Fully Homomorphic Encryption without Modulus Switching from Classical GapSVP

被引:698
作者
Brakerski, Zvika [1 ]
机构
[1] Stanford Univ, Stanford, CA 94305 USA
来源
ADVANCES IN CRYPTOLOGY - CRYPTO 2012 | 2012年 / 7417卷
关键词
KEY;
D O I
10.1007/978-3-642-32009-5_50
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We present a new tensoring technique for LWE-based fully homomorphic encryption. While in all previous works, the ciphertext noise grows quadratically (B -> B-2 . poly(n)) with every multiplication (before "refreshing"), our noise only grows linearly (B -> B . poly(n)). We use this technique to construct a scale-invariant fully homomorphic encryption scheme, whose properties only depend on the ratio between the modulus q and the initial noise level B, and not on their absolute values. Our scheme has a number of advantages over previous candidates: It uses the same modulus throughout the evaluation process (no need for "modulus switching"), and this modulus can take arbitrary form. In addition, security can be classically reduced from the worst-case hardness of the GapSVP problem (with quasi-polynomial approximation factor), whereas previous constructions could only exhibit a quantum reduction from GapSVP.
引用
收藏
页码:868 / 886
页数:19
相关论文
共 21 条
[1]  
Ajtai Miklos, 1997, P 29 ANN ACM S THEOR, P284, DOI [DOI 10.1145/258533.258604, 10.1145/258533.258604]
[2]  
[Anonymous], LNCS
[3]  
[Anonymous], 2012, ITCS 2012
[4]  
[Anonymous], 2011, IACR CRYPTOLOGY EPRI
[5]  
[Anonymous], 1978, FDN SEC COMPUT
[6]  
Applebaum B, 2009, LECT NOTES COMPUT SC, V5677, P595, DOI 10.1007/978-3-642-03356-8_35
[7]  
Brakerski Z, 2011, LECT NOTES COMPUT SC, V6841, P505, DOI 10.1007/978-3-642-22792-9_29
[8]  
Gentry C., 2009, FULLY HOMOMORPHIC EN, V20
[9]  
Gentry C, 2008, ACM S THEORY COMPUT, P197
[10]   Fully Homomorphic Encryption Using Ideal Lattices [J].
Gentry, Craig .
STOC'09: PROCEEDINGS OF THE 2009 ACM SYMPOSIUM ON THEORY OF COMPUTING, 2009, :169-178