IP Library › Granted Patent US 12,500,732
Granted Patent B2
US 12,500,732 · App. 18/152,313 · Granted Dec 16, 2025

Methods of operating on data in a fully homomorphic encryption system using in-situ processing-in-memory and related circuits

Inventors: Saransh Gupta (La Jolla, CA); Tajana Simunic Rosing (San Diego, CA)
Assignee: The Regents of the University of California
H04L9/008H04L9/0825H04L9/3026
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,732
App. No.
18/152,313
Granted
Dec 16, 2025
Kind
B2
Abstract

A method of operating on encrypted data can be performed by receiving ciphertexts at a server that is configured to operate on the ciphertexts generated using a 3 rd generation RGSW based fully homomorphic encryption system, operating on the ciphertexts received at the server in response to requested operations to generate respective input ciphertexts including ciphertext polynomials and ciphertext integers that are representative of the input ciphertexts, and processing the input ciphertexts in a server processing-in-memory device, that is operatively coupled to the server, to perform operations on the input ciphertext using the server processing-in-memory device, in-situ.

Claims (41)

1 . A method for fully homomorphic processing of ciphertexts, the method comprising:

receiving, at a computing platform that comprises a server operatively coupled to a processing-in-memory (PIM) device, one or more ciphertexts produced with a Ring-Gentry-Sahai-Waters (RGSW) based fully homomorphic encryption system that permits evaluation of arbitrary functions on encrypted data;

generating, from the ciphertexts, corresponding input ciphertexts, each input ciphertext including a ciphertext polynomial and a ciphertext integer;

processing the input ciphertexts entirely in-situ within the PIM device, wherein the processing includes performing bootstrapping operations in a pipelined architecture, and dynamically adjusting one or more bootstrapping parameters during the bootstrapping operations based on structural characteristics of the input ciphertexts, wherein the structural characteristics comprise at least one of a polynomial degree, a noise level, or a ciphertext modulus, and wherein the bootstrapping operations include executing stage-wise number-theoretic transform and inverse number-theoretic transform operations using an in-memory coefficient-row mapping architecture in which each stage operates on coefficient pairs resident in a common memory row and transfers intermediate results to a next stage through column-wise data movement internal to the PIM device; and

performing, on the input ciphertexts, at least one homomorphic operation, the at least one homomorphic operation comprising ciphertext addition, ciphertext multiplication, key switching, or modulus switching, wherein each input ciphertext remains in encrypted form within the PIM device during the at least one homomorphic operation.

2 . The method of claim 1 wherein bootstrapping includes:

bootstrapping the input ciphertext with an encrypted private key that is associated with the ciphertexts, to provide an output ciphertext having reduced noise compared to the input ciphertext.

3 . The method of claim 1 wherein bootstrapping further includes:

setting an initial value of an accumulator; and

decomposing polynomials of the input ciphertexts to be compatible with a refreshing key associated with the ciphertexts received at the server.

4 . The method of claim 3 wherein setting the initial value of the accumulator includes:

translating boolean functions into at least one homomorphic computation step to provide respective integer outputs; and

mapping the respective integer outputs to respective bootstrapping compatible polynomials using search based processing-in-memory operations.

5 . The method of claim 3 wherein decomposing the polynomials of the input ciphertexts includes:

decomposing the respective bootstrapping compatible polynomials to coefficients of the respective bootstrapping compatible polynomials.

6 . The method of claim 5 further comprising:

performing Number Theoretic Transform (NTT) transforms on the respective bootstrapping compatible polynomials to provide a frequency domain equivalent of the respective bootstrapping compatible polynomials.

7 . The method of claim 6 further comprising:

performing row-parallel multiplication between the frequency domain equivalent of the respective bootstrapping compatible polynomials and respective refreshing keys to provide respective portions of an N dimensional vector; and

adding the respective portions of an N dimensional vector to provide an accumulator pipeline output.

8 . The method of claim 7 further includes:

performing inverse NTT transforms on the accumulator pipeline output to generate an accumulator output.

9 . The method of claim 1 further comprising:

receiving unencrypted data at a client; and

encrypting the unencrypted data using the RGSW based fully homomorphic encryption system using a client processing-in-memory device, that is operatively coupled to the client, to perform operations on the unencrypted data by the client processing-in-memory device, in-situ.

10 . The method of claim 1 , wherein the fully homomorphic encryption system comprises a third-generation Ring-Gentry-Sahai-Waters (RGSW)-based system configured to support evaluation of arbitrary functions on encrypted data.

11 . The method of claim 1 , further comprising storing, in a plurality of local memory banks physically co-located with respective pipeline stages of the PIM device, digit-decomposed portions of a refreshing key.

12 . The method of claim 1 , wherein the bootstrapping operations further comprises:

performing, in row-parallel fashion, a signed-digit decomposition of the ciphertext polynomials;

executing stage-wise number-theoretic transform and inverse number-theoretic transform operations using an in-memory coefficient-row mapping architecture in which each stage operates on coefficient pairs resident in a common memory row and transfers intermediate results to a next stage through column-wise data movement internal to the PIM device.

13 . The method of claim 1 , wherein the one or more bootstrapping parameters includes at least one of decomposition base, decomposition depth, polynomial degree, modulus set, or pipeline stage width.

14 . The method of claim 1 , wherein the processing further includes selecting, for each bootstrapping operation, an accumulation path of either an algebraic-product (AP) type or a generalized-inverse-number-theoretic-transform (GINX) type, the selection being performed as a function of a statistical distribution of secret-key coefficients associated with the corresponding input ciphertext.

15 . The method of claim 1 , further comprising outputting, from the PIM device, encrypted output ciphertexts that encode respective results of the at least one homomorphic operation.

16 . A method for fully homomorphic processing of ciphertexts, the method comprising:

receiving, at a computing platform that comprises a server operatively coupled to a processing-in-memory (PIM) device, one or more ciphertexts produced with a Ring-Gentry-Sahai-Waters (RGSW) based fully homomorphic encryption system that permits evaluation of arbitrary functions on encrypted data;

generating, from the ciphertexts, corresponding input ciphertexts, each input ciphertext including a ciphertext polynomial and a ciphertext integer;

processing the input ciphertexts entirely in-situ within the PIM device, wherein the processing includes:

performing bootstrapping operations in a pipelined architecture,

selecting, for each bootstrapping operation, an accumulation path of at least one of an algebraic-product type or a generalized-inverse-number-theoretic-transform type, the selection being performed as a function of a statistical distribution of secret-key coefficients associated with a corresponding input ciphertext, and

dynamically adjusting one or more bootstrapping parameters during the bootstrapping operations based on structural characteristics of the input ciphertexts, wherein the structural characteristics comprise at least one of a polynomial degree, a noise level, or a ciphertext modulus; and

performing, on the input ciphertexts, at least one homomorphic operation, the at least one homomorphic operation comprising ciphertext addition, ciphertext multiplication, key switching, or modulus switching, wherein each input ciphertext remains in encrypted form within the PIM device during the at least one homomorphic operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: GUPTA, SARANSH; ROSING, TAJANA SIMUNIC
To: THE REGENTS OF THE UNIVERSITY OF CALIFORNIA
Reel/Frame 062653/0565 →
Continuity (2)
Provisional Application 63297910 · Jan 10, 2022
Related Publication 20230291541A1 · Sep 14, 2023
References Cited (15)
US 10778408B1 · Khedr · 2020 [cited by examiner]
US 11032061B2 · Chen · 2021 [cited by examiner]
US 11196539B2 · Lauter · 2021 [cited by examiner]
US 11476854B2 · Wang · 2022 [cited by examiner]
US 20190334694A1 · Chen · 2019 [cited by examiner]
US 20200403781A1 · Gentry · 2020 [cited by examiner]
US 20220116198A1 · Na · 2022 [cited by examiner]
US 20220366059A1 · Sasidharan Rajalekshmi · 2022 [cited by examiner]
US 20220376890A1 · Eom · 2022 [cited by examiner]
Nejatollahi, CryptoPIM: In-memory Acceleration for Lattice-based Cryptographic Hardware, Oct. 9, 2020 (Year: 2020). [cited by examiner]
Micciancio, Daniele, et al.; Bootstrapping in FHEW-like Cryptosystems; WAHC '21, Virtual Event, Republic of Korea; Nov. 15, 2021; pp. 17-28. [cited by applicant]
Zhou, Junwei, et al.; Deep Binarized Convolutional Neural Network Inferences over Encrypted Data; 2020 7th IEEE International Conference on Cyber Security and Cloud Computing (CSCloud)/2020 6th IEEE International Confer… [cited by applicant]
Micciancio, Daniele, et al.; Bootstrapping in FHEW-like Cryptosystems; Duality Technologies; Jan. 28, 2020; pp. 1-22. [cited by applicant]
Lou, Quian, et al.; SHE: A Fast and Accurate Deep Neural Network for Encrypted Data; 33rd Conference on Neural Information Processing Systems (NeurIPS 2019); Dec. 2019; Vancouver, Canada; pp. 1-9. [cited by applicant]
Guimaraes, Antonio, et al.; Revisiting the functional bootstrap in TFHE; Research Gate; Feb. 2021; 26 pages. [cited by applicant]