key, ej,k denotes a noise term, andE|.k denotes a number of ciphertext modulo reductions performed upon decryption using s'.

10. The system of claim 6, wherein the key-switched ciphertext is based on:where DecomposedCiphertext^.k} denotes a k-th digit of a j-th entry of the fractional decomposition of the ciphertext.

11. A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor cause the processor to perform a method of switching encryption keys of a homomorphically-encrypted ciphertext, the ciphertext being of a first ciphertext modulus, the method comprising: obtaining a key-switching key (KSK), the KSK being based on an encryption, under a first encryption key, of a fractional decomposition of a second encryption key, the first and second encryption keys being of a second ciphertext modulus that is greater than the first ciphertext modulus; computing a fractional decomposition of a value derivative of: the ciphertext, and the first ciphertext modulus; deriving, from the KSK, a modulus-switched KSK that is of the first ciphertext modulus; and deriving, based on the modulus-switched KSK and the fractional decomposition of the value, a key-switched ciphertext, the ciphertext modulus of the key- switched ciphertext being of the first ciphertext modulus.

12. The computer program product of claim 11, wherein each fractional decomposition is a binary fractional decomposition.

13. The computer program product of claim 11, wherein the fractional decomposition is based on: f1(Ciphertext / CiphertextModulus) wherein f1(x) is a function which output the 1 most significant base-b digits of its input, where:Ciphertext denotes the ciphertext,CiphertextModulus denotes the first ciphertext modulus,1 denotes a dimension, and b denotes a base of the decomposition. '14. The computer program product of claim 11, wherein the obtained KSK is based on a sequence of ciphertext elements dl| k\ wherein the sequence is in accordance with:where:n denotes a number of components in the first encryption key, p denotes a plaintext modulus associated with the first and second encryption key, q denotes the second ciphertext modulus, b denotes a decomposition base,1 denotes a dimension of the fractional decomposition of the second encryption key,s[j] denotes a j-th component of the first encryption key, s’ denotes the second encryption key, ej,k denotes a noise term, andE|.k denotes a number of ciphertext modulo reductions performed upon decryption of d^,k^ using s'.

15. The computer program product of claim 11, wherein the key-switched ciphertext is based on:where DecomposedCiphertext^.k} denotes a k-th digit of a j-th entry of the fractional decomposition of the ciphertext.

Citation Information

Patent Citations

  • Fully Homomorphic Encryption

    US20130170640A1

  • Method and apparatus with homomorphic encryption

    US20240106632A1

  • Fully homomorphic encryption method and device and computer readable storage medium

    WO2020006692A1