Bootstrapping of fully homomorphic encrypted ciphertexts based on non-cyclotomic rings
Non-cyclotomic rings are used to encrypt and decrypt data using quotient rings and ideals, addressing the challenges of fully homomorphic encryption, enabling secure computations on encrypted data in cloud environments.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-04-09
AI Technical Summary
Conventional methods of fully homomorphic encryption and decryption face challenges in efficiently performing computations on encrypted data without exposing sensitive information.
The method employs non-cyclotomic rings to encrypt and decrypt data using quotient rings and ideals, utilizing encryption keys, randomizers, and noise values to maintain data security during computations, and employs bootstrapping techniques to reduce noise in fully homomorphic encryption.
Enables secure and efficient performance of computations on encrypted data, preserving privacy and security in cloud computing environments by ensuring data remains encrypted throughout the process.
Smart Images

Figure IL2025050873_09042026_PF_FP_ABST
Abstract
Description
[0001] BOOTSTRAPPING OF FULLY HOMOMORPHIC ENCRYPTED CIPHERTEXTS BASED ON NON-CYCLOTOMIC RINGS
[0002] TECHNICAL FIELD
[0003] The presently disclosed subject matter relates to data security, and in particular to methods of encryption and decryption.
[0004] BACKGROUND
[0005] Problems of performing fully homomorphic encryption and decryption have been recognized in the conventional art and various techniques have been developed to provide solutions.
[0006] SUMMARY
[0007] According to one aspect of the presently disclosed subject matter there is a processing circuitry (PC)-based method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.
[0008] In addition to the above features, the method according to this aspect of the presently disclosed subject matter can comprise one or more of features (i) to (xxii) listed below, in any desired combination or permutation which is technically possible:
[0009] (i) the irreducible non-cyclotomic polynomial is one of: f(x) = xn+ x - b, or f(x) = xn- x + b; and the first ideal is: x-b wherein b is an integer.
[0010] (ii) the method further comprising, prior to the encrypting: encoding a given plaintext, of a given plaintext space, to the element of the first non-cyclotomic ring, the encoding being based on:
[0011] EncodedElement = wherein EncodedElement denotes the element of the first non-cyclotomic ring, Firstldeal denotes the first ideal, and wherein m denotes the given plaintext, and wherein mi is based on: and wherein f(b) is equivalent to a size of the given plaintext space.
[0012] (iii) the third non-cyclotomic ring is an order of a field, the field being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial.
[0013] (iv) the third non-cyclotomic ring is a final extension ring of a series of extension rings, the series of extension rings successively extending the fourth non-cyclotomic ring, the series of extension rings being of a given series length, wherein each successive extension ring is based on an equation:
[0014] CurrentNonCyclotomicExtensionRing =
[0015] PredecessorNonCyclotomicRing[t] / MinimalPolynomial wherein PredecessorNonCyclotomicRing denotes a respective immediately preceding extension ring of the series, t is a respective additional algebraic element, and wherein MinimalPolynomial denotes a respective minimal polynomial, the respective minimal polynomial being based on an equation:
[0016] MinimalPolynomial = wherein Firstldeal denotes the first ideal, and wherein each aj is a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal, n is a respective given integer greater than 1, and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing[t], and the minimal polynomial is irreducible in PredecessorNonCyclotomicRing.
[0017] (v) the given series length is 1, and wherein the final extension ring of the series of final extensions rings is based on:
[0018] CurrentNonCyclotomicExtensionRing =
[0019] FourthNonCyclotomicRing[t] / MinimalPolynomial where FourthNonCyclotomicRing denotes the fourth non-cyclotomic ring.
[0020] (vi) the minimal polynomial defining the final extension ring is one of: a. tn2+ tn+ x, or b. tn2- tn + x, or
[0021] C. tn2+ tn + x, or d. tn2- tn + x, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings.
[0022] (vii) the minimal polynomial defining the final extension ring is one of: a. tn2+ tn+ btn-i, or b. tn2- tn + btn-1, Or
[0023] C. tn2+ tn - btn-1, Or d. tn2- tn - btn-1, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, and wherein tn-i denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring. (viii) the method further comprising, prior to the encrypting, encoding a given number of plaintexts to an element of the first non-cyclotomic ring, wherein the encoding comprises: a) generating, for each plaintext of the given number of plaintexts, a respective per- plaintext ring element of the first non-cyclotomic ring, the generating being based on:
[0024] PerPlaintextRingElement = wherein PerPlaintextRingElement denotes the element of the first non- cyclotomic ring, and wherein m denotes the given plaintext, and wherein mi is based on: m = and wherein f(b) is equivalent to a size of the given plaintext space; and b) calculating an encoded element based on the formula:
[0025] EncodedElementco = wherein EncodedElementco denotes the element of the first non-cyclotomic ring, n denotes the given number of plaintexts, PerPlaintextRingElementi denotes a respective per-plaintext ring element, and denotes a respective Lagrange coefficient. (ix) the given number of plaintexts is: wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring.
[0026] (x) the encrypting the element of a first non-cyclotomic ring comprises: calculating a linear combination, over the second non-cyclotomic ring of, at least: i. the element of the first non-cyclotomic ring, ii. a sum of, at least: a. a product of, at least, an encryption key and a randomizer, and b. a noise value, the calculating thereby resulting in an element of the second non-cyclotomic ring.
[0027] (xi) the encryption key is an element of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.
[0028] (xii) the encrypting is based on:
[0029] EncryptedElementco =
[0030] (PlaintextElement + ((Randomizer * EncryptionKey) +NoiseValue) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer. (xiii) the encrypting is based on:
[0031] EncryptedElementco =
[0032] (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizers is sampled from a distribution over a ring with a bounded expected norm.
[0033] (xiv) the encrypting is based on:
[0034] EncryptedElementco =
[0035] ((PlaintextElement *SeFcirosntdlddeaelal
[0036] (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue))
[0037] + Randomizers) mod (ThirdNonCyclotomicRing / Secondldeal) wherein the first ideal and second ideal are principal ideals, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizers is sampled from a distribution over a ring with a bounded expected norm.
[0038] (xv) the encrypting is based on:
[0039] EncryptedElementco =
[0040] ((PlaintextElement * Secondldeal) +
[0041] ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizers) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizers is sampled from a distribution over a ring with a bounded expected norm.
[0042] (xvi) the encrypting is based on:
[0043] EncryptedElementco =
[0044] (PlaintextElement +
[0045] (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizers) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizers is sampled from a distribution over a ring with a bounded expected norm.
[0046] (xvii) the encryption key is an element of a module derivative of the second non- cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm.
[0047] (xviii) the encrypting is based on:
[0048] EncryptedElementco =
[0049] (PlaintextElement + ((Randomizer * EncryptionKey) +NoiseValue) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.
[0050] (xix) the encrypting is based on:
[0051] EncryptedElementco =
[0052] (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative the second non-cyclotomic ring, and wherein Randomizers is sampled from a distribution over a ring with a bounded expected norm.
[0053] (xx) the encrypting is based on:
[0054] EncryptedElementco =
[0055] . Secondldeal .
[0056] ((PlaintextElement * — Fi : -rstld - —ea —l )7+
[0057] (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue))
[0058] + Randomizers) mod (ThirdNonCyclotomicRing / Secondldeal) wherein the first ideal and second ideal are principal ideals, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizers is sampled from a distribution over a ring with a bounded expected norm.
[0059] (xxi) the encrypting is based on:
[0060] EncryptedElementco =
[0061] ((PlaintextElement * Secondldeal) +
[0062] ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizers) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizers is sampled from a distribution over a ring with a bounded expected norm.
[0063] (xxii) the encrypting is based on:
[0064] EncryptedElementco =
[0065] (PlaintextElement +
[0066] (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizers) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) ) wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Firstldeal denotes the first ideal, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, and wherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizers is sampled from a distribution over a ring with a bounded expected norm.
[0067] According to another aspect of the presently disclosed subject matter there is provided a system of fully homomorphic encryption, the system comprising a processing circuitry (PC) configured to: encrypt an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.
[0068] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xxii) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.
[0069] According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processing circuitry to perform a method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.
[0070] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xxii) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.
[0071] (According to another aspect of the presently disclosed subject matter there is a processing circuitry (PC)-based method of decrypting fully homomorphically encrypted data, the method comprising: decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.
[0072] In addition to the above features, the method according to this aspect of the presently disclosed subject matter can comprise one or more of features (i) to (xvi) listed below, in any desired combination or permutation which is technically possible:
[0073] (i) the irreducible non-cyclotomic polynomial is one of: f(x) = xn+ x - b, or f(x) = xn- x + b; and the first ideal is: x-b wherein b is an integer.
[0074] (ii) the method further comprising, subsequent to the decrypting: decoding the element of the first non-cyclotomic ring to a plaintext of a given plaintext space.
[0075] (Hi) the decoding is based on calculating: felement(b) wherein feiementO is apolynomial function corresponding to the element of the first non-cyclotomic ring.
[0076] (iv) the first non-cyclotomic ring is a quotient ring based on a final ring of a series of successive rings extending a fourth non-cyclotomic ring, and wherein the decoding comprises: a) determining one or more roots of a minimal polynomial associated with the first non-cyclotomic ring; b) for each determined root: calculating a result of substituting, in the element of the first non- cyclotomic ring, a respective extending algebraic element with the respective root, thereby generating one or more elements of a quotient ring derivative of a preceding ring of the series; c) responsive to the preceding ring being an extension ring of the fourth non- cyclotomic ring: for each generated element: repeating a) - b); and d) responsive to the preceding ring being the fourth non-cyclotomic ring: calculating, for each generated element feiement(); felement(b) thereby giving rise to one or more plaintexts.
[0077] (v) the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring: a value based on a product of a decryption key and a randomizing element, the decryption key and the randomizing element being elements of the second non-cyclotomic ring, thereby resulting in an element of the first non-cyclotomic ring.
[0078] (vi) the decrypting is based on:
[0079] DecryptedElement = EncryptedElementco - (DecryptionKey * EncryptedElementci) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, EncryptedElementco denotes the element of the second non-cyclotomic ring, EncryptedElementci denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.
[0080] (vii) the decryption key is a symmetric key.
[0081] (viii) the decryption key is a private key.
[0082] (ix) the randomizing element is derivative of at least one randomizer.
[0083] (x) the randomizing element is further derivative of at least one constant value. (xi) the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring: a value based on a product of a decryption key and a randomizing element, the decryption key and the randomizing element being elements of a module derivative of the second non-cyclotomic ring,
[0084] (xii) the decrypting is based on:
[0085] DecryptedElement = EncryptedElementco - (DecryptionKey * EncryptedElementci) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, Secondldeal denotes the second ideal, EncryptedElementco denotes the element of the second non-cyclotomic ring, EncryptedElementci denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.
[0086] (xiii) the decryption key is a symmetric key.
[0087] (xiv) the decryption key is a private key.
[0088] (xv) The randomizing element is derivative of at least one randomizer.
[0089] (xvi) the randomizing element is further derivative of at least one constant value.
[0090] According to another aspect of the presently disclosed subject matter there is provided a system of decrypting fully homomorphically encrypted data, the system comprising a processing circuitry (PC) configured to: decrypt an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.
[0091] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xvi) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.
[0092] According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processing circuitry to perform a method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.
[0093] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xvi) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.
[0094] According to one aspect of the presently disclosed subject matter there is provided a processor-based method comprising bootstrapping a first ciphertext that is a fully -homomorphic encryption of a plaintext, the plaintext being representable as a vector of coefficients of a polynomial and being associated with a plaintext modulus ak, the bootstrapping comprising: a) obtaining, from the first ciphertext, an encryption of data indicative of one or more coefficients of the plaintext; b) based on a bootstrapping key, performing one or more Torus-fully -homomorphic-encryption (TFHE) bootstrappings on the obtained encryption of data, the bootstrappings resulting in one or more bootstrap outputs; c) deriving, from the one or more bootstrap outputs, a series of one or more encrypted values, each value of the series being based on a coefficient of a respective term of a polynomial based on: coeff_pt • (Numerator / (X - a)), wherein coeff_pt denotes the data indicative of one or more coefficients of the plaintext; and d) creating, from at least a key -switching key and the derived series of encrypted values, data indicative of a ring-based or module-based ciphertext, resulting in a second ciphertext that is an encryption, with reduced noise, of the data indicative of one or more coefficients of the plaintext; wherein a and k are integers and Numerator is a numerator.
[0095] In addition to the above features, the method according to this aspect of the presently disclosed subject matter can comprise one or more of features (i) to (xii) listed below, in any desired combination or permutation which is technically possible:
[0096] (i) homomorphically right-shifting the first ciphertext to obtain a ciphertext encrypting a shifted plaintext, and repeating steps a)-d) upon the ciphertext encrypting the shifted plaintext, thereby resulting in an encryption, with reduced noise, of data indicative of one or more coefficients of the shifted plaintext;
[0097] (ii) repeating feature (i) for one or more additional iterations to obtain a series of ciphertexts comprising a respective ciphertext encrypting data indicative of each coefficient of the plaintext, and combining the ciphertexts of the series to result in a bootstrapped first ciphertext;
[0098] (iii) the Numerator being XAi, where i is a count of right-shifts homomorphically performed on the first ciphertext, the combining being summation; (iv) a = 2;
[0099] (v) obtaining the encryption of data indicative of one or more coefficients comprising performing sample extraction;
[0100] (vi) each coefficient in the vector of coefficients being a multivariate polynomial;
[0101] (vii) the encryption of the one or more coefficients being Brakerski-Fan-Vercauteren (BFV) encryption;
[0102] (viii) each TFHE bootstrapping being a programmable bootstrapping employing a function computing a product of an input with one or more elements of a gadget vector, the one or more programmable bootstrappings resulting in a plurality of bootstrap outputs, each bootstrap output being an encryption of a respective product of the data indicative of one or more coefficients by an element of the gadget vector;
[0103] (ix) the one or more TFHE bootstrappings being a single TFHE bootstrapping, the employed function being a multi-output function outputting a vector of respective products of the data indicative of one or more coefficients by respective elements of the gadget vector;
[0104] (x) the plaintext being an element of a first non-cyclotomic ring and the first ciphertext being an element of a second non-cyclotomic ring, wherein: the first non-cyclotomic ring is a quotient of (a third non-cyclotomic ring derived from an irreducible non-cyclotomic polynomial) by a first non-trivial ideal; and the second non-cyclotomic ring is a quotient of the third non-cyclotomic ring by a second ideal different from the first non-trivial ideal;
[0105] (xi) creating the ring-based or module-based ciphertext being based on a summation: 2 / / . / / (IntermediateCiphertext)^,!} ■ ksk_{j,l}, where j indexes a gadget vector,
[0106] ( I ntcrmcdi atcCi phcrtcxt )_ f j . I ; is a j-th element of a corresponding gadget decomposition of a value encrypted in an 1-th encrypted value of the series of encrypted values, and ksk_{j ,1} is an encryption, under a target key, of a product of an 1-th coefficient of a secret key associated with the first ciphertext with a j-th element of the gadget vector;
[0107] (xii) creating the ring-based or module-based ciphertext further comprising multiplying the summation by (X - a).
[0108] According to another aspect of the presently disclosed subject matter there is provided a system comprising a memory and processing circuitry operatively coupled to the memory, the processing circuitry configured to perform bootstrapping of a first ciphertext that is a fully - homomorphic encryption of a plaintext representable as a vector of coefficients of a polynomial and associated with a plaintext modulus ak, by being configured to: a) obtain, from the first ciphertext, an encryption of data indicative of one or more coefficients of the plaintext; b) based on a bootstrapping key, perform one or more TFHE bootstrappings on the obtained encryption of data, resulting in one or more bootstrap outputs; c) derive, from the one or more bootstrap outputs, a series of one or more encrypted values, each based on coeff_pt • (Numerator / (X - a)); and d) create, from at least a key-switching key and the derived series of encrypted values, data indicative of a ring-based or module-based ciphertext to obtain a second ciphertext that encrypts, with reduced noise, data indicative of one or more coefficients of the plaintext; wherein a and k are integers and Numerator is a numerator.
[0109] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xii) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible.
[0110] According to another aspect of the presently disclosed subject matter there is provided a computer-program product comprising a computer-readable non-transitory storage medium containing program instructions which, when read by processing circuitry, cause the processing circuitry to perform a method comprising bootstrapping a first ciphertext that is a fully - homomorphic encryption of a plaintext representable as a vector of coefficients of a polynomial and associated with a plaintext modulus ak, the bootstrapping comprising: a) obtaining, from the first ciphertext, an encryption of data indicative of one or more coefficients of the plaintext; b) based on a bootstrapping key, performing one or more TFHE bootstrappings on the obtained encryption of data, resulting in one or more bootstrap outputs; c) deriving, from the one or more bootstrap outputs, a series of one or more encrypted values, each based on coeff_pt • (Numerator / (X - a)); and d) creating, from at least a key -switching key and the derived series of encrypted values, data indicative of a ring-based or module-based ciphertext, resulting in a second ciphertext that encrypts, with reduced noise, data indicative of one or more coefficients of the plaintext; wherein a and k are integers and Numerator is a numerator.
[0111] This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xii) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible. BRIEF DESCRIPTION OF THE DRAWINGS
[0112] In order to understand the invention and to see how it can be carried out in practice, embodiments will be described, by way of non-limiting examples, with reference to the accompanying drawings, in which:
[0113] Fig. 1 illustrates an example deployment of fully-homomorphic encryption / decryption, in accordance with some embodiments of the presently disclosed subject matter;
[0114] Fig. 2A illustrates a logical block diagram of an example computer system enabled for performance of fully homomorphic encryption (FHE), in accordance with some embodiments of the presently disclosed subject matter;
[0115] Fig. 2B illustrates a logical block diagram of an example deployment of a computer system enabled for decryption of data encrypted using FHE, in accordance with some embodiments of the presently disclosed subject matter;
[0116] Fig. 2C illustrates a logical block diagram of an example example system that performs FHE operations (evaluations) and bootstrapping, in accordance with some embodiments of the presently disclosed subject matter;
[0117] Fig. 3 illustrates a flow diagram of an example method of ring-based fully- homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter;
[0118] Fig. 4 illustrates a flow diagram of an example method of module-based fully- homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter;
[0119] Fig. 5 illustrates a flow diagram of an example method of decrypting data that was encrypted using ring-based or module-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter; Fig. 6 illustrates a flow diagram of an example method of bootstrapping a ciphertext that is based on a non-cyclotomic ring or module, in accordance with some embodiments of the presently disclosed subject matter; and
[0120] Fig. 7 illustrates a flow diagram of an example method of bootstrapping and repacking a ciphertext that is an encryption of one or more plaintext coefficients extracted from a ring-based or module-based FHE ciphertext, in accordance with some embodiments of the presently disclosed subject matter.
[0121] DETAILED DESCRIPTION
[0122] In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, it will be understood by those skilled in the art that the presently disclosed subject matter may be practiced without these specific details. In other instances, well-known methods, procedures, components and circuits have not been described in detail so as not to obscure the presently disclosed subject matter.
[0123] Unless specifically stated otherwise, as apparent from the following discussions, it is appreciated that throughout the specification discussions utilizing terms such as "processing", "computing", "comparing", "encrypting", “decrypting”, "determining", "calculating", “receiving”, “providing”, “obtaining”, “emulating” or the like, refer to the action(s) and / or process(es) of a computer that manipulate and / or transform data into other data, said data represented as physical, such as electronic, quantities and / or said data representing the physical objects. The term “computer” should be expansively construed to cover any kind of hardware-based electronic device with data processing capabilities including, by way of non-limiting example, the processor, mitigation unit, and inspection unit therein disclosed in the present application.
[0124] The terms "non-transitory memory" and “non-transitory storage medium” used herein should be expansively construed to cover any volatile or non-volatile computer memory suitable to the presently disclosed subject matter. The operations in accordance with the teachings herein may be performed by a computer specially constructed for the desired purposes or by a general-purpose computer specially configmed for the desired purpose by a computer program stored in a non- transitory computer-readable storage medium.
[0125] Embodiments of the presently disclosed subject matter are not described with reference to any particular programming language. It will be appreciated that a variety of programming languages may be used to implement the teachings of the presently disclosed subject matter as described herein.
[0126] Homomorphic encryption is a form of encryption that allows computations to be performed on encrypted data. When mathematical operations are performed on a homomorphically encrypted ciphertext, the result is a ciphertext that, when decrypted, matches the result of identical operations performed on the original plaintext.
[0127] Certain homomorphic encryption schemes allow limited types of operations (e.g. addition or multiplication only). Fully Homomorphic Encryption (FHE) supports both addition and multiplication operations on ciphertexts, making it theoretically possible to perform any computation on encrypted data.
[0128] In distributed computing, homomorphic encryption can be valuable because it allows data to be processed by untrusted third parties without exposing sensitive information. For example, in cloud computing environments, users can offload computations to a cloud server without revealing the underlying data. This is useful in privacy -preserving applications such as secure voting systems, confidential machine learning, and secure data outsourcing. By ensuring that the data remains encrypted throughout the process, homomorphic encryption enhances security and privacy while enabling distributed systems to perform necessary computations.
[0129] Some embodiments of the presently disclosed subject matter are directed to methods of fully-homomorphic encryption and decryption based on non-cyclotomic rings. Some advantages of methods based on non-cyclotomic rings are presented in the additional disclosure section below. Fig. 1 illustrates an example deployment of fully-homomorphic encryption / decryption, in accordance with some embodiments of the presently disclosed subject matter.
[0130] Encryption system 105 can be a computer system adapted to perform encryption in a manner which enables FHE decryption. An example encryption system 105 is described below, with reference to Fig. 2A.
[0131] Communication network 110 can be any kind of suitable network for computer communications (Ethernet, Wi-Fi, 3G wireless network, 4G wireless network, 5G wireless network, Infiniband, etc.). In embodiments, communication network 110 includes a local area network (LAN), a wide area network (WAN), the Internet, and / or one or more Intranets. Communication network 110 can be operably attached to encryption system 105, encrypted calculation system 115, and decryption system 120.
[0132] Encryption calculation system 115 can be a computer system adapted to perform computation on FHE-encrypted data (i.e. without decrypting it first).
[0133] Decryption system 120 can be a computer system adapted to perform FHE decryption. An example encryption system 105 is described below, with reference to Fig. 2B
[0134] In some examples, encryption system 105 can encrypt data using homomorphic encryption in combination with e.g. a public key that is associated with a private key held by decryption system 120. Encryption system 105 can e.g. transmit the encrypted data to encrypted calculations system 115, which performs mathematical operations based on the encrypted data. Encrypted calculations system 115 can transmit the results of the mathematical operations to decryption system 120, which can then decrypt the encrypted results of the mathematical operations e.g. using its private key.
[0135] Fig. 2A illustrates a logical block diagram of an example computer system enabled for performance of fully homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter. T1
[0136] Encryption system (processing circuitry) 200A can include processor 205A and memory 210A.
[0137] Processor 205A can be a suitable hardware-based electronic device with data processing capabilities, such as, for example, a general purpose processor, digital signal processor (DSP), a specialized Application Specific Integrated Circuit (ASIC), one or more cores in a multicore processor, etc. Processor 205A can also consist, for example, of multiple processors, multiple ASICs, virtual processors, combinations thereof etc.
[0138] Memory 210A can be, for example, a suitable kind of volatile and / or non-volatile storage, and can include, for example, a single physical memory component or a plurality of physical memory components. Memory 210A can also include virtual memory. Memory 210A can be configured to, for example, store various data used in computation.
[0139] Encryption system (processing circuitry) 200A can be configured to execute several functional modules in accordance with computer-readable instructions implemented on a non-transitory computer-readable storage medium. Such functional modules are referred to hereinafter as comprised in the processing circuitry. These modules can include, for example, communications unit 215A, optional ring-based encryption unit 220A, optional module-based encryption unit 225A, and optional encoding unit 230A. The functional modules may include hardware modules, software modules, firmware modules, or combinations thereof. In some embodiments, the operations described with reference to one or more of the communications unit 215A, optional ring-based encryption unit 220A, optional module-based encryption unit 225A, and optional encoding unit 230A may be combined into fewer units. In some embodiments, the operations described with reference to one or more of the communications unit 215A, optional ring-based encryption unit 220A, optional modulebased encryption unit 225A, and optional encoding unit 230A may be split up and handled by separate units.
[0140] Communications unit 215A can be any suitable component usable for communicating via communication network 110 (ethemet controller, wi-fi controller etc.). Communications unit 215A can facilitate e.g. reception of data for encryption and / or transmission of encrypted data. Optional ring -based encryption unit 220A can encrypt data using a ring -based fully homomorphic encryption method as detailed herein.
[0141] Some embodiments of the presently disclosed subject matter utilize a plaintext ring which is a quotient ring of a non-cyclotomic ring (termed R) and an Ideal (termed I). Such a plaintext ring (herein termed “P”) can be described formally as:
[0142] P = R / I where R is a ring such that:
[0143] R=Z[x] / f()
[0144] Where:
[0145] Z[x] denotes the set of all polynomials with integer coefficients (and for which the operations of addition and multiplication are defined as polynomial addition and multiplication), f() is an irreducible non-cyclotomic polynomial and the ideal I is a non-trivial ideal of the ring R (i.e. a proper subset of R satisfying additive closure and absorption, as known in the art).
[0146] Some embodiments of the presently disclosed subject matter utilize a ciphertext ring which is a quotient ring of the non-cyclotomic ring R and a second ideal herein termed Q (which is distinct from I). Such a ciphertext ring (herein termed “C”) can be described formally as:
[0147] C = R / Q
[0148] In some embodiments, the plaintext ring and ciphertext ring are based on the following definitions:
[0149] The irreducible non-cyclotomic polynomial from which the non- cyclotomic ring R is derived is: f(x) = xn + x - b for some degree n, and the Ideal of the non-cyclotomic ring is: x-b where b is an integer.
[0150] In some other embodiments, the plaintext ring and ciphertext ring are based on the following definitions:
[0151] The irreducible non-cyclotomic polynomial from which the non- cyclotomic ring R is derived is: f(x) = xn + x + b for some degree n, and the Ideal of the non-cyclotomic ring is: x-b where b is an integer.
[0152] In some other embodiments, the plaintext ring and ciphertext ring are based on other specifications of f() and I.
[0153] Some embodiments of the presently disclosed subject matter are directed to methods of encrypting an element of a non-cyclotomic plaintext ring to an element of a non-cyclotomic ciphertext ring.
[0154] These methods can employ a e.g. symmetric encryption key or a public key / private key scheme. These methods can also employ one or more randomizers and / or constant values. These methods can also employ noise values.
[0155] To facilitate subsequent homomorphic mathematical operations as well as decryption / reconstruction of plaintexts, some embodiments utilize a pair of ciphertext ring elements which can be transmitted together.
[0156] In some examples herein, this pair of elements making up a ciphertext are described as two elements in parentheses, e.g. (co, Cl) where co identifies a ciphertext ring element that is derivative of an encryption operation utilizing e.g. a plaintext element, an encryption key and other parameters, and where ci is a ciphertext ring element that is derivative of e.g. randomizers and / or noise values and / or constant values and / or other parameters.
[0157] In some examples herein, the pair of elements making up a ciphertext are described using the terms EneryptedElementco and EneryptedElementci to refer to the respective elements. In some cases herein, EneryptedElementci is referred to as a “randomizing element”.
[0158] Ring-based encryption unit 220A can, for example, utilize methods such as the methods described below with reference to Fig. 3.
[0159] Optional module-based encryption unit 225A can encrypt data using a modulebased fully homomorphic encryption method.
[0160] A module over a ring R is a generalization of a vector space, where the scalars come from a ring rather than a field.
[0161] Some embodiments of the presently disclosed subject matter are directed to encryption / decryption methods which utilize modules as randomizing elements.
[0162] In such embodiments, the second element (i.e. ci) of the (co, ci) ciphertext (i.e. EneryptedElementci) is a module.
[0163] Module-based encryption can have desirable security properties, as detailed below.
[0164] Module-based encryption unit 225A can, for example, utilize methods such as the methods described below with reference to Fig. 4.
[0165] Optional encoding unit 230A can encode data (e.g. integers, binary data) to elements of a plaintext ring to facilitate encryption. Optional encoding unit 230A can utilize encoding methods as described below with reference to Fig. 3. It is noted that encryption system (processing circuitry) 200A can additionally implement some or all of the functions of encryption system (processing circuitry) 200B.
[0166] Fig. 2B illustrates a logical block diagram of an example deployment of a computer system enabled for decryption of data encrypted using FHE, in accordance with some embodiments of the presently disclosed subject matter.
[0167] Decryption system (processing circuitry) 200B can include processor 205B and memory 210B.
[0168] Processor 205B can be a suitable hardware-based electronic device with data processing capabilities, such as, for example, a general purpose processor, digital signal processor (DSP), a specialized Application Specific Integrated Circuit (ASIC), one or more cores in a multicore processor, etc. Processor 205B can also consist, for example, of multiple processors, multiple ASICs, virtual processors, combinations thereof etc.
[0169] Memory 210B can be, for example, a suitable kind of volatile and / or non-volatile storage, and can include, for example, a single physical memory component or a plurality of physical memory components. Memory 210B can also include virtual memory. Memory 210B can be configured to, for example, store various data used in computation.
[0170] Decryption system (processing circuitry) 200B can be configured to execute several functional modules in accordance with computer-readable instructions implemented on a non-transitory computer-readable storage medium. Such functional modules are referred to hereinafter as comprised in the processing circuitry. These modules can include, for example, communications unit 215B, decryption unit 220B, and optional decoding unit 225B.
[0171] Decryption unit 220B can receive ciphertexts (e.g. ring-based or module-based) and can decrypt them to e.g. plaintext ring elements unit 220B can do this, for example, utilizing methods such as the methods described below with reference to Fig. 5.
[0172] Decoding unit 225B can then decode decrypted plaintext ring elements unit to e.g. integer or binary data. Decoding unit 225B can utilize, for example methods such as those described below with reference to Fig. 5. Attention is directed to Fig. 3, which illustrates a flow diagram of an example method of ring-based fully -homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.
[0173] Optionally: in some examples, it is desirable to perform fully homomorphic encryption (and possibly subsequent encrypted mathematical operations) upon plaintexts consisting of integers, binary data etc.
[0174] To accomplish this, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode (305) such a plaintext. More specifically: encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can map the plaintext to an element of a plaintext ring (e.g. a plaintext ring in accordance with the plaintext ring definition provided above), so as to facilitate performing fully homomorphic encryption on the plaintext ring element.
[0175] In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes a single plaintext to a single element of the plaintext ring. In some other examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes multiple plaintexts to a single plaintext ring element.
[0176] In some examples, a plaintext consists of a series of binary digits of a plaintext space of given size. For example: a binary plaintext can be of length 8 (i.e. the plaintext size is 256). In such embodiments, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode the plaintext to a polynomial element of the plaintext ring (the ring being defined by a polynomial f() ) based on the formula:
[0177] EncodedElement = wherein m denotes the given plaintext, and wherein mi is based on: and where f(b) is equivalent to the size of the plaintext space, and Logb() denotes the logarithm in base b.
[0178] Accordingly, when the value of b is 2 (i.e. the first Ideal is x-2):
[0179] EncodedElement =
[0180] Log2 (SizeOfPlaintextSpace)-l mix1 where m denotes the given plaintext, and wherein mi is based on: m =
[0181] Log2 (SizeOfPlaintextSpace)-l mi2‘
[0182] It is noted that in the formula above (i.e. with b = 2), the indexes of the polynomial terms are identical to the binary digits of the plaintext.
[0183] In some embodiments, multiple plaintexts can be encoded in a single plaintext ring element for encryption.
[0184] In such embodiments, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can utilize a special case of the non-cyclotomic ring R from which the plaintext ring and ciphertext ring are derived. Specifically, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can utilize a non-cyclotomic ring R that is an order of a field, the field in turn being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial.
[0185] In some such embodiments, this ring can be a final ring of a recursive series of extension rings of the fourth non-cyclotomic ring for which: the irreducible non-cyclotomic polynomial f(x) is either xn+ x - b or xn- x + b, and the first ideal (where the plaintext ring is derived by taking the quotient of the fourth non-cyclotomic ring R and the first ideal) is x-b where b is some integer.
[0186] For example, the first extension ring of the fourth non-cyclotomic ring can be based on:
[0187] FourthNonCyclotomicRing[t] / MinimalPolynomial where t is an algebraic element being added to the fourth non-cyclotomic ring, and where the minimal polynomial can be based on: and wherein c(t) and d(t) are polynomials in FourthNonCyclotomicRing[t], and the minimal polynomial is irreducible in the fourth non-cyclotomic ring. In some embodiments, n is an integer greater than one that defines the degree of the minimal polynomial (and determines the number of plaintext slots that will be available). Each aj can be a unique element of a ring that is a quotient of the fourth non-cyclotomic ring and the first ideal.
[0188] Similarly, subsequent extension rings can be based on:
[0189] PredecessorNonCyclotomicRing[ti] / MinimalPolynomial wherein PredecessorNonCyclotomicRing denotes the immediately preceding extension ring of the series, and ti is a respective additional algebraic element being added in this extension.
[0190] In this case, the minimal polynomial of the extension can again be based on: and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing [t], and the minimal polynomial is irreducible in the fourth non-cyclotomic ring, n is an integer greater than one that defines the degree of the minimal polynomial (and determines the number of plaintext slots that will be available). Each aj can be a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal. In some embodiments, n is an integer greater than one that defines the degree of this particular minimal polynomial.
[0191] The series of recursive extensions of the fourth non-cyclotomic ring can have a particular series length (e.g. 5).
[0192] The number of plaintext slots available in an element of the final extension ring of the series of extension rings can then be: wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring.
[0193] In some embodiments, the minimal polynomial defining the final extension ring of the series of extension rings is one of: a) tn2+ tn + x, or b) tn2- tn + x, or c) tn2+ tn + x, or d) tn2- tn + x, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings. In some embodiments, the minimal polynomial defining the final extension ring is one of: a) tn2+ tn + btn-i, or b) tn2- tn + btn-1, Or C) tn2+ tn - btn-1, Or d) tn2- tn - btn-1, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, and wherein tn-i denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring.
[0194] Encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode a given number of plaintexts to a single ring element of the plaintext ring that is the quotient of the final extension ring and the first ideal.
[0195] In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes a number of plaintexts that is equivalent to the number of plaintext slots available in each ring element (as given by the formula above). In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes a number of plaintexts that is less than the number of plaintext slots available, and utilizes other values (e.g. 0) in the unused slots.
[0196] Encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode the plurality of plaintexts based on the following steps: a) generating, for each plaintext of the given number of plaintexts, a respective per- plaintext ring element of the plaintext ring, the generating being based on:
[0197] PerPlaintextRingElement = wherein PerPlaintextRingElement denotes the element of the plaintext ring, and wherein m denotes the given plaintext, and wherein mi is based on: m = and wherein f(b) is equivalent to a size of the given plaintext space; and b) calculating an encoded element based on the formula:
[0198] EncodedElementco =
[0199] (n-1 x
[0200] PerPlaintextRingElementi ■ j mod Firstldea ) i=0 ' wherein EncodedElementco denotes the element of the plaintext ring, n denotes the given number of plaintexts, PerPlaintextRingElementi denotes a respective per- plaintext ring element, and denotes a respective Lagrange coefficient.
[0201] It is noted that this encoding method can be utilized to encode plaintexts to rings other than the rings defined herein. Similarly, it is noted that this encoding method can be utilized in the context of other applications (e.g. other encryption applications, nonencryption applications).
[0202] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can obtain (310) an encryption key. In some examples, the encryption key is received or derived from a secure key exchange mechanism. In some examples, the encryption key is an element of the ciphertext ring. . In some examples, the encryption key is an element of an algebraic structure (e.g. a module) that is derivative of the ciphertext ring.
[0203] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally obtain one or more randomizer. A randomizer can be a random value (with suitable distribution characteristics as described herein), that is used in the encryption to enhance security. In some examples, randomizers are obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use a randomizer.
[0204] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally obtain one or more noise values. Noise values can be a random value (with suitable distribution characteristics as described herein), that are used in homomorphic encryption to enhance security. In some examples, the noise values is obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use noise values.
[0205] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can next encrypt (315) an element of the plaintext ring to an element of the ciphertext ring.
[0206] In some embodiments, encryption system (processing circuitry) 200A (e.g. ringbased encryption unit 220A) performs the encryption by calculating a linear combination, over the ciphertext ring of, at least: the element of the plaintext ring to be encrypted, and a sum of, at least:
[0207] (i) a product of, at least, an encryption key and a randomizer, and
[0208] (ii) a noise value where the encryption key is an element of the ciphertext ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.
[0209] In some such embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a symmetric encryption key, e.g. in accordance with the formula: EncryptedElementco =
[0210] (PlaintextElement + (Randomizer * EncryptionKey + NoiseValue)) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the plaintext ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the plaintext ring, EncryptionKey is the encryption key (i.e. an element of the ciphertext ring), NoiseValue is a noise value is sampled from the first ideal, and Randomizer is sampled from a distribution over a ring with a bounded expected norm.
[0211] In this case the associated randomizing element (e.g. for use in decryption) can be defined in accordance with the formula:
[0212] EncryptedElementc! =
[0213] (Randomizer) mod (ThirdNonCyclotomicRing / Secondldeal)
[0214] It is noted that in this case EncryptedElementco is a linear combination of the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.
[0215] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, e.g. in accordance with the formula:
[0216] EncryptedElementco =
[0217] (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / Secondldeal) where ConstantValue is a constant that is an element of the ciphertext ring, and Randomizers is sampled from distributions over respective rings with bounded expected norms. In this case the associated randomizing element can be defined in accordance with the formula:
[0218] EncryptedElementci = ((Randomizer * ConstantValue)' + Randomizers) mod (ThirdNonCyclotomicRing / Secondldeal) where Randomizer is sampled from a distribution over a ring with a bounded expected norm.
[0219] It is noted that here also EncryptedElementco is a linear combination of, at least, the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.
[0220] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal and second ideal are principal ideals, .in accordance the following formula:
[0221] EncryptedElementco =
[0222] ( (PlaintextElement
[0223] ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / Secondldeal)
[0224] In this case the associated randomizing element can be defined in accordance with the formula:
[0225] EncryptedElementci = ((Randomizer! * ConstantValue)' + Randomizers) mod (ThirdNonCyclotomicRing / Secondldeal)
[0226] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal is not a principal ideal, and the second ideal is a principal ideal, .in accordance the following formula: EncryptedElementco =
[0227] ( (PlaintextElement * Secondldeal) + ((Randomizer! * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )
[0228] In this case the associated randomizing element can be defined in accordance with the formula:
[0229] EncryptedElementci = ((Randomizer! * ConstantValue)' + Randomizers) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )
[0230] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the element of the plaintext ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, _in accordance the following formula:
[0231] EncryptedElementco =
[0232] (PlaintextElement + ((Randomizer! * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )
[0233] In this case the associated randomizing element can be defined in accordance with the formula:
[0234] EncryptedElementci = ((Randomizer! * ConstantValue) + Randomizers) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal)
[0235] )
[0236] Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally store (320) data derivative of the randomizer(s) and / or constant value, for use in decryption. For example: encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can compute EncryptedElementci according to formulas given above.
[0237] Attention is directed to Fig. 4, which illustrates a flow diagram of an example method of module-based fully -homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.
[0238] As in the case of ring-based encryption, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode (405) a plaintext to the plaintext ring. Encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can optionally utilize encoding methods as described with reference to Fig. 3 above.
[0239] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can obtain (410) an encryption key. In some examples, the encryption key is received or derived from a secure key exchange mechanism. In some examples, the encryption key is an element of a module that is derivative of the ciphertext module.
[0240] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally obtain one or more randomizer. A randomizer can be a random value (with suitable distribution characteristics as described herein), that is used in the encryption to enhance security. In some examples, randomizers are obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use a randomizer.
[0241] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally obtain one or more noise values. Noise values can be a random value (with suitable distribution characteristics as described herein), that are used in homomorphic encryption to enhance security. In some examples, the noise values is obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use noise values.
[0242] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can then encrypt (415) an element of the plaintext ring to an element of the ciphertext ring, utilizing an encryption key that is an element of a module that is derivative of the ciphertext ring, as known in the art.
[0243] In some embodiments, encryption system (processing circuitry) 200A (e.g. ringbased encryption unit 220A) performs the encryption by calculating a linear combination, over the ciphertext ring of, at least: the element of the plaintext ring to be encrypted, and a sum of, at least:
[0244] (i) a product of, at least, an encryption key and a randomizer, and
[0245] (ii) a noise value where the encryption key is an element of a module derived from the ciphertext ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm.
[0246] In some such embodiments, encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can perform encryption using a symmetric encryption key, e.g. in accordance with the formula:
[0247] EncryptedElementco =
[0248] (PlaintextElement + (Randomizer * EncryptionKey + NoiseValue)) mod (ThirdNonCyclotomicRing / Secondldeal) wherein ThirdNonCyclotomicRing denotes the plaintext ring, Secondldeal denotes the second ideal, PlaintextElement denotes the element of the plaintext ring, EncryptionKey is the encryption key, NoiseValue is a noise value is sampled from the first ideal, and Randomizer is the randomizer.
[0249] In this case the associated randomizing element (e.g. for use in decryption) can be defined in accordance with the formula: EncryptedElementd =
[0250] (Randomizer) mod (ThirdNonCyclotomicRing / Secondldeal)
[0251] It is noted that in this case EncryptedElementco is a linear combination of the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.
[0252] In some other embodiments, encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can perform encryption using a public / private encryption key pair, e.g. in accordance with the formula:
[0253] EncryptedElementco =
[0254] (PlaintextElement + ((Randomizer! * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / Secondldeal) where ConstantValue is a constant that is an element of a module derivative of the ciphertext ring, Randomizer! and Randomizers are sampled from distributions over respective modules with bounded expected norms, and Randomizers is sampled from a distribution over a ring with a bounded expected norm
[0255] In this case the associated randomizing element can be defined in accordance with the formula:
[0256] EncryptedElementci = ((Randomizer! * ConstantValue)' + Randomizers) mod (ThirdNonCyclotomicRing / Secondldeal)
[0257] It is noted that here also EncryptedElementco is a linear combination of, at least, the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.
[0258] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal and second ideal are principal ideals, .in accordance the following formula:
[0259] EncryptedElementco =
[0260] ( (PlaintextElement
[0261] ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / Secondldeal)
[0262] In this case the associated randomizing element can be defined in accordance with the formula:
[0263] EncryptedElementci = ((Randomizer! * ConstantValue)' + Randomizers) mod (ThirdNonCyclotomicRing / Secondldeal)
[0264] In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal is not a principal ideal, and the second ideal is a principal ideal, in accordance the following formula:
[0265] EncryptedElementco =
[0266] ( (PlaintextElement * Secondldeal) + ((Randomizer! * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )
[0267] In this case the associated randomizing element can be defined in accordance with the formula:
[0268] EncryptedElementci = ((Randomizer! * ConstantValue)' + Randomizers) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal)
[0269] ) In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the element of the plaintext ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, in accordance the following formula:
[0270] EncryptedElementco =
[0271] (PlaintextElement + ((Randomizer! * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizers)) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )
[0272] In this case the associated randomizing element can be defined in accordance with the formula:
[0273] EncryptedElementci = ((Randomizer! * ConstantValue) + Randomizers) mod (ThirdNonCyclotomicRing / (Secondldeal * Firstldeal) )
[0274] Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally store (420) data derivative of the randomizer(s) and / or constant value, for use in decryption. For example: encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can compute EncryptedElementci according to formulas given above.
[0275] Attention is directed to Fig. 5, which illustrates a flow diagram of an example method of decrypting data that was encrypted using ring-based or module-based fully - homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.
[0276] Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain (505) a decryption key corresponding to the encryption key used to encrypt the ciphertext ring element to be decrypted. A decryption key can be e.g. a symmetric key, or a private key of a public / private key pair. In some examples, the decryption key can be received or derived as part of a key distribution protocol. The ecryption key can be, for example a ciphertext ring element, or an element of an algebraic structure (e.g. a module or other algebraic structure) that is derivative of the ciphertext ring.
[0277] Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain data derivative of any randomizers / constants used in encryption. In some examples, decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can simply obtain the randomizers and / or constants. In other examples, decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain a randomizing element that is derivative of the randomizers and / or constants (as described above with reference to encryption methods). Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can utilize the randomizing elements in decryption, as described below.
[0278] Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can decrypt (510) an element of the ciphertext ring to an element of the plaintext ring.
[0279] In some embodiments, decryption system (processing circuitry) 200B (e.g. encryption unit 220B) performs the decryption by a method comprising: subtracting, from the element of the second non-cyclotomic ring, a value based on a product of a decryption key and a randomizing element.
[0280] In some such embodiments, the decryption key and the randomizing element are elements of the ciphertext ring. In some other embodiments, the decryption key and the randomizing element are elements of the module derived from the ciphertext ring, as known in the art.
[0281] More formally: considering a case where an encryption procedure generated the encrypted element (EncryptedElementco, EncryptedElementci), the decrypting can be performed based on the following formula:
[0282] DecryptedElement = EncryptedElementco - (DecryptionKey * EncryptedElementci) mod (ThirdNonCyclotomicRing / Secondldeal) where ThirdNonCyclotomicRing denotes the non-cyclotomic ring R, Secondldeal denotes the second ideal of R (termed Q), DecryptedElement denotes the resulting element of the plaintext ring, and DecryptionKey denotes the decryption key.
[0283] In some embodiments, the decryption key is symmetric (i.e. is the same as the encryption key). In some other embodiments, the decryption key is a private key i.e. a non-public key that corresponds to a public key that was utilized in the encryption operation that generated the element of the ciphertext ring.
[0284] In some embodiments, the randomizing element EncryptedElementci is identical with a randomizer that was multiplied by the encryption key in the encryption operation.
[0285] In some embodiments, the randomizing element EncryptedElementci is derivative of a randomizer that was multiplied by the encryption key in the encryption operation, and is further derivative of - for example - one or more additional randomizers and / or constant values and / or other parameters.
[0286] Decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can decode (515) the plaintext ring element to plaintext data (e.g. binary data).
[0287] In some embodiments, when parameter b is 2, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can map an element of the plaintext ring to a plaintext by calculating: felement(2) where feiement () is the plaintext ring element (i.e. a polynomial) resulting from the decoding. It is noted that this decoding method is the inverse of the encoding method which maps plaintext bits to coefficients of polynomial terms (as described above).
[0288] As described in detail above, a single plaintext ring element can, in some examples, be an encoding of multiple plaintexts.
[0289] Accordingly, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can perform decoding on the plaintext ring element, thereby generating multiple plaintexts. In some examples, the plaintext ring element is a quotient ring of: a final ring of a series of extension rings, and a non-trivial ideal of the final ring.
[0290] It is noted that, as described in detail above each extension ring can be defined as:
[0291] PredecessorNonCyclotomicRing[t] / MinimalPolynomial where t is an algebraic element being added to the predecessor ring (i.e. to extend it), and where the minimal polynomial can be:
[0292] To decode an element of a quotient ring derivative of an extended ring thus defined, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can generate, from the ring element, one or more ring elements of a quotient ring derivative of the immediately preceding extension ring in the series.
[0293] To generate the one or more ring elements of the quotient ring based on the immediately preceding ring, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can: a) determine the roots of the minimal polynomial associated with the ring of the encoded ring element. These can be identical with the aj values in the definition of the minimal polynomial. b) for each determined root aj: calculate a result of substituting, in the encoded ring element, the respective extending algebraic element (i.e. t) with the constant value aj, thereby generating one or more elements of a quotient ring based on the preceding ring of the series (i.e. generating a quotient ring element for each determined aj).
[0294] If the preceding ring is also an extension ring, then decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can then repeat steps a) -b) on this next ring. If the preceding ring is a non-cyclotomic ring based on either xn+ x - b or xn- x + b, with the ideal being x-b (for some integer b) - i.e. not an extension of such a ring, then decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can calculate, for each generated element feiementO; felement(b) thereby resulting in one or more plaintexts.
[0295] It is noted that this decoding method can be utilized to decode from rings other than the rings defined herein. It is similarly noted that this decoding method can be utilized in the context of other applications (e.g. other decryption applications, nondecryption applications).
[0296] Fig. 2C is a logical block diagram of an example system that performs FHE operations (evaluations) and bootstrapping, in accordance with some embodiments of the presently disclosed subject matter.
[0297] In addition to processor 205C, memory 210C, communications unit 215C, optional ring-based encryption unit 220C, optional module-based encryption unit 225C, and optional encoding unit 230C, FHE evaluation system (processing circuitry) 200C can include bootstrapping unit 240C.
[0298] Bootstrapping unit 240C can utilize a bootstrapping key to perform bootstrapping on ciphertext when needed, as described in more detail below.
[0299] A characteristic of many fully homomorphic encryption schemes is that ciphertexts can accumulate noise during successive homomorphic operations. As a consequence, after a number of additions or multiplications, the ciphertext can become undecryp table.
[0300] To address this limitation, systems operating on FHE ciphertexts can perform a “bootstrapping” procedure. In bootstrapping, a ciphertext is refreshed by homomorphically evaluating a decryption circuit on the encrypted data itself. Bootstrapping can reduce or reset the noise of the ciphertext, thereby enabling further homomorphic evaluation. FHE bootstrapping can thus facilitate unlimited sequences of operations upon FHE ciphertexts
[0301] In some embodiments of the presently disclosed subject matter, a system can bootstrap a ring-based or module-based ciphertext (e.g. a non-cyclotomic ring-based or module-based ciphertext) by performing successive extraction of coefficients of the plaintext into a different encryption scheme (e.g. Brakerski-Fan-Vercauteren (BFV)) and performing the Torus-FHE bootstrapping method on these encryptions of individual coefficients.
[0302] Fig. 6 illustrates a flow diagram of an example method of bootstrapping a ciphertext that is based on a non-cyclotomic ring or module, in accordance with some embodiments of the presently disclosed subject matter.
[0303] The FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can receive 605 a non-cyclotomic ring-based or module-based ciphertext for bootstrapping.
[0304] In some embodiments, the ciphertext can be generated under a ring-learning-with- errors (RLWE) or module-leaming-with-errors (MLWE) encryption scheme, in which cases the ciphertext can include at least two ring or module elements, as described in detail herein.
[0305] In some embodiments, the plaintext corresponding to the ciphertext is representable as a vector of coefficients of a polynomial, and is associated with a plaintext modulus. The ciphertext is associated with a ciphertext modulus (herein denoted by CiphertextModulus). The plaintext can be associated with a plaintext modulus is akfor integers a and k.
[0306] FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can next perform sample extraction 610 on the ciphertext.
[0307] Sample extraction can obtain, from the received ciphertext, data indicative of, at least, the free coefficient of the plaintext polynomial encoded within the ciphertext. In some examples, the data resulting from sample extraction is a BFV encryption of the free coefficient only.
[0308] In some examples, the data resulting from sample extraction is a BFV encryption of data indicative of some number of rightmost (i.e. least-significant) coefficients of the plaintext coefficient vector. By way of non-limiting example: the data resulting from sample extraction can be indicative of four coefficients.
[0309] In some examples, each coefficient is binary.
[0310] Sample extraction is described below.
[0311] It is noted that the sample extracted data can be BFV-encrypted, even though the received ciphertext can belong to a non-cyclotomic ring-based or module-based encryption scheme.
[0312] After extracting the data indicative of one or more coefficients, FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can perform bootstrapping on the resulting BFV ciphertext. FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can then perform repacking of the bootstrapped BFV ciphertext into a polynomial ciphertext. The result can be a bootstrapped non-cyclotomic ring -based ciphertext of the extracted coefficients, aligned to the format required for continued homomorphic processing.
[0313] The bootstrapping and repacking can be performed, for example, based on the method described below, with reference to Fig. 7.
[0314] FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can next homomorphically right-shift 620 the received ciphertext (i.e. the initial ciphertext for bootstrapping), so as to enable sample extraction of the next one or more coefficients of the plaintext polynomial.
[0315] For example, if FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) extracted a single coefficient, the FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can perform a singlecoefficient right-shift by: multiplying the ciphertext by X'1modulo the CiphertextModulus.
[0316] As a further example, if FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) extracted two coefficients, the FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can perform a two- coefficient right-shift by: multiplying the ciphertext by X'2modulo the CiphertextModulus.
[0317] The right-shift thus aligns successive coefficients into the least significant positions, where sample extraction can be applied again.
[0318] FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can next examine 625 whether coefficients remain in the shifted ciphertext. This determination may be performed by e.g. maintaining a counter. If coefficients remain, the next one or more coefficients can be extracted 610 and the procedure repeats.
[0319] If no coefficients remain, FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can then e.g. sum the derived ciphertexts, thereby reconstructing an encryption of the entire plaintext encrypted in the original ciphertext that was received for bootstrapping (with reduced noise).
[0320] More specifically: FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can perform, for example, a calculation based on:
[0321] BootstrappedCiphertext = where n is the number of bootstrapped ciphertexts generated, and each BootstrappedCiphertext1is a respective repacked encryption of one or more extracted coefficients. By way of non-limiting example: if a single coefficient has been extracted, and Numerator is x**I, then FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can calculate:
[0322] BootstrappedCiphertext =
[0323] By way of further non-limiting example: if k coefficients were extracted, and the Numerator is x to the power of the sum of the coefficients, this same formula can be utilized.
[0324] It is noted that FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 240C) can calculate BootstrappedCiphertext from BootstrappedCiphertext1in other ways, as appropriate.
[0325] Fig. 7 illustrates a flow diagram of an example method of bootstrapping and repacking a ciphertext that is an encryption of one or more plaintext coefficients extracted from a ring-based or module-based FHE ciphertext, in accordance with some embodiments of the presently disclosed subject matter.
[0326] The method described in Fig. 7 can be applied to an encrypted coefficient or group of coefficients. In Fig. 7, coeffpt denotes data indicative of one or more plaintext coefficients of a ring -based ciphertext that was received for bootstrapping (as described above with reference to Fig. 6). In some embodiments, the method of Fig. 7 operates on a BFV encryption of coeffpt. In some embodiments, coeffpt was extracted via sample extraction (as described above with reference to Fig. 6).
[0327] The FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 230C) can apply 705 TORUS FHE programmable bootstrapping on of coeffpt (i e. which is indicative of one or more coefficients), to generate a product of coeffpt with a gadget vector.
[0328] TORUS FHE bootstrapping is a known technique, as described in additional detail below. TORUS FHE bootstrapping can employ e.g. a bootstrapping key that is associated with the encryption key that was utilized to encrypt the received ring -based or module-based ciphertext that is being bootstrapped.
[0329] In TORUS FHE programmable bootstrapping, a supplied mapping function is homomorphically applied during the bootstrapping, so that the output of the bootstrapping procedure is an encryption of a result of application of a programmable mapping function on coeffpt. Thus: programmable bootstrapping not only refreshes the ciphertext by reducing accumulated noise but simultaneously applies a predefined transformation to the underlying plaintext value (i.e. to coeffpt).
[0330] In some embodiments, the supplied mapping function can be a multi-output function (i.e., the bootstrapping generates multiple outputs), each of which is an encryption of result of application of a particular mapping upon coeffpt.
[0331] In some embodiments, the supplied mapping function can be a multi-output function which multiplies coeffpt by a gadget vector.
[0332] As further described below, a gadget vector can be - for example - a structured vector of elements (e.g., powers of a chosen base). The product of the gadget vector with coeffpt can be subsequently utilized to homomorphically multiply coeffpt by arbitrary ring elements in a manner that limits increase of noise.
[0333] Thus, the outputs of the TORUS FHE programmable bootstrapping are, in some embodiments, encryptions of the product of coeffpt and the gadget vector components, i.e. each output is an encryption of a scaled or shifted form of the original coeffpt.
[0334] It is noted that - as an alternative to utilizing a multi-output mapping function - FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 230C) can perform FHE Torus bootstrapping multiple times which employing a single output mapping function.
[0335] It is further noted that an example method of programmable bootstrapping is described in US Provisional patent 63 / 873,524 filed on 31-Aug-2025
[0336] It is further noted that - alternatively - FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 230C) can perform FHE Torus bootstrapping without application of a mapping function. In this case, noise growth may be larger during subsequent processing.
[0337] From each encrypted product of coeffpt with the gadget vector, FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 230C) can next calculate 710 a series of encrypted coefficients that are derivative of: coeffpt extracted from the received ring-based ciphertext (i.e. the original ciphertext for bootstrapping), and a polynomial based on the inverse of the prime element of the prime ideal of the noise term.
[0338] Specifically, the FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 230C) can calculate the series of encrypted coefficients, wherein each coefficient of the encrypted series is a coefficient of a respective term of a polynomial derivative of:
[0339] Numerator coeffpt’ y ~ A — Cl where Numerator is a numerator (e.g. X1) and the modulus associated with the plaintext r some integer k (e.g. a can be 2).
[0340] In some embodiments, the resulting series of ciphertexts can be termed “intermediate ciphertexts” where each IntermediateCiphertexti is an encryption of the 1-th coefficient of:
[0341] Finally, FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 230C) can, utilizing a key switching key, repack 715 this resulting series of intermediate ciphertexts to a ring or module element.
[0342] The repacking can, for example, calculate ring or module elements based on: where kski is an encryption - under a target key - of the 1-th coefficient of the original secret key associated with the first ciphertext.
[0343] Alternatively the repacking can utilize gadget decomposition to reduce noise. Accordingly, FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 230C) can calculate ring or module elements based on: where j is an index of a new gadget vector, and IntermediateCiphertext(is a j-th element of a corresponding gadget decomposition of Interm ediateCiphertexti, and ksk,.i is an encryption - under a target key - of the 1-th coefficient of the original secret key associated with the first ciphertext, and
[0344] The repacking can thus consolidate the coefficients encrypted in the intermediate ciphertexts into one ring-based or module-based ciphertext aligned with the structure of a non-cyclotomic ring or module. The resulting ciphertext can thus be an encryption of a polynomial based on:
[0345] Numerator coef fpt ■ — -
[0346] A — Cl
[0347] By way of non-limiting example: the generated ring can be a polynomial ring defined by Zq[X] / f(X), wherein Zq[X] denotes polynomials with integer coefficients between 0 and q (where q is CiphertextModulus), and f(X) denotes a given non- cyclotomic polynomial.
[0348] FHE evaluation system (processing circuitry) 200C (for example: bootstrapping unit 230C) can finally multiply this resulting ring-based or module-based ciphertext by (X-a). The result is then a second ciphertext that is a ring-based or module-based encryption, with reduced noise, of coeffpt (i.e. data indicative of one or more coefficients of the plaintext) multiplied by the numerator.
[0349] It is noted that the sections appearing hereinbelow are part of the detailed description, and that any headings included therein are for ease of reference only.
[0350] We present a fully homomorphic encryption scheme which natively supports arithmetic and logical operations over “machine words” . namely plaintexts of the form (e.g. n 64). Our scheme builds on the well-known BGV framework, but deviates in the selection of number field a nd i n t he e ncoding o f m essages. T his a Hows u s t o s upport large message spaces efficiently wi thout re sorting to ba tching. In deed, each ciphertext in our scheme efficiently en codes a si ngle me ssage fr om the message space.
[0351] Arithmetic operations (modulo 2”) are supported natively similarly to BGV-style FHE schemes, and we present an efficient bootstrapping procedure for our scheme. Our bootstrapping algorithm has the feature that along the way it decomposes our machine word into bits, so that during bootstrapping it is possible to perform logical operations (essentially addressing each bit in the message independently). This means that during a single bootstrapping cycle we can perform logical operations on n bits.
[0352] For example, a “greater than” operation (if a: > y output 1, otherwise output 0). only requires a single subtraction and a single bootstrapping cycle.
[0353] Along the way we present a number of new tools and techniques, such as a generalization of the BGV modulus switching; to a setting where the plaintext and ciphertext moduli are ideals (and not numbers).
[0354] 1 Introduction
[0355] Fully homomorphic encryption (FHE) [B.A 1T”78, GenOhal allows us to compute on encrypted data, without decrypting it first a nd w ithout a ny k nowledge of the secret key. This makes it a prominent privacy enhancing technology with numerous potential applications GH19, CJP21j. Whereas there is ample motivation for using FHE in the real world, its utilization in practice is hindered by the overhead it incus's in computation and in storage. More explicitly, the resources. say in running time, required to run a computation over encrypted data may be orders of magnitude longer than running the same computation iti the clear. Narrowing this gap to a tolerable level has been a major research direction of the FHE community for over a decade, and indeed some success has recently been reported, notably the recent announcement of the integration of Swift FHE into Apple devices as a part of iOS 18 [BTR24]. However the overhead remains prohibitive (or at least quite restrictive) for many desirable applications.
[0356] There are two main paradigms in the literature for practically-oriented FHE candidates. Both rely on structure related to the Learning with Errors (LWE) (RegCo) and Ring Learning with Errors (RLWE) [LPR13a], as put forth in (BV1 lb,BVlla,GSW13]. The first is a, more direct extension [BV1 lb,BVl la.j and is utilized in the BGV, B / FV, CKKS schemes [BGV12, Bral2, FV12, CKKS17] a, iid their successors, and is of a, more arithmetic nature. We therefore refer to these as arithmetic schemes. Software libraries that take this approach include [HS20, SEA11, CKKS16], The second follows the paradigm of [GSW13, DM14. CGGI20I and is more native for boolean operations, and we therefore refer to them as boolean schemes. Software libraries that take this approach include [Zam21, tfhlT]. Let us discuss these approaches in slightly more detail below.
[0357] Arithmetic Schemes. These schemes natively support arithmetic operations over some: plaintext modulus p. In BGV and B / FV the operations are carried out exactly over a discrete ring, whereas in CKKS, they are real valued and noisy, but they are all natively arithmetic. When implemented naively, this approach leads to exorbitant information overhead. Namely to very large ciphertexts that encrypt a small amount of data. This is partly mitigated by the use of batching: the ability to encrypt multiple plaintexts in parallel “slots” in the same ciphertext, and apply operations on them in parallel. Batching reduces the amortized overhead, both in terms of storage and in terms of computation, since an operation on the ciphertext corresponds to operations on many plaintexts.
[0358] Importantly, batching uses algebraic properties of the RLWE problem, and in particular requires a specific relation between p and the number field over which the scheme is defined. In particular this means that the strongest form of batchi ng requires p which is an odd prime with some specific structure. There are techniques in the literature that allow to trade off the “amount of batching” with the form of the modulus [GHS12, HS21]. These techniques use field extensions to produce plaintext spaces of the form GF(pd). Thus it is possible to batch finite-field elements of size, e.g., 26’. but it is not possible to properly batch plaintexts from the ring Z2«« ■ We are not aware of solutions that allow batching for message spaces such as those targeted in this work, namely Zpfor a large p, specifically for p being a power of 2.
[0359] Either way, batching requires both aggregation of a large amount of data per ciphertext and the ability to split this large amount of data into small amounts (to fit in each slot) in such a way that per-slot homomorphic operations remain useful. This is simply not; the case 'when we wish to work with large integers, which is how many modem com puter systems operate.
[0360] As in all known approaches for FHE, if one wishes to compute functionalities with a-priori unbounded depth, then a bootstrapping operation needs to be executed periodically. Bootstrapping [Gen09b| reduces the “noise component” that exists in all known FHE candidates. The noise grows with every homomorphic operation, and must be kept below a certain threshold to maintain the correctness of the scheme. Bootstrapping, therefore, is the process that allows to reduce the noise level so that additional homomorphic operations can be carried out. Bootstrapping essentially requires to apply the decryption algorithm ho- momorphically over the ciphertext. This requires applying operations that are not “natively” arithmetic, such as rounding or truncation of least significant bits. Therefore, whereas bootst rapping is heavy on resources in all known FHE instantiations, arithmetic schemes generally si, niggle with bootstrapping more than boolean ones. This is likewise the ease for any non-arithmetic 'operation, in particular boolean operations like “greater than” are challenging to implement.
[0361] Boolean Schemes. In these schemes, each ciphertext essentially encrypts a single bit. It is possible to pack multiple ciphertexts into a more compact representation, and various optimizations have been introduced in [DM14, C(J(JI20|, but homomorphic operations are still performed at the bit level. This allows to perform logical operations natively. A particularly successful approach is taken by* the TFHE scheme [CGGI20], This proposed a way to perform the bootstrapping operation very efficiently, and therefore elect to perform bootstrapping after (or rather, as a part of) every operation. This framework makes it harder to work with data types that are naturally composed of multiple bits, such as number modulo p. In boolean schemes, one needs to represent, large numbers as a, sequence of bits and apply the appropriate boolean circuits to perform operations like addition and multiplication. Tills is possible, and indeed works naturally even for moduli of the form 2”, but requires a large number of bootstrapping opera tions even for the simplest of operations (e.g. adding two n bit numbers as integers modulo n) . We note that boolean schemes are very convenient for logical operations, e.g. “if” statements. For example, boolean comparison between two numbers, i.e. the predicate a > b. can be computed as easily as the difference a — b. Note that this is not the case for arithmetic schemes.
[0362] The Challenge: Arithmetic-Logic Unit for Machine Words. Our goal when using FHE is to be able to take existing code and covert it into running homomrophically with as little change as possible. Indeed, our algorithms and data types should remain oblivious to our choice of privacy preserving technique. We may therefore put forth the task of constructing a. homomorphic framework that natively supports the “standard” operations of computer programs. In particular, this includes arithmetics over integers modulo 2n, since integer data types in most architectures are of this form. At the same time we wish to be able to execute conditional statements, and apply logical operations on the bits of our numbers.1Indeed, the “slogan” for our goal is to implement an “Arithmetic Logic Unit” (ALU) inspired by such components that exist in CPUs. Such a unit would support arithmetics modulo 2n, as well as logical operations at the bit level.
[0363] We note that both aforementioned approaches are universal (a.k.a Turing complete) and therefore allow in principle to implement an ALU. However, when concrete efficiency is concerned, if the native representation is only arithmetic or only boolean, then a change of representation will be required for some operations, which is usually prohibitive in terms of resources. This work therefore focuses on the following question.
[0364] 1We are not considering float-point operations at this point. 1.1 Our Contribution — FHE for Arithmetic and Logical Operations
[0365] We present a number of novel ideas that allow us to break from the existing paradigm and present a fully homomorphic encryption scheme with new capabilities. We first show how to construct a BGV-style scheme with native support for arithmetics over while not incurring the penalty that is usually associated with such plaintexts in "legacy" BGV. We then present a bootstrapping algorithm for our scheme which not only performs the “standard” bootstrapping features of reducing the noise in the ciphertext, but also, along them way, provides us access to the; n individual bits in the binary representation of our Z2’1message. This allows us, in the course of bootstrapping, to perform logical operations natively. Thus achieving both arithmetic and boolean logic without additional overhead.
[0366] For the first part, we construct an encryption scheme whose native plaintext space is Zgn (where n is a parameter). We show that arithmetic homomorphic operations (addition, multiplication) over this plaintext space can be performed essentially the same as in BGV-style FHE. However, the parameters of the scheme and noise scaling are comparable to BGV with plaintext [0, 1} . This is a crucial difference since prior to this work, a plaintext space of Z "2n meant an additional factor of 2”“ in the noise, when evaluating a depth d arithmetic circuit. In contrast, in our scheme the growth would be roughly n^, which as explained above is comparable to binary plaintext. This has a cascading effect on all parameters of the scheme, since mild noise growth allows io reduce the so-called “noise ratio” of the underlying algebraic LWE problem, which in turn upgrades the security level of the scheme, which then allows to reduce the size of other parameters and maintain the same security level as previous schemes. As a result, we can instantiate our scheme with very large plaintext spaces that were previously prohibitive, with only minimal loss in performance. We note that we did not explore the possibility of batching in our scheme, so we only consider the setting of a single message per ciphertext. However, it may be possible to incorporate batching into our framework as well.
[0367] This is achieved by examining the properties of the BGV scheme in the algebraic setting (i.e. when it is based on structures stemming from the RLWE assumption and similar ones). We notice that, under the hood, BGV encryption can seemlessly be made to support any message space that is defined by an ideal in the ring where the scheme is defined (the ring of integers of some number field, or a, subring thereof). This property was already noticed in the context of the NTRU scheme by Hoflstein and Silverman [HS00], and was used in the context of FHE in a number of works, e.g. [CLPX18, BCI V20|. However, these works fell short of achieving the goal of naturally supporting Z2« since they insisted on sticking with the use of cyclotomic number fields which has indeed been prevailing in the FHE literature. We deviate from this paradigm and show’ that working with non-cyclotomic number fields opens the door for great versatility in the design of the message space. We view this as a major contribution of tliis work. Indeed, this modification requires us to use algebraic variants of LWE that axe defined over such number fields. Whereas this is not as widely used in the literature, we notice that to the best of our knowledge there is no reason to speculate that cyclotomic number fields would lead to more secure constructions (in fact, some argue that the opposite is more likely). We provide a. det ruled discussion on the security of algebraic LWE in our context.
[0368] As an additional contribution, we discuss the possibility of creating “Double CRT” encoding of the ciphertexts in our scheme. Double CRT [HS20] is a way to encode ciphertexts that relies on the decomposition of the ciphertext, mod ulus into prime ideals of a, cyclotomic ring. This implies a representation of a large ciphertext as an array of fairly-small numbers, where addition and multiplication in the; ring translates i nto pointwise addition and multiplication of the elements of the array. Whereas on the face of it we may not use Double CRT in our scheme, since we do not know how to decompose ordinary integers into prime ideals in our ring, we show that it is possible to take the opposite approach and construct the ciphertext modulus as a product of “simple” ideals. This would indeed allow for decomposition, but would imply that the ciphertexts in our scheme can no longer be represented as vectors of polynomials, where each coefficient is in for some integer < / , but; instead are cosets of some ideal in our ring. We show that nevertheless it is possible to apply homomorphic evaluation in this case.
[0369] In the second part we wish to devise a bootstrapping algorithm for our scheme. The bootstrapping process is computationally labor-intensive since it requires evaluating a pretty complex function. Furthermore, the noise accumulation during bootstrapping directly reduces the homomorphic capacity of the scheme after bootstrapping. Therefore, there is a lot of effort in the 1 it- erature in order to reduce the complexity of bootstrapping in various FHE schemes GHS12,}?IS21 ,DW14,CGGI2G, KDE‘!‘24;. In particular, to come up with “decryption circuits” that require the least amount of resources and have the least noise accumulation.
[0370] In our scheme, we manage to introduce a decryption functionality which is both relatively mild in terms of resources, and allows us to extract the individual bits of the message in the course of bootstrapping. This means that during bootstrapping we can perforin bi t-level operations on the encrypted message, which we leverage to obtain logical / booleari evaluation capacity for our scheme.
[0371] Our starting point is the method of [KDE ”24] who proposed to bootstrap BG V-style ciphertext by reducing the task to that of bootstrapping non- algebraic ciphertexts (i.e. ones that are not defined over a ring). In fact, this is quite straightforward in BGV-style encryption, since one can decompose an algebraic ciphertext into a. collection of non-algebraic ciphertexts simply by thinking about ring elements as polynomials, and considering one coefficient at a, time (see technical overview below for additional details). They then use the [CGGI20,CJP21j bootstrapping approach which has been designed for non-algebraic ciphertexts, and use it essentially as a building block.
[0372] We cannot follow this blueprint as is, since our algebraic ciphertexts do not decompose well in terms of coefficients. That is, our use of a general ideal to define the ciphertext space means that noise in our ciphertext is not added per- coefficient as in previous FHE schemes. We therefore design a novel approach for recursive decomposition of our algebraic ciphertext into a collection of non- algebraic ciphertexts. Essentially this works by noticing that; we can extract a non-algebraic ciphertext encrypting the least; significant bit. We then bootstrap this ciphertext and show how to use the bootstrapped ciphertext in order to produce a non-algebraic encryption of the next bit of the message. At the end of the process, we have bootstrapped versions of non-algebraic encryptions of all bits of the message. This allows us to perform many logical operations “for free": e.g. apply any permutation or shift on the bits, remove some of the bits or XOR them with each other. We can also apply more sophisticated operations such as bit', vise AND using a bit more work.
[0373] We refer the reader to the technical overview below for a more detailed explanation on how our scheme; works.
[0374] Finally, we consider concrete parameters for our scheme, with a plaintext space of n = 64 bits. We implemented our scheme and report implementationspecific details.
[0375] 1.2 Other Related Works
[0376] This work addresses FHE in the circuit model. This means that we consider computation that is represented in a combinatorial form as a, circuit with boolean or arithmetic gates. Until recently, FHE was only known to be applicable in this model. Recently, Lin, Mook and Wichs [LMW23] introduced the first; FHE scheme that operates in the RAM model (with suitable preprocessing). Whether our techniques have implications on RAM-FHE remains a subject for future inquiry.
[0377] 1.3 Paper Organization
[0378] Section 2 contains a, technical overview of our scheme. Section 3 contains preliminaries and definitions. The basic scheme and basic arithmetic homomorphic evaluation are presented in Sections 4, 5. Our bootstrapping algorithm and (lie derived homomorphic logical operations are described in Section 6. In Section 7 we provide a. det ailed discussion on the security of algebraic-LWE in our ring. Implementation details are provided in Section 8. Our analysis for using algebraic modulus for the sake of double CRT is provided in Appendix A.
[0379] 2 Technical Overview
[0380] We start with a common blueprint for LWE-based encryption. The ciphertext is a (column) vector c. say in Z”, and the secret key s is a (row) vector of the same; dimension, say in Z’!. The ciphertext is generated so that s • c = p + p,s (mod q) . (1)
[0381] We refer to q is the “ciphertext modulus” and p is the “plaintext mod ulus” , and we require that p, q are coprime. The encrypted message p can be interpreted as an element in Zipand the variable >•: is the “noise”. So long as |s| C q. it is possible; to recover m from the ciphertext.
[0382] In algebraic LWE variants, Z is replaced with some other ring. Particularly the “ring of integers” of a number field, or a full-rank subring thereof. A very common choice for such a ring is R. = Z[x\ / {f(x)}, where f is an irreducible monic polynomial of degree nx A prevalent choice for f is a cydotomic polynomial, in particular of the; form fix) ------ xn+ 1 for n being a power of 2. The reader may keep this example in mind until we explain how we deviate from it in this w’ork.
[0383] Given such a ring, we may analogously consider c t Th., (where Th., = TZp'qTV), s q R- SO that s • c = p + pe: (mod q7V) , (2) where s € R- arid the messages are now drawn from Since elements in 'Racan be represented as degree (n — 1) polynomials, the term p -r p£ (mod <?) can be considered one coefficient; at a time. In each such coefficient there is a. message part that comes from Zpand a noise part that comes from the respective coefficient of e. We conclude that if all coefficients of s are small compared to q, denote this e W q, then p g TZPcan be fully recovered.4
[0384] As shown in [BVllb, BVlla, BGV12], the above scheme can be made homomorphic and support arithmetic operations over the plaintext ring 7ZP. Namely, addition and multiplication. Each such operation incurs a penalty in the size of e. most significantly during multiplication. Indeed, even in the most noise-efficient multiplication methods, a depth d multiplication incurs a penalty of roughly pain the noise (in addition to other penalties that are not directly dependent on p). Furthermore, arithmetics in R.pjis often not what is actually required. Indeed, common data types take a form of and not of polynomials with coefficients that are multiplied modulo f(x). One way to achieve; homomorphism with respect to Zpis to encode messages m £ ZPas polynomials p t by j us t setting the free coefficient of p to be m. and keep all other coefficients at 0 (or in more abstract term use the fact that Zpis a subring of 7Z-Pp This indeed does the trick but has two main drawbacks. First, the information rate achieved is quite poor. An element in 7?.pcan encode n elements from Zpin terms of information content, but the homomorphic requirement forces us to lose a factor of n in utilizing this capacity. Second, if p is large, then the noise growth is completely prohibitive.
[0385] Prior works, starting with [SS 10] , proposed a way to amortize the information utility. They show that by properly selecting f and p, it is possible to set up the Tv so that RPZ”, as rings, with pointwise addition and multiplication. This means that it is possible to pack n elements from Zpand apply operations on them in parallel (see also [GHS12] and other followup works). However, this solution is limited to specific values of p, and to a setting where it is indeed possible to “collect” n messages into one ciphertext. This method had been extended to other types of plaintext spaces, specifically field or ring extensions, see pHS21j. We are not aware of solutions that allow’ batching for message spaces such as those targeted in this work, namely 2Pfor a large p, and in particular p = 2* for some I. However, using the existing methods, even if batching can be achieved, the noise blowup problem remains.
[0386] Using Ideal Plaintext Modulus. We notice, as others before ]IIS00, GC14. CLFX18]. that p needs not be in Z in order for the scheme to work. Indeed, we may consider an ideal p in the ring R, and consider ciphertexts for which s • c = p + e (mod q'R) , (3) where we are guaranteed that e 6 p. For our purposes we consider p = lx — 2), so we can think of e = (x— 2)e, where e is as before. In this case, the plaintext p is in the ring 7?,P= 7?. / p. Importantly, in many cases there is a ring homomorphism 7?.p — Zpfor p = | / (2)] (tins holds for any fix) that is of interest in this work). However, in a cyclotomic ring, such p can never be a power of 2. We therefore propose to use non-cyclotomic polynomials. In particular we consider polynomials of the form fix') ----- xn— x 2.
[0387] We note while the FHE literature mostly uses cyclotomies, this is done for reasons of convenience and structure (e.g. having automorphisms that can be used for some functionalities). There is no evidence that working over cyclotomies makes algebraic LWE more secure. In fad;, some; claim that to the contrary, that the additional structure of cyclotomic rings makes them more risky in terms of security, and designers should opt for other polynomials |BCLvV16]. We refer the reader to Section 7 for a more detailed discussion.
[0388] We can now explain our scheme. Our message space is Z2» for some parameter n. and our ring is R. = Z|;r] / ( / (a;)), f)x) = x!l— x + 2. We require an encoding method to map an elements m t into p t Rsand vice versa. It is important that \p\ is as small as possible, for reasons we explain below. This is in fact not very difficult as one can verify that one can map any m into p with {0, 1} coefficients by simply considering the binary representation of the number m (mod 2”). In the other direction, for any p — p(;c), we may consider p(2) (mod 2”). This mapping indeed implement the aforementioned ring homomorphism. In addition it has the useful property that the bits of m are exactly the coefficients of p. This is a consequence of using the non-cyclotomic polynomial ami will be invaluable to us down the line. Therefore, when we wish to encrypt a message m, we first encode it into a. polynomial p and Hum use; the above scheme. The arithmetic homomorphic properties such as addition and multiplication work very similarly to previous schemes, but now, instead of papenalty for depth d multiplication as in [BGV 12] and related schemes, the penalty scales roughly with (logp)“, which is a significant improvement . We will not go into the details here, but the reason, essentially, is that the noise growth factor depends on the maximal t) norm of plaintexts in the space. Since we can encode m into p with {0, 1} coefficient, this factor is roughly n = logp.
[0389] We remark that in the description so far, n plays a double role. Both as a dimension for the algebraic LWE problem and as a parameter that determines the plaintext space. If desired we can decouple these two roles by working with the so-called “module” version of the algebraic LWE problem. In this case c t for some “rank” r (and likewise for s). This means that the dimension for the LWE problem is r ■ n. but the plaintext space is determined by n. This subtlety is not going to be of particular importance for this high level discussion.
[0390] Arithmetic Homomorphic Operations. Homomorphic addition and multiplication are performed similarly to the BGV scheme [BGV12,HS20]. Whereas many of the subroutines carry over, there is one that requires rethinking and updating. This is the so-called “modulus switching” procedure. The goal of this operation is essentially to “shrink down” the; ciphertext modulus q into a. new smaller q'' . In this process, the relative noise level \e\ / q remains roughly im- changed: \e\ / q ~ eh / g', which means that the absolute noise level goes down (since q' < q~). This subroutine is quite central to BGV-style schemes and it needs to be carried out after every multiplication operation, and it also plays a role in the bootstrapping procedure (to be discussed below). Furthermore, [HS20] requires modulus switching in order to optimize the performance of another subroutine, called “key switching” , which can in principle be carried out without modulus switching but with worse performance in terms of noise growth.
[0391] In this context, we first consider the straightforward extension of “legacy” modulus switching to the setting where p is a, general ideal. This is a, relatively straightforward extension but it requires that q = q' (mod p). Whereas prior to our work this was not considered a, problem since essentially by definition, the plaintext space was such that p q, q' . in our case this could be rather prohibitive. In fact, our paradigm even supports a setting where q W p. In prior works, (G0141 considered the straightforward extension as defined above, without noticing its drawbacks for very large p, whereas [CLPX18I did not face this challenge since they worked with the so-called B / FV approach, and do not perform bootstrapping, so at least asymptotically one can do without modulus switching, an approach that is not suitable for our needs.
[0392] We propose two methods to mitigate this problem. 'The first is to notice that even if a = qq'~!(mod p) / 1. so long as this value a is invertible modulo p, it is possible to “correct” the modulus switching procedure at the cost of an additional homomorphic scalar multiplication, which is relatively mild in terms of noise cost. The second is to do away with the ciphertext modulus q being an integer, and taking it as an element of the ring as well. This means tliat for any q it is possible to find q' with the proper “volume” (the volume in this context is the index of tire ideal in tire ring) so that modulus switching has the desired properties. We notice that working with such algebraic ciphertext modulus may have additional advantages. For example, setting q ~ fT q?, where each q., is “small” will allow to perform modulus switching as desired, and also provide a method for double- CRT encoding of the ciphertext, as explained above. We elaborate on this in Section A. Finally, going back to the first method, we notice that the scaling by a may be performed only “conceptually” without actually performing the multiplication. We can just “carry” the a factor throughout the computation and cancel it only at decryption (or at; bootstrapping).
[0393] Bootstrapping. We now describe the bootstrapping procedure for our scheme. As explained above, we follow IKDE'”241 and rely on the TFHE bootstrapping procedure [CGGI20] as a building block. Their goal was to bootstrap schemes with syntax similar to Eq. (2). They do this by decomposing the ciphertext into n non- algebraic ciphertexts, each of the form of Eq. (1). To see why this is the case, we recall that Eq. (2) is an equality between two ring elements, which can be seen as an equality between two polynomials of degree n — 1. If we consider the «~th coefficient of this polynomial, then on the right hand side we get tp + p£i, and on the left hand side we get a bilinear operation on the coefficients of c and s. This can be interpreted as a non-algebraic ciphertext that is decryptable using the coefficient vector of s. The [KDE”24j approach is to bootstrap each such non-algebraic ciphertext using the methods of [?|, and then putting the outcomes back together.
[0394] This approach doesn’t carry over to our setting. We embrace the basic idea of splitting ari algebraic ciphertext into multiple non-algebraic ones, but we require a very different mechanism for this purpose, one that will ultimately also allow us to perform boolean operations in the course of bootstrapping. To see why this is the case, let us analyze the right hand side of Eq. (3) similarly to what we did with Eq. (2). The i-th coefficient of of u + e equals q,:+ e, , but now recall that e = (x — 2)s (mod / (a;)), so ea can no longer be written as pet as before. Let us write down the coefficients of e for n = 4 to get a sense of what is going on (note that c„...i wraps around because of the modulation in f(x}}.
[0395] Note that other than e3, in all other components there is no guarantee that the noise belongs to some ideal. Indeed the structure of the noise in our setting is not axis-parallel in the coefficient embedding. Nevertheless, we notice that at least for e{j we do have a guarantee that it can be written as e3= 2e,j. We may therefore extract the free coefficient from equation Eq. (3), and use it to bootstrap and obtain a non-algebraic low-noise encryption of pa. It may seem that we have reached a dead end, since the other e, are not as accommodating. To get us out of this barrier, let us consider a. ciphertext for which we are guaranteed th at po -= 0. Namely, it is possible to write p = ;cp\ We also notice that in our ring, since we work modulo f(x) ----- xn--x-\-2. it holds that (it: — 2) — xn. It follows that we can write the right-hand side of Eq. (3), for such a ciphertext, as xu! xne. Using a standard technique (essentially multiplying the ciphertext by x~l(mod g)) it is possible to remove the common factor and convert this to one whose right hand side is u1Letting e' = xn~1e, we can see that e(, = — 2,si, which is again even. In fact, for every power of .r it holds that the free component of x’e is even. This is not an accident and follows directly from our choice of ring polynomial f(x). Our approach, therefore, is to first extract po, arid then subtract it from the original ciphertext to obtain a ciphertext as described above. Then extract pi from this ciphertext and so on. However, implementing this approach is not without difficulties.
[0396] So far, we did not get into the question of what the output of the bootstrapping actually looks like. We only mentioned that it is a “non-algebraic low-noise encryption". The right-hand side of this encryption would normally be of the form | g / 2jp(j + (mod q) for some small integer value s0€ Z. How can we use it to cancel out from an algebraic ciphertext? To do this, we utilize idle versatility of the bootstrapping procedure of [?j, which allows to produce non- algebraic ciphertexts witti-right hand side g(jio) + £o (mod q), for any function g with values (in fact, it is even somewhat more versatile, but this suffices for us). We use it to recover all powers of two multiples of po. That is 2- po Am (mod q). This allows us, via subset sum, to recover an encryption for any integer multiple of po. Indeed, this is only for non-algebraic ciphertexts, but it can be extended to algebraic ciphertexts as well. We therefore recover an algebraic ciphertext of the form (x — ‘2)~lge + si), which can then be scaled to obtain a ciphertext of the form ;j.e. 4- (x — 2)eo' . This ciphertext can then be subtracted from the original algebraic encryption of p, and allow us to continue to p; and then further down the line.
[0397] To summarize, in each step of the bootstrapping, we recover an algebraic ciphertext of the form x‘gi + [x -- 2)e). We can eventually add all of these together to obtain an encryption of u with small noise, which concludes the bootstrapping functionality.
[0398] Logical Operations. As explained above, and demonstrated in our description of bootstrapping, in the course of bootstrapping we recover individual encryptions of ail bits pj, scaled by any algebraic or non-algebraic integer. This allows us to very easily perform bitwise operations on the ciphertext. Bit shifts and permutations are essentially trivial since we can recover x2(;c — 2)eJ for any J, and add them together to obtain the new ciphertext. Linear GF(2) operations over the bits of the message can likewise be computed.
[0399] More elaborate operations are also easily possible. For example the logical “a > b” predicate which outputs 1 if a > b and 0 otherwise can be implemented homomorphically by computing (arithmetically) idle difference a — b (mod 2”) and then extract the most significant bit of the difference which exactly implements the above; functionality.
[0400] We may even consider further operations such a.s bitwise AND between ciphertexts. which can also be performed once we extract all bits. One way to implement this is to recover non-algebraic ciphertexts of the form p, de,. Adding two ciphertexts of this form, and then extracting the second-least-significant bit, recovers the AND of the two numbers. One may think of more sophisticated algorithms that can be carried out in this way.
[0401] 3 Preliminaries
[0402] 3.1 Notation
[0403] The security parameter is denoted by K. We use bold letters for vectors and matrices.
[0404] An expression that includes a multiplication of a matrix and a ciphertext, or a vector of ciphertexts as in D ■ (co, . . . . c„-i )!is done as in the regular way. however when a matrix entry by a vector entry, the operation is a homomorphic scalar- by-ciphertext multiplication one.
[0405] 3.2 Algebraic Number Theory
[0406] We consider a monic irreducible polynomial / (;<:) of degree n and integer coefficients, the number field K ---- Q[x\ / {f (x)} , and the ring ??. = X\x] / {fix}} . Note that this ring is not necessarily the ring of integers of K. but it is nonetheless an order of the field (a full-rank subring of the ring of integers). For any ideal p in 7?. we denote 7cP= K / p. For brevity, when q = (g) is generated by an integer q E Z, we denote 7?.,, = TZ / qTZ. If p = {x — a) then there exists a ringisomorphism TZp T where p = ffi(p) = \f(af)\ (the notation Tl(-) refers to the absolute norm of the ideal which is defined as the index of the ideal in the ring: 9I(p) = (7?, : p)). In this work we will consider ideals for which the above holds. We are particularly interested in the setting where fix} ------ xn- x. + 2 for some n, and p = {x — 2). This results in p ----- \f(2)\ ------- 2n.
[0407] We consider two popular methods for embedding elements in K into Euclidean or complex space.
[0408] — The Coefficient Embedding. For a number field K as above, it is always possible to express any element of K uniquely as a polynomial of degree less than n and rational coefficients. This induces a map K —> Q" by mapping t t K whose polynomial representation is t ---- to [t]:::(to, • ■ • An-l)* € Qn.
[0409] -- The Canonical Embedding. A number field K has exactly n ring embeddings (injective ring homomorphisms) into C, which are induced by taking x to the (complex) roots of f. Denote them by oy : K -4 C. The canonical embedding of t is the vector [t] = (crj (t). . . . . a„ (t))1£ C-n. It is also possible to embed this vector into R" (essentially since f is a real-valued polynomial so its complex roots come in conjugate pairs). However, we will not require this real embedding here. In the canonical embedding, field addition and multiplication axe done component-wise.
[0410] These embeddings induce geometric norms on elements of K by using tpnorms over tin; embedding vectors. In this work we work mostly with the coefficient embedding (even though in some cases the canonical embedding would allow for a tighter analysis). We therefore Id; £„(•) demote the; Lf, norm of a field element in the coefficient embedding.
[0411] When working with the coefficient embedding, it is useful to consider the expansion factor of the field: a,
[0412] By default, when p is not specified, we consider the infinity norm p = co.
[0413] For w t 7Z we define
[0414] Our secret key lias small norm, therefore we also define:
[0415] Note that 7 > 7 / n. The following proposition bounds the expansion factor for our polynomial.
[0416] Proposition 3.1. Let f(x) --- xn--- x -r 2, then for all ei , e2t R- it holds that the expansion factor p is upper bounded by An, and moreover 7 is upper bounded by 3.
[0417] Proof. For e g 'R. we have:
[0418] < An ■ Wolei ) ■ 0x>(e2) .
[0419] For any field element t £ K, we can consider the “multiply by t” operator mult* : K — K, where multt(w) = t ■ w. This is a linear operator (in any embedding) and can be described by a matrix acting on the embedding of w. In the canonical embedding, this matrix is diagonal and less useful for our purposes. In the coefficient embedding we define Mt € Q"x" as the matrix such that for all w it; holds that [w'] = .Mt[wj, where ur = t / w. 3.3 Homomorphic Encryption
[0420] We now define homomorphic encryption and its desired properties. Throughout this section (and this work) we use K to indicate the security parameter.
[0421] A homomorphic (public-key) encryption scheme
[0422] HE = (HE. Keygen, HE.Enc, HE.Dec, HE. Eval) is a. quadruple of PPT algorithms as follows:
[0423] — Key generation: The algorithm (pk, evk, sk) 4- HE.Keygen(l*, aux) takes a unary representation of the security parameter and auxilary input that in our case encodes the plaintext space and the homomorphic capcity and outputs a public encryption key pk, a, public evaluation key evk, and a secret decryption key sk.
[0424] --- Encryption: The algorithm c <— HE.EnCpiTu) takes the public key pk and a message u e Z / pZ and outputs a ciphertext c.
[0425] — Decryption: The algorithm p* 4- HE.DeCjk(c) takes the secret key sk and a ciphertext c and outputs a, message p* t Z / pZ.
[0426] -- Homomorphic evaluation: The algorithm Cf <— HE,Evalevk( / , cy . . . , cy) takes the evaluation key evk, a function f : (Z / pZ' )t-- > Z / pZ, and a set of £ ciphertexts ci, . . . , ct, and outputs a ciphertext Cf.
[0427] Definition 3.1. A homomorphic encryption scheme is said to correctly evaluate a circuit family F if for all f t F and for all mi, . . . , mt 6 EfpFL, the following holds: If sk, pk are correctly generated by HE. Keygen with security parameter K, and if Cj — HE.EnCpkirry) for ail i, and Cf — HE.Evalpk( / >cj , . . . , cf), then
[0428] The only security notion we consider in this chapter is semantic security, namely security with respect to passive adversaries. We use its widely known formulation as IND-CPA security, defined as follows.
[0429] Definition 3.2 (IND-CPA Security).
[0430] Adv':pa\A\(K ) : Pr{Lffp?hPT / l](lK) 1} - PrfSaprf’VKl*)::: 1}i::::negl(,K).
[0431] 3.4 Gadget Decomposition
[0432] We present a ring generalization of the widely used “gadget decomposition” technique For a ring 7Z, a gadget vector g £ 'Rf , is a row vector of ring elements, equipped with a (not necessarily linear) decomposition operator g“!: '7?. — > Pt . We require that for all x f? 7c, it holds that g - g~ (a:) = x. Namely the gadget is an “inverse” of the decomposition operator. Importantly, the gadget is defined so as to ensure that for all x t P it holds that g-1(a:) is “small”, with respect to some measure. Thus the decomposition operator allows to trade-off size for dimension, while allowing linear reconstruction.
[0433] The gadget matrix Ggcorresponding to a gadget vector g is defined as Gg=
[0434] -= diagig, . . . , g) t 7J,KXfc((where the diag operators organizes its operands along the block-diagonal of a matrix, with 0 in the off-diagonal), where Ifeis the identity matrix of size k. The decomposition operation, G“1: 7?.KX fc— > , applies g~!coordinate-wise, expanding each entry into an / -dimensional column vectors.
[0435] More generally we may consider a gadget matrix that is generated by a set. of different gadget vectors: Ggl gfc. This is defined as Ggl gfc= diagfgi, . . . , gfc) € 7^.'cx<2_!=)yrhe decomposition operation, denoted as G”1: 'Rk*K— > 7?.(S2!i) x'cis defined analogously.
[0436] Next we define a specific class of gadgets that are commonly used in the paper.
[0437] 3.5 Learning with Errors and Related Problems
[0438] The Learning with Errors (LWE) problem was introduced by Regev IB.eg95] and became one of the most widely used and influential building blocks in cryptography. We use the following definition.
[0439] Definition 3.4 (Learning with Errors). Let n, q € N, %sa distribution over ZP . Xe a distribu
[0440] For a. row vec {(a, sa + e (mod Then the (decisional) Learning with Errors (LWE) problem with respect to parameters Iweparams = (n, q, x:i. ye) is to distinguish A, from the uniform distribution over Z”+1, given on a-priori unbounded number of samples, where s is drawn from Xs .
[0441] We refer to xs as the secret distribution and to veas the noise distribution.
[0442] The Module LWE problem (MLWE) was introduced by the name “Generalized LWE” in [BGV12] as a generalization of the Ring LWE problem (RLWE) iLPR10.LFE13ai. Here we use a variant that analogous to the Polynomial LWE (PLWE) problem LRSW131, and defined as follows?
[0443] Definition 3,5 (Module Polynomial LWE). Let f(x) be an irreducible manic polynomial of degree n, let K = Q(a:j / ( / (a:))anumber field, define the ring R. = T\x\ j If (a:)) and let q be an ideal in this ring, denoting 7vq= 7< / q. Let r 6 N, Xs a distribution over RJ and. xea distribution over 'R,.
[0444] For a row vector s € 7?.r;consider the distribution Asover Tcm1defined as {(a, sa + e (mod q))}. where a is uniform in Rf , e is sampled from ye.
[0445] Then the (decisional) Module Polynomial LWE problem (MPLWE) with respect to parameters mplweparams = ( / , n. r, q. ys, xf) is to distinguish .4Sfrom the uniform distribution over 7W+1, given an a-priori unbounded number of samples, where s is drawn from vs.
[0446] Remark 3.1. The special case of MPLWE where r = 1 is known as Polynomial LWE (PLWE) [?i.
[0447] Remark 3.2. Letting ye= t ■ Xe foraring element t which is coprime to q, it bolds that MPLWE with noise sampled from yeis equivalent to the setting where the noise is sampled from
[0448] Remark 3.3, In this work, we use the term MPLWE to refer to the module polynomial LWE problem. We note that in prior work RSSS171. the name MPLWE is used for the “middle-product” LWE problem. The latter is not directly related to our work.
[0449] Starting with iRogObj there are numerous hardness results relating the hardness of LWE to the worst-case hardness of lattice problems, for ensembles of iweparams that range asymptotically with the security parameter. Similarly, there are worst-case hardness results for RLWE and MLWE ?] . There are also known methods for relating PLWE security to that of RLWE RSW18i. These methods readily apply also to relate MPLWE security to MLWE. See Section 7 for a thorough discussion about the security of our assumptions.
[0450] 5The difference between our variant in MLWE is the same as the difference between PLWE and RLWE. Whereas in RLW E, MLWE the secret, noise and arithmetics are done modulo the dual ring 1Z ” , in PLWE and MPLWE everything is defined over TZ. Indeed one has to be careful when analyzing the security of such variants which we address in the appropriate section. 4 Our Scheme
[0451] In this section, we introduce the encryption scheme, with the homomorphic properties being discussed in the subsequent section. As global parameters for our scheme, we consider the parameters f(x) -- xn--x-t-2, K ---- Q\x],' {fix')') . 7Z ----- i7\x] / IJ {xX) . p = (a: ~ 2),p = 2”, as defined in Section 3.2. We recall the ring isomorphism Zp== 7?P.
[0452] The ciphertext space is defined over R.qas defined in 3.2. Unless stated otherwise, additions and multiplications in the following sections are over Rq. Given a P 7?., we denote by € 'R the unique ring element with coefficients in the range \—q / 2, q / 2') such that = a mod (a).
[0453] In Section 4.1 we describe an encoding - decoding procedure for elements in Zpinto elements in 1Z*. We proceed by introducing our encryption scheme in Section 4.2 and analyze correctness and security in Section 4.3. Homomorphic properties are discussed in subsequent sections.
[0454] 4.1 Messages vs. Plaintexts
[0455] Our scheme encrypts plaintexts q which are elements in 7c«, i.e. as cosets of the ideal p. We use these plaintexts to encode messages m t ZP, where we recall that p ---- (R : p).
[0456] We therefore require an efficient implementation of the ring isomorphism ZP= in both directions, so that messages can be properly encoded and decoded. In terms of terminology, we differentiate between “messages” which are elements in ZP, and “plaintexts” which are elements in 7?.-. Our encoding and decoding translate messages into plaintexts and vice versa.
[0457] We note that both Zp= Z / pZ and 7?.p= 7?, / p are quotient rings, so we need to consider specific representatives that are produced by the encoding and decoding. W7e consider two procedures Encode, Decode that run in polylog(p) time, take as input elements from Z, R respectively, and output elements from 7Z, Z, and implement the ring isomorphism. We further require that Encode produces “short” elements. Our measure of length in this context is infinity norm in the coefficient embedding. We let Bsnc= maxmez ||Encode(m)|| .
[0458] Notably, in our scheme with p = (a: — 2), it is possible to achieve j3enc= 1 since any coset of TZp has a representative with {0, 1} coefficients obtained by considering the binary representation of m (mod p) Namely, assume without loss of generality that m € [0,p — 1) arid that m = £^2*, where p, £ {0, 1}. Then Encode(m) = u(x~) ------ 5J, ptx1is a valid en coding procedure whose output only has {0, 1} coefficients. For Decode, we notice that given p ---- (W piX‘ , we can output p.,2l(mod p).
[0459] We let \ denote the set of plaintexts of our scheme. That is, 7?qoj \ is the set of elements in 7Z that can be represented as degree (n — 1) polynomials with {0, 1} coefficients.
[0460] We extend the Encode(-) function to act also on elements from 7Z by taking their small-coefficient representative modulo p. More formally, for p £ R, we define Encode(p) = Encode(Decodeip)) q 7?.m 4.2 The Encryption Scheme
[0461] In this section we present our encryption scheme called Ring Embedding FEE (REFHE), based on the MPLWE hardness assumption (see Definition 3.5). We embed messages m t as ring elements p = Encode(m) € 7?-ro.ij, which results in a. compact ciphertext.
[0462] Conventions e is sampled form yein 'R. e is in p. We denote by BXsthe bound on the tW of y. and by Bx_ the bound on the of (x — 2) ■ y£
[0463] S 1. Setup: pp <— REFHE. Setup(l”, Is) gets n the degree of the | ( polynomial, K the security parmeter and Returns ys, ys, g. r |
[0464] ( as pp, such that gcd(g. 2) = 1. the MPLWE problem with |
[0465] ( mplweparams( / , n, r, g, xs, xe) is K-hard, and q > q^ as defined in |
[0466] ( lemma 4.2. |
[0467] ( 2. Key Generation: (pk. sk, evk) <— REFHE. Keygenf 1*, pp). Sample | i row vectors sxt— ys, e <--- yf, and a uniformly random matrix A t |
[0468] ( Ha*r. Returns the secret key s = (1, — Si ), and public key pk = (b, A) |
[0469] ( where b = si A+(a:— 2)e. evk consists of the public parameters needed |
[0470] ( for homomorphic evaluations - relinearization key and bootstrap key, |
[0471] S which we will describe through the paper. i
[0472] S 3. Encryption: c 6 Hq+1REFHE.EnCpk(p). For p E 7crQ 1p sample |
[0473] | r 4- y3, e- ye, ei yf- Then ca= b ■ r + (x - 2)e0+ p, c:= |
[0474] S Ar + (a: — 2)ei. Return the column vector c = (cy. ci). |
[0475] S 4. Decryption: p REFHE. Decgk(c) returns [s - c]??. mod p = [CQ — |
[0476] S si • c:L| Tiamod p . S
[0477] When the scheme is used as an homomorphic encryption scheme, the setup and key generation phases also depend on the homomorphic capacity, meaning in which circuit evaluation the scheme supports. In this case for the key generation also generates ‘Key Switch matrices’ as seen in Algorithm 5.3. The decryption REFHE. Dec might be with respect to another modulus, as the modulus changes during the circuit evaluation due to the Key Switching and Modulus switching Algorithms 5.3, 5.5.
[0478] 4.3 Correctness and Security
[0479] To keep track of the noise, we have the following definition:
[0480] Definition 4.1,
[0481] We define (mod q)} .
[0482] We omit the subscript when s is clear from the context. We also omit p. when clear from, context Lemma 4.1. If %(c, / x) < [(g — l) / 2j . then REFHE.Decs(c) = p.
[0483] Proof. By the assumption there is e g p such that s • c = p + e mod q. Since €oo(p + e) < [{q - l) / 2j we also have:
[0484] Now (p e) mod p -= p as we wanted.
[0485] In the following sections we will use Lemma 4.1 when analyzing correctness of homomorphic evaluation. Indeed, given a function f : (Z / p)1'1Z / p and input ciphertexts c.j = REFHE. Encipi c_v = REFHE. Enc(pw), let c. be the output ciphertext of the homomorphic evaluation. Then by Lemma 4.1 it suffices to bound p(c, p) for p = Encode c f o Decode(p3, . . . . p v ).
[0486] First, we analyse correctness of REFHE as an encryption scheme, without applying additional homomorphic operations: • 7 • (s)) •
[0487] Proof. Notice that s ■ c = b ■ r -T- e
[0488] = (si A +
[0489] — fi Y ■ C
[0490] Where si , r y3, e, ei t eo t %e, and ^oo(^) = 1- It follows that c-s ~ p+e$ when eg < (1 2 • 7 • A is)) ■ BXe1
[0491] Lemma 4.3. The public-key encryption scheme REFHE is IND-CPA secure
[0492] Proof (Proof Sketch.). The proof of this lemma follows the standard argument for proving security for encryption schemes based on LWE-style assumptions. See. e.g., [Reg05;LPRIOj. The proof follows by a hybrid argument where we consider an adversary that is given the public key pk and a ciphertext c which axe properly generated by the scheme and encrypt some value <r. We recall Remark 3.2 with t = (x — 2).
[0493] We first replace the b vector in the public key to be sampled uniformly rather than being computed using MPLWE. By the MPLWE assumption with secret si , tills hybrid is computationally indistinguishable from the original experiment.
[0494] 'Then we replace c by a uniform vector. This is computationally indistinguishable from the previous hybrid again relying on MPLWE with secret r.
[0495] Finally, c is completely uniform and independent of p. which implies the security of the scheme.
[0496] In Section 7, we relate the hardness of MPLWE to that of more commonly used assumptions in lattice-based cryptography, such as RLWE, and discuss the proper choice of parameters. 5 Homomorphic Arithmetic Operations
[0497] In this section we present; our algorithms for the homomorphic evaluation of arithmetic operations: addition, multiplication by a scalar and multiplication of ciphertexts. For the sake of the multiplication operations, we also introdce our versions of the key switching and modulus switching techniques.
[0498] Homomorphic evaluation of logical operations will be implemented as a part of our bootstrapping process, see Section ?? for details.
[0499] During this section there are addition and multiplication between elements that naturally live in different spaces, some of them are in Tv.j (the ciphertexts), some in p (the errors), some in H / p (the messages), and some in '7?. (the secret keys). Although they live in different spaces, the operations and equalities in this section are iri Th.,, unless stated otherwise.
[0500] Also always e. g p, p. is the message.
[0501] 5.1 Addition
[0502] REFHE.Add takes two ciphertexts encrypted under the same secret key s. The addition is performed by adding the two ciphertexts (as vectors of ring elements). |
[0503] Lemma 5,1. Forc$ = REFHE.Add(c; , c2) we have 17(03, p:i+p2) < p(ci. pi) r?(c2, p2).
[0504] Proof. Let s • ci = Pi -+ e> , e:ie p such that t'oo(pi + ei ; = ps(p; + e:i), s ■ c2= p2+ 62, 63 6 p such that £,x( / t2 + ep) = ns(p2+ 62)- Then s • (cj + c2) = pi + e:L+ p24- e2= (pi + p2) + (ei y- e2).
[0505] 5.2 Scalar Multiplication
[0506] Sarne as with the message, wx: have to encode the scalar as a. polynomial th at equal to the scalar mod p. Then multiply each coordinate of the ciphertext by it. Notice that since the norm of the encoded scalar is small, when multiplying by* it the noise grows roughly by the expansions factor, which is logarithmic in the size of the plaintext space. In BG V this factor is linear in the size of the plaintext space, so for large plaintext spaces we get a significant improvement in the noise growth. Lemma 5.2. Let c be, a ciphertext, then for c' = REFHE.ScalarMult(c, a) we have <7s(c', a ■ p) < n ■ Bat,c■ T>S(C, p).
[0507] Proof. Lei, s ■ c' = p + e when £<x>(l* + e)' = r / sC(i+ e). Observe that s • c' = REFHE.Encode(a) • / / + REFHE. Encode! a-) • e
[0508] Since £oo(REFHE.Encode(a)) < Be!lc. we have
[0509] Lx(REFHE.Encode(ct) • p 4- REFHE.Encode(ct) ■ e) < 7 • Benc■ ^(p + e)
[0510] Also REFHE.Encode(a)-ju+REFHE.Encode(a)-e mod p = a-REFHE.Decode( / z) mod p as we wanted
[0511] 5.3 Key switching
[0512] 5.3.1 HElib inspired optimized keyswitch The following Key switching technique is based on the one presented in |HS20] , and is done in order to reduce the relative noise, in comparison to the standard approach in [BGV12j. This is indeed a generalization of the BGV keyswitching , which can be obtained as a. special case if q ----- q . w will be chosen as an elemnt in Kto n In order for everything to be defined T, p need to be co-prime. In practice, we always take q!\q odd integers, so this condition is satisfied.
[0513] Lemma 5.3. Let &i, 82, q, <f be as in SwitchKeyGen(g, q' . si, 83). Let ci € Rff , Ci ~ w ■ ci mod q and co SwitehKey(rSl_»#2 >ci, w). Then,
[0514] S9C2 = e • G-1(ci) + T • si • c'[ mod q’
[0515] Proof. Let A -= rSj. We have:
[0516] S2 • c? ----- so - A - G (ci )
[0517] = ( T • si • G + e) • G~x(c'1)
[0518] = e • C’^lcj + T ■ (si • c'i + qE)
[0519] ------ e • G-1(Cj) + T • (si • c'i + qEi When the equations are mod q' .
[0520] »2 ’ C2 — e • G- 1(c^) -i- T - si • C| mod q'
[0521] Corollary 5.1. Let cq t 'Rff and c2- SwitchKey(rSj..>S2, Ci). Then for the powers of d gadget GpowerSi, (defined in Definition $.3) we have that rSl s, is
[0522] Lil !\. Q ;7, •lllt.
[0523] J?S2(c2, qu> - T mod p) < fi / q ■ nw■ p&1(cq, y) 4- m ■ |a / 2j ■ [log.^g)! (Bxfiq fi) ■ -g
[0524] Proof. Notice thia.t e ■ GLfci J T - s2' c" mod p — IfiTiv ■ y — Tw - e -j- e'l mod p — Twp.
[0525] Lemma 5.4 (Security). For every known si t Rf1and a. random s2<-- Ys, the SwitchKeyGen(«i, .s2) distribution is computationally indistinguishable from uniforni.
[0526] 5.3.2 Relinearization Typically, homomorphic multiplication outputs a ciphertext encrypted under s®s. In order to keep the dimension fixed, it is common to wrap this procedure with a relinearization procedure that switches the key from s ® s back to s. The relinearization key is SwitchKeyGen(s, s ® s). which is considered as part of the public key. We can then invoke REFHE.SwitchKey from s ® s to s after every multiplication.
[0527] 5.4 Modulus Switching
[0528] We denote y ---- [a | ’'-rFthe 1- rounding algorithm with respect to for the lattice p, meaning for a 6 Q® / f (;r) , c 6 R. finding a. y t R such that (y — c) t p, f-ooly — a) < 1.
[0529] S Given an input a. output |
[0530] ; performed saperetly to each coefficient in the coefficient embedding. !
[0531] Lemina 5.5. Al spect to loo. Mea
[0532] Proof. Let a' ----- [a |, b ---- c(2) — a' (2) mod (2”), c ---- rn]c2.p. We need to prove that c — c 4 p and that £xfa — c') < 1. For the second claim we have
[0533] And regarding the first claim, we have: mod 2" Now using the fact that a: divides x — a?""1= 2 we get:
[0534] As desired.
[0535] Notice that since the ciphertext contains multiple elements from 7?. the rounding is done on each element seperately.
[0536] We start with a lemma, on the error rate of modulus switching for (rational) irrtejger moduli. While this is the most efficient modulus switching we haw; for our scheme, it provides a good sense of the underlying concepts.
[0537] Lemma 5.6, M o d S w i t c hq, ,3 r / (c i , / r - -Wft > ) <- 7,„ • —cl ?y(c, p -) + 7.7 ( .si
[0538] <7 ?
[0539] Proof. We have, and
[0540] We harm
[0541] Denote . then:
[0542] , , , q’ d'm ,, ixA' i A ~~hvj • hlC: / •') w tco^S ■ ( c’ — - - C;' '< q ' ? a1. . , .
[0543] N — 7w - dAh tA + 7 - tils) q we also have s • c' — q' wE = v. We have that s • c' mod p =3--~s ■ c mod p. Therefore, i / s • c. , — q , w£ -ix) mod , p ~ - ‘3—>wi / s • c. — aEr^ ) mod . p which gives us
[0544] . q'w v mod ? - / L
[0545] Q
[0546] So to conclude, s - c' mod and v mod p = This completes the proof.
[0547] Remark 5.1. If q = q' mod p and multiplication by w is trivial and we can see from the proof that; JJ(C') < ^-ri(c) + yfi fs) which removes the 7,,. from the noise bound. As mentioned at; the beginning of this section, it may not be ideal to choose integers q and q' that are congruent modulo p, as this could lead to very large ciphertext moduli values. Specifically, this condition implies q ss q' (mod p). resulting in q > p. This would require a much larger ciphertext modulus than what is typically used in our implementations. For that we will have to choose w 1 and suffer from a multiplicative expansion factor in the resulting error. In order to overcome that we introduce the ideal modulus switching, which will result in working modulo q which is not a rational number.
[0548] 5.5 Multiplication
[0549] Given ciphertexts encrypting p< . p2under s. the algorithm returns ciphertext that encrypts pi • p2mod p under s ® s. This is formalized via the following Lemma:
[0550] Lemma 5.7. Let ci, c26e ciphertexts that encrypt pi, ;J.O under #1, 02 respectively. Then jfe®s(RBFHE.TensorMult(ci, c2), p:L• p2) < p • <7s(ci, pi) • rjs(c2. p2)
[0551] Proof. Let s • ci = e3, s • c2= e2, where e-. = tp + e( , e2= p2+e2-ei >ez € P and ?7s(ci. p3) = €c»(ei), hs(c2, pa) = £,TC,(e2). Observe that
[0552] (s ® s) • (ci ® c2) = (s • d) • (s • c2) = ei • e2and t’i • e2mod p = (yp + e'() ■ (q24- e2) mod p = pi • p2. The lemma follows. The dimension of REFHE.TensorMult(ci, cj) is squared compared to the input ciphertexts. Therefore, when multiplying we perform C4 = REFHE.SwitchKeyfrsg®-^, c3) and then eg = ModSwitch9>g'.w(c4) for q, < / determined in the scheme parameters, in order to reduce the noise.
[0553] Notice that VJ. VJ' can be chosen in A-pyc, such that c3encrypts the multiplication of the messages ci. cg encrypt (given that the noise is small), and not a scalar multiplication of it.
[0554] Moduli ladder As in (BGV12], the setup phase of the scheme in algorithm 4.1 produces also a “ladder” of the cipher text moduli that will be used during the evaluation of the scheme. Notice that after each multiplication we perform key switch and then modulus switch, so the evaluation key should consist of a Public keyswitch matrix for each multiplication before the bootstrapping, and the relevant modulus.
[0555] 5.6 Optimizations
[0556] Optimization for keyswitch and modulus switch
[0557] Notice that there is a multiplication by a scalar in both algorithms: multiplying ci by w in Algorithm ??, and multiplying c by vi in Algorithm ??. It; turns out that we can ignore these scalar multiplications and account for them only in the final step. Specifically, by skipping these scalar multiplications, i.e., setting w --- w' ------ 1, and given bounds on ps(c; , pi) and ps(C2. Pa), Algorithm 5.7 provides a bound on %(c3, pi • p3• a), where a is determined solely by the evaluated circuit, and the chosen primes. This means that the multiplication algorithm effectively becomes a composition of multiplication and a multiplication by a known constant scalar a.
[0558] We now claim that every circuit can be evaluated using tilts modified multiplication instead of the regular one. Indeed, we take the same circuit — with the modified multiplication in place of the standard one, and associate with each cell in the circuit a scalar a, G Zp. Let circuit 1 represent the circuit using the ”new” multiplication and circuit 2 the one using standard multiplication. Before computation, we can determine the scalar a{for each cell I, which is the ratio of the value of the cell in circuit 1 to the value in circuit 2 (and we need to prove that this ratio is independent of the inputs to the circuit).
[0559] Notice that when performing a homomorphic evaluation, we generally work with layered circuits, where each cell corresponds to a layer that reflects the <iept;h of multiplications required to reach that cell. Homomorphic operations have inputs only from the same layer, as the inputs must have the same key and modulus, which are determined by the depth of multiplications. Returning to our claim, we wish to show that all the cells in the same layer have the same scalar multiplier. Indeed, we need to explain that for multiplication, addition, and scalar multiplication. For multiplication it is clear: aj • m; x a^ma x a?.. = cq+ix m-. x m-2 where ai+1depends only on a,, a. For addition: a; ■ (mi +mj) = a, ■ mi + a> ■ m®. And for multiplication by scalar a' • (a> ■ m) = ai ■ (a' ■ m).
[0560] Notice that without multiplying by scalar we have
[0561] There are several ways to take advantage of tliis, depending on the specific
[0562] — The first and simplest way is to always use the modulus switching and key switching without the multiplication by scalar, arid only in the last modswitch before bootstrapping multiply by a scalar w, that instead of being chosen as equal to q' / q mod p it will be chosen such that the associated scalar with the new cell is 1.
[0563] — Another way is that the decryption algorithm will include also division by the relevant scalar mod p. The issue with this approach is that it can’t be used during binary operations during bootstrapping.
[0564] -- We can also try to affect this factor during encryption, middle steps, or choosing of moduli ladder, in order for the final multiplier to have an inverse with small norm.
[0565] Tradeoff between n and r Security of the scheme depends on n ■ r. While working with a ciphertext Z / 2”1, f can be every n > m. In practice when nj = 64 we work with n > 64 in order to reduce the size of the Key Switching matrix in Algorithm 5.3.
[0566] 6 Bootstrapping and Boolean Operations
[0567] We now present our bootstrapping algorithm. We start by introducing a generic notation that will be used throughout this section. In the course of the bootstrapping we switch between a number of forms of algebraic and non-algebraic LWE. All of these schemes have a very similar syntax, namely a linear decryption over some ring results in an encoding of a plaintext with some noise. To capture tliis, we denote by LWE^’(p; e) the sei, of vectors of elements in such that for a secret key s it holds that s - c = bp + etc (mod q), Intuitively LWE^(« e) can be thought of as a set of ciphertexts and related objects (i.e. modulus-switching parameters) generated by a, scheme which is based on the LWE assumption. We therefore refer to such objects as “LWE ciphertexts” .
[0568] Similarly, we denote by MPLWE / ' / (p: E) the set of vectors of elements in some polynomial ri ng A. such that for a secret key s it. holds that s - c = bji + ae (mod q). a. b 6 7?., .
[0569] MPLWE“’g( / x; e) can be thought of as the analogous notion to MPLWE“’g( / z; e) but for schemes based on the MPLWE assumption. We therefore refer to such objects as “MPLWE ciphertexts” .
[0570] We then denote BGVg>s( / z; £), BFVgjs( / z; e), REFHE„s(p; E) to mean LWE( / / (p: s), E) respectively, which in the same manner can intuitively be thought of as BGV, BFV, REFHE ciphertexts. We occasionally omit one or more of the parameters s, a, b when they are clear from the context. Also, we use q. Q t Z to denote ciphertext space moduli. Q is used to denote the modulus of a newly encrypted REFHE ciphertext, as opposed to q which denotes a modulus of a ciphertext that is the result of homomorphic operations and has potentially consumed ciphertext levels reaching to a level for which the modulus is q.
[0571] The rest of this section is organized as follows. In Section 6. 1 we cover the subroutines in more depth, and in Section 6.2 we present our bootstrap algorithm in detail. The description above is provided mainly for intuition. In Section we show how logical operations can be preformed homomorph ically during bootstrap.
[0572] 6.1 Subroutines of the Bootstrapping Algorithm
[0573] 6.1.1 Programmable Bootstrapping for B / FV This is the procedure from [KDE‘”24] that allows to use the programmable bootstrapping of the TFHE scheme in order to bootstrap schemes that are based on the BGV and B / FV paradigms.
[0574] --- Setup algorithm PB.Setup(l", I9, s, 1” , q') that takes as input the security parameter, as well as the following parameters. LWE dimension and modulus parameters \n. q), both given in unary representation, and a corresponding binary LWE secret key s 6 {0, 1}". Additional LWE dimension and modulus parameters (n', q1), where n' is given in unary representation, as well as a vector c of Ring-LWE zero-encryptions with noise bound B. The algorithm outputs the programmable bootstrapping public parameters pbpp of bit length poly(n, q. n' , log q'}.
[0575] — Programmable Bootstrapping Algorithm PB.Bootstrap(pbpp, c, / ) which takes as input the programmable bootstrapping parameters pbpp an LWE ciphertext c with dimension n and modulus q, a function J : represented by its truth table. It outputs c' . an LWE ciphertext, with dimension n' and modulus if .
[0576] We overload the notation of PB. Bootstrap with respect to the last operand.
[0577] Let F be a matrix of functions: F e (Zg— > then PB.Bootstrap(pbpp, c, F} is a shorthand for the procedure that applies PB.Bootstrap(pbpp, c, Fff) for every entry of F arid outputs a matrix rm x m2 of LWE ciphertexts corresponding to the outputs of the executions.
[0578] Theorem 6.1 (Programmable Bootstrapping [KDE+24]). There exist polynomial time algorithms with syntax as above, with the following properties:
[0579] — Correctness. Letting pbpp = PB.Setup(ln, I9, s. 1" , q‘ , c) and then computing c' = PB.Bootstrap(pbpp, c, / ), it holds that s' • c’’ (mod <- / ) = f(s - c) + e , (5) -poly (n, log q, n' , log q'). for some (fixed) polynomial. nts of c are computationally indistinguishable from uniform, then pbpp earn be simulated without any knowledge of s.
[0580] 6.1.2 Sample Extract We next describe how to extract a LWE sample encrypting the free coefficient; (recall that we face the constraint of being able to only use the free coefficient in out bootstrapping mechanism, the reason for which is explained in Section 2) of the input REFHE ciphertext as a BGV ciphertext. For a field element t G K we consider the operator J : K — ♦ Q to be the operator that outputs the free coefficient u e Q, of the multiplication of t by a field element w ft K. Note that if we consider such a multiplication of elements in the ring 7?. the result is in Z and hence, viewed as a linear operator acting on the coefficient embedding of w 6 Tv, its output is a coefficient vector in Z". Extending J to operate on vectors of such ring elements Frwe take the output to be a concatenation of the resulting coefficient vectors, one for each of the ring elements, arid denote it formally a.s J : TV — > Z”r.
[0581] The extraction of the first coefficient of a REFHE ciphertext c = (co, c.i) encrypted under the secret key s -- (1, — si) is simply (|colo, J(c:. ■ which will output an BGV ciphertext encrypting the same message under the extracted secret key, namely the coefficient embedding of sj .
[0582] After extraction we switch the output BGV ciphertext to a BFV ciphertext. This is done for two reasons: the first is that TFHE requires a modulus switching to one that is a, power of 2 which is not possible for BGV since BGV requires q and p to be coprime, and the second is that during programmable bootstrapping we evaluate a function that takes as input a ciphertext in which the noise term e is not multiplied by a coefficient as in BFV.
[0583] Starting with a BGV ciphertext c s.t. s • c. ~ p 2s mod q, we switch it to a BFV ciphertext c by multiplying by 2"1(mod s) — (g 1 ) / 2, so we have: and get: s • c ' = ~(i Y + ~1■ 11 + - ?y- • £ mod , q
[0584] --- — •1 + ~ — 1 • / J ~r { g -H- 1 X J • c HlOC ■i (!
[0585] Since we are performing modular arithmetic modulus q, we can omit the term q ■ £ and obtain: mod q which is indeed a BFV ciphertext.
[0586] 6.1.3 Repacking with Key Switching [remsited version}
[0587] The aim of the Repacking procedure is to construct a MPLWE ciphertext from the n LWE encryptions of its message polynomial. This means converting each of them into a MPLWE ciphertext encrypting the same message multiplied by the corresponding power of the formal: variable x\ and sum them up in the end. We next show how to accomplish this using key-switching. We start with a vector of the n LWE ciphertexts: (co, . . . , c,t..i), each such that: s - c,;= (ct(a’)y 4- c, (mod Q) however, each a is a potentially large vector, so we binary-decompose it f)
[0588] At this stage, since the terms s, which are elements of the private key and hence are obviously not given, we substitute the term 2lsj with the key-switching keys (which are created at Section 6.2.1). Recall that; the key-switching keys are MPLWE encryptions of powers of 2 multiplied by the secret key elements over the scheme's ring under a, different key denoted here as s, and so are of the form: aJyi+ bws = 2lSj + e{x) (mod Q, f) we substitute for 2'’s.;in the last equation and denote the resulting MPLWE (in the scheme’s ring we now denote obtain: d(j + di s — 'S ( rile Cl ~r djilisla:" — a(x) + epr) 6 RQ
[0589] 6.2 Bootstrapping Procedure and Analysis
[0590] 6.2.1 Bootstrapping Setup The procedure REFHE. BS. Setup defines public parameters bspp. which include: a function D the function we evaluate during bootstrapping, gadget decomposition elements (as defined in Section 3.4): a decomposition base B used for the decomposition, gadget vector: g = §B,Q — (1, B1. . . . . ), gadget matrix G = Gg= Ifc® g and a gadget decomposition operation G-1= G~1. key-switcing keys; for a secret key s generated by REFHE. Keygen as in Algorithm 4.1 in Section 4.2 a vector' of key-switching keys consists of encryptions of the different powers of 2 multiplied by the hits of the secret key s, namely a key-switching key kskj.i) is in a, REFHE encryption of 2“ • s.; where 0 < I. < [log2QJ , TFHE bootstrapping parameters; tfbspp output by the algorithm TF. Bootstrap as in Section 6.1.1
[0591] 6.2.2 Bootstrapping Algorithm
[0592] Definition 6.1. For q, Q t N we define D : Z, — > ZQ to be the function that extracts the most significant bit of its input. Specifically D(z) represents z as (qflfp + e where e has the smallest possible absolute value and p t {0, 1}, and outputs p.
[0593] 6.2.3 Correctness and Security Analysis For the purpose of correctness analysis we consider an execution of the bootstrapping algorithm (Algorithm 6.3) on inputs bspp = REFHE. BS.Setup(l", l4, s, 1" , O, c), £ REFHE, (p; e),
[0594] H <?.
[0595] We recall Theorem ??
[0596] Lemma 6.1 (Blind Rotation). For all i, consider c,, computed in Line j of Algorithm. 6.3. If we denote c, = (eg, . . . , cj) then it holds that c'- e BFV(BJ■ p; df);0 < j < I (6) poly(n, log(c), ?? / . log(Q)). 6.3 Boolean Operations
[0597] We iiow explain bow to use our bootstrapping framework :l-i order to perform boolean operations on the ciphertext in the course of bootstrapping. Our solution hinges on the property that; the coefficients of the encoded plaintext p are the bits of the message m, and those are the values that are recovered in the course of our bootstrapping procedure. We start by considering boolean operations that permute ciphertext bits, and move on to logical operations.
[0598] Permuting Ciphertext Bits. In Steps 5, 6, 7 of Algorithm 6.3 we construct c(?EFHE= REFHEqfrqa:1; tw). Let us consider a slight change to Step 5 and set that is, the operand of Gg'^f) becomes independent of i. In this case we get CRFFHF~ REFHEqf / ry e'’’') instead of the above. However, we note that this is almost as good, since we can always multiply post-facto by ar7, for any j that we want, to obtain c(iEFHE= REFHEqipiW; t7"), at the cost of a. factor 7 < 3 increase in the noise bound. In particular, c) / EFHEwould l)e the value c^FFHFfrom Step 7 in the algorithm, which allows to continue the execution of the bootstrapping loop as before.
[0599] After the end of the execution of the loop, we can compute immediately any cFEFHEthat we want. Therefore, any shuffling of the bits may be implemented seamlessly. Let <f> : {0, . . . , n — 1} -4 {0, ... , n — 1, ±} be any function, then we can return, in Step 10 of Algorithm 6.3, the value W"”1Coccu- where we syntactically define c^FFHEto indicate 0. By properly choosing d>. it is possible to implement circular / non-circular shifts (e.g. 0(i) = i + 1 (mod n ) is a singleslot cyclic left shift), apply bit-masks, duplicate values, extract specific bits and perform similar operations. It is also possible to output more than one output ciphertext. e.g. store the lower n / 2 bits in one ciphertext and tlie upper n / 2 bits in another.
[0600] All of these operat ions incur a minimal penalty in terms of noise and runtime compered to ordinary bootstrapping.
[0601] Comparisons. An additional class of logical operations is producing a boolean value which corresponds to the truth value of some numerical comparison. It suffices to consider the setting where we have two input ciphertexts C] , cj encrypting messages m; , m2, and we wish to recover c' that encrypts the value 1 if mi > m2, and 0 otherwise. This is of course instrumental for branching operations, loop variables and such. This can be achieved straightforwardly using our techniques. First we can use arithmetic homomorphism to subtract C3 = c2— cp Then we can bootstrap eg and extract a ciphertext containing only the most significant bit; of the message encrypted by C3. Indeed, by standard boolean logic (two’s complement representation), the most significant bit is 1 if and only if the output is negative, which is the case if and only if mi > m2.
[0602] Multi-Bit Boolean Operations. Let us now consider operations that are performed over multiple bits. We note that using the above, equality to 0 can be tested by checking that both m > — 1 and m < 1, which can be done using two parallel bootstrapping sessions. Equality to 0 is also the n-bit NOR, operation. Similarly other logical operators over the n bits can be implemented. We may then turn our attention to performing bitwise AND, say between two numbers. That is. we have two plaintexts p, fi , a.nd we want to recover p / ' so that; pf' ----- pi • pi for all i. This requires a bit; more work, and we describe one possible method for performing this operation using a constant number of bootstrapping operations. First, we use a shuffling subroutine to split each input operand into two ciphertexts, where all even bits are set to 0, and the odd bits correspond to the odd bits of the original ciphertexts. That is. we have (from LSB to MSB): p!ower— (ptjQpiO ■ • ■ un / 20), ^“PP6’ = (foi / a-j iO ■ ' ’ Mn-10), and likewise for p'. We then add c"low<sr= c:,ower+ c'lower, c""**6’’ = c,lpper+ c',lpper, and notice that the even bits of the c”'lower. c"“PPerare exactly the bits of p". Another bootstrapping operation will allow to reorganize the bits and obtain a since c" that encrypts u” as desired.
[0603] 7 Security of MPLW’E in Our Ring
[0604] In the section we discuss the hardness of the MPLWE problem (Definition 3 5). We do so by first explaining how it relates to other algebraic variants of the Learning With Errors problems. Later we argue about the security in our specific ring, defined by polynomials of the form fix) = xn— x + 2.
[0605] 7.1 Algebraic Variants of LWE and Their Relations
[0606] Algebraic variants of LWE work over a number field K. The Ring LWE (RLWE) problem [?j is defined over the so-called ring of integers of K, whereas the O rder LWE problem (OLWE) [?] is more general and can be instantiated over any full rank subring of the ring of integers (such subrings are called “orders”, and the ring of integers itself is the maximal order). Also relevant; to our work is the Polynomial LWE (PLWE) problem [?] which lias a somewhat simpler definition. In PLWE, all arithmetics are done in the ring itself (rather than the “dual ring” which can be thought of as a fraction over the ring), and noise is generated in the coefficient embedding (rather than the canonical embedding). We provide some formal definitions below.
[0607] Let f{x) be an irreducible monic polynomial of degree n, let K = ’Q[ad / ( / (a’)) be a number field, define the ring H = Z[®j / (J(r)), OK to be its ring of integers of the number field.
[0608] Definition 7.1 (Module Order LWE). Let O be an order of K a.nd q be an ideal, in the order. Denoting Oq ----- O / q. Let r t N, ysa. distribution over (O'1'' f and xsa distribution over Ov.
[0609] For a row vector s 4- y.s. consider the distribution Asover Of x C5)7defined as { (a, sa c (mod q)) } , where a is uniform in Of , e is sampled from ye.
[0610] Then the (decisional) Module Order LWE problem (MOLWE) with respect to parameters moiweparams = ( / , n. O, r. q, v5, yE) is to distinguish Asfrom the uniform distribution over O) x Of , given an a-priori unbounded, number of samples, where s is drawn from %s.
[0611] We point out a few important special cases:
[0612] Fig. 1. Reduction relations between various relevant Algebraic LWE problems. The numbering refers to the different security issues 1, 2, 3 and 4 numbered below.
[0613] Known connections between the problems are summarized in Figure 1. The numbers on the arrows correspond to the following reductions,
[0614] 1. Coefficient vs. Canonical Sampling [RSW18]. Let X be a, Gaussian random variable with expected value p and co-variance matrix E and V some linear transformation. Then IA.¥ is also a Gaussian random variable with expected value Vu and co-variance matrix In particular when moving between the coefficient and canonical embedding when uses the Vandermonde matrix Vf defined by the complex roots of f. Thus in order to control the error after the transformation one has to analyze the Singular Value Decomposition (SVD) of the matrix Vf.
[0615] 2. The Dual Ring [RSW18]. Every order is a full rank lattice and thus one can define the dual of this lattice as (9V= {a t K : TrK / Q(oO) C Z}. The trick is to multiply by an element in the co-different ideal [OonObl , this takes an instance from the dual ring to the ring itself. When this is done the error growth by the norm of this element. As it turns out understanding the dual ring and finding an element of small norm there is rather difficult. In RS W 18] the authors show that it is always possible to find such element in non-uniform time. Another options is to note that f‘(x) is always a member of the different ideal (meaning that / Ta:)”1is in the co-different ideal) [Cor 3.5 [Con09]j which in some: cases may give a decent reduction.
[0616] Implicit. 3. The Order Z)r] / ( / (:r)) VS. The Maximal Order [RSW18]. For any order O of K one can define the conductor ideal Co ----- {x K : XOK Q O}. Multiplying by an element of the conductor can move a RLWE instance into an OLWE instance, again increasing the error by it’s norm. In a similar way to the co different ideal RSW 18] shows it is always possible to find a small element in the conductor or use f'(x}.
[0617] 4. Module to Ring Reductions [PP24]. The reduction here looks at a order O' of higher degree in a field extension of K' / K such that it is also a module over the base order O. The reduction maintains the " total degree” (The degree of the module times the degree of the ring) and works for a wide class of extension fields.
[0618] 7.2 Security in Our Ring Compared to a Cyclotomic
[0619] It is a common choice to take K to be the cyclotomic field, this is done as many structural properties are known about them. This enables faster computations [LPR .13bj but also simplifies some of the security assumptions. Namely cyclotomic polynomials are monogenic, meaning that OK ----- Z / (f(x)). Furthermore as long as the defining cyclotomic number m does not admit a. but of distinct factors the transformation between the coefficient ami canonical embeddings is asymptotically tame |BC22]. Lastly for power of two cyclotomic one can see that the dual ring is a scaling of the ring.
[0620] Where it comes to the polynomial fix) ------ xn— x 2 we make the following notes. We verified numerically that for all n < 64 our order T-t is indeed the ring of integers. We provide the details for n ----- 32, 64 in Section 3.1.2. For larger values of n it becomes hard to verify square-freeness. However, there is no evidence that working in the ring of integers provides additional security compared to other orders. In particular we are not familiar with attacks that exploit this. In addition it admits a, good transformation between the canonical and coefficient embeddings. For n = 2'cthis can be argued directly via R.ouche’s theorem similarly to the classes of polynomials describe in |RSW18j. Otherwise a. heuristic argument can be made, as t he polynomial lias a large; gap and therefore its roots are somewhat equidistributed in terms of their angle from the origin, and its roots are between 1 to 3~ with a geometric average of 2“ . We calculated numerically the largest and smallest singular values up to n = 1000, and we see that they both scale withv'n with a small constant, see Section 3.1.3 for details. For n = 32 and n = 64 we get 4.6, ~ 15.2) and (« 6.5, ~ 22.3) respectively
[0621] As for working in the dual or the ring itslef the case for our polynomial and cyclotomies are similar, in that we have to either multiply by the inverse of f'(x) enlarging the error in the order of magnitude of the degree, or follow the reduction in IRSW18].
[0622] We also point out that some have argued that cyclotomic polynomials may be a worse choice in terms of security, compared to non-cyclotomics, since their structure may give raise to attacks. For example, in the context of tlie NTRU- Prime scheme, [BCLvV16] proposed to work with the non-cyclotomic xn— ,r + 1 (which is quite similar to ours). They claim that working with such polynomials can also be done quite efficiently, and is less risky in terms of security.
[0623] Lastly we want to address a line of attacks on polynomial LWE using polynomials of the form x” 4- ax + b iEHL14.ELOS 15,CIV16k The general concept is to start with polynomials of the form xn+ b for a “large” b and show it behave similarly to xn+ ax + b for a “small” a. The first idea is that if b = q — 1 we get that / (I) = 0 mod q which in turns means that if there is a, ring equation modulo both / and q it is possible to assign x = 1 and still obtain a valid equation. This collapses the PLWE instance into a one-dimension al instance with small noise. Notice that this attack hinges on the coefficient embedding of the noise e(x) being small. Peikert [Feilhl surveys such “field dependent attacks” and concludes that they result from improper choice of noise parameters, that is enabled by pathological properties of the number field. Our interpretation of Peikert ’s conclusion is that so long as we add the noise “properly”, i.e. in such a way that when looking at the respective dual instance, the noise is large enough, then no vulnerabilities are known. In essence this means that while we discuss tlie trails formation between the canonical and coefficient embeddings for the security reduction, this distinction may be void for practical attacks as long as we work in the; dual ring.
[0624] 8 Performance and Implementation
[0625] We didn’t implement the optimized Key switch yet, and the algebraic modulus. We expect additional improvements from those.
[0626] Our parmeters y are for security x
[0627] 8.1 Parameter Estimations
[0628] We are going to estimate para, meters generically i.e. for a, plaintext of a certain size, a polynomial with certain parameters and varying security levels. In particular for / we will denote by oy the singular values of the Vandermonde matrix Vf defined by the roots of f . We assume that a is sampled such that it has enough entropy but not anymore then necessary for the security parameter. In particular s is chosen uniformly from {c / e Ti. : q, € {0, 1), c,'(l) -- k] . This provides enough entropy given that n choose k is greater then 2*. As for security we are going to assume that the RLWE problem is as hard as the LWE problem i.e. there are no better attacks on RLWE. Further we are going to assume that the hardness of a RLWE instance is determined by the smallest singular values of the co-variance matrix. Pictorially, the error is sampled from an ellipsoid and we assume instead the error is taken from the largest sphere contained in the ellipsoid. Lastly we are going to assume that modulus switching and re-linearization are preformed after each operation.
[0629] 8.1.1 Irreducibility of our polynomials Lemma 8.1. The polynomial f(x) = xn— x + 2 is irreducible over the integers for n > 2.
[0630] Proof. Notice that the complex roots of f have absolute value > 1, by the triangle inequality, assume fix) = h(x) ■ g(x). We have that h(0) • g(0) = 2, and since h(0), o(0) are integers, one of them is of absolute value 1. with out loss of generality' g. Then g must; have a root of absolute value < 1, a contradiction since this root; is also a root; of f .
[0631] 8.1.2 Monogenicity of our polynomials It is well known that if the discriminant of a polynomial f is square free, then Z[x\ / f(x) is the ring of integers of Q(a?) / / (:r). For a polynomial of the form x2— x 4- 2, by theorem 4 in [GD84] , the discriminant is D = 2K”1■ 2fc'2— (2k— I)2" "1. For k = 64:
[0632] 2fi3■ 264'264- 6363factorizes into the following primes:
[0633] 1399,
[0634] 315883,
[0635] 1054894487,
[0636] 1609025206302091,
[0637] 300524395301294803,
[0638] 102580173634571360137,
[0639] 8668017673543442201810164494961,
[0640] 1813131374962222709188812217190299
[0641] For k = 32: factorizes into the following primes:
[0642] 53,
[0643] 683,
[0644] 1189674929,
[0645] 72879316190189456125055364884319727806855527
[0646] So both of the polynomials are monogenic.
[0647] 8.1.3 Computing Singular Values We have computed the singular values of the polynomial xn— x 2 from n ----- 4 to n ------ 1000.
[0648] This gives O(\ / n) similar to the power of two case. 9
[0649] Fig. 2. Logarithmic Fit for the square of the minimal and maximal singular values as a function of the degree
[0650] 8.1.4 Parameters for Security We sample our error from a Spherical Gaussian with standard deviation r then in the canonical embeding we have a distribution with a smallest singular value of £ where e r is the distortion factor resulting from the linear transformation Vf. For now we are going to assume that £ / • -= s2since this will be the singular value of the matrix V>- Vf but I think we mav be able to switch it with something like - V” . o-2. This assures us that if there is no advantage to using cyclotomic field in the canonical embedding then our scheme is as secure as as RLWE in the cyclotomic field with error r. That being said there is an at tack called Au rora-Go which actually work: in the coefficient embedding: Assume that the error is bounded in the range — t, t] then the following polynomial P(ax~c) ----- This is a polynomial equation without error. I don’t see how this would transfer into the cannonical embedding in which errors behave considerably different. Thus we may be able to take for security e = max(e.f, Z' / n) since I’m not fully convinced in this observation I’ll see the parameters when assuming it and one not assuming it. So overall the parameter for security will be:
[0651] 1. The computational security parameter K taking the values 128, 160, 192
[0652] 2. The statistical security parameter 7 taking the values 40, 80, it
[0653] 3. The distortion of the Vandermonde matrix gy taking the values 1, 10, IO2, IO3, 104, 105.
[0654] 4. A boolean value indicating the respect to the Aurora-Ge attack in the canonical embedding i.e. is the error at least for True or max(2y / n, gf) for False. 5. Which gap proof do we use, with gap proportional to 27or exact.
[0655] We would like to choose parameters n, q such that the scheme is secure according to the LWE estimator with errors that exact commands shall be params = LWE.Parameters(n, q. ys, vA; LW E.Estimateiparams)
[0656] Where yf. -- ND.DiscreteGaussian(r), x» ~ ND.Choose(n, k)?
[0657] 8.2 Implementation
[0658] This section evaluates concrete runtime of our scheme encryption and decryption procedures, homomorphic arithmetic operations: addition arid multiplication, as well as modulus switching and key switching, without algebraic ciphertext modulus and bootstrapping.
[0659] Parameters
[0660] We generated parameters for our scheme, such that correctness is achieved with high probability based on the somewhat naive bounds given in sections ?? and that the lattice problems are 128-bit secure according to the lattice estimator.
[0661] Setup The tests and results presented in the next section were obtained with a naive implementation in which no specific optimizations were applied to enhance performance. These results thus, reflect the raw computational costs associated with the building blocks of our scheme without the influence of advanced heuristics, algorithms or hardware-specific optimizations. The test bed for our results is as follows. We implemented our tests in Rust run on and bench- marked single-threaded speed for all procedures.
[0662] We use the Key Switching Algorithm for d ---- 2 and q ----- q' , And while the implementation supports working over modulus, for the concrete parameters we chose r = 1. While talking about depth of multiplications - Each plaintext goes through the following procedure:
[0663] 1. Encoding
[0664] 2. Encryption
[0665] 3. Modulus Switching
[0666] And then for each Multiplication:
[0667] --- 'Tensor multiplication
[0668] — Key Switching
[0669] — Modulus Switching
[0670] In case of zero multiplications, after the third action (the modulus switch) addition is performed. The ciphertext size is measured after the modulus switch, as this is the size required for transmission during communication.
[0671] Results Comparison with BGV We generated parameters to the original BGV [BGV 12] scheme, with similar to those we obtaines. We did that for plaintext spaces of sizes 2lt:, 2'i2, 2°4. Bellow you can see the comparison in the ciphertext sizes, when modulus switch is performed right after encryption to reduce the ciphertext size.,
[0672] A Optimizing Performance Using Ideal Ciphertext Moduli
[0673] We shortly present the scheme working with 7?qwhere q is not a rational integer. We believe it holds both theoretical and practical significance. In particular, we don’t need to use multiplication by w in the key switching and modulus s witching algorithms, since we can switch bet ween input and output moduli with an element which is congruent to 1 mod p. Indeed there are algebraic elements which are congruent to 1 mod p of much smaller b!Xnorm, then rational ones. Another advantage is that we can work with ciphertexts in the “Double CRT Representation” ?] which means representing the ciphertext ring as a, direct product of Z / n*. This representation allows multiplying ciphertexts without an FFT transformation to the frequency domain. Returning to our case, notice that 7? / [ax — i>) = Z / (tT — ban~14- 2a” 1, So for cipher text modulus of the from q = H'RW — bi}, we have a double CRT representation.
[0674] In particular, we notice that for our scheme it is beneficial to set; up the moduli-ladder by setting q, = (1 — kj(x — 2)) for rational integers fc, € E>, for which ip are coprime. We then let q<= qp. ■ Hi-o HereSo € N is the “bottom step” in the ladder, which means that as we get to decrypt or bootstrap we fall back into the rational setting.
[0675] A.l Algebraic Number Theory facts
[0676] N(t) i.e. the algebraic norm of the element t = ax — b (and the ideal (t) in our ring is the resultant of ax — b a, rsd xn— x + 2, which is bn— ban~l+ 2an. The quotient ring satisfies 7?, / (t /
[0677] A.2 The difference in the scheme from rational q
[0678] The scheme remains structurally identical, where operations which previously performed modulo q are now conducted modulo q. The only aspect of the original scheme, as outlined in Algorithm 4.1, that requires further definition is the decryption algorithm. However, it is important to note that our modulus bidder ends with a, rational integer. Consequently, decryption is only necessary when the modulus is a rational integer, which ensures that the scheme functions correctly without further modification.
[0679] Correctness and Security. Standard security assumptions talk about R.LWE type problems with respect to a rational ciphertext modulus. Although there are assumptions with respect to alebraic ideals - as the GLWE security assumption in [PP19], we wish to talk about a simple reduction from M / P / R / O - LWE problems over an algebraic ciphertext modulus to a rational one. Working with an algebraic modulus q, we can perform modulus switch to the modulus a ■ q for a rational q and a a polynomial with 0,1 coefficients. Notice that (q} \ {a ■ q) so in particular we get an MPLWE problem with the ciphertext modulus q - which is rational - where we lose roughly a factor of the expansion factor in the parameters.
[0680] We measure noise in tfi, in the coefficient embedding, the same as in definition 4.1. Note that the analysis of the noise growth after encryption, and the bounds needed for decyption stay the same.
[0681] Homomorphic Properties, Multiplication, Multiplication by scalar and Addition are the same as in integer modulus, with q replaced by q in the algorithm. The analysis and bounds on the noise %(c, m) stay the same. There difference is a new gadget in the key switching and a new modulus switching.
[0682] A.3 Representing the Ciphertext
[0683] Lemma A.l, Assume z mod (ax — b) (for b = 2a + 1, a = k) can be written as a polynomial of degree n— 1 with coefficients in the range (—6 / 4(1 — 1 / 2"), 6 / 4(1 — 1 / 2")) which is ([ — 7), [7J) fix(z) < b / d). Then there is an efficient algorithm to find this polynomial. Also there is a unique way to write it that way.
[0684] Proof. For (res) the resultant of ax — b and f(x) the generating polynomial of the number field we have:
[0685] Notice that the RHS is in the interval (— res / 2, res / 2). Indeed:
[0686] So we look at z' = z ■ a,"”1mod res as an element in Z and provide an algorithm to write it there as a sum 5 / c,fiian~1~~. Assuming such a representation exists, we must have CQ = z' / an~1mod b. Similar equation holds for ci - b- an~J' 10C mod (fe2) and we can continue for the latter coefficients by taking mod 6* every time. Notice it also proves that there is a unique way to write the element as a polynomial with coefficients in this range.
[0687] Lemina A.2. Every element t in R. is congruent modulo ax — b (where b ---- 2a+l
[0688] Proof. Let z ------ with a,:e Z. Define |z| (c) as the evaluation of 'ff \aj\x1at c e R, i.e., r (c) V aycL Consider the polynomial z with minimal |.z|(£) that is congruent to t modulo ax — b. We claim that this z cannot have coefficients with absolute value larger than ■ a.
[0689] Indeed, if the i-th coefficient is larges', then we add or subtract axi+-' — bx* to reduce the absolute value of the ?.-th coefficient (by at least min(b, ~ • (2o: — 2)) ) and claim that z| (cj) decreases. There are two cases to consider:
[0690] 1. Case i < n — 1: In this case, the absolute value of the (i + l)-th coefficient increases by at most a. If a ■ C < min(&, • (2a — 2)) (which holds by the assumption on a), then W(i() decreases.
[0691] 2. Case i = n — 1: The absolute value of the constant term increases by at most 2a, and the absolute value of the xlcoefficient increases by at most a. Therefore, fol (C) decreases if which after dividing by fi””1is the same inequality as in the previous case.
[0692] Working Modulo qrRecall that q, = go ■ EK0*® ~ M- lAs long as the a-iX — bi are coprime (also to g0), by CRT we have RJg = 'R / qo, { J 'R. / {a.jX — N), so calculations can be done coordinatewise. Notice that when doing the calculations modulo (agx — bP we can choose t 6 Z as a representative in the conjugacy class for each c t Tv / fagc — bP, So its like working in Z / ibf -- biaf~[‘dad1; in each coordinate, and then NTT can be used for multiplying elements in the quotient ring efficiently.
[0693] A.4 Key Switching
[0694] We use a variant of the Key Switching presented in algorithm 5.3, with q. q = q, q' and T -= .... For that we introduce the following gadget:
[0695] CRT decomposition gadget Notice that we have the CRT isomorphism given that the q*. are coprime. For c 6 7£pi „ we look at the gadget vector gcrt = ( / - l(ei))». The decomposition operation = / (c) viewed as a vector in B'" . Notice that this embedding is not uniquely defined. For q. = ax — b we choose the smallest representative in absolute value in Z of c mod {ax — b}. For pj = qa q. we choose the smallest representative in £.xin the coefficient embedding of c mod qe,. composition with powers-of-d gadget We can compose the CRT decomposition operator with the gp^,^, operator. The output of g“l is a vector when each coordinate is in Z with £x< tV(q,) / 2 (N is the algebraic norm) or in with £;ja< qo / 2. The composition is applying gp^,^ to each coordinate of the output meaning Gp^^^ • g“i (W- Notice that applying gp^^ result in different vector size in each coordinate. Notice also that this operator is the decomposition operator for the gadget gcrt• G.„c,„jer3Ora0. bounding the inner product To use the Keyswitch algorithm with the powers- oftd composed to CRT decomposition gadget, we need to bound (G”l(c'1). e) as seen in lemma 5.3.
[0696] Lemma
[0697] (G1(c'1
[0698] A.5 Modulus Switching
[0699] We now describe the modulus switching algorithm for switching from (ideal) modulus q int (ideal) modulus q'. Formally, we let q, q' be ideals in the ring B. We considered the special case where q = (< / ), q' = (o • q'i for (rational) integers F F -
[0700] We let zip denote: a rounding algorithm for the; plaintext lattice; p in the canonical embedding, with distance parameter da. Indeed, we always select p so that it has a short basis, so such should exist, however its exact properties are determined by the specific instantiation we choose.
[0701] We require the existence of a ratio parameter t € K (we stress that t is a fraction so usually t R) with the following properties: t 6 q' • q-1and furthermore t = 1 (mod p). In the integer setting, if we may take q = q (mod p) then t = q' / q is a valid ratio parameter. The following lemma summarizes the performance of the algorithm.
[0702] JJ(C', if) < r(t') ■ g(e, Lt) -T- 7 • €i(s)
[0703] Proof. Denote s - c = v + E where E ti q. By definition of ModSwitch, it holds that
[0704] Then s • e = t • v + t ■ E + (c' — t ■ c, s) .
[0705] Denote v' = t ■ v + (c1— i ■ c, s), E1= tE. Then s • c' = v1+ E' . (8)
[0706] Since t 7 q'q-1. it holds that E' G q'. Let us now analyze the norm of v' .
[0707] Finally, since t 1 mod p, then E!----- tE ;;; E mod p, Furthermore we recall that c' =EE C mod p. Therefore (12) mod p) (13)
[0708] = « . (14)
[0709] This concludes the proof of the lemma.
[0710] Next we show a bound on r(t). 1 norm by at least Proof. We upper bound the tp norm of the rows of A as a, linear operator, by 2 / 3 • (k 1). which proves the lemma.
[0711] The; inverse; matrix of ax + b:
[0712] The matrix A that represents multiplying by ax + b in the coefficient embedding is the following: b’s on the main diagonal, a’s is the diagonal bellow ((n — 2) a’s), A(0, n — 1) -2a, .4(1, n - 1) = a (indices are between 0 and n — 1). For n — 4 it looks like
[0713] We claim that for even n. the inverse of that matrix, is multiplied by tire following matrix B:
[0714] For n = ‘ 1, the matrix B is given by: Let’s see that it is indeed the inverse:
[0715] For a = — k, b = 2k + 1 we can see that by multiplying by the inverse of A the of the vector is multiplied by at most the maximum between the of the rows of the matrix, which is approximately Indeed
[0716] References
[0717] BC22. Ivan Blanco-Chacon. On the rlwe / p]we equivalence for cyclotomic number fields. Applicable Algebra in Engineering, Communication and. Computing, 33(1):53-71 , 2022. Proceedings. Part I, volume 10624 of Lecture Notes in Computer Science, pages 409 437. Springer, 2017.
[0718] CLPX18. Hao Chen, Kim Laine, Rachel Player, and Yuhou Xia. High-precision arithmetic in homomorphic encryption. In Nigel P. Smart, editor, Topics in Cryptology - CT-RSA SOI 8 - The Cryptographers’ Track at the RS A Conference 2018, San Francisco, CA, USA, April 16-20, 2018, Proceedings, volume 10808 of Lecture Notes in Computer Science, pages 116-136. Springer, 2018.
[0719] Con09. Kieth Conrad. The different ideal. Expository papers / Lecture notes. Available at: h:ttp: / / wunv. math. uconn. edu / kcon- rad / blurbs / gradnumthy / diff erent, pdf, 2009.
[0720] DM14. Leo Ducas and Daniele Micciancio. FHEW: Bootstrapping homomorphic encryption in less than a second. Cryptology ePrint Archive, Paper 2014 / 816, 2014.
[0721] EHL14. Kirsten Eisentraeger, Sean Hallgren, and Kristin Lauter. Weak instances of PLWE. Cryptology ePrint Archive, Paper 2014 / 784, 2014,
[0722] ELOS15. Yara Elias, Kristin E. Lauter, Ekin Ozatnan, and Katherine E. Stange. Prov- ablv weak instances of ring-lwe, 2015.
[0723] FV12. Junfeng Fan and Frederik Vercauterem Somewhat practical fully homomorphic encryption. IACR Cryptol. ePrint Arch., page 144, 2012.
[0724] GC14. Matthias Geihs and Daniel Cabarcas. Efficient integer encoding for ho momorphic encryption via ring isomorphisms. In Diego F. Aranha and Alfred Menezes, editors, Progress in Cryptology - LAT1NCRYPT 2014 - Third International Conference on Cryptology and Information Security in Latin America, Flonandpolis, Brazil, September 17-19, 2014, Revised Selected Papers, volume 8895 of Lecture Notes in Computer Science, pages 48-63. Springer, 2014.
[0725] GD84. Gary R. Greenfield and Daniel Drucker. On the discriminant of a trinomial. Linear Algebra and its Applications, 62:105-112, 1984.
[0726] Gen09a. Craig Gentry. Fully homomorphic encryption using ideal lattices. In Proceedings of the Forty-First Annual ACM Symposium, on Theory of Computing, STOC ’09, page 169 178, New York, NY, USA, 2009. Association for Computing Machinery.
[0727] Gen09b, Craig Gentry. Fully homomorphic encryption using ideal lattices. Symposium on the Theory of Computing, page 169-178, 2009.
[0728] GH19. Craig Gentry and Shai Halevi. Compressible FHE with applications to PIR. In Dennis Hofheinz and Alon Rosen, editors, Theory of Cryptography - 17th Internmtional Conference, TCC 2019, Nuremberg, Germany, December 1- 5, 2019, Proceedings, Part II, volume 11892 of Lecture Notes in Computer Science, pages 438-464. Springer, 2019.
[0729] GHS12. Craig Gentry, Shai Halevi, and Nigel P. Smart. Fully homomorphic encryption with polylog overhead. In David Pointcheval and Thomas Johansson, editors, Advances in Cryptology EUROCRYPT 2012, pages 465 482, Berlin, Heidelberg, 2012. Springer Berlin Heidelberg.
[0730] GSW13. Craig Gentry, Amit Sahai, and Brent Waters. Homomorphic encryption from learning with errors: Conceptually-simpler, asymptotically- faster, attribute-based. Cryptology ePrint Archive, Paper 2013 / 340, 2013.
[0731] HS00. Jeffrey Hoffstein and Joseph H Silverman. Optimizations for ntru. In Proc, the Conf, on Public Key Cryptography and Computational Number Theory, Warsaw, pages 77-88, 2000. HS20. Shai Halevi and Victor Shoup. Design and implementation of HElib: a homomorphic encryption library. Cryptology ePrint Archive. Paper 2020 / 1481, 2020. https : / / eprint . iacr - org / 2020 / 1481.
[0732] HS21. Shai Halevi and Victor Shoup. Bootstrapping for helib. J. Cryptol., 34(1):7, 2021.
[0733] KDE+24. Andrey Kim, Maxim Derj / abin, Jieun Eom, Rakyong Choi, Yongwoo Lee, Whan Ghang, and Donghoon Yoo. General bootstrapping approach for rlwe-based homomorphic encryption. IEEE Trans. Computers, 73(11:86- 96, 2024.
[0734] LMW23. Wei-Kai Lin, Ethan Mook, and Daniel Wichs. Doubly efficient private information retrieval and fully homomorphic RAM computation from ring L.WE. In Barna Saba and Rocco A. Servedio, editors, Proceedings of the 55th Annual ACM Symposium, on Theory of Computing, STOC BOSS, Orlando, FL, USA, June 30-33, S0S3, pages 595-608. ACM, 2023.
[0735] LPR10. Vadim Lyubashevsky, Chris Peikert, and Oded Regev, On ideal lattices and learning with errors over rings. In Henri Gilbert, editor, Advances in Cryptology - EUROCRYPT 2010, 39 th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Monaco / French Riviera, May 30 - June 3, 2010. Proceedings, volume 6110 of Lecture Notes in Computer Science, pages 1-23. Springer, 2010.
[0736] LPR13a. Vadim Lyubashevsky, Chris Peikert, ami Oded Regev. On ideal lattices and learning with errors over rings. J. A CM, 60(6):43:l-43:35, 2013.
[0737] LPR13b. Vadim Lyubashevsky, Chris Peikert, and Oded Regev. A toolkit for ring- Iwe cryptography. In Annual international conference on the theory and applications of cryptographic techniques, pages 35-54. Springer, 2013.
[0738] MP12, Daniele Micciancio and Chris Peikert, Trapdoors for lattices: Simpler, tighter faster, smaller. In Annual International Conference on the Theory and Applications of Cryptographic Techniques, pages 700-718. Springer, 2012.
[0739] Peil6. Chris Peikert. How (not) to instantiate ring-LWE. Cryptology ePrint Archive, Paper 2016 / 351, 2016.
[0740] PP19. Chris Peikert and Zachary Pepin. Algebraically structured LWE. revisited. In Theory of Cryptography: 17 th International Conference, TCC SOI 9, Nuremberg, Germany, December 1-5, SO 19, Proceedings, Part I 17, pages 1-23. Springer, 2019.
[0741] PP24. Chris Peikert and Zachary Pepin. Algebraically structured Iwe, revisited. J. Cryptol., 37(3):28, 2024.
[0742] RAD+78. Ronald L Rivest, Len Adleman, Michael L Dertonzos, et al. On data banks and privacy homomorphisms. Foundations of secure computation, 4(U):169-180, 1978.
[0743] Reg05. Oded Regev. On lattices, learning with errors, random linear codes, and cryptography. In Harold N. Gabow and Ronald Fagin, editors, Proceedings of the 37th Annual ACM Symposium on Theory of Computing, Baltimore, MD, USA, May SS-Sf, 3005, pages 84-93. ACM, 2005,
[0744] RSSS17. Miruna Rosea, Amin Sakzad, Damien Stehle, and Ron Steinfeld. Middleproduct learning with errors. In Jonathan Katz and Hovav Shacliam, editors, Advances in Cryptology - CRYPTO 3017 - 37th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 20-24, 3017, Proceedings, Part III, volume 10403 of Lecture Notes in Computer Science, pages 283-297. Springer, 2017.
[0745] OVERVIEW
[0746] A homomorphic encryption scheme enables mathematical operations or computations to be performed on encrypted data without requiring its decryption. Therefore, the data remains confidential while being processed, even in an untrusted environment. As a result, useful operations may be performed on the encrypted data by a third party without requiring the third party to properly secure the data, as the original data cannot be identified without the decryption key. For example, a person or organization may apply standard encryption techniques to secure sensitive data on cloud platforms, but processing or validating the encrypted data in the cloud would require its decryption, which raises privacy issues and security vulnerabilities and may entail additional costs and resources. By utilizing homomorphic encryption, private data may be shared and evaluated securely in commercial cloud environments without endangering privacy The cloud service provider only has access to the encrypted data (ciphertext) and can perform computations on the data without decryption. The results of the encrypted processing may be provided to the owner of the private data who can then decrypt the data (into plaintext) via the decryption key. In addition to cloud services, homomorphic encryption can be used by entities in a wide vary of businesses and industries, such as financial services, healthcare, retail, information technology and artificial intelligence systems, to allow access to encrypted data while protecting client or patient privacy
[0747] Homomorphic encryption schemes may be classified into several categories, including partially homomorphic encryption, somewhat homomorphic encryption, and fully homomorphic encryption. A partially homomorphic encryption allows only a single operation to be performed on the ciphertext, such as addition or multiplication In contrast, fully homomorphic encryption (FHE) supports multiple operations indefinitely, such as both addition and multiplication, enabling a wider range of arbitrary computations to be performed on the ciphertext. However, FHE is characterized by certain limitations, particularly a very large computational overhead and high inefficiency due to protracted time for performing computations. Many FHE schemes are based on lattice mathematics, such as derived from the ring learning with errors (RLWE) problem, and are generally considered secure from breaches by quantum computing (i.e., post-quantum cryptography).
[0748] The present disclosure relates to a fully homomorphic encryption (FHE) scheme based on lattice problems which natively support a large plaintext space, such as a 256-bit value or higher. 1 1 C
[0749] SUMMARY
[0750] In accordance with one aspect of the present disclosure, there is provided a method for a fully homomorphic encryption (Fi ll ') scheme that natively supports a large plaintext space. The method includes the step of, given a desired plaintext size “p”, generating an irreducible polynomial “f” of a chosen degree d > logp, such that f(a) = p for some a co-prime to p. The method further includes the step of defining a set of parameters including: a number field: K ~ QU'] / / 7; a corresponding ring of integers: OK; an order of ring: R ~ Z[x] / f, ' a linear polynomial: g(x~) — x ~ a, and an ideal I generated by g and p, such that a quotient ring / ? / / is isomorphic to a desired plaintext space Zp, and such that constitute a short basis for a lattice defined by the ideal / , where a value “q” is selected to be large enough and co-prime to p such that the corresponding Order-LWE problem is considered hard. The method further includes the step of applying an encryption process. In a first variation, the encryption process includes: sampling a secret key “s” from a dual of R, sampling an error “e” from a Gaussian distribution defined on R with standard deviation “o”, and sampling a randomizer “a” uniformly from / ?; and determining an encryption according to: E(m, e) ---- (a, m + as + ge)' mod(R. q). In a second variation, the encryption process includes: sampling a secret key “s” from a dual of R, sampling an error “e” from a Gaussian distribution on a lattice defined by the ideal / , and sampling a randomizer “a” uniformly from R\ and determining an encryption according to: E(m, e) — (a, m + as + e)mod(R, q'). In a third variation, the encryption process includes sampling a secret key “s” from a dual of R, sampling an error “e” from a Gaussian distribution defined on a lattice translated by the message “m”, and sampling a randomizer “a” uniformly from R; and determining an encryption according to: E(m, e) = (a, as + e)mod(R, q).
[0751] According to an aspect of the present disclosure, a decryption of the encrypted data includes subtracting “as” and reducing modulo the lattice basis.
[0752] According to an aspect of the present disclosure, the method further includes the step of applying a Brakerski, Gentry, Vaikuntanathan (BGV) construction to transform the scheme into a public key FHE scheme
[0753] In accordance with another aspect of the present disclosure, there is provided a method for a fully homomorphic encryption (FHE) scheme that natively supports a large plaintext space The method includes the step of applying a double Chinese Remainder Theorem (CRT) encryption process. The encryption includes the steps of: receiving as input a power of two n, and a message in an extended plaintext space: a E (Zp)’', where: P = Pt f°r asplitting coprime sequence p of length k, wherein the splitting coprime sequence comprises a vector such that: pi ~ lmod(2n) and gcd(pirpj) ~ 0 unless i = j; and outputting a message: (il1?••• , il&), where iq E applying a pre-processing step comprising identifying roots: 6LJ of a cyclotomic polynomial: + Imod(pj); applying a rational CRT conversion step: set a --- (a mod(p}), ,a modip^; applying a polynomial CRT conversion step: set providing an output of a.
[0754] According to an aspect of the present disclosure, the method may further include the step of applying a double CRT decoding process. The decryption includes the steps of: receiving as input a power of two n, and a message in an extended plaintext space a where p is a splitting coprime sequence of length k; and outputting a message in the extended plaintext space: a £ (Zp) , where: P — nt=i,-,kPb applying a pre-processing step comprising identifying roots: 0f / - of a cyclotomic polynomial : 02n(x) ” x” -r lmod(pj; calculating an inverse of a Vandermonde matrix defined by the roots and calculating that: dj f°rJ ” ,n; and providing an output of a.
[0755] According to an aspect of the present disclosure, the method may further include the step of constructing a leveled FHE for an arbitrary plaintext space The constructing includes the the steps of: for a desired plaintext space size “p”, selecting a splitting coprime sequence p of length k such that: P — Ils— 1,-- .z« Pt > Pi wherein a desired depth of the leveled THE is denoted by k; using k instances of a BGV scheme, constructing an encryption scheme that operates in a plaintext space using the CRT representation, transforming the plaintext space into an extended plaintext space (ZP)n; for every BGV ciphertext encryption, applying a zero knowledge (ZK) proof nrangesuch that the encryption is of value 0 < x < p, to ensure that after h homomorphic operations, the encrypted value will not modulate and the homomorphic operations will be valid in Z and therefore in ZP; after BGV homomorphic evaluations and before published values, adding an encryption of a random multiple of p to the new ciphertext, to ensure that no information on a value of a computation over Z is revealed other than a result mod(p), whereby for a ciphertext c, sampling: temp [20pft] and providing an output: c!— add (c, temp • p), where “a” represents a statistical security parameter, to provide a final value bounded by: (1 +
[0756] According to an aspect of the present disclosure, at least one of the FHE schemes is used by a client to encrypt private and / or sensitive data to be shared with a third party operative for performing computations or processing the encrypted data without decryption thereof.
[0757] According to an aspect of the present disclosure, the third party may include at least one of: a cloud service provider; a medical service provider; a financial service provider; or an information technology service provider.
[0758] According to an aspect of the present disclosure, the large plaintext space comprises an integer size of at least 256-bit.s. According to an aspect of the present disclosure, the method is applied in a decentralized network.
[0759] According to an aspect of the present disclosure, the method is applied in a blockchain system.
[0760] According to an aspect of the present disclosure, the method is applied in a large scale secret information sharing system.
[0761] DETAILED DESCRIPTION
[0762] The present disclosure relates to a fully homomorphic encryption (FHE) scheme based on lattice problems which natively support a large plaintext space, such as a 256-bit value or higher. Specifically, this may be achieved based on the Order-LWE problem, which is proven to be equivalent to known lattice problems [bolboceanu2019order].
[0763] The FHE scheme is detailed hereinbelow
[0764] First, given a desired plaintext size “p” (i.e., the size of the plain message before encryption), it can be shown how to generate a relatively sparse irreducible polynomial “f” of a chosen degree d > logp, such that f (a) = p for some a co-prime to p.
[0765] The following parameters are then considered: the number field K — Q[x] / f; the corresponding ring of integers OK; and an order of this ring R — Z[x\ / f. A linear polynomial is defined as follows: / / ( v ) x ■■■■ a, and an ideal / generated by g and p is further defined. It is observed that the quotient ring / ? / / is isomorphic to the desired plaintext space Zp, and that {.gx1} constitute a short basis for the lattice defined by the ideal / . A value “q” is selected to be large enough and co-prime to p such that the corresponding Order-LWE problem is considered hard.
[0766] Using the aforementioned notations, the following three encryption schemes are provided: i. In a first variation, a secret key “s” is sampled from the dual of R, an error “e” is sampled from a Gaussian distribution defined on R with standard deviation “o'”; and a randomizer “a” is sampled uniformly from / ?. An encryption is then calculated as follows: E(m, e) ---- (a, m + as + ge)mod(R, q). ii. A second variation is similar to the first variation, but the error e is sampled from a Gaussian distribution on a lattice defined by the ideal / , and the encryption is of the form: E(m, e) = (a, m + as + e)mod( / ?, g) iii. A third variation is similar to the second variation, but the Gaussian distribution is defined on a lattice translated by the message “m”. and the encryption is defined as follows’ E(m, e) = (ci, as + e)mod(R, q).
[0767] For all these variations, decryption may be performed by subtracting “as” and reducing modulo the lattice basis.
[0768] A construction similar to Brakerski, Gentry, Vaikuntanathan (BGV) [cryptoeprint:2011 / 277] encryption may be utilized to transform the aforementioned symmetric cryptosystems to a public key FHE
[0769] Two alternative approaches may be considered.
[0770] In a first alternative approach, the plaintext m G [— p, p] is represented in a Chinese Remainder Theorem (CRT) representation. In other words, considering the message modulo multiple small primes Pj such that H / Py » p. Taking the product to be greater than p is necessary to avoid modulations, making computation hold essentially over the integers However, this may introduce an inefficiency as most of the plaintext space is not used. In addition, a large multiple of p must be added before decryption, to hide the number of modular reductions mod p that take place in the homomorphic evaluations, which can expose additional information. Moreover, for security reasons should add range proofs to convince that no modular reductions []; P / took place, which may further entail a large computational overhead.
[0771] In a second alternative approach, a BGV encryption scheme may be applied in its existing form with a large plaintext space. However, this approach may require a large ciphertext modulus “q”, which in turn requires a large number of slots “n”, which may become intractable and infeasible relatively quickly.
[0772] According to an embodiment based on the first alternative approach, the plaintext space of BGV -based FHE schemes may be represented utilizing both rational and polynomial CRT This technique may be useful for optimizations and for representing larger plaintext spaces. An alternative scheme is described hereinbelow
[0773] In a double CRT encoding process, an algorithm receives as input a power of two n, a message in the extended plaintext space: a E (Zp)”, where: P = FIi=u, -.kPi f°rsome splitting coprime sequence p of length k. A splitting coprime sequence is a vector which satisfies that: Pi x: lmod(2n) and gcd(pi,Pj) ---- 0 unless i ---- j. The algorithm then outputs a message: (u1;■■■ , where 6 A subsequent pre-processing stage involves finding the roots: Ojj of the cyclotomic polynomial: d2n(x) = *n+ lmod(p£). Next is a rational CRT conversion step: set a = (a modtp-i), , a mod(pfe)). This is followed by a polynomial CRT conversion step: set a., for i --- 1, ••■ , k. The encoding process then provides an output of a.
[0774] In a double CRT decoding process, an algorithm receives as input a power of two n, a message in the extended plaintext space a where p is some splitting coprime sequence of length k. The algorithm then outputs a message in the extended plaintext space: a E (Zp) , where: P = A subsequent pre-processing stage involves finding the roots: Oij of the cyclotomic polynomial' ~ + lmod(pi). In addition, the preprocessing includes calculating the inverse of the Vandermonde matrix Vj defined by the roots
[0775] Gtj, and calculating the rational CRT coefficients: Next in the decoding process is a polynomial CRT conversion step
[0776] This is followed by a rational CRT conversion step whe r j = 1, , n. The decoding process then provides an output of a.
[0777] The above alternative scheme can be used to construct a leveled FHE for an arbitrary plaintext space as follows. For a desired plaintext space size “p”, a splitting coprime sequence p of length k is selected such that: P ---■ Pi > P- Preferably, the elements of the sequence are roughly the same size and P is close to p. The desired depth of the leveled FHE is denoted by h. Using k instances of the BGV scheme, an encryption scheme that operates in the plaintext space may be constructed. Using the CRT representation, the plaintext space of the scheme may be transformed into the extended plaintext space (Zp)n. For every BGV ciphertext encryption, a zero knowledge (ZK) proof nranqemay be applied such that the encryption is of value 0 < x < p. This may ensure that after h homomorphic operations, the encrypted value will not modulate and thus the homomorphic operations will be valid in Z and therefore in ZP. After BGV homomorphic evaluations and before the values are published, an encryption of a random multiple of p is added to the new cipher text. This may ensure that no information on the value of the computation over Z is revealed other than the result mod(p'). This may be required for circuit privacy. In particular, for a ciphertext c, one may sample’ temp *- [2ffpft] and output: c' = add(c, temp • p), where “a” represents a statistical security parameter. It is noted that this may provide a final value bounded by: o support depth-h multiplication, the ciphertext modulus q must be The described scheme can be batched, as typical for BGV schemes.
[0778] The different variations and approaches presented herein may enable configurable, native plaintext space for a fully homomorphic encryption (FHE.) scheme. The disclosed FHE scheme can allow for encrypting message in ZPand performing homomorphic operations on such messages in ZP. As opposed to the aforementioned alternative approaches (i.e., based on CRT or based on BGV), the size of the ciphertext is comparable and proportional to the size of the plaintext (and does not grow exponentially with “p” for example). The disclosed FHE scheme may be employed in various applications. One example relates to cloud computing services. A lightweight client (i.e., computationally or memory limited) may use third party cloud services while maintaining data privacy by sending private data encrypted to the cloud, which could homomorphically operate on the ciphertext and return an encrypted output Only the client who holds the private key can restore the output into its original form. For example, such a client may be a smartphone application that, performs real-time face recognition operations but cannot, store and compute the required large complex neural network architectures. Additional exemplary applications involve sensitive data analysis, such as in the fields of medical or financial services. Such corporations or institutions may possess mass quantities of sensitive client information that can be kept encrypted under a carefully protected private key, while allowing third parties to perform requisite analyses over the encrypted sensitive data
[0779] The disclosed fully homomorphic encrypdon (FHE.) scheme may overcome certain disadvantages over existing FHE schemes having a limited size plaintext space. Firstly, for a sufficiently large plaintext space, the ciphertext consists of a single slot, in which the ciphertext bloat is constant (i.e., independent of security parameter). Other schemes may rely on packing technique, encrypting multiple plaintexts in a single ciphertext to obtain an amortized small ciphertext bloat. However, these extra slots cannot always be exploited, and in any case they increase the latency. Furthermore, supporting large plaintext space, such as 2128, is consistent with the operation of modern computers, processors and data registers. This may result not only in faster homomorphic computation, but also provide for a more natural, straightforward and more efficient translation between an ordinary computer program and one operating with encrypted data.
[0780] METHODS
[0781] 1. A method for a fully homomorphic encryption (FHE) scheme that natively supports a large plaintext space, the method comprising the steps of: given a desired plaintext size “p”, generating an irreducible polynomial “f” of a chosen degree d > logp, such that f (a.) = p for some a co-prime to p; defining a set of parameters comprising: a number field: K ---■ 0 [x] / / ; a corresponding ring of integers: OK; an order of ring: R ---- a linear polynomial: g(x) ---- x — a, and an ideal / generated by g and p, such that a quotient ring R / I is isomorphic to a desired plaintext space Zp, and such that {pxJ} constitute a short basis for a lattice defined by the ideal / , wherein a value “q” is selected to be large enough and co-prime to p such that the corresponding Order-LWE problem is considered hard; and applying an encryption process selected from the group consisting of:
[0782] (i) sampling a secret key “s” from a dual of R, sampling an error “e” from a Gaussian distribution defined on E with standard deviation “o”, and sampling a randomizer “a” uniformly from / ?; and determining an encryption according to: E(m, e) = (a, m + as + ge)mod(R, q);
[0783] (ii) sampling a secret key “s” from a dual of R, sampling an error “e” from a Gaussian distribution on a lattice defined by the ideal / , and sampling a randomizer “a” uniformly from R; and determining an encryption according to: E(m, e) ~ (a, m + as + e)mod( / ?, q); and
[0784] (iii) sampling a secret key “s” from a dual of R, sampling an error “e” from a Gaussian distribution defined on a lattice translated by the message “tn”, and sampling a randomizer “a” uniformly from R; and determining an encryption according to: E(m, e) = (a, as + e)mod(R, q).
[0785] 2. The method of method 1, wherein a decryption of the encrypted data comprises subtracting “as” and reducing modulo the lattice basis.
[0786] 3. The method of method 1, further comprising the step of applying a Brakerski, Gentry, Vaikuntanathan (BGV) construction to transform the scheme into a public key FHE scheme. A method for a fully homomorphic encryption (FHE) scheme that natively supports a large plaintext space, the method comprising the steps of: applying a double Chinese Remainder Theorem (CRT) encryption process comprising the steps of: receiving as input a power of two n, and a message in an extended plaintext space: a E where: P for a splitting coprime sequence p of length k, wherein the splitting coprime sequence comprises a vector such that: p) ~ lmod(2n) 0 unless i ---- j; and outputting a message: where uLG Rp. ; applying a pre-processing step comprising identifying roots: of a cyclotomic polynomial: lmou(pj: applying a rational CRT conversion step: set d ----- (a applying a polynomial CRT conversion step: set for i = 1, , fc; and providing an output of d. The method of method 4, further comprising applying a double CRT decoding process comprising the steps of: receiving as input a power of two n, and a message in an extended plaintext space d E where p is a spliting coprime sequence of length k; and outputting a message in the extended plaintext space: a E , where: P --- pp applying a pre-processing step comprising identifying roots: of a cyclotomic polynomial: 02n(x) = xn4- ImodQpi), calculating an inverse of a Vandermonde matrix V, defined bv the roots 0. ‘-•7 and calculatin og rational CRT coefficients: V i ti applying a polynomial CRT conversion step such that: d = ) > applying a rational CRT conversion step such that: dj — Ei=i,- -.kYtdij for / = 1, , n; and providing an output of a.
[0787] The method of method 4, further comprising the step of constructing a leveled THE for an arbitrary plaintext space, the constructing comprising the steps of: for a desired plaintext space size “p”, selecting a splitting coprime sequence p of length k such that: P = fli= i.-,k Pt > P', wherein a desired depth of the leveled FHE is denoted by using k instances of a BGV scheme, constructing an encryption scheme that operates in a plaintext space using the CRT representation, transforming the plaintext space into an extended plaintext space (ZP)n; for every BGV ciphertext encryption, applying a zero knowledge (ZK) proof nrangesuch that the encryption is of value 0 < x < p, to ensure that after h homomorphic operations, the encrypted value will not modulate and the homomorphic operations will be valid in Z and therefore in ZP; after BGV homomorphic evaluations and before published values, adding an encryption of a random multiple of p to the new ciphertext, to ensure that no information on a value of a computation over Z is revealed other than a result mod(p), whereby for a ciphertext c, sampling: temp <■■■• [2°ph] and providing an output: c' = add(c, temp ■ p), where “o” represents a statistical security parameter, to provide a final value bounded by: (1 +2ff)p / l+1.
[0788] The method of either of methods 1 or 4, wherein the FHE scheme is used by a client to encrypt private and / or sensitive data to be shared with a third party operative for performing computations or processing the encrypted data without decryption thereof.
[0789] The method of method 7, wherein the third party is selected from the group consisting of: a cloud service provider; a medical service provider; a financial services provider; and 12C an information technology service provider. The method of either of methods 1 or 4, wherein the large plaintext space comprises an integer size of at least 256-bits. The method as in any of the method 1 to 9, applied in a decentralized network.
[0790] The method as in any of the method 1 to 10, applied in a blockchain system. The method as in any of the method 1 to 1 1 , applied in a large scale secret information sharing system.
[0791] It is to be understood that the invention is not limited in its application to the details set forth in the description contained herein or illustrated in the drawings. The invention is capable of other embodiments and of being practiced and carried out in various ways. Hence, it is to be understood that the phraseology and terminology employed herein are for the purpose of description and should not be regarded as limiting. As such, those skilled in the art will appreciate that the conception upon which this disclosure is based may readily be utilized as a basis for designing other structures, methods, and systems for carrying out the several purposes of the presently disclosed subject matter. It will also be understood that the system according to the invention may be, at least partly, implemented on a suitably programmed computer. Likewise, the invention contemplates a computer program being readable by a computer for executing the method of the invention. The invention further contemplates a non-transitory computer-readable memory tangibly embodying a program of instructions executable by the computer for executing the method of the invention.
[0792] Those skilled in the art will readily appreciate that various modifications and changes can be applied to the embodiments of the invention as hereinbefore described without departing from its scope, defined in and by the appended claims.
Claims
CLAIMS1. A processor-based method comprising: bootstrapping a first ciphertext that is a fully -homomorphic encryption of a plaintext, the plaintext being representable as a vector of coefficients of a polynomial, and being associated with a plaintext modulus ak, the bootstrapping comprising: a) obtaining, from the first ciphertext, an encryption of data indicative of one or more coefficients of the plaintext; b) based on a bootstrapping key, performing one or more Torus-fully- homomorphic-encryption (TFHE) bootstrappings on the obtained encryption of data, the bootstrappings resulting in one or more bootstrap outputs; c) deriving, from the one or more bootstrap outputs, a series of one or more encrypted values, each value of the series being based on a coefficient of a respective term of a polynomial based on:Numerator coef fpt — -A — Cl wherein coeffpt denotes the data indicative of one or more coefficients of the plaintext; and d) creating, from, at least, a key-switching-key and the derived series of encrypted values, data indicative of a ring-based or module-based ciphertext, resulting in a second ciphertext that is an encryption, with reduced noise, of the data indicative of one or more coefficients of the plaintext; wherein a and k are integers and Numerator is a numerator.
2. The method of claim 1, the method additionally comprising: e) homomorphically right-shifting the first ciphertext, resulting in a ciphertext encrypting a shifted plaintext; and f) repeating a) -d) upon the ciphertext encrypting the shifted plaintext, resulting in an encryption, with reduced noise, of the data indicative of one or more coefficients of the shifted plaintext.
3. The method of claim 2, the method additionally comprising: g) repeating e) - f) for one or more additional iterations, resulting in a series of ciphertexts, the series comprising a respective ciphertext encrypting data indicative of each coefficient of the plaintext; and h) combining each ciphertext of the resulting series of ciphertexts, resulting in a bootstrapped first ciphertext.
4. The method of claim 3, wherein the Numerator is X1, wherein i is a count of rightshifts homomorphically performed on the first ciphertext, and wherein the combining is summation.
5. The method of claim 1, wherein a is 2.
6. The method of claim 1, wherein the obtaining the encryption of data indicative of one or more coefficients comprises performing sample extraction.
7. The method of claim 1, wherein each coefficient in the vector of coefficients is a multivariate polynomial.
8. The method of claim 1, wherein the encryption of the encrypted one or more coefficients is Brakerski-Fan-Vercauteren (BFV) encryption.
9. The method of claim 1, wherein each of the one or more Torus-fully- homomorphic-encryption (TFHE) bootstrappings is a programmable bootstrapping employing a function computing a product of an input with one or more elements of a gadget vector, the one or more programmable bootstrappings resulting in a plurality of bootstrap outputs, each of the plurality of bootstrap outputs being an encryption of a respective product of the data indicative of one or more coefficients by an element of the gadget vector.
10. The method of claim 9, wherein one or more TFHE bootstrappings is a single TFHE bootstrapping, and the employed function is a multi -output function outputting a vector of respective products of the data indicative of one or more coefficients by respective elements of the gadget vector.
11. The method of claim 1 , wherein the plaintext is an element of a first non- cyclotomic ring, and the first ciphertext is an element of a second non-cyclotomic ring, and wherein: the first non-cyclotomic ring is a quotient of: a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of: a. the third non-cyclotomic ring, andb. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first non-trivial ideal.
12. The method of claim 1, wherein the creating the ring -based or module-based ciphertext is based on a summation:IntermediateCiphertextjt■ kskj(where j is an index of a gadget vector, and IntermediateCiphertext is a j-th element of a corresponding gadget decomposition of a value encrypted in an 1-th encrypted value of the series of encrypted values, and ksk,.i is an encryption, under a target key, of a product of an 1-th coefficient of a secret key associated with the first ciphertext with a j-th element of the gadget vector.
13. The method of claim 12, wherein the creating the ring -based or module-based ciphertext further comprises multiplying the summation by (X-a).
14. A system comprising: a memory; and processing circuitry operatively coupled to the memory, the processing circuitry configured to perform bootstrapping a first ciphertext that is a fully -homomorphic encryption of a plaintext, the plaintext being representable as a vector of coefficients of a polynomial, and being associated with a plaintext modulus ak, wherein to perform the bootstrapping the processing circuitry is to: a) obtain, from the first ciphertext, an encryption of data indicative of one or more coefficients of the plaintext;b) based on a bootstrapping key, perform one or more Torus-fully- homomorphic-encryption (TFHE) bootstrappings on the obtained encryption of data, the bootstrappings resulting in one or more bootstrap outputs; c) derive, from the one or more bootstrap outputs, a series of one or more encrypted values, each value of the series being based on a coefficient of a respective term of a polynomial based on:Numerator coef fpt• — -A — Cl wherein coeffpt denotes the data indicative of one or more coefficients of the plaintext; and d) create, from, at least, a key-switching-key and the derived series of encrypted values, data indicative of a ring-based or module-based ciphertext, resulting in a second ciphertext that is an encryption, with reduced noise, of the data indicative of one or more coefficients of the plaintext; wherein a and k are integers and Numerator is a numerator.
15. A computer-program product comprising a computer-readable non -transitory storage medium containing program instructions which, when read by processing circuitry, cause the processing circuitry to perform a method comprising: bootstrapping a first ciphertext that is a fully -homomorphic encryption of a plaintext, the plaintext being representable as a vector of coefficients of a polynomial, and being associated with a plaintext modulus ak, the bootstrapping comprising: a) obtaining, from the first ciphertext, an encryption of data indicative of one or more coefficients of the plaintext;b) based on a bootstrapping key, performing one or more Torus-fully- homomorphic-encryption (TFHE) bootstrappings on the obtained encryption of data, the bootstrappings resulting in one or more bootstrap outputs; c) deriving, from the one or more bootstrap outputs, a series of one or more encrypted values, each value of the series being based on a coefficient of a respective term of a polynomial based on:Numerator coef fpt• — -A — Cl wherein coeffpt denotes the data indicative of one or more coefficients of the plaintext; and d) creating, from, at least, a key-switching-key and the derived series of encrypted values, data indicative of a ring-based or module-based ciphertext, resulting in a second ciphertext that is an encryption, with reduced noise, of the data indicative of one or more coefficients of the plaintext; wherein a and k are integers and Numerator is a numerator.
Citation Information
Patent Citations
Calculation of LWE cryptographic values
CN117643012A
Data processing method of ring surface fully homomorphic encryption algorithm based on integer bootstrap
CN117857008A
Homomorphic encryption method and associated devices and system
US20240064000A1
Cited By
A linear computation-based fully homomorphic encryption ciphertext transmission method and system
CN122247763A