Practical Bootstrapping in Quasilinear Time

نویسندگان

  • Jacob Alperin-Sheriff
  • Chris Peikert
چکیده

Gentry’s “bootstrapping” technique (STOC 2009) constructs a fully homomorphic encryption (FHE) scheme from a “somewhat homomorphic” one that is powerful enough to evaluate its own decryption function. To date, it remains the only known way of obtaining unbounded FHE. Unfortunately, bootstrapping is computationally very expensive, despite the great deal of effort that has been spent on improving its efficiency. The current state of the art, due to Gentry, Halevi, and Smart (PKC 2012), is able to bootstrap “packed” ciphertexts (which encrypt up to a linear number of bits) in time only quasilinear Õ(λ) = λ · log λ in the security parameter. While this performance is asymptotically optimal up to logarithmic factors, the practical import is less clear: the procedure composes multiple layers of expensive and complex operations, to the point where it appears very difficult to implement, and its concrete runtime appears worse than those of prior methods (all of which have quadratic or larger asymptotic runtimes). In this work we give simple, practical, and entirely algebraic algorithms for bootstrapping in quasilinear time, for both “packed” and “non-packed” ciphertexts. Our methods are easy to implement (especially in the non-packed case), and we believe that they will be substantially more efficient in practice than all prior realizations of bootstrapping. One of our main techniques is a substantial enhancement of the “ring-switching” procedure of Gentry et al. (SCN 2012), which we extend to support switching between two rings where neither is a subring of the other. Using this procedure, we give a natural method for homomorphically evaluating a broad class of structured linear transformations, including one that lets us evaluate the decryption function efficiently. ∗School of Computer Science, College of Computing, Georgia Institute of Technology. Email: [email protected] †School of Computer Science, Georgia Institute of Technology. Email: [email protected]. This material is based upon work supported by the National Science Foundation under CAREER Award CCF-1054495, by the Alfred P. Sloan Foundation, and by the Defense Advanced Research Projects Agency (DARPA) and the Air Force Research Laboratory (AFRL) under Contract No. FA8750-11-C-0098. The views expressed are those of the authors and do not necessarily reflect the official policy or position of the National Science Foundation, the Sloan Foundation, DARPA or the U.S. Government.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Quasilinear Schrödinger equations involving critical exponents in $mathbb{textbf{R}}^2$

‎We study the existence of soliton solutions for a class of‎ ‎quasilinear elliptic equation in $mathbb{textbf{R}}^2$ with critical exponential growth‎. ‎This model has been proposed in the self-channeling of a‎ ‎high-power ultra short laser in matter‎.

متن کامل

Better Bootstrapping in Fully Homomorphic Encryption

Gentry’s bootstrapping technique is currently the only known method of obtaining a “pure” fully homomorphic encryption (FHE) schemes, and it may offers performance advantages even in cases that do not require pure FHE (such as when using the new noise-control technique of Brakerski-GentryVaikuntanathan). The main bottleneck in bootstrapping is the need to evaluate homomorphically the reduction ...

متن کامل

ON QUASILINEAR ELLIPTIC SYSTEMS INVOLVING MULTIPLE CRITICAL EXPONENTS

In this paper, we consider the existence of a non-trivial weaksolution to a quasilinear elliptic system involving critical Hardyexponents. The main issue of the paper is to understand thebehavior of these Palais-Smale sequences. Indeed, the principaldifficulty here is that there is an asymptotic competition betweenthe energy functional carried by the critical nonlinearities. Thenby the variatio...

متن کامل

Global existence‎, ‎stability results and compact invariant sets‎ ‎for a quasilinear nonlocal wave equation on $mathbb{R}^{N}$

We discuss the asymptotic behaviour of solutions for the nonlocal quasilinear hyperbolic problem of Kirchhoff Type [ u_{tt}-phi (x)||nabla u(t)||^{2}Delta u+delta u_{t}=|u|^{a}u,, x in mathbb{R}^{N} ,,tgeq 0;,]with initial conditions $u(x,0) = u_0 (x)$ and $u_t(x,0) = u_1 (x)$, in the case where $N geq 3, ; delta geq 0$ and $(phi (x))^{-1} =g (x)$  is a positive function lying in $L^{N/2}(mathb...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2013  شماره 

صفحات  -

تاریخ انتشار 2013