Homomorphic cryptographic system including noise estimator and operation method thereof
An operation method of a homomorphic encryption system comprises generating a ciphertext, performing an operation on the ciphertext, generating history information about the operation, generating a noise prediction value by predicting noise accumulated in the ciphertext by the operation based on the history information, and generating an encryption parameter including a guard interval inserted into the ciphertext based on the noise prediction value.
1 . A method of operating a homomorphic encryption system, comprising:
generating a ciphertext;
performing an operation on the ciphertext, to obtain an operation intermediate value that comprises a modification of the ciphertext;
generating history information about the operation;
generating, using the history information, a cryptographic noise prediction value by predicting a size of cryptographic noise accumulated in the ciphertext by the operation, wherein the cryptographic noise comprises a value inserted into the ciphertext by the operation;
stopping the operation in response to the cryptographic noise prediction value exceeding a reference value;
transmitting the cryptographic noise prediction value and the operation intermediate value of the stopped operation to a user device;
generating, using the cryptographic noise prediction value, an encryption parameter including a guard interval; and
performing, using the encryption parameter, homomorphic encryption on the operation intermediate value.
2 . The method of claim 1 , wherein generating the history information includes:
tagging the history information with a result of the operation on the ciphertext.
3 . The method of claim 2 , wherein the history information includes at least one of (1) a number of multiplications or additions between ciphertexts included in the operation, (2) a number of multiplications or additions between the ciphertext and a plaintext, (3) binary tree multiplication of the ciphertext, or (4) binary tree addition.
4 . The method of claim 1 ,
wherein the homomorphic encryption on the operation intermediate value generates a second ciphertext, and
wherein the method comprises transmitting the second ciphertext from the user device.
5 . The method of claim 1 , comprising:
prior to the cryptographic noise prediction value exceeding the reference value, repeatedly:
(1) performing a homomorphic operation on a prior ciphertext result, (2) generating updated history information, and (3) generating an updated value for the cryptographic noise prediction value.
6 . The method of claim 1 , further comprising:
transmitting, to the user device, remaining operation information; and
executing, by the user device, an operation subsequent to the stopping the operation using the remaining operation information.
7 . The method of claim 6 , wherein the user device includes an arithmetic circuit configured for the subsequent operation.
8 . The method of claim 6 , wherein generating the encryption parameter comprises:
selecting a first parameter range corresponding to a security level and hardware complexity of the homomorphic encryption system based on the cryptographic noise prediction value;
selecting a second parameter range corresponding to a capability or size of a homomorphic encryption functional block of the homomorphic encryption system based on the cryptographic noise prediction value; and
determining the encryption parameter based on the first parameter range and the second parameter range.
9 . A homomorphic encryption system, comprising:
a server configured to:
perform an operation on a first ciphertext, to obtain an operation intermediate value that comprises a modification of the first ciphertext,
generate a cryptographic noise prediction value by estimating a size of cryptographic noise accumulated in the first ciphertext by the operation, wherein the cryptographic noise comprises a value inserted into the first ciphertext by the operation,
stop the operation in response to the cryptographic noise prediction value exceeding a reference value, and
transmit the cryptographic noise prediction value and the operation intermediate value to a user device; and
the user device, wherein the user device is configured to:
generate, using the cryptographic noise prediction value, an encryption parameter including a guard interval, and
perform homomorphic encryption on the operation intermediate value using the encryption parameter.
10 . The system of claim 9 , wherein the server comprises:
a homomorphic encryption operator configured to perform the operation on the first ciphertext and generate history information including characteristics of the operation; and
a noise predictor configured to generate the cryptographic noise prediction value based on the history information.
11 . The system of claim 10 , wherein the history information is tagged with the first ciphertext.
12 . The system of claim 10 , wherein the history information includes at least one of a number of multiplications or additions included in the operation, a number of binary tree multiplications of the first ciphertext, or a number of binary tree additions.
13 . The system of claim 9 ,
wherein the homomorphic encryption on the operation intermediate value generates a second ciphertext, and
wherein the user device is configured to transmit the second ciphertext to the server.
14 . The system of claim 9 , wherein the server is configured to transmit remaining operation information of the stopped operation to the user device,
wherein the user device is configured to execute a subsequent operation of the stopped operation using the remaining operation information.
15 . The system of claim 9 , wherein the user device comprises:
a parameter generator configured to generate the encryption parameter, including the guard interval, based on the cryptographic noise prediction value; and
an encryption/decryption circuit configured to perform the homomorphic encryption on the operation intermediate value.
16 . A method of operating a homomorphic encryption system, comprising:
performing, by a server, an operation on a ciphertext, to obtain an operation intermediate value that comprises a modification of the ciphertext;
generating, by the server, history information about the operation;
generating, by the server, a cryptographic noise prediction value by predicting a size of cryptographic noise accumulated in the ciphertext by the operation using the history information, wherein the cryptographic noise comprises a value inserted into the ciphertext by the operation;
suspending the operation in response to the cryptographic noise prediction value exceeding a reference value;
transmitting, by the server, the cryptographic noise prediction value and the operation intermediate value to a user device; and
generating, by the user device and using the cryptographic noise prediction value, encryption parameters including guard intervals for encryption; and
performing, by the user device and using the encryption parameters, homomorphic encryption on the operation intermediate value.
17 . The method of claim 16 , wherein generating the history information includes:
tagging, by the server, the history information with an operation result of the ciphertext.