IP Library › Granted Patent US 12,619,745
Granted Patent B2
US 12,619,745 · App. 18/396,342 · Granted May 5, 2026

Homomorphic operation system and operating method thereof

Inventors: Hanbyeul Na (Suwon-si, KR); Sangpyo Kim (Seoul, KR); Jongmin Kim (Seoul, KR); Jung Ho Ahn (Seoul, KR); Dong-Min Shin (Suwon-si, KR)
Assignees: SAMSUNG ELECTRONICS CO., LTD.; SEOUL NATIONAL UNIVERSITY R&DB FOUNDATION
G06F21/602G06F5/06G06F7/523G06F21/78
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,745
App. No.
18/396,342
Granted
May 5, 2026
Kind
B2
Abstract

A homomorphic operation system according to an embodiment includes a homomorphic encryption device configured to output a first ciphertext data generated based on a first base, a homomorphic encryption server including a storage device storing base conversion table configured to convert ciphertext data based on the first base into a second ciphertext data based on a second base and the first ciphertext data received from the homomorphic encryption device, and a homomorphic encryption operation device configured to perform a predetermined operation using the base conversion table on the first ciphertext data to convert the first ciphertext data into the second ciphertext data based on the second base.

Claims (71)

1 . A homomorphic operation system, comprising:

a homomorphic encryption device outputting a first ciphertext data generated based on a first base; and

a homomorphic encryption server comprising a storage device storing a base conversion table for converting ciphertext data based on the first base into a ciphertext data based on a second base and the first ciphertext data received from the homomorphic encryption device, and

a homomorphic encryption operation device performing a predetermined operation using the base conversion table on the first ciphertext data to convert the first ciphertext data into a second ciphertext data based on the second base.

2 . The homomorphic operation system of claim 1 , wherein:

the first ciphertext data includes a plurality of coefficients,

the homomorphic encryption operation device comprises:

a plurality of lanes receiving the plurality of coefficients, performing multiply and accumulate (MAC) operations to generate a plurality of accumulated output values, and performing modulo operations for each of the plurality of the accumulated output values to generate result values corresponding to the coefficients of the second ciphertext data;

a plurality of broadcasting units supplying a base conversion value corresponding to each of the plurality of coefficients of the first ciphertext data based on the base conversion table; and

a homomorphic operation manage circuit setting operation periods of the plurality of broadcasting units.

3 . The homomorphic operation system of claim 2 , wherein:

the homomorphic operation manage circuit determines the plurality of coefficients corresponding to each of the plurality of lanes according to a predetermined method,

each of the plurality of lanes includes a plurality of MAC units, a first lane of the plurality of lanes receives a first coefficient of the plurality of coefficients, and a first MAC unit of the plurality of MAC units of the first lane perform a MAC operation on a first element value in the first coefficient including a plurality of element values and a first base conversion value corresponding to the first MAC unit among the base conversion table, to generate a first accumulated output value among the plurality of accumulated output values.

4 . The homomorphic operation system of claim 3 , wherein:

the number of MAC units in the first lane and the number of the plurality of broadcasting units are the same.

5 . The homomorphic operation system of claim 3 , wherein:

the first lane comprises:

a multiplexer that receives a plurality of accumulated output values from each of a plurality of MAC units in the first lane, and selects one of the plurality of accumulated output values by the homomorphic operation manage circuit; and

a modular operation device coupled to the multiplexer to perform a modular operation on each of the plurality of accumulated output values.

6 . The homomorphic operation system of claim 5 , wherein:

the first MAC unit comprises:

a plurality of input buffers sequentially receiving and storing a plurality of element values in the first coefficient from the storage device;

a broadcasting buffer receiving the first base conversion value corresponding to the first MAC unit from the broadcasting unit; and

a multiplier coupled to the plurality of input buffers and the broadcasting buffer to generate a multiplication value by multiplying the plurality of element values and the first base conversion value.

7 . The homomorphic operation system of claim 6 , wherein:

the multiplication value includes a first multiplication value obtained by multiplying the first element value among a plurality of element values in the first coefficient and the first base conversion value, and the multiplier generates a second multiplication value by multiplying a second element value among the plurality of element values and the first base conversion value,

the first MAC unit further comprises:

a plurality of output buffers storing multiplication values from the multiplier; and

an adder connected to the plurality of output buffers and the multiplier, and generating a third addition value by adding the first multiplication value and the second multiplication value.

8 . The homomorphic operation system of claim 7 , wherein:

the first MAC unit further comprises a demultiplexer connected to the adder and transferring the third addition value to the output buffer or the multiplexer under control of the homomorphic operation manage circuit.

9 . The homomorphic operation system of claim 7 , wherein:

a second MAC unit of the plurality of MAC units receives the first coefficient from the input buffer of the first MAC unit,

the second MAC unit performs a MAC operation on the second base conversion value corresponding to the second MAC unit among the base conversion table and the second element value in the first coefficient.

10 . The homomorphic operation system of claim 7 , wherein:

the homomorphic operation manage circuit sets an operation period of the broadcasting unit based on the number of the plurality of input buffers and the number of the plurality of output buffers.

11 . The homomorphic operation system of claim 7 , wherein:

the broadcasting unit updates the base conversion value based on the operation period.

12 . The homomorphic operation system of claim 11 , wherein:

the first accumulated output value is a value obtained by adding all values obtained by multiplying each of a plurality of element values in the first coefficient by the first base conversion value.

13 . An operating method of a homomorphic operation system, comprising:

receiving a first ciphertext data generated based on a first base; and

performing a predetermined operation to convert the first ciphertext data into a second ciphertext data based on a second base, based on a base conversion table for converting ciphertext data based on the first base into ciphertext data based on the second base, the predetermined operation comprising multiply-accumulate operations using base conversion values from a base conversion table and modulo operations to generate coefficients of the second ciphertext data, the base conversion table comprising numerical values for mathematical base conversion of ciphertext coefficients.

14 . The operating method of the homomorphic operation system of claim 13 , wherein:

the first ciphertext data comprises a plurality of coefficients,

the performing of the predetermined operation comprises:

generating a plurality of accumulated outputs by performing a MAC operation on a base conversion value corresponding to each of the plurality of coefficients of the first ciphertext data among the base conversion table and the plurality of coefficients; and

generating a result value corresponding to the coefficient of the second ciphertext data by performing a modular operation on each of the plurality of accumulated output values.

15 . The operating method of the homomorphic operation system of claim 14 , wherein:

the generating of the plurality of accumulated output values comprises

generating a first accumulated output value among the plurality of accumulated output values, by a first MAC unit among a plurality of MAC units, by performing a MAC operation on a plurality of elements in a first coefficient among the plurality of coefficients and a first base conversion value corresponding to the first MAC unit in the base conversion table.

16 . The operating method of the homomorphic operation system of claim 15 , wherein:

the generating of the plurality of accumulated output values further comprises:

receiving the first coefficient from the first MAC unit, by a second MAC unit among the plurality of MAC units; and

generating a second accumulated output value among the plurality of accumulated output values by performing a MAC operation on a plurality of elements in the first coefficient and a second base conversion value corresponding to the second MAC unit in the base conversion table, by the second MAC.

17 . The operating method of the homomorphic operation system of claim 16 , wherein:

the generating the second accumulated output value is performed after a predetermined operation period after the generating the first accumulated output value.

18 . The operating method of the homomorphic operation system of claim 17 , wherein:

the generating the first accumulated output value and the receiving the first coefficient are performed simultaneously.

19 . A homomorphic operation accelerator, comprising:

a first MAC unit comprising:

a plurality of first input buffers receiving and storing a first coefficient of a plurality of coefficients from a storage device in which a first ciphertext data generated based on a first base and including a plurality of coefficients is stored,

a first broadcasting buffer storing a first base conversion value among a base conversion table for converting data based on the first base into a second base, and

a first multiplier connected to the plurality of first input buffers and the first broadcasting buffer generating a first multiplication value by multiplying the first coefficient and the first base conversion value; and

a modulo operation device coupled to the first MAC unit, wherein the modulo operation device is performing a modulo operation on the first multiplication value.

20 . The homomorphic operation accelerator of claim 19 , further comprising:

a second MAC unit comprising:

a plurality of second input buffers connected to the plurality of first input buffers of the first MAC unit to receive and store the first coefficient from the first MAC unit,

a second broadcasting buffer storing a second base conversion value among the base conversion table, and

a second multiplier connected to the plurality of second input buffers and the second broadcasting buffer, and generating a second multiplication value by multiplying the first coefficient and the second base conversion value,

wherein the modulo operation device is coupled to the second MAC unit, wherein the modulo operation device is performing a modulo operation on the second multiplication value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 26, 2023
From: NA, HANBYEUL; KIM, SANGPYO; KIM, JONGMIN; AHN, JUNG HO; SHIN, DONG-MIN
To: SAMSUNG ELECTRONICS CO., LTD.; SEOUL NATIONAL UNIVERSITY R&DB FOUNDATION
Reel/Frame 065955/0060 →
Priority Claims (2)
KR 10-2023-0055429 · Apr 27, 2023 · national
KR 10-2023-0080427 · Jun 22, 2023 · national
Continuity (1)
Related Publication 20240362343A1 · Oct 31, 2024
References Cited (22)
US 7343389B2 · Macy et al. · 2008 [cited by applicant]
US 9996499B2 · Suvakovic et al. · 2018 [cited by applicant]
US 10797858B2 · Suresh et al. · 2020 [cited by applicant]
US 20030212727A1 · Macy et al. · 2003 [cited by applicant]
US 20060033608A1 · Juels · 2006 [cited by examiner]
US 20070198901A1 · Ramchandran et al. · 2007 [cited by applicant]
US 20090319804A1 · Qi et al. · 2009 [cited by applicant]
US 20120079236A1 · Suvakovic et al. · 2012 [cited by applicant]
US 20150270957A1 · Uzun · 2015 [cited by examiner]
US 20190245679A1 · Suresh et al. · 2019 [cited by applicant]
US 20200313856A1 · Basu · 2020 [cited by examiner]
US 20210377016A1 · Perlman · 2021 [cited by examiner]
US 20220286282A1 · Jeljeli · 2022 [cited by examiner]
US 20220329414A1 · Gaddam · 2022 [cited by examiner]
US 20230081763A1 · Boemer et al. · 2023 [cited by applicant]
US 20240195618A1 · Paul · 2024 [cited by examiner]
JP 2005043637 · 2005 [cited by applicant]
KR 101753467 · 2017 [cited by applicant]
Kim, et al., “ARK: Fully Homomorphic Encryption Accelerator with Runtime Data Generation and Inter-Operation Key Reuse”, arXiv preprint arXiv:2205.00922v1 [cs.CR] May 2, 2022, pp. 1-14. [cited by applicant]
Feldmann, et al., “F1: A Fast and Programmable Accelerator for Fully Homomorphic Encryption”, in MICRO, 2021, https://doi.org/10.1145/3466752.3480070, pp. 238-252. [cited by applicant]
Kim, et al., “BTS: An Accelerator for Bootstrappable Fully Homomorphic Encryption”, in ISCA, 2022, arXiv preprint arXiv:2112.15479v2 [cs.CR] Apr. 29, 2022, https://doi.org/10.1145/3470496.3527415, 15 pages. [cited by applicant]
Samardzic, et al., “CraterLake: A Hardware Accelerator for Efficient Unbounded Computation on Encrypted Data”, in ISCA, 2022, https://doi.org/10.1145/3470496.3527393, pp. 173-187. [cited by applicant]