IP Library › Granted Patent US 12,095,896
Granted Patent B1
US 12,095,896 · App. 18/420,897 · Granted Sep 17, 2024

Fully homomorphic encryption and decryption apparatus and method for operating the same

Inventors: Vladimir Retivykh (Dover, DE); Grigori Leshenko (Dover, DE); Aleksei Retivykh (Dover, DE); Dmitrii Anokhin (Surat Thani, TH)
Assignee: Fhela Inc
H04L9/008H04L9/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,095,896
App. No.
18/420,897
Granted
Sep 17, 2024
Kind
B1
Abstract

A fully homomorphic encryption and decryption apparatus and method are provided, which provide efficient (in terms of computational speed and resource consumption) encryption and decryption operations in fully homomorphic encryption schemes. The apparatus comprises a control module configured to obtain a secret key (SK) in response to a configuration message and provide the SK to both encryption and decryption modules via an interconnect bus. The encryption module is configured to obtain a public key (PK), encrypt a plaintext into a ciphertext based on the PK and SK, divide the ciphertext into a set of ciphertext slices based on a PK length and an interconnect bus width, and concurrently provide the set of ciphertext slices together with the PK to the decryption module. The decryption module is configured to concatenate the set of ciphertext slices into the ciphertext and decrypt the ciphertext into the plaintext based on the PK and SK.

Claims (56)

1. A fully homomorphic encryption and decryption apparatus comprising:

an encryption module;

a decryption module;

a control module; and

an interconnect bus configured to connect the encryption module, the decryption module and the control module to each other, the interconnect bus having a bus width;

wherein the control module is configured to:

receive a configuration message comprising:

information about a source for a public key (PK);

information about a source for a secret key (SK);

a scaling shift; and

a number of noise bits;

obtain the SK based on the information about the source for the SK;

provide, via the interconnect bus, the SK, the information about the source for the PK, the number of noise bits, and the scaling shift to the encryption module; and

provide, via the interconnect bus, the SK, the number of noise bits, and the scaling shift to the decryption module;

wherein the encryption module is configured to:

(i) obtain the PK based on the information about the source for the PK;

(ii) receive a plaintext;

(iii) left-shift the plaintext by a number of bits defined by the scaling shift;

(iv) after said left-shifting, add the number of noise bits to the plaintext;

(v) after said adding, obtain a ciphertext by combining the plaintext with a scalar product of the PK and the SK, the ciphertext having a bit length;

(vi) divide the ciphertext into a set of ciphertext slices based on the bus width of the interconnect bus and the bit length of the ciphertext; and

(vii) concurrently provide each ciphertext slice of the set of ciphertext slices together with the PK to the interconnect bus; and

wherein the decryption module is configured to:

(viii) concatenate the set of ciphertext slices into the ciphertext;

(ix) subtract the scalar product of the PK and the SK from the ciphertext;

(x) after said subtracting the scalar product of the PK and the SK, subtracting the number of noise bits from the ciphertext; and

(xi) after said subtracting the number of noise bits, obtain the plaintext by right-shifting the ciphertext by the number of bits defined by the scaling shift.

2. The apparatus of claim 1 , wherein the encryption module comprises at least one random number generator (RNG), and the information about the source for the PK indicates the at least one RNG as the source for the PK and a target length of the PK, and wherein the encryption module is configured to obtain the PK by triggering the at least one RNG based on the target length of the PK.

3. The apparatus of claim 1 , wherein the encryption module comprises a memory sub-module configured to store a set of PKs each having a different PK length, and the information about the source for the PK indicates the memory sub-module as the source for the PK and a target length of the PK, and wherein the encryption module is configured to obtain the PK by accessing the memory sub-module and selecting the PK from the set of PKs based on the target length of the PK.

4. The apparatus of claim 1 , wherein the information about the source for the SK indicates an external user device as the source for the SK, and wherein the control module is configured to receive the SK from the external user device.

5. The apparatus of claim 1 , wherein the control module comprises a memory sub-module configured to store a set of SKs, and the information about the source for the SK indicates the memory sub-module as the source for the SK and a target length of the SK, and wherein the control module is configured to obtain the SK by accessing the memory sub-module and selecting the SK from the set of SKs based on the target length of the SK.

6. The apparatus of claim 1 , wherein each of the encryption module, the decryption module and the control module is implemented based on at least one of a Field-Programmable Gate Arrays (FPGA) and an Application Specific Integrated Circuits (ASIC).

7. The apparatus of claim 1 , wherein the encryption module is configured to perform operations (i)-(vii) in CL/P 2 +2 clock cycles, and the decryption module is configured to perform operations (viii)-(xi) in CL/P 2 +1 clock cycles, where C is the bit length of the ciphertext, L is a PK length of the PK, and P is a degree of parallelism provided by each of the encryption module and the description module.

8. A method for operating the fully homomorphic encryption and decryption apparatus according to claim 1 , the method comprising:

by using the control module:

receiving a configuration message comprising:

information about a source for a public key (PK);

information about a source for a secret key (SK);

a scaling shift; and

a number of noise bits;

obtaining the SK based on the information about the source for the SK;

providing, via the interconnect bus, the SK, the information about the source for the PK, the number of noise bits, and the scaling shift to the encryption module; and

providing, via the interconnect bus, the SK, the number of noise bits, and the scaling shift to the decryption module;

by using the encryption module:

obtaining the PK based on the information about the source for the PK;

receiving a plaintext;

left-shifting the plaintext by a number of bits defined by the scaling shift;

after said left-shifting, adding the number of noise bits to the plaintext;

after said adding, obtaining a ciphertext by combining the plaintext with a scalar product of the PK and the SK, the ciphertext having a bit length;

dividing the ciphertext into a set of ciphertext slices based on the bus width of the interconnect bus and the bit length of the ciphertext; and

concurrently providing each ciphertext slice of the set of ciphertext slices together with the PK to the interconnect bus; and

by using the decryption module:

concatenating the set of ciphertext slices into the ciphertext;

subtracting the scalar product of the PK and the SK from the ciphertext;

after said subtracting the scalar product of the PK and the SK, subtracting the number of noise bits from the ciphertext; and

after said subtracting the number of noise bits, obtaining the plaintext by right-shifting the ciphertext by the number of bits defined by the scaling shift.

Cited By (1)
US 12,750,205