欢迎来到天天文库
浏览记录
ID:41210662
大小:387.28 KB
页数:13页
时间:2019-08-18
《Optimization of Fully Homomorphic Encryption》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、OptimizationofFullyHomomorphicEncryptionJean-SebastienCoron1,DavidNaccache2,andMehdiTibouchi1;21UniversiteduLuxembourg6,rueRichardCoudenhove-Kalergil-1359Luxembourg,Luxembourgjean-sebastien.coron@uni.lu2EcolenormalesuperieureDepartementd'informatique,G
2、roupedecryptographie45,rued'Ulm,f-75230ParisCedex05,Francefdavid.naccache,mehdi.tibouchig@ens.frAbstract.Wedescribeacompressiontechniquethatreducesthepublic-keysizeofthevanDijketal.6:55fullyhomomorphicschemeovertheintegersfromO~()toO~().Ourvariantremainss
3、emanticallysecure,butintherandomoraclemodel.Weobtainanimplementationofthefullschemewithapublic-keysizeof4:6MBinsteadof802MBusingthesameparametersandwiththesameeciencyasin[3].AsimilarcompressiontechniqueisalsoapplicabletoBrakerskiandVaikuntanathan'sfullyhom
4、omorphicscheme.WealsoshowhowtoadaptthenewframeworkfromBrakerski,GentryandVaikuntanathanforleveledfullyhomomorphicencryptiontothevanDijketal.schemeovertheintegers.1IntroductionFullyHomomorphicEncryption.Anencryptionschemeissaidtobefullyhomomorphicwhenitispos
5、sibletoperformimplicitadditionandmultiplicationofplaintextwhilemanipulatingonlyciphertexts.TherstconstructionofafullyhomomorphicschemewasdescribedbyGentryin[5].Gentryrstdescribedasomewhathomomorphic"schemethatsupportsalimitednumberofadditionsandmultiplic
6、ationsonciphertexts.Thisisbecausetheciphertextnoiseincreaseswitheverymultiplicationandmustremainupper-bounded;thereforeonlyapolynomialofsmalldegreecanbeappliedonciphertexts.ThesecondstepinGentry'sframeworkconsistsinsquashing"thedecryptionproceduresothatitc
7、anbeexpressedasalowdegreepolynomialinthebitsoftheciphertextandthesecretkey.ThenGentry'skeyideaconsistsinevaluatingthisdecryptionpolynomialnotonthebitsoftheciphertextandthesecret-key(whichwouldgivetheplaintext),buthomomorphicallyontheencryptionofthosebits,wh
8、ichgivesanotherciphertextforthesameplaintext.Ifthedegreeofthedecryptionpolynomialissmallenough,thenoiseofthenewciphertextcanbeactuallysmallerthanintheoriginalciphertext,andthereforethisnewciphertextcan
此文档下载收益归作者所有