IP Library Granted Patent US 12,506,608
Granted Patent B2
US 12,506,608 · App. 19/006,608 · Granted Dec 23, 2025

Method for enhancing key-switching efficiency following modraise in fully homomorphic encryption

Inventors: Noam Kleinburd (Hashmonaim, IL); Oren Vrubel (Tel Aviv, IL); Ilan Rosenfeld (Petah Tikva, IL)
Assignee: Chain Reaction, Ltd.
H04L9/3026G06F21/575H04L9/008G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,608
App. No.
19/006,608
Filed
Dec 31, 2024
Granted
Dec 23, 2025
Kind
B2
Art Unit
2499
USPC
380/30
Abstract

A method and system of the device may include identifying, in an FHE program, key-switching operations occurring after a ModRaise operation. In addition, the device may include determining a first aggregated polynomial sum and a second aggregated polynomial sum; and configuring instructions for performing a MultSum operation based on the determined first aggregated polynomial sum and the second aggregated polynomial sum, the instructions are programmed to be executed during runtime, where the MultSum operation outputs two polynomials, each of which is an inner product between a single cyphertext polynomial and the first aggregated polynomial sum and a single cyphertext polynomial and the second aggregated polynomial sum, thereby reducing memory usage and computational overhead and enhancing key-switching efficiency.

Claims (22)

1 . A method for enhancing key-switching efficiency in a fully homomorphic encryption (FHE) system, the method comprising:

identifying, in an FHE program stored within a hardware memory, key-switching operations occurring after a ModRaise operation;

determining a first aggregated polynomial sum and a second aggregated polynomial sum, wherein the first aggregated polynomial sum and the second aggregated polynomial sum are pre-computed sums; and

configuring instructions for performing a MultSum operation based on the determined first aggregated polynomial sum and the second aggregated polynomial sum, the instructions are programmed to be executed during runtime, wherein the MultSum operation outputs two polynomials, each of which is an inner product between a single cyphertext polynomial and the first aggregated polynomial sum and a single cyphertext polynomial and the second aggregated polynomial sum which reduces memory usage and computational overhead and enhances key-switching efficiency.

2 . The method of claim 1 , wherein the first aggregated polynomial sum is a sum of a first part of key-switching key (KSK) and the second aggregated polynomial sum is a sum of a second part of KSK, wherein each of the first part of the KSK and the second part of the KSK includes a number of d polynomials, wherein the number d represents a digit decomposition count.

3 . The method of claim 2 , wherein the ModRaise operation expands a ciphertext modulus from a small modulus (q) to large modulus (Q) to prepare a ciphertext for subsequent transformations.

4 . The method of claim 2 , wherein configuring the instructions further comprises: pre-multiplying the second part KSK by its corresponding diagonal plaintext.

5 . The method of claim 2 , further comprising: optimizing the digit decomposition count d; and lowering a temporary modulus to decrease the number of single-residue polynomial multiplications and reduce an auxiliary data size.

6 . The method of claim 1 , wherein configuring the instructions further comprises: reusing a single-digit decomposition result across multiple key-switching operations originating from the same ciphertext.

7 . The method of claim 1 , wherein configuring the instructions further comprises: dynamically generating the second aggregated polynomial sum from a seed value.

8 . The method of claim 1 , configuring the instructions further comprises: applying the key-switching operation to coefficients-to-slots (C2S) transformations in a bootstrapping process, wherein the transformations include transitions between sparse secret keys and dense secret keys while maintaining ciphertext integrity across iterative processing.

9 . The method of claim 1 , configuring the instructions further comprises: performing subsequent key-switching operations during a bootstrapping process of the FHE program, wherein each of the key-switching operations is optimized by the determined first aggregated polynomial sum and the second aggregated polynomial sum.

10 . A non-transitory computer-readable medium storing a set of instructions for enhancing key-switching efficiency in a fully homomorphic encryption (FHE) system, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

identify, in an FHE program, key-switching operations occurring after a ModRaise operation;

determine a first aggregated polynomial sum and a second aggregated polynomial sum, wherein the first aggregated polynomial sum and the second aggregated polynomial sum are pre-computed sums; and

configure instructions for performing a MultSum operation based on the determined first aggregated polynomial sum and the second aggregated polynomial sum, the instructions are programmed to be executed during runtime, wherein the MultSum operation outputs two polynomials, each of which is an inner product between a single cyphertext polynomial and the first aggregated polynomial sum and a single cyphertext polynomial and the second aggregated polynomial sum which reduces memory usage and computational overhead and enhances key-switching efficiency.

11 . A system for enhancing key-switching efficiency in a fully homomorphic encryption (FHE) system comprising:

one or more processors configured to:

identify, in an FHE program stored within a hardware memory, key-switching operations occurring after a ModRaise operation;

determine a first aggregated polynomial sum and a second aggregated polynomial sum, wherein the first aggregated polynomial sum and the second aggregated polynomial sum are pre-computed sums; and

configure instructions for performing a MultSum operation based on the determined first aggregated polynomial sum and the second aggregated polynomial sum, the instructions are programmed to be executed during runtime, wherein the MultSum operation outputs two polynomials, each of which is an inner product between a single cyphertext polynomial and the first aggregated polynomial sum and a single cyphertext polynomial and the second aggregated polynomial sum which reduces memory usage and computational overhead and enhances key-switching efficiency.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2025
From: KLEINBURD, NOAM; VRUBEL, OREN; ROSENFELD, ILAN
To: CHAIN REACTION, LTD.
Reel/Frame 070084/0657 →
Continuity (2)
Provisional Application 63568472 · Mar 22, 2024
Related Publication 20250300832A1 · Sep 25, 2025
References Cited (47)
US 20130216044A1 · Gentry · 2013 [cited by examiner]
US 20160164670A1 · Gentry · 2016 [cited by examiner]
US 20160164671A1 · Gentry · 2016 [cited by examiner]
US 20160164676A1 · Gentry · 2016 [cited by examiner]
US 20180109376A1 · Gentry · 2018 [cited by examiner]
US 20190334694A1 · Chen · 2019 [cited by examiner]
US 20190394019A1 · Gao · 2019 [cited by examiner]
US 20200076570A1 · Musuvathi · 2020 [cited by examiner]
US 20210194666A1 · Georgieva · 2021 [cited by examiner]
US 20210328766A1 · No · 2021 [cited by examiner]
US 20220271922A1 · No · 2022 [cited by examiner]
US 20220360428A1 · Creeger · 2022 [cited by examiner]
US 20230112840A1 · Micciancio · 2023 [cited by examiner]
US 20230145760A1 · Cheon · 2023 [cited by examiner]
US 20230291541A1 · Gupta · 2023 [cited by examiner]
US 20230325529A1 · Sav · 2023 [cited by examiner]
US 20230361986A1 · Genise · 2023 [cited by examiner]
US 20240048355A1 · Joye · 2024 [cited by examiner]
US 20240171374A1 · Tan · 2024 [cited by examiner]
US 20240364496A1 · Chevallier-Mames · 2024 [cited by examiner]
US 20240421971A1 · Agrawal · 2024 [cited by examiner]
US 20250005101A1 · Taneja et al. · 2025 [cited by applicant]
US 20250023715A1 · Bae · 2025 [cited by examiner]
US 20250167976A1 · Van Beirendonck · 2025 [cited by examiner]
US 20250211435A1 · Maji · 2025 [cited by examiner]
US 20250266984A1 · Cheon · 2025 [cited by examiner]
US 20250300806A1 · Vrubel · 2025 [cited by examiner]
US 20250300807A1 · Vrubel · 2025 [cited by examiner]
US 20250300832A1 · Kleinburd · 2025 [cited by examiner]
US 20250337560A1 · Bae · 2025 [cited by examiner]
US 20250343671A1 · Bae · 2025 [cited by examiner]
CN 116488788A · 2023 [cited by applicant]
KR 102616119B1 · 2023 [cited by applicant]
Bossuat, Jean-Philippe, Mouchet, Christian, Troncoso-Pastoriza, Juan, and Hubaux, Jean-Pierre, “Efficient Bootstrapping for Approximate Homomorphic Encryption with Non-Sparse Keys” accessed Jul. 9, 2024. [cited by applicant]
Cheon, Jung Hee, Han, Kyoohyung, Han, Minki, “Faster Homomorphic Discrete Fourier Transforms and Improved FHE Bootstrapping”, accessed Dec. 23, 2024, pp. 1-18, Seoul National University, Seoul, Korea. [cited by applicant]
Halevi, Shai, Shoup, Victor, “Bootstrapping for HElib”, dated Apr. 20, 2020, pp. 1-38. [cited by applicant]
Kim, Jongmin, Kim, Sangpyo, Choi, Jaewan, Park, Jaiyoung, Kim, Donghwan, Ahn, Jung Ho, “SHARP: A Short-Word Hierarchical Accelerator for Robust and Practical Fully Homomorphic Encryption”, Jun. 17-21, 2023, pp. 1-15, IS… [cited by applicant]
Kim, Jongmin, Lee, Gwangho, Kim, Sangpyo, Sohn, Glna, Kim, John, Rhu, Minsoo, Ahn, Jung Ho, “ARK:Fully Homomorphic Encryption Accelerator with Runtime Data Generation and Inter-Operation Key Rescue”, May 3, 2022, pp. 1-… [cited by applicant]
Lattigo, “Lattigo: lattice-based multiparty homomorphic encryption library in Go”, Aug. 2024, Github, https://github.com/tuneinsight/lattigo, date accessed Dec. 23, 2024. [cited by applicant]
Samardzic, Nikola, Feldmann, Axel, Manohar, Nathan, Genise, Nicholas, Eldefrawy, Karim Peikert, Chris, “Crater Lake: A Hardware Accelerator for Efficient Unbounded Computation on Encrypted Data”, Jun. 18-22, 2022, pp. 1… [cited by applicant]
Zhou, Minxuan, et al. “FHEmem: A Processing In-Memory Accelerator for Fully Homomorphic Encryption”, arXiv:2311.16293v1 [cs.AR] Nov. 27, 2023. [cited by applicant]
International Search Report for PCT/IB2025/050820, dated May 7, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
International Search Report for PCT/IB2025/050822, dated Apr. 30, 2025. Searching Authority, Israel Patent Office, Jerusalem. [cited by applicant]
International Search Report for PCT/IB2025/050824, dated May 7, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2025/050820, dated May 7, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2025/050822, dated Apr. 30, 2025. Searching Authority, Israel Patent Office, Jerusalem. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2025/050824, dated May 7, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]