作为态射的自举:一种实现渐近更快同态加密的算术几何方法
Bootstrapping as a Morphism: An Arithmetic Geometry Approach to Asymptotically Faster Homomorphic Encryption
AI总结:
针对全同态加密自举过程受解密电路乘法深度限制的瓶颈,本文提出基于算术几何的自举新方法,将其转化为理想格上CVP的代数折叠求解,复杂度消除了乘法深度因子,实现了渐近性能的根本性提升。
AI中文摘要:
全同态加密(Fully Homomorphic Encryption, FHE)为安全计算提供了强大的范式,但其自举过程极高的计算成本严重阻碍了实际应用。当前所有自举方法的复杂度从根本上都与解密电路的乘法深度(记为$L_{dec}$)相关,使其成为主要的性能瓶颈。本文提出了一种全新的自举方法,完全绕开了传统的电路求值模型。我们运用现代算术几何工具,将自举操作重新定义为直接的几何投影。我们的框架将密文空间建模为仿射概形,并严格将可解密密文与新鲜密文的轨迹定义为不同的闭子概形。随后,自举变换被实现为这两个空间之间的态射。在计算层面,该投影等价于在高度结构化的理想格上求解特定的最近向量问题(Closest Vector Problem, CVP)实例,我们证明可以通过一种名为“代数折叠”的技术高效完成该求解。本文的主要成果是提出了一套完整且可证明正确的自举算法,其计算复杂度为$O(d \cdot \text{poly}(\log q))$,其中$d$为环维数,$q$为密文模数。该结果的重要意义在于从复杂度中完全消除了$L_{dec}$因子,相较于现有技术实现了根本性的渐近提升。这一几何视角为实现真正实用、高性能的FHE提供了一条极具前景的新路径。
英文摘要:
Fully Homomorphic Encryption (FHE) provides a powerful paradigm for secure computation, but its practical adoption is severely hindered by the prohibitive computational cost of its bootstrapping procedure. The complexity of all current bootstrapping methods is fundamentally tied to the multiplicative depth of the decryption circuit, denoted $L_{dec}$, making it the primary performance bottleneck. This paper introduces a new approach to bootstrapping that completely bypasses the traditional circuit evaluation model. We apply the tools of modern arithmetic geometry to reframe the bootstrapping operation as a direct geometric projection. Our framework models the space of ciphertexts as an affine scheme and rigorously defines the loci of decryptable and fresh ciphertexts as distinct closed subschemes. The bootstrapping transformation is then realized as a morphism between these two spaces. Computationally, this projection is equivalent to solving a specific Closest Vector Problem (CVP) instance on a highly structured ideal lattice, which we show can be done efficiently using a technique we call algebraic folding. The primary result of our work is a complete and provably correct bootstrapping algorithm with a computational complexity of $O(d \cdot \text{poly}(\log q))$, where $d$ is the ring dimension and $q$ is the ciphertext modulus. The significance of this result lies in the complete elimination of the factor $L_{dec}$ from the complexity, representing a fundamental asymptotic improvement over the state of the art. This geometric perspective offers a new and promising pathway toward achieving truly practical and high-performance FHE.