Homomorphic decryption method, non-volatile storage medium, and electronic device

By generating a blind rotation key for the blind rotation algorithm using LWE ciphertext and NTRU private key, the problem of unsatisfactory bootstrapping efficiency in FHE is solved, achieving lightweight and efficient homomorphic decryption, which is suitable for resource-constrained devices.

WO2026016096A1PCT designated stage Publication Date: 2026-01-22BEIJING ACAD OF INFORMATION SCI & TECH

Patent Information

Application Number
PCT/CN2024/106013
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-17
Publication Date
2026-01-22

AI Technical Summary

Technical Problem

Existing Fully Homomorphic Encryption (FHE) implementations require significant computational resources and storage space during computation, especially in resource-constrained IoT devices, where bootstrapping efficiency is not ideal, leading to increased computational overhead.

Method used

The blind rotation key of the blind rotation algorithm is generated using LWE ciphertext and NTRU private key. Homomorphic decryption is achieved by iterative processing through multiple computation keys EVK and automorphic keys KSK, reducing the storage requirements of the bootstrap key.

Benefits of technology

It achieves a lightweight and efficient bootstrapping process, improves homomorphic decryption efficiency, reduces the requirements for computing resources, and is suitable for resource-constrained devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024106013_22012026_PF_FP_ABST
    Figure CN2024106013_22012026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present invention are a homomorphic decryption method, a non-volatile storage medium, and an electronic device. The method comprises: acquiring first LWE ciphertext and a private key of the first LWE ciphertext; determining an NTRU private key and a rotation polynomial in a second-layer homomorphic encryption scheme; on the basis of the private key of the first LWE ciphertext and the NTRU private key, generating a blind rotation key corresponding to a blind rotation algorithm; on the basis of the rotation polynomial, the blind rotation key and the blind rotation algorithm, performing homomorphic decryption on the first LWE ciphertext to obtain target NTRU ciphertext; and performing processing on the basis of the target NTRU ciphertext to obtain target LWE ciphertext. The present invention solves the technical problem in the related art of unsatisfactory homomorphic decryption efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Homomorphic decryption method, nonvolatile storage medium and electronic device TECHNICAL FIELD

[0001] The present application relates to the field of encryption technology, the field of lattice cryptography, in particular to a homomorphic decryption method, a non-volatile storage medium and an electronic device. BACKGROUND

[0002] Fully Homomorphic Encryption (FHE) has become an important encryption tool, allowing computations on encrypted data without decryption. However, all existing FHE implementations must introduce noise into the encryption process, which accumulates throughout the computation. To maintain accuracy at depth, noise-elimination steps, called Bootstrapping, must be performed periodically during the computation. Blind rotation is an important step in the bootstrapping process, used to adjust certain properties of the ciphertext without revealing the plaintext information, such as homomorphically decrypting the ciphertext on the exponent.

[0003] Operations such as homomorphic addition and homomorphic multiplication in FHE can require a large amount of computing resources, and as the number of operations increases, the computational overhead will also increase significantly. The blind rotation algorithm in the related art is time-consuming in calculation, and the bootstrapping efficiency is not ideal. The bootstrapping efficiency bottleneck prompts people to continuously research innovative methods to coordinate the calculation efficiency and security, however, the current bootstrapping algorithm requires the calculation end (for example, servers, embedded devices, etc.) to store a large bootstrapping key. At a security strength of 128 bits, all these methods require storage of bootstrapping keys from seventy megabytes to more than one hundred megabytes, which creates limitations in resource-constrained scenarios, such as Internet of Things devices with limited processing power, low bandwidth and power consumption, or limited storage capacity.

[0004] At present, no effective solution has been proposed to solve the above problems.

[0005] SUMMARY

[0006] The embodiments of the present application provide a homomorphic decryption method, a non-volatile storage medium and an electronic device, which at least solve the technical problem of inefficient homomorphic decryption in the related art.

[0007] According to an aspect of an embodiment of the present application, a homomorphic decryption method is provided, comprising: obtaining a first LWE ciphertext and a private key of the first LWE ciphertext, wherein the first LWE ciphertext is a ciphertext to be homomorphic decrypted in a first layer homomorphic encryption scheme, and the first LWE ciphertext is obtained by vector processing based on text information or image information; determining an NTRU private key and a rotation polynomial in a second layer homomorphic encryption scheme, wherein the NTRU private key is used to decrypt an NTRU ciphertext in the second layer homomorphic encryption scheme; generating a blind rotation key corresponding to a blind rotation algorithm according to the private key of the first LWE ciphertext and the NTRU private key, wherein the blind rotation key comprises a plurality of calculation keys EVK and a plurality of self-automorphism keys KSK, the plurality of calculation keys EVK are obtained by encrypting the private key of the first LWE ciphertext based on a vector NTRU encryption method using the NTRU private key respectively, the plurality of self-automorphism keys KSK are key switching keys for self-automorphism processing, and the plurality of self-automorphism keys KSK are obtained by encrypting the self-automorphized NTRU private key based on the vector NTRU encryption method using the NTRU private key; and homomorphic decrypting the first LWE ciphertext based on the rotation polynomial, the blind rotation key, and the blind rotation algorithm in the following manner: generating an intermediate parameter ACC based on the first LWE ciphertext, the rotation polynomial, and a generator in a self-automorphism manner in , wherein the intermediate parameter ACC in is an element on a ring R Q ; obtaining a constant NTRU ciphertext based on the intermediate parameter ACC in and an nth calculation key evk n in the plurality of calculation keys EVK in a ciphertext outer product method ; performing iterative processing based on the constant NTRU ciphertext until a predetermined number of iterations is reached to obtain a constant NTRU ciphertext ; obtaining a target NTRU ciphertext based on the constant NTRU ciphertext , wherein the target NTRU ciphertext corresponds to the NTRU private key; and obtaining a target LWE ciphertext by processing the target NTRU ciphertext.

[0008] Optionally, generating the blind rotation key corresponding to the blind rotation algorithm based on the private key of the first LWE ciphertext and the NTRU private key includes: encrypting the 0th to (n-1th)th components included in the private key of the first LWE ciphertext according to the NTRU private key, the parameters of the NTRU ciphertext corresponding to the NTRU private key, and the lattice dimension associated with the LWE ciphertext, to obtain the computation keys corresponding to the 0th to (n-1th)th components in the plurality of computation keys EVK, wherein the private key is represented as s = (s0, ... s n-1 ), s0,……s n-1 These represent the 0th to (n-1)th components, respectively, and the computation key corresponding to each of these components is denoted as evk. k The evk k The key is the k-th computational key among the plurality of computational keys EVK, where n is the lattice dimension, 0 ≤ k ≤ n-1; based on the NTRU private key, the parameters of the NTRU ciphertext corresponding to the NTRU private key, and the lattice dimension associated with the LWE ciphertext, the sum of the 0th to (n-1)th components included in the private key of the first LWE ciphertext is encrypted to obtain evk included in the plurality of computational keys EVK. n Key; based on the evk k Key and evk n The multiple computation keys EVK are obtained; based on the multiple computation keys EVK, the blind rotation key is obtained.

[0009] Optionally, the evk k Key and the evk n The keys are obtained in the following ways:

[0010] Where NTRU'() represents the vector NTRU encryption method, Q represents the ciphertext modulus of the NTRU ciphertext, and f(X) represents the NTRU private key. The exponent is s k The variable s of the polynomial ring k This represents the component corresponding to the k-th computation key. Indicates the exponent is The variables of the polynomial ring, The sum of the 0th to (n-1)th components corresponding to the 0th to (n-1)th computation keys is represented by g, where g represents the generator.

[0011] Optionally, generating the blind rotation key corresponding to the blind rotation algorithm based on the private key of the first LWE ciphertext and the NTRU private key includes: obtaining the plurality of self-similar keys KSK based on the parameters of the NTRU ciphertext corresponding to the NTRU private key and the NTRU private key in the following manner;

[0012] Among them, the ksk included in the plurality of self-isomorphic keys KSK l Let represent the l-th automorphic key, η be the predetermined batch size, l∈{1,…,η}, and NTRU'() represent the vector NTRU encryption method. Let f(X) represent the NTRU private key after self-isolation, g represent the generator, and Q represent the ciphertext modulus of the NTRU ciphertext; based on the multiple self-isolated keys KSK, the blind rotation key is obtained.

[0013] Optionally, the ciphertext based on the constant NTRU Perform iterative processing until the predetermined number of iterations is reached, and obtain the constant NTRU ciphertext. Includes: the constant NTRU ciphertext As the start of the iterative process, the initial value of iteration number i is assigned to 1, and the predetermined number is... N is the polynomial degree corresponding to the NTRU ciphertext; a cumulative parameter τ is set with an initial value of 0, where the cumulative parameter τ is a positive integer used to record the number of consecutive empty sets in set U; if the iteration number i has not reached the predetermined number, based on the number of iterations included in set U... a set The elements included in the calculation are matched to determine the computation key that matches the element among the plurality of computation keys EVK; based on the plurality of matched computation keys and the constant NTRU ciphertext obtained in the previous iteration, the calculation is performed. Perform the ciphertext outer product processing to obtain the constant NTRU ciphertext for the current iteration number. The cumulative parameter τ is incremented; wherein the previous iteration number is i-1; the set U includes the i-th iteration. a set It is an empty set, and the cumulative parameter τ has not reached the batch size η, and If the value is not equal to 1, then the intermediate parameter ACC will be... i The constant NTRU ciphertext obtained as the current iteration number And execute the next iteration; the set U includes the first a set is not empty, or the cumulative parameter τ reaches the batch size η, or is equal to 1, based on the intermediate parameter ACC i and the g-exponent of the generator τ is equal to 1, based on the intermediate parameter ACC i ' based on the intermediate parameter ACC i ' and the τth self-automorphism key in the plurality of self-automorphism keys KSK, to obtain the constant NTRU ciphertext obtained in the current iteration and the cumulative parameter is reset to zero, and the next iteration is performed; in the case where the iteration number i reaches the predetermined number, based on the elements included in the 0th set U0 included in the set U, the calculation key matched with the elements in the plurality of calculation keys EVK is determined; based on the plurality of matched calculation keys and the constant NTRU ciphertext obtained in the last iteration performing outer product processing to obtain the constant NTRU ciphertext

[0014] Optionally, the set U includes the jth set U j , the set U j represents a set obtained by pre-computing based on the first LWE ciphertext, a i represents one or more elements in the first LWE ciphertext that satisfy the following formula: where g j represents the j-exponent of the generator.

[0015] Optionally, the processing based on the target NTRU ciphertext to obtain the target LWE ciphertext comprises: in the case where the ciphertext modulus of the first LWE ciphertext is q and the ciphertext modulus of the target NTRU ciphertext is Q, performing modulus switching using the NTRU method to obtain a first NTRU ciphertext with modulus Q ks ; performing key switching on the first NTRU ciphertext using the NTRU method to obtain a second NTRU ciphertext with key ; extracting the constant term from the second NTRU ciphertext to obtain a second LWE ciphertext with dimension N, ciphertext modulus Q ks , and private key ; truncating the second LWE ciphertext to obtain a third LWE ciphertext with dimension n, ciphertext modulus Q ks , and private key ; performing modulus switching on the third LWE ciphertext to obtain the target LWE ciphertext with the ciphertext modulus q.

[0016] Optionally, the key switching on the first NTRU ciphertext by the NTRU method to obtain a second NTRU ciphertext with a key includes: the key switching on the first NTRU ciphertext by the NTRU method to obtain the second NTRU ciphertext with a key by the following way:

[0017] c ks =NTRU.KeySwitch(ACC ks ,ksk * )

[0018] wherein, ACC ks represents the first NTRU ciphertext, ksk * represents a key switching key, and c ks is the second NTRU ciphertext; and NTRU.KeySwitch(ACC ks ,ksk * ) is obtained by the following way:

[0019]

[0020] wherein, represents ciphertext outer product, represents a ring with a modulus Q ks , and Q ks represents a modulus of the second LWE ciphertext.

[0021] According to another aspect of the embodiments of the present application, there is provided a non-transitory storage medium storing a plurality of instructions adapted to be loaded and executed by a processor to implement the homomorphic decryption method.

[0022] According to another aspect of the embodiments of the present application, there is provided an electronic device comprising one or more processors and a memory for storing one or more programs, wherein the one or more programs, when executed by the one or more processors, cause the one or more processors to implement the homomorphic decryption method.

[0023] In the embodiment of the present application, a blind rotation method is adopted, a first LWE ciphertext and a private key of the first LWE ciphertext are obtained, wherein the first LWE ciphertext is ciphertext to be homomorphic decrypted in a homomorphic encryption first-layer scheme, and the first LWE ciphertext is obtained by vector processing based on text information or image information; an NTRU private key and a rotation polynomial in a homomorphic encryption second-layer scheme are determined, wherein the NTRU private key is used for decrypting NTRU ciphertext in the homomorphic encryption second-layer scheme; a blind rotation key corresponding to a blind rotation algorithm is generated according to the private key of the first LWE ciphertext and the NTRU private key, wherein the blind rotation key includes a plurality of calculation keys EVK and a plurality of self-automorphism keys KSK, the plurality of calculation keys EVK are obtained by respectively encrypting the private key of the first LWE ciphertext based on the NTRU private key using a vector NTRU encryption method; the plurality of self-automorphism keys KSK are key switching keys for self-automorphism processing, and the plurality of self-automorphism keys KSK are obtained by encrypting the self-automorphized NTRU private key based on the NTRU private key using the vector NTRU encryption method; based on the rotation polynomial, the blind rotation key, and the blind rotation algorithm, the first LWE ciphertext is homomorphic decrypted in the following manner: based on the first LWE ciphertext, the rotation polynomial, and a generator, an intermediate parameter ACC is generated in a self-automorphism manner in , wherein the intermediate parameter ACC in is an element on a ring R Q ; based on the intermediate parameter ACC in and an nth calculation key evk n in the plurality of calculation keys EVK, a constant NTRU ciphertext is obtained by using a ciphertext outer product method , based on the constant NTRU ciphertext , iteration processing is performed until a predetermined number of iterations is reached, a constant NTRU ciphertext is obtained , based on the constant NTRU ciphertext , a target NTRU ciphertext is obtained, wherein the target NTRU ciphertext corresponds to the NTRU private key; and based on the target NTRU ciphertext, a target LWE ciphertext is obtained. The purpose of realizing lightweight and efficient bootstrap is achieved, the technical effect of improving homomorphic decryption efficiency is achieved, and the technical problem of unsatisfactory homomorphic decryption efficiency in the related art is solved. BRIEF DESCRIPTION OF DRAWINGS

[0024] The drawings described herein are used to provide further understanding of the present application, and form a part of the present application. The illustrative embodiments of the present application and their descriptions serve to explain the present application, and do not constitute improper limitations on the present application. In the drawings:

[0025] Figure 1 is a flowchart of an optional homomorphic decryption method provided according to an embodiment of the present invention;

[0026] Figure 2 is a schematic diagram of the framework of an optional homomorphic decryption method provided according to an embodiment of the present invention;

[0027] Figure 3 is a schematic diagram of an optional homomorphic decryption device provided according to an embodiment of the present invention. Detailed Implementation

[0028] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0030] For ease of description, the following explains some of the nouns or terms used in the embodiments of this application:

[0031] LWE ciphertext refers to ciphertext obtained by encryption based on the learning with errors problem. The learning with errors (LWE) problem is a problem of solving a system of linear equations with noise.

[0032] NTRU (Number Theory Research Unit) ciphertext refers to the result obtained after encrypting data using the NTRU encryption algorithm. The NTRU algorithm is a public-key encryption algorithm that uses a lattice-based encryption algorithm to encrypt data.

[0033] Bootstrapping is a ciphertext refresh technique that uses homomorphic decryption to reduce ciphertext noise.

[0034] Cyclotomic polynomial is an important concept in mathematics, especially in number theory and cryptography. It is often denoted as R and is related to the nth root of the unit circle.

[0035] The quotient ring is a concept defined in abstract algebraic ring theory. It defines a congruence relation on a ring R and provides a method for studying the properties of the original ring R on a smaller algebraic structure (i.e., the quotient ring).

[0036] Define a 2Nth degree cyclotomic polynomial as Φ 2N =X N +1, related circular ring and its business ring In Z and Z respectively Q In this context, the elements of the ring are represented by a vector composed of their corresponding coefficients.

[0037] Symbol C n This refers to a cyclic group of order n. (symbol) The symbol indicates rounding, <, ·> indicates the inner product of vectors, and ⊙ indicates the outer product. x←D represents a sample x according to distribution D. For a positive integer k, [k]={0,1,…,k-1} represents the index set.

[0038] Two symmetric versions of NTRU ciphertext are defined: Scalar NTRU encryption: Input the message polynomial u to be encrypted, extract the private key f(X) from the private key distribution (hereinafter abbreviated as f), extract g from the error distribution, and output the ciphertext:

[0039] Vector NTRU encryption: Input the message polynomial v to be encrypted, let... Extract the private key f(X) from the private key distribution, and extract g0,…,g from the error distribution. d-1 Output ciphertext:

[0040] In the field of fully homomorphic encryption (FHE), a specific variant of the FHEW scheme, DM, and its derivative TFHE scheme, specifically the CGGI version, stand out for their efficiency in bit-level homomorphic computation. Each scheme employs different bootstrapping techniques—the AP method and the GINX method—to optimize performance for specific scenarios.

[0041] In related technologies, different FHE methods exhibit their respective advantages under different key distribution scenarios. Specifically, when the LWE (Learning With Errors) key follows a Gaussian distribution, the AP method demonstrates faster computation speed; while the GINX method is more efficient with binary distributed keys. Within the framework recommended by the HE (Homomorphic Encryption) security standard, in optimized configurations around a ternary key distribution, the AP and GINX bootstrap schemes are comparable in runtime efficiency, but the GINX method, with its significantly smaller bootstrap key size (by an order of magnitude), is considered the preferred solution for this configuration.

[0042] However, the bootstrapping process is a major bottleneck in FHE technology, and its efficiency cannot be ignored. Currently, all mainstream bootstrapping algorithms require computing devices (such as servers and embedded devices) with a large amount of storage space to accommodate the massive bootstrapping key set, including blind key rotation and key switching keys. Specifically, under standard parameter settings, the AP and GINX methods require as much as 902.39MB and 106.60MB of key storage space for a single bootstrapping operation, respectively, which places stringent demands on computing resources.

[0043] The aforementioned FHEW fully homomorphic encryption scheme was proposed by Ducas and Micciancio at the European Conference on Cryptography 2015, along with the bootstrapping process of its variants: one is the original AP / FHEW method, which supports arbitrary secret key distributions; the other is an improved GINX / TFHE method that uses a smaller evaluation key, thus limiting the applicability of the scheme.

[0044] Blind rotation is a core challenge in bootstrapping algorithms, characterized by low computational efficiency and high memory consumption. To address this, XZDDF and LMKCDEY methods, currently the most efficient blind rotation solutions, are both deeply optimized based on automorphism operations. LMKCDEY was published by Yongwoo Lee et al. on June 10, 2023, and XZDDF was also published in the same year. XZDDF utilizes the design principle of the NTRU (Number Theory Research Unit) algorithm to significantly reduce the number of number-theory transformations, the most time-consuming part of the blind bootstrapping process, thus effectively reducing the storage burden of the bootstrap key. The LMKCDEY method, on the other hand, introduces a generator-based algebraic structure, significantly reducing the bootstrap key storage cost in the AP and GINX methods. Nevertheless, both methods still require bootstrap keys exceeding 70MB (megabytes), posing a challenge for resource-constrained applications.

[0045] To address the aforementioned problems, this invention provides a method embodiment for homomorphic decryption. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0046] Figure 1 is a flowchart of an optional homomorphic decryption method according to an embodiment of the present invention. As shown in Figure 1, the method includes the following steps:

[0047] Step S102: Obtain the first LWE ciphertext and the private key of the first LWE ciphertext, wherein the first LWE ciphertext is the ciphertext to be homomorphically decrypted in the first layer of homomorphic encryption scheme, and the first LWE ciphertext is obtained by vector processing based on text information or image information.

[0048] It can be understood that in the first layer of homomorphic encryption, the first LWE ciphertext obtained after homomorphic encryption is based on vector processing of the original data (such as text or image information), followed by encryption using the LWE (Learning With Errors) encryption algorithm. LWE is a public-key encryption technique based on lattice theory that allows homomorphic operations (such as addition and multiplication) to be performed on encrypted data without decrypting the original data. Therefore, the first LWE ciphertext is the starting point for subsequent homomorphic decryption and transformation processes. Corresponding to the first LWE ciphertext, its private key is the unique key used to decrypt the ciphertext and is a necessary condition for recovering the original data.

[0049] Step S104: Determine the NTRU private key and rotation polynomial in the second layer homomorphic encryption scheme, wherein the NTRU private key is used to decrypt the NTRU ciphertext in the second layer homomorphic encryption scheme;

[0050] It's understandable that NTRU (Number Theory Research Unit) is a public-key encryption technique based on polynomial rings, used to decrypt NTRU ciphertext in a second-layer encryption scheme. Rotation polynomials play a crucial role in blind rotation algorithms for homomorphic encryption. Blind rotation is a technique that allows rotation operations on ciphertext without decryption; rotation polynomials define the rotation operation as a polynomial, used to perform cyclic shifts or similar operations on the ciphertext vector.

[0051] Step S106: Based on the private key and NTRU private key of the first LWE ciphertext, generate a blind rotation key corresponding to the blind rotation algorithm. The blind rotation key includes multiple computation keys EVK and multiple automorphic keys KSK. The multiple computation keys EVK are obtained by encrypting the private key of the first LWE ciphertext using the NTRU private key based on the vector NTRU encryption method. The multiple automorphic keys KSK are key switching keys used for automorphic processing. The multiple automorphic keys KSK are obtained by encrypting the automorphic NTRU private key using the NTRU private key based on the vector NTRU encryption method.

[0052] The blind rotation key consists of two parts: multiple computational keys (EVK) and multiple autosimilar keys (KSK). Both keys are generated based on the vector NTRU encryption method. The multiple computational keys (EVK) are obtained by encrypting the private key of the first LWE ciphertext using the NTRU private key. Each computational key included in the multiple computational keys (EVK) is used to operate on the ciphertext using methods such as ciphertext outer products without decrypting the LWE ciphertext. The multiple autosimilar keys (KSK) are key switching keys used for autosimilar processing. In the blind rotation algorithm, autosimilar processing is a way to change the internal representation of the ciphertext while maintaining its structural integrity. The KSK is obtained by encrypting the autosimilar NTRU private key using the NTRU private key and is used to switch or update the key state during the blind rotation process to ensure the correctness and security of the algorithm.

[0053] In one optional embodiment, generating a blind rotation key corresponding to the blind rotation algorithm based on the private key of the first LWE ciphertext and the NTRU private key includes: encrypting the 0th to (n-1)th components included in the private key of the first LWE ciphertext according to the NTRU private key, the parameters of the NTRU ciphertext corresponding to the NTRU private key, and the lattice dimension associated with the LWE ciphertext, to obtain a plurality of computation keys EVK, each corresponding to one of the 0th to (n-1)th components, wherein the private key is represented as s = (s0, ... s... n-1 ), s0,……s n -1 represents the 0th to (n-1)th components, and the computation key corresponding to the 0th to (n-1)th components is represented as evk. k evk k The key is the k-th computational key among multiple computational keys EVK, where n is the lattice dimension, 0 ≤ k ≤ n-1. Based on the NTRU private key, the parameters of the NTRU ciphertext corresponding to the NTRU private key, and the lattice dimension associated with the LWE ciphertext, the sum of the 0th to (n-1)th components included in the private key of the first LWE ciphertext is encrypted to obtain evk included in the multiple computational keys EVK. n Key; based on evk k Key and evk nThe key is used to obtain multiple computation keys EVK; based on the multiple computation keys EVK, a blind rotation key is obtained.

[0054] It can be understood that, based on the NTRU private key, the parameters of the NTRU ciphertext (such as the modulus of the polynomial ring), and the lattice dimension associated with the LWE ciphertext (i.e., the length of the private key vector), each component (from the 0th to the (n-1th)th component) of the private key in the first LWE ciphertext is encrypted separately. The private key is represented as a vector, where each component represents an element in the private key vector. The encryption process uses the NTRU encryption algorithm to generate a computational key evk corresponding to each component. k Here, k represents the identifier of the component. Besides encrypting individual components, the sum of all components in the private key also needs to be encrypted to support certain homomorphic operations. This requires using the sum of the private key components, and the multiple computation keys EVK include evk. n Key. Based on the evk obtained in the above steps. k (k = 0, ..., n-1) and evk n The keys can be used to construct a complete computation key set EVK. The EVK set contains all the computation keys used for subsequent blind rotation operations during the bootstrapping process. Based on the computation key set EVK, blind rotation keys can be further generated. The blind rotation keys may also include other elements, such as multiple automorphic keys KSK.

[0055] In one alternative embodiment, evk k Key and evk n The keys are obtained in the following ways:

[0056] Where NTRU'() represents the vector NTRU encryption method, Q represents the ciphertext modulus of the NTRU ciphertext, and f(X) represents the NTRU private key. The exponent is s k The variable s of the polynomial ring k This represents the component corresponding to the k-th computation key. Indicates the exponent is The variables of the polynomial ring, denoted by , represents the sum of the 0th to (n-1th)th components corresponding to the 0th to (n-1th)th computation keys, and g represents the generator.

[0057] Understandable. Let s represent the exponentiation of a variable X in a polynomial ring. k Mapping, where s kThis is the value of the k-th component in the first LWE ciphertext private key (k can take multiple values), meaning that each component of the private key is treated as the exponent of a polynomial, and the corresponding polynomial is encrypted using the NTRU encryption method. evk n The generation is the sum of all private key components. Multiplying this by a generator g (a constant or polynomial used to ensure that cryptographic operations conform to certain specific properties), and mapping X to the exponent of the sum, we obtain... Divide this result polynomial by the private key f(X), and encrypt the result using the same NTRU encryption method to obtain evk. n .

[0058] By encrypting each component of the private key and the sum of the components in different ways into a blind rotation key, the difficulty for attackers to crack the blind rotation key is increased, thereby enhancing the security of the encryption scheme.

[0059] In an optional embodiment, a blind rotation key corresponding to the blind rotation algorithm is generated based on the private key of the first LWE ciphertext and the NTRU private key, including: obtaining multiple self-similar keys KSK according to the parameters of the NTRU ciphertext corresponding to the NTRU private key in the following manner;

[0060] Among them, the ksk included in multiple self-isomorphic keys KSK l Let represent the l-th automorphic key, η be the predetermined batch size, l∈{1,…,η}, and NTRU'() denote the vector NTRU encryption method. Let f(X) represent the NTRU private key after self-isolation, g represent the generator, and Q represent the ciphertext modulus of the NTRU ciphertext. Based on multiple self-isolated keys KSK, a blind rotation key is obtained.

[0061] It is understandable that in NTRU, both the public and private keys are elements of a polynomial ring and satisfy specific mathematical relations. Automorphic keys are generated based on the NTRU private key and specific transformations involving generators g, used to generate a series of automorphisms (i.e., mappings that preserve the ring structure) within the polynomial ring. η is a predetermined batch size, which can represent the number of automorphic keys generated. Based on the generated multiple automorphic keys KSK, blind rotation keys can be further generated. These blind rotation keys may also include other elements, such as multiple computation keys EVK.

[0062] It should be noted that blind rotation keys are used in encryption algorithms to achieve blindness, that is, to process data without revealing the original data. The aforementioned blind rotation key is a part of bootstrap keys.

[0063] Optionally, input the private key of the first-level LWE ciphertext. The private key f∈R of the second-level NTRU Q Calculate the bootstrap key:

[0064] Where the batch size η is a positive integer, the key generation algorithm is denoted as BSKGen(s,f), and the blind rotation key BRK = (EVK,KSK), where EVK = (evk0,…,evk) n ) and KSK = (ksk1, ..., ksk η ), ksk * This indicates a key switching operation, returning the bootstrap key BSK = (BRK, ksk) * ).

[0065] Based on the extended private key (s,0) and NTRU extended private key of the first LWE ciphertext Generate the key switching key ksk corresponding to the bootstrap algorithm. * Based on the following formula:

[0066] Where NTRU'() represents the vector NTRU encryption method, and (s,0) is a polynomial. The coefficient.

[0067] Step S108: Based on the rotation polynomial, the blind rotation key, and the blind rotation algorithm, the first LWE ciphertext is homomorphically decrypted in the following way: Based on the first LWE ciphertext, the rotation polynomial, and the generator, the intermediate parameter ACC is generated using an automorphic method. in Among them, the intermediate parameter ACC in It is ring R Q Elements on; based on intermediate parameter ACC in and the nth computation key evk in multiple computation keys EVK n The constant NTRU ciphertext is obtained by using the ciphertext outer product method. Based on constant NTRU ciphertext Perform iterative processing until the predetermined number of iterations is reached, and obtain the constant NTRU ciphertext. Based on constant NTRU ciphertext Obtain the target NTRU ciphertext, where the target NTRU ciphertext corresponds to the NTRU private key;

[0068] It is understandable that, without decrypting the original LWE ciphertext (first LWE ciphertext), a series of transformations and processes can ultimately yield a target NTRU ciphertext corresponding to the NTRU private key. The first LWE ciphertext consists of an n-dimensional vector a and a scalar b. Based on the first LWE ciphertext, a... This method is used to generate intermediate parameters ACC based on rotational polynomials and generators, employing an automorphism approach. in intermediate parameter ACC in It is ring R Q The elements on the [text]. Through self-similar operations, the information in the first LWE ciphertext is transformed to support subsequent ciphertext external product methods. Using ciphertext external product, the ACC [text] is transformed... in With evk n Combine to generate a constant NTRU ciphertext. Ciphertext outer product (CEB) is used in homomorphic encryption to allow multiplication of ciphertext without decryption. CEB transforms LWE ciphertext into NTRU ciphertext.

[0069] from Iterative processing begins, with each iteration involving a transformation or calculation of the current NTRU ciphertext, until a predetermined number of iterations is reached. The process involves iteratively transforming the NTRU ciphertext into a form closer to the target NTRU private key, or reaching an intermediate state suitable for subsequent decryption or processing. Here, N represents the polynomial degree corresponding to the NTRU ciphertext.

[0070] Optionally, determine based on the first LWE ciphertext. And multiple w, the calculation formula is as follows

[0071] Among them, a i Let represent the i-th element of the first LWE ciphertext, N represent the degree of the polynomial ring corresponding to the target NTRU ciphertext, q represent the ciphertext modulus of the first LWE ciphertext, and b represent the scalar.

[0072] Optionally, the automorphism algorithm Auto(t,k) takes a ring element t(X) on R as input and an automorphism X→X. k Output t(X) k Auto() represents the automorphism algorithm, r(X) represents the rotation polynomial, ⊙ represents the ciphertext outer product, and evk n evk represents evk in multiple computation keys EVK n The key. The formula for calculating Auto() is as follows:

[0073] Auto(t(X),k)=t(X k )∈R Q

[0074] Wherein, input R Q The ring element t(X) on the ring, and an automorphism X→X k Output R Q The ring element t(X) on k The ciphertext outer product ⊙ is calculated as follows:

[0075] Where t is the ring R Q The elements on It is ring R Q The vector consisting of the elements on t i It is a decomposition of t, satisfying

[0076] In one alternative embodiment, based on constant NTRU ciphertext Perform iterative processing until the predetermined number of iterations is reached, and obtain the constant NTRU ciphertext. Includes: encrypting constant NTRU text As the start of the iterative process, the initial value of iteration number i is assigned to 1, and the predetermined number of iterations is... N is the polynomial degree corresponding to the NTRU ciphertext; a cumulative parameter τ is set to an initial value of 0, where τ is a positive integer used to record the number of consecutive empty sets in set U; if the iteration number i has not reached the predetermined number, the result is based on the number of iterations in set U. a set The elements included in the key are matched to determine the computation key that matches the element among multiple computation keys EVK; based on the multiple matched computation keys and the constant NTRU ciphertext obtained from the previous iteration, the key is then used. Perform ciphertext outer product processing to obtain the constant NTRU ciphertext for the current iteration number. The cumulative parameter τ is incremented; where the previous iteration number is i-1; and the set U includes the i-th iteration. a set It is an empty set, and the cumulative parameter τ has not reached the batch size η, and If the value is not equal to 1, then the intermediate parameter ACC will be... i The constant NTRU ciphertext obtained as the current iteration number And execute the next iteration; the set U includes the first... a set It is not an empty set, or the cumulative parameter τ reaches the batch size η, or When the value is equal to 1, based on the intermediate parameter ACC i and g that maps the τ exponent to the generator. τ Perform self-similar processing to obtain the intermediate parameter ACC. i Based on intermediate parameter ACC i The τ-th automorphic key in the KSK is subjected to ciphertext outer product processing to obtain the constant NTRU ciphertext obtained at the current iteration number. The accumulated parameters are reset to zero, and the next iteration is executed. When the iteration number i reaches a predetermined number, the elements included in the 0th set U0 of the set U are matched to determine the computation key that matches the element among the multiple computation keys EVK. Based on the multiple matched computation keys and the constant NTRU ciphertext obtained in the previous iteration, the process continues. Perform outer product processing to obtain constant NTRU ciphertext.

[0077] It is understandable that the iterative processing of the NTRU encryption scheme involves a series of iterative calculations to transform an initial constant NTRU ciphertext. Step by step, we derive Matching and computation are performed using multiple computation keys (EVK), automorphic keys (KSK), and elements in set U.

[0078] The iterative process is as follows: Set the iteration number i to 1, and the target iteration number to 1. N represents the polynomial degree corresponding to the NTRU ciphertext. The cumulative parameter τ is set to 0, which is used to record the number of consecutive empty sets in set U.

[0079] Take the first from set U a set It attempts to find a key that matches an element in the set among multiple computation keys EVK, which can be one or more, using these keys along with the one obtained in the previous iteration. Perform ciphertext outer product processing to obtain the current iteration. And increase the value of τ.

[0080] if It is an empty set, and τ has not reached the predetermined batch size η, and If the value is not equal to 1, then the constant NTRU ciphertext obtained from the current iteration number will be used directly. Set as the intermediate parameter ACC of the previous iteration i And continue to the next iteration.

[0081] if It is not an empty set, or τ reaches the predetermined batch size η, or If the value is 1, then the intermediate parameter ACC i and g that maps the τ exponent to the generator. τ Obtain intermediate parameter ACC i Then use the τth automorphic key KSK and the intermediate parameter ACC i Perform ciphertext outer product processing to obtain the constant NTRU ciphertext for the current iteration number.

[0082] End iteration: When the iteration count i reaches... When, from the 0th set U0 of set U (i.e., in of Extract elements from the ) and search for matching keys in EVK. Use these keys and the key obtained in the last iteration. (Right now Perform outer product processing to obtain

[0083] In one alternative embodiment, set U includes the j-th set U j set U j a represents the set obtained by pre-computing based on the first LWE ciphertext. i This represents one or more elements in the first LWE ciphertext that conform to the following formula: Among them, g j Let j represent the mapping index on the generator.

[0084] It is understandable that a set U consists of multiple subsets U j Composed of, each subset U j All of them are pre-calculated based on the first LWE ciphertext, U j The definition depends on element a in the LWE ciphertext. i and the power of generator g j U j It contains all identifiers i that satisfy specific conditions, which are related to element a in the LWE ciphertext. i and the power of generator g j related.

[0085] Step S110: Process the target NTRU ciphertext to obtain the target LWE ciphertext.

[0086] It is understandable that processing is performed based on the target NTRU ciphertext, including analog-to-digital switching, key switching, extraction of LWE ciphertext from the accumulator, and analog-to-digital switching, to obtain the target LWE ciphertext.

[0087] In one optional embodiment, processing is performed based on the target NTRU ciphertext to obtain the target LWE ciphertext, including: when the ciphertext modulus of the first LWE ciphertext is q and the ciphertext modulus of the target NTRU ciphertext is Q, performing modulus switching using the NTRU method to obtain a modulus of Q. ks The first NTRU ciphertext; the first NTRU ciphertext is then subjected to key switching using the NTRU method to obtain the key. The second NTRU ciphertext; extract the constant term from the second NTRU ciphertext to obtain a ciphertext of dimension N and modulus Q. ks The private key is The second LWE ciphertext; truncate the second LWE ciphertext to obtain a ciphertext of dimension n with a modulus of Q. ks The private key is The third LWE ciphertext; the modulus of the third LWE ciphertext is switched to obtain the target LWE ciphertext with a modulus of q.

[0088] It is understandable that there exists a process of converting the target NTRU ciphertext back to the target LWE ciphertext. This process involves modulus switching, key switching, constant term extraction, truncation, and finally, modulus switching. The target NTRU ciphertext (ciphertext modulus Q) uses the modulus switching technique of NTRU encryption to switch the modulus of the target NTRU ciphertext from Q to another modulus Q. ks We obtain the first NTRU ciphertext, and then make sure that the modulus of the NTRU ciphertext matches the modulus required in subsequent operations.

[0089] Perform a key switch on the first NTRU ciphertext, changing its key from the original key to a new key. The second NTRU ciphertext is obtained. Key switching is a feature of NTRU encryption that allows the key to be changed without decryption.

[0090] Extract the constant term from the second NTRU ciphertext to obtain a ciphertext with dimension N and ciphertext modulus Q. ks The private key is The second LWE ciphertext is used to transform the NTRU ciphertext back into LWE ciphertext.

[0091] The second LWE ciphertext is truncated (e.g., unnecessary high-dimensional parts are removed) to obtain a ciphertext of dimension n with a modulus of Q. ks The private key is The third LWE ciphertext.

[0092] Modulus switching is performed on the third LWE ciphertext, changing its modulus from Q... ks Switch back to the original modulus q to obtain the target LWE ciphertext.

[0093] In one optional embodiment, the first NTRU ciphertext is key-switched using the NTRU method to obtain the key as follows: The second NTRU ciphertext includes: a key is obtained by performing a key switch on the first NTRU ciphertext using the NTRU method, and the key is obtained in the following way: Second NTRU ciphertext:

[0094] c ks =NTRU.KeySwitch(ACC ks ,ksk * )

[0095] Among them, ACC ks This represents the first NTRU ciphertext, ksk * Indicates key switching, c ks This is the second NTRU ciphertext; NTRU.KeySwitch(ACC) is obtained through the following method. ks ,ksk * ):

[0096] Where ⊙ represents the ciphertext outer product, The modulus is Q. ks The ring, Q ks This represents the modulus of the second LWE ciphertext.

[0097] It is understandable that key switching is accomplished through specific operations of NTRU encryption, which uses a ciphertext outer product (usually denoted as ⊙) to convert the first NTRU ciphertext (ACC) into a single ciphertext. ks ) and key switching key (ksk) * This combination generates a new NTRU ciphertext, namely the second NTRU ciphertext (c). ks ), its key is

[0098] In one optional embodiment, the NTRU method is used for analog-to-digital switching to obtain a modulus of Q. ks First NTRU ciphertext (ACC) ks ), including calculation in This indicates that in the blind rotation algorithm, the first LWE ciphertext is homomorphically decrypted to obtain the target NTRU ciphertext, NTRU.ModSwitch(c,Q ks The calculation formula for ) is as follows:

[0099] Where c represents scalar NTRU ciphertext with a modulus of Q, and Q ks This represents the modulus of the target ciphertext (the modulus of the second NTRU ciphertext).

[0100] In an optional embodiment, based on the extended private key (s,0) of the first LWE ciphertext and the NTRU extended private key Generate the key switching key ksk corresponding to the bootstrap algorithm. * Based on the following formula:

[0101] Where NTRU′() represents the vector NTRU encryption method, and (s,0) is a polynomial. The coefficient.

[0102] In one alternative embodiment, from the second NTRU ciphertext (c ks Extracting the constant term from ) yields the second LWE ciphertext (ct″), including calculating ct″ = NTRU.Extract(c ks ), where NTRU.Extract(c) is calculated as follows: given a scalar NTRU ciphertext c ks ∈R Q First of all, let and These are the NTRU private keys f(x) and c, respectively. ks Let f(x) be the coefficient vector, or simply f. To pass through vector c ks The vector obtained by rearranging the coefficients returns the second LWE ciphertext. Where b = 0,

[0103] In one optional embodiment, the second LWE ciphertext (ct″) is truncated to obtain the third LWE ciphertext (ct″′), including calculating ct″′ = Truncation(ct″,n), where Truncation(ct″,n) is calculated as follows: input N-dimensional LWE ciphertext Let a″′ be the first n terms of vector a″, and b″′ = b″. Return the truncated third LWE ciphertext.

[0104] In one optional embodiment, the third LWE ciphertext is modulo-switched to obtain the target LWE ciphertext (ct) with a ciphertext modulus of q. out This includes running the modulus switching algorithm LWE.ModSwitch(ct″′,q) to obtain the final LWE ciphertext ct. out =LWE.ModSwitch(ct″′,q). The calculation method for LWE.ModSwitch(ct″′,q) is as follows:

[0105] Through the above steps S102 to S110, the goal of lightweight and efficient bootstrapping is achieved, the technical effect of improving homomorphic decryption efficiency is realized, and the technical problem of unsatisfactory homomorphic decryption efficiency in related technologies is solved.

[0106] Based on the above embodiments and optional embodiments, this invention proposes an optional implementation method. This application proposes a novel bootstrapping algorithm that requires only a 3MB bootstrapping key and completes the process in less than 7 milliseconds, significantly outperforming existing methods. The key size is reduced by 32 times, and the bootstrapping speed is increased by 1.2 times. This improvement is based on two main factors: optimization of the bootstrapping process, reducing the size of the key switching key from... Reduce to Improvements are made by reducing the number of automorphisms and optimizing the bootstrap key.

[0107] I. Automorphism using generators

[0108] The automorphism algorithm Auto(t,k) takes a ring element t(X) on R as input and an automorphism X→X. k Output t(X) k The goal of blind rotation is to calculate:

[0109] We need to use the automorphism X→X a , noise represents noise, and m represents plaintext.

[0110] For N=2 k k≥3, group Composed of coprime elements. It is a second-order torsion group (i.e., the square of each element is 1), so It is not a cyclic group. The powers of 5 {1, 5, 9, ..., 2N-3} are... A cyclic subgroup of order , therefore:

[0111] The subgroup generated by 5 is Right now <5> The base is The following operations assume a modulus of 2N. The generator g = 5 plays a crucial role in representing automorphisms. For powers of two N, There are N elements, and <g>= {1,5,...,2N-3} has only elements. There exists a bijection from the set to g j such that

[0112] Thus for any element w e <g>It can be represented as w = g j Define set U j ={i:w i =g j }. Note The following equations hold true:

[0113] However, in fast blind rotations, the automorphism mapping is It is worth noting that if generated sets are used to implement the automorphism X→X k It must satisfy the condition that k is coprime to 2N. Since 2N is a power of 2, k must be odd. In addition, k must remainder 1 modulo 4. In this embodiment, an automorphic mapping is used. in This satisfies the above requirements.

[0114] II. Novel Bootstrapping Framework

[0115] Figure 2 is a schematic diagram of the framework of an optional homomorphic decryption method provided according to an embodiment of the present invention. As shown in Figure 2, the framework differs from related technologies in that key switching is performed on NTRU ciphertext instead of LWE ciphertext. Some definitions are introduced below for this purpose.

[0116] Private key mode switching SwitchModulus(f,Q) ks Given a private key f(x) ∈ R Q , which can be abbreviated as f, let Let t be the coefficient vector of f. ks For each f i If f i >Q / 2,f i ←f i -t, and if f i Q ks ,f i ←f i mod Q ks .

[0117] Modification of LWE key generation: In order to achieve indirect switching from private key f to private key s on NTRU ciphertext, the LWE key generation needs to be modified.

[0118] LWE.KeyGen * ():sampling Pad Nn zeros after vector s to obtain a vector of length N. Let (s,0) be a polynomial The coefficient. If If irreversible, resample s; otherwise, calculate... The reverse and set sk = s.

[0119] Define a truncation operation on LWE ciphertexts:

[0120] Truncation(ct, n): Input an N-dimensional LWE ciphertext Let a' be the first n terms of vector a, b' = b, and return the truncated LWE ciphertext

[0121] III. Lightweight Blind Rotation Algorithm Based on NTRU

[0122] The lightweight blind rotation algorithm based on NTRU is described as follows: Key generation BSKGen(s, f): Input the private key of the first layer LWE ciphertext and the private key f(x) ∈ R of the second layer NTRU Q , calculate bootstrap key:

[0123] NAND gate calculation NAND(ct0, ct1, BSK): Input LWE ciphertext ct0 = LWE s,q,n (m0; e0), ct1 = LWE s,q,n (m1; e1) and bootstrap key BSK. The algorithm returns the calculation of homomorphic AND gate, and the refreshed LWE ciphertext The implementation of this algorithm includes five stages: homomorphic NAND gate calculation, initialization and iterative calculation of homomorphic accumulator, modulus switching, key switching, extraction of LWE ciphertext from accumulator, truncation and modulus switching.

[0124] Several algorithms used in the process are as follows:

[0125] Extraction algorithm NTRU.Extract(c): Input a scalar NTRU ciphertext c = NTRU f,Δ (μ; g) ∈ R Q . First let the private key be the coefficients of the polynomial f, c. Let c * = (c0, -c N-1 , …, -c1) obtained by rearranging the vector c. The algorithm returns an LWE ciphertext where b = 0, a = c * , μ0 is the constant term of the polynomial μ.

[0126] Modulus switching algorithm LWE.ModSwitch(ct, q'): Input an LWE ciphertext Output ciphertext after switching where

[0127] The detailed procedure is as follows: Stage 1: Homomorphic computation of NAND gate, where mod denotes the modulo operation:

[0128] Stage 2: In this stage, i.e., computation of homomorphic accumulator, involves performing decryption circuit of LWE ciphertext using outer product of NTRU scheme to realize blind rotation. Given LWE ciphertext b', a'0,..., a' n-1 are parameters in the ciphertext, run Algorithm 2 to obtain:

[0129] Table 1 ACC out ← BlindRotration (ct', BRK)

[0130] Table 2

[0131] Stage 3: First, convert the modulus of the result ACC out (i.e. ) in the previous stage to Q ks :

[0132] ACC ks ← NTRU.ModSwitch (ACC out , Q ks )

[0133] Then run c ks ← NTRU.KeySwitch (ACC ks , ksk * ).

[0134] Stage 4: Run NTRU.Extract (c ks ) to extract the second LWE ciphertext from the accumulator, where b" and a" are parameters in the LWE ciphertext.

[0135] Let have:

[0136] Stage 5: Run the truncation algorithm Truncation (ct", n) to obtain the truncated third LWE ciphertext, b'" and a'" are parameters in the third LWE ciphertext.

[0137] Phase 6: In the last phase of the algorithm, input the third LWE ciphertext ct''' and run the modulus switching algorithm LWE.ModSwitch(ct''', q) to switch the modulus from Q ks to q, obtaining the final target LWE ciphertext b out a out , which are parameters in the target LWE ciphertext, satisfy:

[0138] The above optional implementation at least achieves the following effects: significantly reduces the storage cost of bootstrap key, while improving the computing efficiency, and proposes a unified and improved fully homomorphic encryption bootstrap technology.

[0139] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.

[0140] In this embodiment, a homomorphic decryption device is also provided, which is used to implement the above-mentioned embodiments and preferred embodiments, and will not be described again. As used below, the term "module" "device" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware implementation is also possible and contemplated.

[0141] According to the embodiments of the present application, a device embodiment for implementing the homomorphic decryption method is also provided, and FIG. 3 is a schematic diagram of a homomorphic decryption device according to an embodiment of the present application. As shown in FIG. 3, the homomorphic decryption device includes a first acquisition module 302, a second acquisition module 304, a generation module 306, an iteration module 308, a bootstrap completion module 310. The device will be described below.

[0142] The first acquisition module 302 is configured to acquire a first LWE ciphertext and a private key of the first LWE ciphertext, wherein the first LWE ciphertext is a ciphertext to be homomorphic decrypted in a homomorphic encryption first-layer scheme, and the first LWE ciphertext is obtained by vector processing based on text information or image information;

[0143] The second acquisition module 304 is connected with the first acquisition module 302 and is configured to determine an NTRU private key and a rotation polynomial in a homomorphic encryption second-layer scheme, wherein the NTRU private key is used to decrypt an NTRU ciphertext in the homomorphic encryption second-layer scheme;

[0144] The generating module 306 is connected with the second acquiring module 304, and is used for generating a blind rotation key corresponding to a blind rotation algorithm according to the private key of the first LWE ciphertext and the NTRU private key, wherein the blind rotation key comprises a plurality of calculation keys EVK and a plurality of automorphism keys KSK, the plurality of calculation keys EVK are obtained by encrypting the private key of the first LWE ciphertext by using the NTRU private key based on the vector NTRU encryption method, and the plurality of automorphism keys KSK are key switching keys used for automorphism processing, and the plurality of automorphism keys KSK are obtained by encrypting the NTRU private key after the automorphism by using the NTRU private key based on the vector NTRU encryption method;

[0145] The iteration module 308 is connected with the generating module 306, and is used for homomorphically decrypting the first LWE ciphertext by the following manner based on the rotation polynomial, the blind rotation key, and the blind rotation algorithm: generating an intermediate parameter ACC by using an automorphism manner based on the first LWE ciphertext, the rotation polynomial, and the generator in , wherein the intermediate parameter ACC in is an element on the ring R Q ; obtaining a constant NTRU ciphertext by using a ciphertext outer product method based on the intermediate parameter ACC in and an nth calculation key evk n in the plurality of calculation keys EVK , performing iteration processing based on the constant NTRU ciphertext until the iteration number reaches a predetermined number, obtaining a target NTRU ciphertext based on the constant NTRU ciphertext , and obtaining the target NTRU ciphertext based on the target NTRU ciphertext , wherein the target NTRU ciphertext corresponds to the NTRU private key;

[0146] The bootstrap completion module 310 is connected with the iteration module 308, and is used for processing based on the target NTRU ciphertext to obtain a target LWE ciphertext.

[0147] In the homomorphic decryption device provided by the embodiment of the application, the first acquiring module 302, the second acquiring module 304, the generating module 306, the iteration module 308, and the bootstrap completion module 310 are arranged, so that the purpose of lightweight and efficient bootstrap is achieved, the technical effect of improving the homomorphic decryption efficiency is achieved, and the technical problem of the unsatisfactory homomorphic decryption efficiency in the related art is solved.

[0148] It should be noted that the above modules can be implemented by software or hardware, for example, for the latter, the above modules can be located in the same processor, or the above modules are located in different processors in any combination.

[0149] It should be noted that the first obtaining module 302, the second obtaining module 304, the generating module 306, the iterating module 308, and the bootstrap completion module 310 correspond to steps S102 to S110 in the embodiment, and the above modules have the same instances and application scenarios as the corresponding steps, but are not limited to the above disclosed contents. It should be noted that the above modules can run in a computer terminal as a part of the device.

[0150] It should be noted that the optional or preferred embodiments of the present embodiment can refer to the related description in the embodiment, which will not be repeated here.

[0151] The above homomorphic decryption device can further include a processor and a memory, and the first obtaining module 302, the second obtaining module 304, the generating module 306, the iterating module 308, and the bootstrap completion module 310 are stored in the memory as program units, and the processor executes the above program units stored in the memory to realize the corresponding functions.

[0152] The processor includes a core, and the core retrieves the corresponding program unit from the memory. The core can be set to one or more. The memory can include a non-permanent memory in a computer readable medium, a random access memory (RAM) and / or a non-volatile memory such as a read-only memory (ROM) or a flash memory (flash RAM), and the memory includes at least one memory chip.

[0153] The embodiment of the present application provides a non-volatile storage medium, which stores a program, and the program is executed by a processor to realize the homomorphic decryption method.

[0154] An electronic device is provided, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, the following steps are implemented: obtaining a first LWE ciphertext and a private key of the first LWE ciphertext, wherein the first LWE ciphertext is a ciphertext to be homomorphic decrypted in a homomorphic encryption first-layer scheme, and the first LWE ciphertext is obtained by performing vector processing based on text information or image information; determining an NTRU private key and a rotation polynomial in a homomorphic encryption second-layer scheme, wherein the NTRU private key is used to decrypt an NTRU ciphertext in the homomorphic encryption second-layer scheme; generating a blind rotation key corresponding to a blind rotation algorithm according to the private key of the first LWE ciphertext and the NTRU private key, wherein the blind rotation key includes a plurality of calculation keys EVK and a plurality of self-automorphism keys KSK, the plurality of calculation keys EVK are obtained by encrypting the private key of the first LWE ciphertext based on a vector NTRU encryption method using the NTRU private key respectively, and the plurality of self-automorphism keys KSK are key switching keys for self-automorphism processing, and the plurality of self-automorphism keys KSK are obtained by encrypting the self-automorphized NTRU private key based on the vector NTRU encryption method using the NTRU private key; and homomorphic decrypting the first LWE ciphertext based on the rotation polynomial, the blind rotation key, and the blind rotation algorithm by the following manner: generating an intermediate parameter ACC based on the first LWE ciphertext, the rotation polynomial, and a generator using a self-automorphism manner in , wherein the intermediate parameter ACC in is an element on a ring R Q ; obtaining a constant NTRU ciphertext based on the intermediate parameter ACC in and an nth calculation key evk n in the plurality of calculation keys EVK using a ciphertext outer product method , performing iterative processing based on the constant NTRU ciphertext until a predetermined number of iterations is reached to obtain a constant NTRU ciphertext based on the constant NTRU ciphertext , obtaining a target NTRU ciphertext based on the constant NTRU ciphertext, wherein the target NTRU ciphertext corresponds to the NTRU private key; and obtaining a target LWE ciphertext by processing based on the target NTRU ciphertext. The device herein can be a server, a PC, etc.

[0155] The application further provides a computer program product, which is suitable for executing the program of the following method steps when executed on a data processing device: obtaining a first LWE ciphertext and a private key of the first LWE ciphertext, wherein the first LWE ciphertext is a ciphertext to be homomorphic decrypted in a homomorphic encryption first-layer scheme, and the first LWE ciphertext is obtained by performing vector processing based on text information or image information; determining an NTRU private key and a rotation polynomial in a homomorphic encryption second-layer scheme, wherein the NTRU private key is used for decrypting an NTRU ciphertext in the homomorphic encryption second-layer scheme; generating a blind rotation key corresponding to a blind rotation algorithm according to the private key of the first LWE ciphertext and the NTRU private key, wherein the blind rotation key comprises a plurality of calculation keys EVK and a plurality of self-automorphism keys KSK, the plurality of calculation keys EVK are obtained by respectively encrypting the private key of the first LWE ciphertext based on the vector NTRU encryption method and using the NTRU private key, and the plurality of self-automorphism keys KSK are key switching keys used for self-automorphism processing, and the plurality of self-automorphism keys KSK are obtained by encrypting the self-automorphized NTRU private key based on the vector NTRU encryption method and using the NTRU private key; and homomorphic decrypting the first LWE ciphertext based on the rotation polynomial, the blind rotation key, and the blind rotation algorithm by the following way: generating an intermediate parameter ACC based on the first LWE ciphertext, the rotation polynomial, and a generator in a self-automorphism manner in , wherein the intermediate parameter ACC in is an element on a ring R Q ; obtaining a constant NTRU ciphertext based on the intermediate parameter ACC in and an nth calculation key evk n in the plurality of calculation keys EVK in a ciphertext outer product method ; performing iterative processing based on the constant NTRU ciphertext until the number of iterations reaches a predetermined number to obtain a constant NTRU ciphertext ; obtaining a target NTRU ciphertext based on the constant NTRU ciphertext , wherein the target NTRU ciphertext corresponds to the NTRU private key; and obtaining a target LWE ciphertext by processing based on the target NTRU ciphertext.

[0156] Those skilled in the art will understand that embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage media, etc.) having computer-usable program code embodied therein.

[0157] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.

[0158] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks.

[0159] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.

[0160] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0161] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) and / or cache memory, for storing instructions and data used by one or more of the components of the computing device. The memory can further include non-volatile memory, such as read-only memory (ROM), electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other non-volatile memory.

[0162] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0163] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusions, such that a process, method, article or apparatus that comprises a list of elements does not only include those elements, but also other elements not explicitly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element.

[0164] Those skilled in the art will appreciate that embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0165] The above merely illustrates the embodiments of the present application and is not intended to limit the present application. The present application can have various modifications and changes for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principles of the present application shall be included in the scope of the claims of the present application.

[0166] Industrial applicability

[0167] The scheme provided by the embodiments of the present application can be applied in the field of cryptography, and is used for data encryption and decryption processing, is a practical homomorphic encryption bootstrap technology, can quickly realize ciphertext bootstrap, significantly reduces the storage cost of the bootstrap key, and improves the calculation efficiency.< / g> < / g>

Claims

1. A homomorphic decryption method, comprising: obtaining a first LWE ciphertext and a private key of the first LWE ciphertext, wherein the first LWE ciphertext is a ciphertext to be homomorphic decrypted in a homomorphic encryption first-layer scheme, and the first LWE ciphertext is obtained by performing vector processing based on text information or image information; determining an NTRU private key and a rotation polynomial in a homomorphic encryption second-layer scheme, wherein the NTRU private key is used for decrypting an NTRU ciphertext in the homomorphic encryption second-layer scheme; generating a blind rotation key corresponding to a blind rotation algorithm according to the private key of the first LWE ciphertext and the NTRU private key, wherein the blind rotation key comprises a plurality of calculation keys EVK and a plurality of self-automorphism keys KSK, the plurality of calculation keys EVK are obtained by respectively encrypting the private key of the first LWE ciphertext by using the NTRU private key based on a vector NTRU encryption method, and the plurality of self-automorphism keys KSK are key switching keys for self-automorphism processing, and the plurality of self-automorphism keys KSK are obtained by encrypting a self-automorphized NTRU private key by using the NTRU private key based on the vector NTRU encryption method; Based on the rotation polynomial, the blind rotation key, and the blind rotation algorithm, the first LWE ciphertext is homomorphically decrypted by: based on the first LWE ciphertext, the rotation polynomial, and a generator, an intermediate parameter ACC is generated in a self-automorphism manner in , wherein the intermediate parameter ACC in is an element on a ring R Q ; based on the intermediate parameter ACC in and an nth computation key evk of a plurality of computation keys EVK n , a constant NTRU ciphertext NTRU is obtained by using a ciphertext outer product method based on the constant ntru ciphertext The iteration is performed until the iteration number reaches a predetermined number, and a constant NTRU ciphertext is obtained based on the constant ntru ciphertext obtaining a target NTRU ciphertext, wherein the target NTRU ciphertext corresponds to the NTRU private key; processing based on the target NTRU ciphertext to obtain a target LWE ciphertext.

2. The method of claim 1, wherein, The generating a blind rotation key corresponding to a blind rotation algorithm according to the private key of the first LWE ciphertext and the NTRU private key comprises: According to the NTRU private key, the parameters of the NTRU ciphertext corresponding to the NTRU private key, the lattice dimension associated with the LWE ciphertext, and the 0th to (n-1)th components included in the private key of the first LWE ciphertext are respectively encrypted to obtain the calculation keys EVK corresponding to the 0th to (n-1)th components in the plurality of calculation keys EVK, wherein the private key is represented as s=(s0,...,sn-1). n-1 s0,...,sn-1 represent the 0th to (n-1)th components, respectively, and the calculation keys corresponding to the 0th to (n-1)th components, respectively, are represented as evk n-1 evk k The evk k key is the kth calculation key in the plurality of calculation keys EVK, n is the lattice dimension, and 0≤k≤n-1. According to the NTRU private key, the parameters of the NTRU ciphertext corresponding to the NTRU private key, the lattice dimension associated with the LWE ciphertext, the sum of the 0th to n-1th components included in the private key of the first LWE ciphertext is encrypted, and the evk included in the plurality of calculation keys EVK is obtained n key; based on the evk k key and evk n key, obtaining the plurality of computation keys EVK; obtaining the blind rotation key based on the plurality of calculation keys EVK.

3. The method of claim 2, wherein, The evk k The key and the evk n The key and the evk are obtained, respectively, by: wherein NTRU'() represents the vector NTRU encryption method, Q represents a ciphertext modulus of the NTRU ciphertext, and f(X) represents the NTRU private key, denotes a variable of a polynomial ring of index s k s k denotes a component corresponding to the k-th calculation key, denotes an index the variable of the polynomial ring, wherein g represents the generator.

4. The method of claim 1, wherein, The generating a blind rotation key corresponding to a blind rotation algorithm according to the private key of the first LWE ciphertext and the NTRU private key comprises: According to the NTRU private key, the parameters of the NTRU ciphertext corresponding to the NTRU private key, the plurality of automorphism keys KSK are obtained by the following way; wherein the plurality of automorphism keys KSK includes ksk l denotes the l-th automorphism key, η is a predetermined batch size, l ∈ {1,..., η}, NTRU'() denotes the vector NTRU encryption method, wherein f (X) represents the NTRU private key, g represents the generator, and Q represents a ciphertext modulus of the NTRU ciphertext; obtaining the blind rotation key based on the plurality of self-automorphism keys KSK.

5. The method of claim 1, wherein, The constant NTRU ciphertext is obtained based on the constant NTRU plaintext The iteration is performed until the iteration number reaches a predetermined number, and a constant NTRU ciphertext is obtained The method comprises the following steps: The constant NTRU ciphertext As a start of the iteration process, the iteration number i is initially assigned the value 1, and the predetermined number of iterations is N is a polynomial degree corresponding to the NTRU ciphertext; setting an accumulation parameter τ with an initial value of 0, wherein the accumulation parameter τ is a positive integer and is used for recording a number of consecutive empty sets in a set U; In case that the iteration number i does not reach the predetermined number, the first a set matching an element included in the set U0 to determine a calculation key matched with the element in the plurality of calculation keys EVK; based on the plurality of matched computing keys, and the constant NTRU ciphertext obtained in the last iteration performing the ciphertext outer product processing to obtain a constant NTRU ciphertext obtained in the current iteration number and increasing the accumulation parameter τ by 1; wherein the last iteration number is i-1; The first a set is empty and the cumulative parameter τ has not reached the batch size η, and if the intermediate parameter ACC is not equal to 1, the intermediate parameter ACC is multiplied by a constant NTRU constant i , as a constant NTRU ciphertext obtained for the current iteration number and performing next iteration processing; The first a set is not empty, or the accumulated parameter τ reaches the batch size η, or In case of equal to 1, based on the intermediate parameter ACC i and g generating the meta-mapping τ index τ Performing the automorphism processing to obtain the intermediate parameter ACC' i ; based on the intermediate parameter ACC' i and the τth automorphism key in the plurality of automorphism keys KSK, performing the ciphertext outer product processing to obtain the constant NTRU ciphertext obtained by the current iteration number and resetting the accumulation parameter τ to 0 and performing next iteration processing; in a case where the iteration number i reaches the predetermined number, matching an element included in a first set U0 included in the set U to determine a calculation key matched with the element in the plurality of calculation keys EVK; based on the plurality of matched plurality of computing keys, and a constant NTRU ciphertext obtained in the last iteration times performing an outer product operation to obtain the constant NTRU ciphertext 6. The method of claim 5, wherein, The set U includes a jth set U j The set U j represents a set pre-computed based on the first LWE ciphertext, a i represents one or more elements in the first LWE ciphertext that satisfy the following formula: where g j represents an exponent j mapped on a generator.

7. The method of any one of claims 1 to 6, wherein, The processing based on the target NTRU ciphertext to obtain a target LWE ciphertext comprises: In the case that the ciphertext modulus of the first LWE ciphertext is q, and the ciphertext modulus of the target NTRU ciphertext is Q, the NTRU method is used to perform modulus switching, to obtain a first NTRU ciphertext with modulus Q ks . key switching the first NTRU ciphertext using the NTRU method to obtain a ciphertext with a key a second NTRU ciphertext; extracting a constant term from the second NTRU ciphertext, resulting in a ciphertext of dimension N and modulus Q ks , and a private key a second LWE ciphertext; truncating the second LWE ciphertext to obtain a ciphertext of dimension n and a ciphertext modulus Q ks , and a private key a third LWE ciphertext; Performing a modulus switching on the third LWE ciphertext to obtain a target LWE ciphertext with a ciphertext modulus q.

8. The method of claim 7, wherein, The first NTRU ciphertext is subjected to the NTRU method for key switching, and a second NTRU ciphertext with a key of is obtained, comprising: key switching the first NTRU ciphertext using the NTRU method to obtain a ciphertext with a key The second NTRU ciphertext of c ks = NTRU.KeySwitch(ACC ks , ksk * ) wherein ACC ks denotes the first NTRU ciphertext, ksk * denotes a key switch key, c ks is the second NTRU ciphertext; NTRU.KeySwitch(ACC ks , ksk * ) is obtained by: wherein, denotes the ciphertext outer product, The modulus is Q. ks The ring, Q ks This represents the modulus of the second LWE ciphertext.

9. A non-volatile storage medium, wherein, The non-volatile storage medium stores a plurality of instructions, which are adapted to be loaded by a processor and execute the homomorphic decryption method of any one of claims 1 to 8.

10. An electronic device, comprising: Comprise: One or more processors and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the homomorphic decryption method of any one of claims 1 to 8.

Citation Information

Patent Citations

  • An NTRU type multi-key fully homomorphic encryption method with a fast homomorphic operation process

    CN109936435A

  • Homomorphic encryption bootstrap method and device, processor, system on chip and computing equipment

    CN115834020A

  • Homomorphic decryption method and device, nonvolatile storage medium and computer equipment

    CN116192361A

  • Executing a cryptographic operation

    US20200313886A1

Cited By

  • Convolutional neural network security reasoning method and system based on homomorphic encryption optimization

    CN121750201A