首页> 外文会议>International coference on provable security >Bootstrapping Fully Homomorphic Encryption with Ring Plaintexts Within Polynomial Noise
【24h】

Bootstrapping Fully Homomorphic Encryption with Ring Plaintexts Within Polynomial Noise

机译:在多项式噪声内以环纯文本自​​举全同态加密

获取原文

摘要

Despite a great deal of progress in resent years, efficiency of fully homomorphic encryption (FHE) is still a major concern. Specifically, the bootstrapping procedure is the most costly part of a FHE scheme. FHE schemes with ring element plaintexts, such as the ring-LWE based BGV scheme, are the most efficient ones, since they can not only encrypt a ring element instead of a single bit in one ciphertext, but also support CRT-based ciphertext packing techniques. Thanks to homomorphic operations in a SIMD fashion (Single Instruction Multiple Data), the ring-LWE BGV scheme can achieve a nearly optimal homomorphic evaluation. However, the BGV scheme, as implemented in HElib, can only bootstrap within super-polynomial noise so far. Note that such a noise rate for a ring-LWE based scheme is less safe and more costly, because one has to choose larger dimensions to ensure security. On the other hand, existing polynomial noise bootstrapping techniques can only be applied to FHE schemes with bit plaintexts. In this paper, we provide a polynomial noise bootstrapping method for the BGV scheme with ring plaintexts. Specifically, our bootstrapping method allows users to choose any plaintext modulus p > 1 and any modulus polynomial (X) for the BGV scheme. Our bootstrapping method incurs only polynomial error O(n~3) · B for lattice dimension n and noise bound B comparing to (B · poly(n))~(O(log(n))) for previous best methods. Concretely, to achieve 70 bit security, the dimension of the lattice that we use is no more than 2~(12), while previous methods in HElib need about 2~(14) to 2~(16).
机译:尽管最近几年取得了很大进展,但是完全同态加密(FHE)的效率仍然是一个主要问题。具体而言,自举过程是FHE计划中最昂贵的部分。具有环元素纯文本的FHE方案(例如基于环LWE的BGV方案)是最有效的方案,因为它们不仅可以加密环元素而不是一个密文中的单个比特,而且还支持基于CRT的密文打包技术。由于采用SIMD方式(单指令多数据)的同态运算,ring-LWE BGV方案可以实现几乎最佳的同态评估。但是,到目前为止,在HElib中实现的BGV方案只能在超多项式噪声内进行引导。注意,对于基于环LWE的方案,这样的噪声速率不太安全,而且成本更高,因为必须选择更大的尺寸来确保安全性。另一方面,现有的多项式噪声自举技术只能应用于具有位明文的FHE方案。在本文中,我们为具有环形明文的BGV方案提供了多项式噪声自举方法。具体来说,我们的自举方法允许用户为BGV方案选择任何明文模数p> 1和任何模数多项式(X)。与以前的最佳方法相比,我们的自举方法对于晶格尺寸n和噪声边界B仅产生多项式误差O(n〜3)·B,而噪声界B则不会。具体而言,要实现70位安全性,我们使用的晶格尺寸不超过2〜(12),而HElib中的先前方法大约需要2〜(14)至2〜(16)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号