Homomorphic Encryption Error Cancellation via Set Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fully Homomorphic Encryption (FHE) schemes face challenges in managing errors introduced during arithmetic operations on encrypted data, particularly with multiplication operations, which can significantly degrade performance and require constraining operations or additional error-removal methods.

Innovation Solution

Employing a set-system with specific intersection properties and a covering vector family, where vectors' inner product equals a multiple of a non-prime integer, to cancel out errors during evaluation, allowing for unbounded arithmetic operations without constraining the number or type of operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional FHE schemes perform multiplication operations on encrypted data, then arithmetic computation capability is improved, but error accumulation significantly degrades performance

Engineering Contradiction:
Improvearithmetic computation capabilityVSAvoiderror accumulation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent converts the harmful error accumulation into a beneficial feature by designing the encryption scheme such that errors naturally cancel out during multiplication operations. The error terms in the ciphertext multiplication expand to include cross-terms that, due to the specific algebraic structure and choice of parameters, sum to zero or negligible values, thereby transforming the harmful effect of error propagation into a self-correcting mechanism that enables unbounded computation without requiring additional error removal steps

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If error-removal operations are implemented in traditional FHE, then error accumulation is reduced, but computational overhead and complexity increase

Engineering Contradiction:
Improveerror controlVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption scheme is designed to be self-correcting, where the mathematical structure of the ciphertext and the error terms inherently provide error cancellation during multiplication operations. The system serves its own error correction needs through the algebraic properties of the underlying lattice-based cryptography, eliminating the requirement for external error removal operations and their associated computational overhead

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If unbounded arithmetic operations are enabled, then computational versatility is improved, but error management becomes intractable

Engineering Contradiction:
Improvecomputational versatilityVSAvoiderror management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs specific parameter choices in the lattice-based encryption scheme, including the modulus q, the error distribution parameters, and the dimensions of the underlying lattice, that ensure error terms remain bounded and cancel out during multiplication. These parameter configurations enable the system to handle unbounded sequences of arithmetic operations while maintaining tractable error management through the inherent mathematical properties of the chosen parameters

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11522672B2Fully homomorphic encryption from error canceling set systems
Publication Date: 2022.12.06 SEAGATE TECH LLC
  • US11522672B2 patent drawing
  • US11522672B2 patent drawing
  • US11522672B2 patent drawing

AI summary

A homomorphic encryption system evaluates homomorphically encrypted data, including receiving ciphertext input homomorphically encrypted from a plaintext input using a set-system including sets having an intersection property. An arithmetic function is evaluated on the ciphertext input to generate a ciphertext output, the arithmetic function including one or more additive gates and one or more multiplicative gates, wherein the evaluating operation generates errors during evaluation of the arithmetic function and the intersection property of the sets cancel out the errors during the evaluating operation. The ciphertext output is transmitted for homomorphic decryption to generate a plaintext result.