IP Library Granted Patent US 12,425,182
Granted Patent B2
US 12,425,182 · App. 18/524,573 · Granted Sep 23, 2025

Apparatus and method with homomorphic encryption

Inventors: Rakyong Choi (Suwon-si, KR); Andrey Kim (Suwon-si, KR); Yongwoo Lee (Suwon-si, KR); Maksim Deriabin (Suwon-si, KR); Jieun Eom (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
H04L9/008H04L9/3093
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,182
App. No.
18/524,573
Granted
Sep 23, 2025
Kind
B2
Abstract

An apparatus and method with homomorphic encryption are provided. A method for performing a homomorphic encryption operation may include generating a second ciphertext, having a second total number of dimensions, by performing a key switching operation using a key-switching key to generate the second ciphertext, encrypted by a second secret key, based on a homomorphic encrypted first ciphertext on a first modulus encrypted by a first secret key, where the first ciphertext has a first total number of dimensions, and generating a ciphertext on a second modulus by performing a blind rotation operation based on the second ciphertext and an operation key.

Claims (50)

1. A processor-implemented method for performing a homomorphic encryption operation, the method comprising:

generating a second ciphertext, having a second total number of dimensions, by performing a key switching operation using a key-switching key to generate the second ciphertext, encrypted by a second secret key, based on a homomorphic encrypted first ciphertext on a first modulus encrypted by a first secret key, where the first ciphertext has a first total number of dimensions; and

generating a ciphertext on a second modulus by performing a blind rotation operation based on the second ciphertext and an operation key.

2. The method of claim 1 , wherein the second total number of dimensions is less than the first total number of dimensions, and the second modulus is greater than the first modulus.

3. The method of claim 1 , wherein the key-switching key is based on a scaled up version of the first secret key.

4. The method of claim 3 , wherein the performing of the blind rotation operation comprises:

generating a result of a summation of respective products of each element of the second ciphertext and the operation key; and

generating a result of a product of the result of the summation and an initial function that is determined based on the key-switching key.

5. The method of claim 1 , wherein the key switching key is based on a scaled up error corresponding to the key switching operation.

6. The method of claim 1 , wherein the second secret key is a sub-vector of the first secret key.

7. The method of claim 1 , further comprising receiving the key-switching key, the operation key which is dependent on the second secret key, and a ring learning with errors (RLWE) ciphertext as the first ciphertext,

wherein the RLWE ciphertext corresponds to the RLWE ciphertext having been generated from data set for performing a homomorphic encryption operation.

8. The method of claim 7 ,

wherein the second ciphertext is a second learning with errors (LWE) ciphertext,

wherein the method further comprises:

performing a homomorphic rounding operation on the RLWE ciphertext; and

generating a first LWE ciphertext having the first total number of dimensions based on a result of the homomorphic rounding operation, and

wherein the generating of the second ciphertext comprises generating the second ciphertext by performing the key switching operation on the first LWE ciphertext.

9. The method of claim 8 ,

wherein the ciphertext on the second modulus is a RLWE ciphertext, and

wherein the second modulus is greater than the first modulus.

10. A non-transitory computer-readable storage medium storing instructions that, when executed by a processor, configure the processor to perform the method of claim 1 .

11. A processor-implemented method for homomorphic encryption, the method comprising:

receiving a first secret key of a first ciphertext having a first total number of dimensions and a second secret key for a second ciphertext having a second total number of dimensions less than the first total number of dimensions;

generating a key-switching key configured to generate the second ciphertext based on the first ciphertext and the first secret key;

generating an operation key, based on the second secret key, configured to generate bootstrapping blind rotation results with respect to a homomorphic encryption operation that is dependent on the key-switching key; and

outputting the key-switching key and the operation key.

12. The method of claim 11 , wherein the generating of the key-switching key comprises:

scaling up the first secret key; and

generating the key-switching key based on the scaled up first secret key.

13. The method of claim 11 , wherein the generating of the key-switching key comprises:

scaling up an error used corresponding to a use of the key-switching key to perform a key-switching operation; and

generating the key-switching key based on the scaled up error.

14. An apparatus, the apparatus comprising:

a processor configured to:

generate a second ciphertext, having a second total number of dimensions, through performance of a key switching operation that uses a key-switching key to generate the second ciphertext, encrypted by a second secret key, based on a homomorphic encrypted first ciphertext on a first modulus encrypted by a first secret key, where the first ciphertext has a first total number of dimensions; and

generate a ciphertext on a second modulus by performing a blind rotation operation based on the second ciphertext and an operation key.

15. The apparatus of claim 14 , wherein the second total number of dimensions is less than the first total number of dimensions, and the second modulus is greater than the first modulus.

16. The apparatus of claim 14 , wherein the key-switching key is based on a scaled up version of the first secret key.

17. The apparatus of claim 16 , wherein, for the performing of the blind rotation operation, the processor is further configured to:

generate a result of a summation of respective products of each element of the second ciphertext and the operation key; and

generate a result of a product of the result of the summation and an initial function that is determined based on the key-switching key.

18. The apparatus of claim 14 , wherein the key switching key is based on a scaled up error corresponding to the key switching operation.

19. The apparatus of claim 14 , wherein the second secret key is a sub-vector of the first secret key.

20. The apparatus of claim 14 , further comprising a receiver to receive the key-switching key, the operation key which is dependent on the second secret key, and a ring learning with errors (RLWE) ciphertext on the first modulus as the first ciphertext,

wherein the second ciphertext is a second learning with errors (LWE) ciphertext,

wherein the processor is further configured to:

perform a homomorphic rounding operation on the RLWE ciphertext; and

generate a first LWE ciphertext having the first total number of dimensions based on a result of the homomorphic rounding operation, and

wherein, for the generation of the second ciphertext, the processor is configured to generate the second ciphertext through performance of the key switching operation on the first LWE ciphertext.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: CHOI, RAKYONG; KIM, ANDREY; LEE, YONGWOO; DERIABIN, MAKSIM; EOM, JIEUN
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 065717/0332 →
Priority Claims (1)
KR 10-2023-0035315 · Mar 17, 2023 · national
Continuity (1)
Related Publication 20240313944A1 · Sep 19, 2024
References Cited (17)
US 11374736B2 · Gao · 2022 [cited by examiner]
US 20150237020A1 · Rohloff · 2015 [cited by examiner]
US 20220271922A1 · No et al. · 2022 [cited by applicant]
US 20220376890A1 · Eom et al. · 2022 [cited by applicant]
US 20230188320A1 · Park · 2023 [cited by examiner]
US 20250158802A1 · Lam · 2025 [cited by examiner]
EP 4096148A1 · 2022 [cited by applicant]
KR 1020220120410A · 2022 [cited by applicant]
Brenner et al., “performing homomorphic encryption by generating ciphertext using key switching operation and a secret key”, 5th IEEE International Conference on Digital Ecosystems and Technologies (IEEE DEST 2011), May… [cited by examiner]
Gentry, Craig et al., “Homomorphic Encryption from Learning with Errors: Conceptually-Simpler, Asymptotically-Faster, Attribute-Based,” Advances in Cryptology—Crypto 2013: 33rd Annual Cryptology Conference, Jun. 8, 2013… [cited by applicant]
Ducas, Léo, et al., “FHEW: Bootstrapping Homomorphic Encryption in Less Than a Second,” Annual International Conference on The Theory and Applications of Cryptographic Techniques, 2015, (18 Pages in English). [cited by applicant]
Chillotti, Ilaria, et al., “TFHE: Fast Fully Homomorphic Encryption over The Torus,” Journal of Cryptology, 2020, (62 Pages in English). [cited by applicant]
Xu, Runhua et al., “Privacy-Preserving Machine Learning: Methods, Challenges and Directions”, arXiv:2108.04417v2, Sep. 22, 2021, (40 Pages in English). [cited by applicant]
Kim, Audrey et al., “General Bootstrapping Approach for RLWE-based Homomorphic Encryption,” Samsung Advanced Institute of Technology, Sep. 27, 2021, (28 Pages in English). [cited by applicant]
Lee, Yongwoo et al., “Efficient FHEW Bootstrapping with Small Evaluation Keys, and Applications to Threshold Homomorphic Encryption,” Samsung Advanced Institute of Technology, Oct. 11, 2022, (28 Pages in English). [cited by applicant]
Li, Ruiqi, et al, “Homomorphic Modular Reduction and Improved Bootstrapping for BGV Scheme.” Information Security and Cryptology: 17th International Conference, Inscrypt 2021, Oct. 18, 2021 (19 pages). [cited by applicant]
Extended European search report issued on Aug. 23, 2024, in counterpart European Patent Application No. 24163817.0 (7 pages). [cited by applicant]