Polynomial Ring Vector Inner Product Circuit Using NTT and Hadamard Transform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The computation of inner products between polynomial ring vectors, which are used in fully homomorphic encryption, becomes increasingly complex and time-consuming as the size of the vectors grows, necessitating an efficient computational technique.

Innovation Solution

A polynomial ring vector inner product computation circuit is designed to compute the inner product between two polynomial ring vectors by utilizing a number theoretic transform processing circuit, an Hadamard inner product computation circuit, an inverse number theoretic transform processing circuit, and an inner product output circuit, thereby accelerating the computation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the size of polynomial ring vectors is increased to enhance security and functionality in fully homomorphic encryption, then the computational complexity and time required for inner product computations increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the inner product computation into three distinct stages: (1) Number Theoretic Transform (NTT) to convert time-domain polynomial ring vectors to frequency-domain representations, (2) Hadamard product computation in the frequency domain, and (3) Inverse NTT to transform back to time domain. This segmentation reduces the computational complexity from O(N²) to O(N log N) by leveraging the properties of transform domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces frequency-domain representations as an intermediary step between the input polynomial ring vectors and the final inner product result. By transforming vectors into the frequency domain, performing element-wise multiplication (Hadamard product), and then transforming back, the system achieves efficient computation while maintaining the mathematical properties required for secure homomorphic encryption operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the size of polynomial ring vectors is increased to enhance security and functionality in fully homomorphic encryption, then the time required for computation increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomputation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The computation is divided into three parallelizable stages: NTT transformation, Hadamard product calculation, and inverse NTT transformation. Each stage can be independently optimized and executed, reducing overall computation time while handling large vector sizes required for cryptographic security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces direct time-domain polynomial multiplication (which would require O(N²) operations) with a transform-based approach using NTT and Hadamard products. This substitution leverages the convolution theorem, replacing complex mechanical multiplication operations with simpler element-wise operations in the frequency domain, thereby reducing computation time from O(N²) to O(N log N).

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250123803A1Polynomial ring vector inner product computation circuit, computation processing circuit, and control method
Publication Date: 2025.04.17 KIOXIA CORP
  • US20250123803A1 patent drawing
  • US20250123803A1 patent drawing
  • US20250123803A1 patent drawing

AI summary

According to one embodiment, the polynomial ring vector inner product computation circuit computes an inner product between a first frequency domain polynomial ring vector and a second frequency domain polynomial ring vector, based on the first frequency domain polynomial ring vector obtained by preliminarily executing a process of multiplying each of one or more constant polynomials by 1/N and a process of applying the number theoretic transform to each of the one or more constant polynomials, and outputs a time domain polynomial obtained by applying inverse number theoretic transform to the computed inner product as an inner product between a first polynomial ring vector and a second polynomial ring vector.