str r rt - - PowerPoint PPT Presentation

st r r r t tstr
SMART_READER_LITE
LIVE PREVIEW

str r rt - - PowerPoint PPT Presentation

str r rt tstr ss t ss tt 1 2 , 1


slide-1
SLIDE 1

❋❛st❡r ❢✉❧❧② ❤♦♠♦♠♦r♣❤✐❝ ❡♥❝r②♣t✐♦♥✿ ❇♦♦tstr❛♣♣✐♥❣ ✐♥ ❧❡ss t❤❛♥ ✵✳✶ s❡❝♦♥❞s

■✳ ❈❤✐❧❧♦tt✐1 ◆✳ ●❛♠❛2,1 ▼✳ ●❡♦r❣✐❡✈❛3 ▼✳ ■③❛❜❛❝❤è♥❡4

1 2 3 4

❙é♠✐♥❛✐r❡ ●❚❇❆❈ ❚é❧é❝♦♠ P❛r✐s❚❡❝❤ ❆♣r✐❧ ✻✱ ✷✵✶✼

✶ ✴ ✹✸

slide-2
SLIDE 2

❚❛❜❧❡ ♦❢ ❝♦♥t❡♥ts

✶ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♣♣❧✐❝❛t✐♦♥s

✷ ❚▲❲❊

❚❤❡ r❡❛❧ t♦r✉s ▲❲❊ ❛♥❞ ❚▲❲❊

✸ ❚●❙❲ ❛♥❞ t❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t

❊♥❝r②♣t✐♦♥ ❛♥❞ ●❛❞❣❡t ❚▲❲❊ ❛♥❞ ❚●❙❲

✹ ❋❛st❡r ❇♦♦tstr❛♣♣✐♥❣

  • ❛t❡ ❜♦♦tstr❛♣♣✐♥❣

❙❡❝✉r✐t② ❛♥❛❧②s✐s

✺ ❈♦♥❝❧✉s✐♦♥

✷ ✴ ✹✸

slide-3
SLIDE 3

❚❛❜❧❡ ♦❢ ❝♦♥t❡♥ts

✶ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♣♣❧✐❝❛t✐♦♥s

✷ ❚▲❲❊

❚❤❡ r❡❛❧ t♦r✉s ▲❲❊ ❛♥❞ ❚▲❲❊

✸ ❚●❙❲ ❛♥❞ t❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t

❊♥❝r②♣t✐♦♥ ❛♥❞ ●❛❞❣❡t ❚▲❲❊ ❛♥❞ ❚●❙❲

✹ ❋❛st❡r ❇♦♦tstr❛♣♣✐♥❣

  • ❛t❡ ❜♦♦tstr❛♣♣✐♥❣

❙❡❝✉r✐t② ❛♥❛❧②s✐s

✺ ❈♦♥❝❧✉s✐♦♥

✸ ✴ ✹✸

slide-4
SLIDE 4

❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

■❉❊❆✿ ♣❡r❢♦r♠ ❝♦♠♣✉t❛t✐♦♥s ♦♥ ❡♥❝r②♣t❡❞ ❞❛t❛✱ ✇✐t❤♦✉t ❞❡❝r②♣t✐♥❣ ✐t✳ b1, b2 ∈ {0, 1} b1 b1 ⊕hom b2 = b1⊕b2 − → b2 b1 ∧hom b2 = b1∧b2

✹ ✴ ✹✸

slide-5
SLIDE 5

❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

▼♦r❡ ❣❡♥❡r❛❧❧② b1 ✳ ✳ ✳ − → ϕhom( b1 , . . . , bn ) = ϕ(b1, . . . , bn) bn ✇❤❡r❡ b1, . . . , bn ∈ {0, 1} ❛♥❞ ϕ ✐s ❛ ❜♦♦❧❡❛♥ ❝✐r❝✉✐t✳

✺ ✴ ✹✸

slide-6
SLIDE 6

❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♥ ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥ s❝❤❡♠❡ ✐s ❝♦♠♣♦s❡❞ ❜② ✹ ❛❧❣♦r✐t❤♠s✿ ❑❡② ●❡♥❡r❛t✐♦♥ ❑❡②●❡♥ ✿ ❉❡❝r②♣t✐♦♥ ❉❡❝ ✭❞❡t❡r♠✐♥✐st✐❝✮ ✿ ❊♥❝r②♣t✐♦♥ ❊♥❝ ✭r❛♥❞♦♠✐③❡❞✮ ✿ s✉❝❤ t❤❛t ❉❡❝

✻ ✴ ✹✸

slide-7
SLIDE 7

❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♥ ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥ s❝❤❡♠❡ ✐s ❝♦♠♣♦s❡❞ ❜② ✹ ❛❧❣♦r✐t❤♠s✿ ❑❡② ●❡♥❡r❛t✐♦♥ ❑❡②●❡♥ ✿ λ − → (sk, pk) ❉❡❝r②♣t✐♦♥ ❉❡❝ ✭❞❡t❡r♠✐♥✐st✐❝✮ ✿ ❊♥❝r②♣t✐♦♥ ❊♥❝ ✭r❛♥❞♦♠✐③❡❞✮ ✿ s✉❝❤ t❤❛t ❉❡❝

✻ ✴ ✹✸

slide-8
SLIDE 8

❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♥ ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥ s❝❤❡♠❡ ✐s ❝♦♠♣♦s❡❞ ❜② ✹ ❛❧❣♦r✐t❤♠s✿ ❑❡② ●❡♥❡r❛t✐♦♥ ❑❡②●❡♥ ✿ λ − → (sk, pk) ❉❡❝r②♣t✐♦♥ ❉❡❝ ✭❞❡t❡r♠✐♥✐st✐❝✮ ✿ (c, sk) − → m ❊♥❝r②♣t✐♦♥ ❊♥❝ ✭r❛♥❞♦♠✐③❡❞✮ ✿ s✉❝❤ t❤❛t ❉❡❝

✻ ✴ ✹✸

slide-9
SLIDE 9

❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♥ ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥ s❝❤❡♠❡ ✐s ❝♦♠♣♦s❡❞ ❜② ✹ ❛❧❣♦r✐t❤♠s✿ ❑❡② ●❡♥❡r❛t✐♦♥ ❑❡②●❡♥ ✿ λ − → (sk, pk) ❉❡❝r②♣t✐♦♥ ❉❡❝ ✭❞❡t❡r♠✐♥✐st✐❝✮ ✿ (c, sk) − → m ❊♥❝r②♣t✐♦♥ ❊♥❝ ✭r❛♥❞♦♠✐③❡❞✮ ✿ (m, pk) − → c s✉❝❤ t❤❛t ❉❡❝(c, sk) = m

✻ ✴ ✹✸

slide-10
SLIDE 10

❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❊✈❛❧✉❛t✐♦♥ ❊✈❛❧ ✭♣♦ss✐❜❧② r❛♥❞♦♠✐③❡❞✮ ✿ (ϕ, c1, . . . , ck) − → c s✉❝❤ t❤❛t ❉❡❝(c, sk) = ϕ(m1, . . . , mk)

mk . . . ck . . . Eval(ϕ, . . .) m1 c1 c ϕ(m1, . . . , mk)

❆ s❝❤❡♠❡ t❤❛t ❝❛♥ ❤♦♠♦♠♦r♣❤✐❝❛❧❧② ❡✈❛❧✉❛t❡ ❛❧❧ ❢✉♥❝t✐♦♥s✴❝✐r❝✉✐ts ✐s s❛✐❞ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ✭❋❍❊✮✳

✼ ✴ ✹✸

slide-11
SLIDE 11

❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❊✈❛❧✉❛t✐♦♥ ❊✈❛❧ ✭♣♦ss✐❜❧② r❛♥❞♦♠✐③❡❞✮ ✿ (ϕ, c1, . . . , ck) − → c s✉❝❤ t❤❛t ❉❡❝(c, sk) = ϕ(m1, . . . , mk)

mk . . . ck . . . Eval(ϕ, . . .) m1 c1 c ϕ(m1, . . . , mk)

❆ s❝❤❡♠❡ t❤❛t ❝❛♥ ❤♦♠♦♠♦r♣❤✐❝❛❧❧② ❡✈❛❧✉❛t❡ ❛❧❧ ❢✉♥❝t✐♦♥s✴❝✐r❝✉✐ts ✐s s❛✐❞ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ✭❋❍❊✮✳

✼ ✴ ✹✸

slide-12
SLIDE 12

❆♣♣❧✐❝❛t✐♦♥s

✽ ✴ ✹✸

slide-13
SLIDE 13

❆♣♣❧✐❝❛t✐♦♥s

Statistic computations on sensitive data

✽ ✴ ✹✸

slide-14
SLIDE 14

❆♣♣❧✐❝❛t✐♦♥s

Statistic computations on sensitive data Secure multiparty computation

✽ ✴ ✹✸

slide-15
SLIDE 15

❆♣♣❧✐❝❛t✐♦♥s

Statistic computations on sensitive data Secure multiparty computation Electronic voting

✽ ✴ ✹✸

slide-16
SLIDE 16

❆♣♣❧✐❝❛t✐♦♥s

Statistic computations on sensitive data Secure multiparty computation Electronic voting Cloud computing

✽ ✴ ✹✸

slide-17
SLIDE 17

❆♣♣❧✐❝❛t✐♦♥s

Statistic computations on sensitive data Secure multiparty computation Electronic voting Cloud computing and even more...

✽ ✴ ✹✸

slide-18
SLIDE 18

❆ ✇♦r❧❞ ❢✉❧❧ ♦❢ ♥♦✐s❡✳✳✳

❛♥✐♠✳❤t♠❧

✾ ✴ ✹✸

slide-19
SLIDE 19

❇♦♦tstr❛♣♣✐♥❣ ♥♦✇

c1 cℓ ciphertext secret key c2 . . . . . . message bits bits k1 kn k2 Decryption circuit (public)

✶✵ ✴ ✹✸

slide-20
SLIDE 20

❇♦♦tstr❛♣♣✐♥❣ ♥♦✇

c1 cℓ ciphertext secret key c2 . . . . . . message bits bits k1 kn k2 Decryption circuit (public) encrypted encrypted Decryption circuit (public) hom.

✶✵ ✴ ✹✸

slide-21
SLIDE 21

❇♦♦tstr❛♣♣✐♥❣ ♥♦✇

❇♦♦tstr❛♣♣✐♥❣ ✐s t❤❡ ♠♦st ❡①♣❡♥s✐✈❡ ♣❛rt ♦❢ t❤❡ ❡♥t✐r❡ ❤♦♠♦♠♦r♣❤✐❝ ♣r♦❝❡❞✉r❡ ❖r✐❣✐♥❛❧ ✐❞❡❛ ❜② ●❡♥tr② ❬●❡♥✵✾❪ ▲❛st ②❡❛rs✿ ✇♦r❦ t♦ r❡❞✉❝❡ t❤❡ ❡①❡❝✉t✐♦♥ t✐♠❡ ❛♥❞ ♠❡♠♦r② ❝♦♥s✉♠✐♥❣ ✳✳✳❜✉t ❛ ❧♦t ❤❛✈❡ t♦ ❜❡ ❞♦♥❡✦

✶✶ ✴ ✹✸

slide-22
SLIDE 22

❚❛❜❧❡ ♦❢ ❝♦♥t❡♥ts

✶ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♣♣❧✐❝❛t✐♦♥s

✷ ❚▲❲❊

❚❤❡ r❡❛❧ t♦r✉s ▲❲❊ ❛♥❞ ❚▲❲❊

✸ ❚●❙❲ ❛♥❞ t❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t

❊♥❝r②♣t✐♦♥ ❛♥❞ ●❛❞❣❡t ❚▲❲❊ ❛♥❞ ❚●❙❲

✹ ❋❛st❡r ❇♦♦tstr❛♣♣✐♥❣

  • ❛t❡ ❜♦♦tstr❛♣♣✐♥❣

❙❡❝✉r✐t② ❛♥❛❧②s✐s

✺ ❈♦♥❝❧✉s✐♦♥

✶✷ ✴ ✹✸

slide-23
SLIDE 23

▲❲❊

▲❲❊ ❂ ▲❡❛r♥✐♥❣ ❲✐t❤ ❊rr♦rs ❬❘❡❣✵✺❪ ❘✐♥❣✲▲❲❊ ❬▲P❘✶✵❪

■♥ ♦✉r ♣❛♣❡r

▲❲❊✿ ❞❡✜♥✐t✐♦♥ s✐♠✐❧❛r t♦ ❬❇▲P❘❙✶✸❪✱❬❈❙✶✺❪✱❬❈●●■✶✻❪ ❚▲❲❊✿ ❣❡♥❡r❛❧✐③❡❞ ❞❡✜♥✐t✐♦♥ s✐♠✐❧❛r t♦ ❬❇●❱✶✷❪

✶✸ ✴ ✹✸

slide-24
SLIDE 24

▲❲❊

▲❲❊ ❂ ▲❡❛r♥✐♥❣ ❲✐t❤ ❊rr♦rs ❬❘❡❣✵✺❪ ❘✐♥❣✲▲❲❊ ❬▲P❘✶✵❪

■♥ ♦✉r ♣❛♣❡r

▲❲❊✿ ❞❡✜♥✐t✐♦♥ s✐♠✐❧❛r t♦ ❬❇▲P❘❙✶✸❪✱❬❈❙✶✺❪✱❬❈●●■✶✻❪ ❚▲❲❊✿ ❣❡♥❡r❛❧✐③❡❞ ❞❡✜♥✐t✐♦♥ s✐♠✐❧❛r t♦ ❬❇●❱✶✷❪

✶✸ ✴ ✹✸

slide-25
SLIDE 25

❚❤❡ r❡❛❧ t♦r✉s T = R/Z = R mod 1

(T, +, ·) ✐s ❛ Z✲♠♦❞✉❧❡ ✭· : Z × T → T ❛ ✈❛❧✐❞ ❡①t❡r♥❛❧ ♣r♦❞✉❝t✮ ■t ✐s ❛ ❣r♦✉♣✿ ❛♥❞ ■t ✐s ❛ ✲♠♦❞✉❧❡✿ ✐s ❞❡✜♥❡❞✦ ■t ✐s ♥♦t ❛ ❘✐♥❣✿ ✐s ♥♦t ❞❡✜♥❡❞✦

❱❡❝t♦rs✴♠❛tr✐❝❡s

❇② ❡①t❡♥s✐♦♥✱ ✐s ❛ ✲♠♦❞✉❧❡

✶✹ ✴ ✹✸

slide-26
SLIDE 26

❚❤❡ r❡❛❧ t♦r✉s T = R/Z = R mod 1

(T, +, ·) ✐s ❛ Z✲♠♦❞✉❧❡ ✭· : Z × T → T ❛ ✈❛❧✐❞ ❡①t❡r♥❛❧ ♣r♦❞✉❝t✮ ✔ ■t ✐s ❛ ❣r♦✉♣✿ x + y mod 1 ❛♥❞ −x mod 1 ■t ✐s ❛ ✲♠♦❞✉❧❡✿ ✐s ❞❡✜♥❡❞✦ ■t ✐s ♥♦t ❛ ❘✐♥❣✿ ✐s ♥♦t ❞❡✜♥❡❞✦

❱❡❝t♦rs✴♠❛tr✐❝❡s

❇② ❡①t❡♥s✐♦♥✱ ✐s ❛ ✲♠♦❞✉❧❡

✶✹ ✴ ✹✸

slide-27
SLIDE 27

❚❤❡ r❡❛❧ t♦r✉s T = R/Z = R mod 1

(T, +, ·) ✐s ❛ Z✲♠♦❞✉❧❡ ✭· : Z × T → T ❛ ✈❛❧✐❞ ❡①t❡r♥❛❧ ♣r♦❞✉❝t✮ ✔ ■t ✐s ❛ ❣r♦✉♣✿ x + y mod 1 ❛♥❞ −x mod 1 ✔ ■t ✐s ❛ Z✲♠♦❞✉❧❡✿ 0 · 1

2 = 0 ✐s ❞❡✜♥❡❞✦

■t ✐s ♥♦t ❛ ❘✐♥❣✿ ✐s ♥♦t ❞❡✜♥❡❞✦

❱❡❝t♦rs✴♠❛tr✐❝❡s

❇② ❡①t❡♥s✐♦♥✱ ✐s ❛ ✲♠♦❞✉❧❡

✶✹ ✴ ✹✸

slide-28
SLIDE 28

❚❤❡ r❡❛❧ t♦r✉s T = R/Z = R mod 1

(T, +, ·) ✐s ❛ Z✲♠♦❞✉❧❡ ✭· : Z × T → T ❛ ✈❛❧✐❞ ❡①t❡r♥❛❧ ♣r♦❞✉❝t✮ ✔ ■t ✐s ❛ ❣r♦✉♣✿ x + y mod 1 ❛♥❞ −x mod 1 ✔ ■t ✐s ❛ Z✲♠♦❞✉❧❡✿ 0 · 1

2 = 0 ✐s ❞❡✜♥❡❞✦

✘ ■t ✐s ♥♦t ❛ ❘✐♥❣✿ 0 × 1

2 ✐s ♥♦t ❞❡✜♥❡❞✦

❱❡❝t♦rs✴♠❛tr✐❝❡s

❇② ❡①t❡♥s✐♦♥✱ ✐s ❛ ✲♠♦❞✉❧❡

✶✹ ✴ ✹✸

slide-29
SLIDE 29

❚❤❡ r❡❛❧ t♦r✉s T = R/Z = R mod 1

(T, +, ·) ✐s ❛ Z✲♠♦❞✉❧❡ ✭· : Z × T → T ❛ ✈❛❧✐❞ ❡①t❡r♥❛❧ ♣r♦❞✉❝t✮ ✔ ■t ✐s ❛ ❣r♦✉♣✿ x + y mod 1 ❛♥❞ −x mod 1 ✔ ■t ✐s ❛ Z✲♠♦❞✉❧❡✿ 0 · 1

2 = 0 ✐s ❞❡✜♥❡❞✦

✘ ■t ✐s ♥♦t ❛ ❘✐♥❣✿ 0 × 1

2 ✐s ♥♦t ❞❡✜♥❡❞✦

❱❡❝t♦rs✴♠❛tr✐❝❡s

❇② ❡①t❡♥s✐♦♥✱ (Tn, +, .) ✐s ❛ Z✲♠♦❞✉❧❡

  • 3

−2 4

  • ·

    1 −2 3 4 5   · 0.252 0.672 0.231 0.991   =   3 −2 4 ×   1 −2 3 4 5     · 0.252 0.672 0.231 0.991

  • ✶✹ ✴ ✹✸
slide-30
SLIDE 30

❚♦r✉s ♣♦❧②♥♦♠✐❛❧s TN[X]

(TN[X], +, ·) ✐s ❛ R✲♠♦❞✉❧❡ ❍❡r❡✱ R = Z[X]/(XN + 1) ❆♥❞ TN[X] = T[X] mod (XN + 1)

❊①❛♠♣❧❡s

❉❡❝♦♠♣♦s❡ ♦✈❡r ✇✐t❤ s♠❛❧❧ ❝♦❡❢s

✶✺ ✴ ✹✸

slide-31
SLIDE 31

❚♦r✉s ♣♦❧②♥♦♠✐❛❧s TN[X]

(TN[X], +, ·) ✐s ❛ R✲♠♦❞✉❧❡ ❍❡r❡✱ R = Z[X]/(XN + 1) ❆♥❞ TN[X] = T[X] mod (XN + 1)

❊①❛♠♣❧❡s

(1 + 2X) · ( 1

3 + 4 7X) =

❉❡❝♦♠♣♦s❡ ♦✈❡r ✇✐t❤ s♠❛❧❧ ❝♦❡❢s

✶✺ ✴ ✹✸

slide-32
SLIDE 32

❚♦r✉s ♣♦❧②♥♦♠✐❛❧s TN[X]

(TN[X], +, ·) ✐s ❛ R✲♠♦❞✉❧❡ ❍❡r❡✱ R = Z[X]/(XN + 1) ❆♥❞ TN[X] = T[X] mod (XN + 1)

❊①❛♠♣❧❡s

(1 + 2X) · ( 1

3 + 4 7X) =( 4 21 + 5 21X) mod (X2 + 1) mod 1

❉❡❝♦♠♣♦s❡ ♦✈❡r ✇✐t❤ s♠❛❧❧ ❝♦❡❢s

✶✺ ✴ ✹✸

slide-33
SLIDE 33

❚♦r✉s ♣♦❧②♥♦♠✐❛❧s TN[X]

(TN[X], +, ·) ✐s ❛ R✲♠♦❞✉❧❡ ❍❡r❡✱ R = Z[X]/(XN + 1) ❆♥❞ TN[X] = T[X] mod (XN + 1)

❊①❛♠♣❧❡s

(1 + 2X) · ( 1

3 + 4 7X) =( 4 21 + 5 21X) mod (X2 + 1) mod 1

❉❡❝♦♠♣♦s❡ ( 3

8 + 7 8X) ♦✈❡r [ 1 2, 1 4, 1 8] ✇✐t❤ s♠❛❧❧ ❝♦❡❢s

✶✺ ✴ ✹✸

slide-34
SLIDE 34

❚♦r✉s ♣♦❧②♥♦♠✐❛❧s TN[X]

(TN[X], +, ·) ✐s ❛ R✲♠♦❞✉❧❡ ❍❡r❡✱ R = Z[X]/(XN + 1) ❆♥❞ TN[X] = T[X] mod (XN + 1)

❊①❛♠♣❧❡s

(1 + 2X) · ( 1

3 + 4 7X) =( 4 21 + 5 21X) mod (X2 + 1) mod 1

❉❡❝♦♠♣♦s❡ ( 3

8 + 7 8X) ♦✈❡r [ 1 2, 1 4, 1 8] ✇✐t❤ s♠❛❧❧ ❝♦❡❢s

( 3

8 + 7 8X) = (0 + X) · 1 2 + (1 + X) · 1 4 + (1 + X) · 1 8

✶✺ ✴ ✹✸

slide-35
SLIDE 35

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

▲❲❊ ❊♥❝r②♣t✐♦♥

✶ ❈❤♦♦s❡

  • ❛✉ss✐❛♥ ❊rr♦r

✷ ❈❤♦♦s❡ ❛ r❛♥❞♦♠ ♠❛s❦ ✸ ❘❡t✉r♥ t❤❡ ❧♦❝❦❡❞ r❡♣r❡s❡♥t❛t✐♦♥ ✶✻ ✴ ✹✸

slide-36
SLIDE 36

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

1/3 2/3 Example: M = {0, 1/3, 2/3} mod 1 µ = 1/3 mod 1 ∈ M

▲❲❊ ❊♥❝r②♣t✐♦♥

✶ ❈❤♦♦s❡

  • ❛✉ss✐❛♥ ❊rr♦r

✷ ❈❤♦♦s❡ ❛ r❛♥❞♦♠ ♠❛s❦ ✸ ❘❡t✉r♥ t❤❡ ❧♦❝❦❡❞ r❡♣r❡s❡♥t❛t✐♦♥ ✶✻ ✴ ✹✸

slide-37
SLIDE 37

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

1/3 2/3 Example: M = {0, 1/3, 2/3} mod 1 µ = 1/3 mod 1 ∈ M ( , ϕ)

▲❲❊ ❊♥❝r②♣t✐♦♥

✶ ❈❤♦♦s❡ ϕ = µ + ●❛✉ss✐❛♥ ❊rr♦r ✷ ❈❤♦♦s❡ ❛ r❛♥❞♦♠ ♠❛s❦ ✸ ❘❡t✉r♥ t❤❡ ❧♦❝❦❡❞ r❡♣r❡s❡♥t❛t✐♦♥ ✶✻ ✴ ✹✸

slide-38
SLIDE 38

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

1/3 2/3 Example: M = {0, 1/3, 2/3} mod 1 µ = 1/3 mod 1 ∈ M a (a, ϕ)

▲❲❊ ❊♥❝r②♣t✐♦♥

✶ ❈❤♦♦s❡ ϕ = µ + ●❛✉ss✐❛♥ ❊rr♦r ✷ ❈❤♦♦s❡ ❛ r❛♥❞♦♠ ♠❛s❦ a ∈ Tn ✸ ❘❡t✉r♥ t❤❡ ❧♦❝❦❡❞ r❡♣r❡s❡♥t❛t✐♦♥ ✶✻ ✴ ✹✸

slide-39
SLIDE 39

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

1/3 2/3 Example: M = {0, 1/3, 2/3} mod 1 µ = 1/3 mod 1 ∈ M a (a, ϕ) a (a, b) b = s · a + ϕ secret key: s ∈ {0, 1}n

▲❲❊ ❊♥❝r②♣t✐♦♥

✶ ❈❤♦♦s❡ ϕ = µ + ●❛✉ss✐❛♥ ❊rr♦r ✷ ❈❤♦♦s❡ ❛ r❛♥❞♦♠ ♠❛s❦ a ∈ Tn ✸ ❘❡t✉r♥ t❤❡ ❧♦❝❦❡❞ r❡♣r❡s❡♥t❛t✐♦♥ (a, b) ✶✻ ✴ ✹✸

slide-40
SLIDE 40

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

a (a, b) secret key: s ∈ {0, 1}n

▲❲❊ ❉❡❝r②♣t✐♦♥

✶ ❯♥❧♦❝❦ t❤❡ r❡♣r❡s❡♥t❛t✐♦♥ ✷ ❘♦✉♥❞

t♦ t❤❡ ♥❡❛r❡st ♠❡ss❛❣❡

✸ ♣❧♦✉❢✦ ✶✻ ✴ ✹✸

slide-41
SLIDE 41

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

a (a, ϕ) a (a, b) secret key: s ∈ {0, 1}n ϕ = b − s · a

▲❲❊ ❉❡❝r②♣t✐♦♥

✶ ❯♥❧♦❝❦ t❤❡ r❡♣r❡s❡♥t❛t✐♦♥ (a, ϕ) ✷ ❘♦✉♥❞

t♦ t❤❡ ♥❡❛r❡st ♠❡ss❛❣❡

✸ ♣❧♦✉❢✦ ✶✻ ✴ ✹✸

slide-42
SLIDE 42

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

a (a, ϕ) a (a, b) secret key: s ∈ {0, 1}n ϕ = b − s · a 1/3 2/3

▲❲❊ ❉❡❝r②♣t✐♦♥

✶ ❯♥❧♦❝❦ t❤❡ r❡♣r❡s❡♥t❛t✐♦♥ (a, ϕ) ✷ ❘♦✉♥❞ ϕ t♦ t❤❡ ♥❡❛r❡st ♠❡ss❛❣❡ µ ∈ M ✸ ♣❧♦✉❢✦ ✶✻ ✴ ✹✸

slide-43
SLIDE 43

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

a (a, ϕ) a (a, b) b = s · a + ϕ secret key: s ∈ {0, 1}n ϕ = b − s · a

✶✻ ✴ ✹✸

slide-44
SLIDE 44

▲❲❊ s②♠♠❡tr✐❝ ❡♥❝r②♣t✐♦♥

a (a, b) b = s · a + ϕ secret key: s ∈ {0, 1}n ϕ = b − s · a

❚r✐✈✐❛❧ ▲❲❊ s❛♠♣❧❡s

▲❲❊ s❛♠♣❧❡s ✇✐t❤ ♠❛s❦ a = 0 ❛r❡ tr✐✈✐❛❧✳ ❚❤❡② ♥❡✈❡r ♦❝❝✉r ✐♥ ❣❡♥❡r❛❧ ✳✳✳❜✉t ❛r❡ st✐❧❧ ✇♦rt❤ ♠❡♥t✐♦♥♥✐♥❣✦

✶✻ ✴ ✹✸

slide-45
SLIDE 45

▲❲❊

❍♦♠♦♠♦r♣❤✐❝ Pr♦♣❡rt✐❡s

a a′ a′′ + = b′′ b b′ x a′′ = x · a + y · a′ b′′ = x · b + y · b′ y

✶✼ ✴ ✹✸

slide-46
SLIDE 46

▲❲❊

❍♦♠♦♠♦r♣❤✐❝ Pr♦♣❡rt✐❡s

a a′ a′′ + = b′′ b b′ x a′′ = x · a + y · a′ b′′ = x · b + y · b′ y a a′′ a′ + = ϕ′′ ϕ ϕ′ ϕ′′ = x · ϕ + y · ϕ′ x y

✶✼ ✴ ✹✸

slide-47
SLIDE 47

▲❲❊

❍♦♠♦♠♦r♣❤✐❝ Pr♦♣❡rt✐❡s

a a′ a′′ + = b′′ b b′ x a′′ = x · a + y · a′ b′′ = x · b + y · b′ y a a′′ a′ + = ϕ′′ ϕ ϕ′ ϕ′′ = x · ϕ + y · ϕ′ x y µ′′ µ = E(ϕ) µ′ µ′′ = x · µ + y · µ′ µ′′ µ = E(ϕ) µ′ µ′′ = x · µ + y · µ′

✶✼ ✴ ✹✸

slide-48
SLIDE 48

▲❲❊

❍♦♠♦♠♦r♣❤✐❝ Pr♦♣❡rt✐❡s

a a′ a′′ + = b′′ b b′ x a′′ = x · a + y · a′ b′′ = x · b + y · b′ y a a′′ a′ + = ϕ′′ ϕ ϕ′ ϕ′′ = x · ϕ + y · ϕ′ x y µ′′ µ = E(ϕ) µ′ µ′′ = x · µ + y · µ′ µ′′ µ = E(ϕ) µ′ µ′′ = x · µ + y · µ′ α′′ α = stdev(ϕ) α′ α′′2 = x2α2 + y2α′2

✶✼ ✴ ✹✸

slide-49
SLIDE 49

▲❲❊

❍♦♠♦♠♦r♣❤✐❝ Pr♦♣❡rt✐❡s

a a′ a′′ + = b′′ b b′ x a′′ = x · a + y · a′ b′′ = x · b + y · b′ y a a′′ a′ + = ϕ′′ ϕ ϕ′ ϕ′′ = x · ϕ + y · ϕ′ x y µ′′ µ = E(ϕ) µ′ µ′′ = x · µ + y · µ′ µ′′ µ = E(ϕ) µ′ µ′′ = x · µ + y · µ′ α′′ α = stdev(ϕ) α′ α′′2 = x2α2 + y2α′2 Ω: The only proba. space where this intuitive picture makes sense!

✶✼ ✴ ✹✸

slide-50
SLIDE 50

▲❲❊

▲❲❊ ❂ ▲❡❛r♥✐♥❣ ❲✐t❤ ❊rr♦rs ❬❘❡❣✵✺❪ ❘✐♥❣✲▲❲❊ ❬▲P❘✶✵❪

■♥ ♦✉r ♣❛♣❡r

▲❲❊✿ ❞❡✜♥✐t✐♦♥ s✐♠✐❧❛r t♦ ❬❇▲P❘❙✶✸❪✱❬❈❙✶✺❪✱❬❈●●■✶✻❪ ❚▲❲❊✿ ❣❡♥❡r❛❧✐③❡❞ ❞❡✜♥✐t✐♦♥ s✐♠✐❧❛r t♦ ❬❇●❱✶✷❪

✶✽ ✴ ✹✸

slide-51
SLIDE 51

▲❲❊

▲❲❊ ❂ ▲❡❛r♥✐♥❣ ❲✐t❤ ❊rr♦rs ❬❘❡❣✵✺❪ ❘✐♥❣✲▲❲❊ ❬▲P❘✶✵❪

■♥ ♦✉r ♣❛♣❡r

▲❲❊✿ ❞❡✜♥✐t✐♦♥ s✐♠✐❧❛r t♦ ❬❇▲P❘❙✶✸❪✱❬❈❙✶✺❪✱❬❈●●■✶✻❪ ❚▲❲❊✿ ❣❡♥❡r❛❧✐③❡❞ ❞❡✜♥✐t✐♦♥ s✐♠✐❧❛r t♦ ❬❇●❱✶✷❪

✶✽ ✴ ✹✸

slide-52
SLIDE 52

❚▲❲❊ ❊♥❝r②♣t✐♦♥

T

N[X]k+1

H

TLWE Samples ϕs : T

N[X]k+1 → T N[X]

(a, b) → b − s · a

✶✾ ✴ ✹✸

slide-53
SLIDE 53

❚▲❲❊ ❊♥❝r②♣t✐♦♥

T

N[X]k+1

H

TLWE Samples Trivial {(0, µ)}

M

µ Im ϕs isom samples ϕs : T

N[X]k+1 → T N[X]

(a, b) → b − s · a

✶✾ ✴ ✹✸

slide-54
SLIDE 54

❚▲❲❊ ❊♥❝r②♣t✐♦♥

Homogeneous ker ϕs

Γ

samples

= ⊕

T

N[X]k+1

H

TLWE Samples Trivial {(0, µ)}

M

µ Im ϕs isom samples ϕs : T

N[X]k+1 → T N[X]

(a, b) → b − s · a

✶✾ ✴ ✹✸

slide-55
SLIDE 55

❚▲❲❊ ❊♥❝r②♣t✐♦♥

Homogeneous ker ϕs

Γ

samples

= ⊕

T

N[X]k+1

H

TLWE Samples Trivial {(0, µ)}

M

µ Im ϕs isom samples ϕs : T

N[X]k+1 → T N[X]

(a, b) → b − s · a encrypt: add z ∈ ker ϕs µ c = z + (0, µ) decrypt: apply ϕs c µ = ϕs(c)

✶✾ ✴ ✹✸

slide-56
SLIDE 56

❚▲❲❊ ❊♥❝r②♣t✐♦♥

(Approx of R-module) Homogeneous ker ϕs

Γ

samples

= ⊕

T

N[X]k+1

H

TLWE Samples Trivial {(0, µ)}

M

µ Im ϕs isom samples ϕs : T

N[X]k+1 → T N[X]

(a, b) → b − s · a encrypt: add approx(z ∈ ker ϕs) µ c = z + (0, µ) decrypt: apply ϕs... c approx(µ) = ϕs(c)

✶✾ ✴ ✹✸

slide-57
SLIDE 57

❚▲❲❊ ❊♥❝r②♣t✐♦♥

(Approx of R-module) Homogeneous ker ϕs

Γ

samples

= ⊕

T

N[X]k+1

H

TLWE Samples Trivial {(0, µ)}

M

µ Im ϕs isom samples ϕs : T

N[X]k+1 → T N[X]

(a, b) → b − s · a encrypt: add approx(z ∈ ker ϕs) µ c = z + (0, µ) decrypt: apply ϕs... c approx(µ) = ϕs(c) Option 1: µ = E(ϕs(c)) (in the relevant proba. space) Option 2: µ = round(ϕs(c)) On a given finite message space M The Ω-space logic The logic of the decryption algorithm

! !

How to recover µ exactly?

✶✾ ✴ ✹✸

slide-58
SLIDE 58

❚❛❜❧❡ ♦❢ ❝♦♥t❡♥ts

✶ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♣♣❧✐❝❛t✐♦♥s

✷ ❚▲❲❊

❚❤❡ r❡❛❧ t♦r✉s ▲❲❊ ❛♥❞ ❚▲❲❊

✸ ❚●❙❲ ❛♥❞ t❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t

❊♥❝r②♣t✐♦♥ ❛♥❞ ●❛❞❣❡t ❚▲❲❊ ❛♥❞ ❚●❙❲

✹ ❋❛st❡r ❇♦♦tstr❛♣♣✐♥❣

  • ❛t❡ ❜♦♦tstr❛♣♣✐♥❣

❙❡❝✉r✐t② ❛♥❛❧②s✐s

✺ ❈♦♥❝❧✉s✐♦♥

✷✵ ✴ ✹✸

slide-59
SLIDE 59
  • ❙❲

❲❡ ✇❛♥t ❋❍❊✦ ❲❤❛t ✐s st✐❧❧ ♠✐ss✐♥❣ t♦ ❤❛✈❡ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥❄

  • ❙❲ ❬●❙❲✶✸❪ ✐s ❛ ❋❍❊ s❝❤❡♠❡ ❜❛s❡❞ ♦♥ ▲❲❊

❘❡❧✐❡s ♦♥ ❛ ❣❛❞❣❡t ❞❡❝♦♠♣♦s✐t✐♦♥ ❢✉♥❝t✐♦♥

■♥ t❤✐s t❛❧❦

❆❜str❛❝t✐♦♥ ♦❢ ❬●❙❲✶✸❪ ❜② ❬●■◆❳✶✻❪ ❚●❙❲✿ ✧●❙❲✧ ♦♥

✷✶ ✴ ✹✸

slide-60
SLIDE 60
  • ❙❲

❲❡ ✇❛♥t ❋❍❊✦ ❲❤❛t ✐s st✐❧❧ ♠✐ss✐♥❣ t♦ ❤❛✈❡ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥❄

  • ❙❲ ❬●❙❲✶✸❪ ✐s ❛ ❋❍❊ s❝❤❡♠❡ ❜❛s❡❞ ♦♥ ▲❲❊

❘❡❧✐❡s ♦♥ ❛ ❣❛❞❣❡t ❞❡❝♦♠♣♦s✐t✐♦♥ ❢✉♥❝t✐♦♥

■♥ t❤✐s t❛❧❦

❆❜str❛❝t✐♦♥ ♦❢ ❬●❙❲✶✸❪ ❜② ❬●■◆❳✶✻❪ ❚●❙❲✿ ✧●❙❲✧ ♦♥

✷✶ ✴ ✹✸

slide-61
SLIDE 61
  • ❙❲

❲❡ ✇❛♥t ❋❍❊✦ ❲❤❛t ✐s st✐❧❧ ♠✐ss✐♥❣ t♦ ❤❛✈❡ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥❄

  • ❙❲ ❬●❙❲✶✸❪ ✐s ❛ ❋❍❊ s❝❤❡♠❡ ❜❛s❡❞ ♦♥ ▲❲❊

❘❡❧✐❡s ♦♥ ❛ ❣❛❞❣❡t ❞❡❝♦♠♣♦s✐t✐♦♥ ❢✉♥❝t✐♦♥

■♥ t❤✐s t❛❧❦

❆❜str❛❝t✐♦♥ ♦❢ ❬●❙❲✶✸❪ ❜② ❬●■◆❳✶✻❪ ❚●❙❲✿ ✧●❙❲✧ ♦♥ T

✷✶ ✴ ✹✸

slide-62
SLIDE 62

❚●❙❲ ❚❤❡ ❣❛❞❣❡t

v = ( v1 | . . . | vk+1 ) ∈ H h =                  1/2 . . . 1/22 . . . ✳ ✳ ✳ ✳✳✳ ✳ ✳ ✳ 1/2ℓ . . . ✳ ✳ ✳ ✳✳✳ ✳ ✳ ✳ . . . 1/2 . . . 1/22 ✳ ✳ ✳ ✳✳✳ ✳ ✳ ✳ . . . 1/2ℓ                 

h ❣❡♥❡r❛t✐♥❣ ❢❛♠✐❧② ♦❢ H

h ∈ Mℓ′,k+1(TN[X]) h ✐s ❜❧♦❝❦ ❞✐❛❣♦♥❛❧ s✉♣❡r✲✐♥❝r❡❛s✐♥❣ ❲❡ ❛r❡ ❛❜❧❡ t♦ ❞❡❝♦♠♣♦s❡ ❡❧❡♠❡♥ts ✐♥ t❤❡ s✉❜✲♠♦❞✉❧❡ H ❚❤❡ ❝♦❡✣❝✐❡♥ts ✐♥ t❤❡ ❞❡❝♦♠♣♦s✐t✐♦♥ ❛r❡ s♠❛❧❧ ❆♣♣r♦①✐♠❛t❡❞ ❞❡❝♦♠♣♦s✐t✐♦♥ ✭✉♣ t♦ s♦♠❡ ♣r❡❝✐s✐♦♥ ♣❛r❛♠❡t❡rs✮ ■♠♣r♦✈❡ t✐♠❡ ❛♥❞ ♠❡♠♦r② r❡q✉✐r❡♠❡♥ts ❢♦r ❛ s♠❛❧❧ ❛♠♦✉♥t ♦❢ ❛❞❞✐t✐♦♥❛❧ ♥♦✐s❡

✷✷ ✴ ✹✸

slide-63
SLIDE 63

❚●❙❲

P❛r❛♠❡t❡rs ▲❡t H = TN[X]k × TN[X] h = (h1, . . . , hl) ∈ Hℓ′ ❛ s✉♣❡r✲✐♥❝r❡❛s✐♥❣ ❣❡♥❡r❛t✐♥❣ ❢❛♠✐❧② ♦❢ H Dech t❤❡ ✧s♠❛❧❧✧ ❞❡❝♦♠♣♦s✐t✐♦♥ ❢✉♥❝t✐♦♥ ❢r♦♠ H → Rℓ′ ✭R = Z[X]/(XN + 1)✮ s✉❝❤ t❤❛t Dech(x) · h = x ❢♦r ❛❧❧ x ∈ H Γ = kerϕs ❞❡♥♦t❡s ❤♦♠♦❣❡♥❡♦✉s ❚▲❲❊ s❛♠♣❧❡s

❊♥❝r②♣t✐♦♥✿

✇❤❡r❡

❍♦♠♦♠♦r♣❤✐❝ ♦♣❡r❛t✐♦♥s✿

▲❡t ❛♥❞ ▲✐♥❡❛r ❝♦♠❜✐♥❛t✐♦♥s✿ ❡♥❝r②♣ts ✭ ✮ ▼✉❧t✐♣❧✐❝❛t✐♦♥ ✿ ❡♥❝r②♣ts

✷✸ ✴ ✹✸

slide-64
SLIDE 64

❚●❙❲

P❛r❛♠❡t❡rs ▲❡t H = TN[X]k × TN[X] h = (h1, . . . , hl) ∈ Hℓ′ ❛ s✉♣❡r✲✐♥❝r❡❛s✐♥❣ ❣❡♥❡r❛t✐♥❣ ❢❛♠✐❧② ♦❢ H Dech t❤❡ ✧s♠❛❧❧✧ ❞❡❝♦♠♣♦s✐t✐♦♥ ❢✉♥❝t✐♦♥ ❢r♦♠ H → Rℓ′ ✭R = Z[X]/(XN + 1)✮ s✉❝❤ t❤❛t Dech(x) · h = x ❢♦r ❛❧❧ x ∈ H Γ = kerϕs ❞❡♥♦t❡s ❤♦♠♦❣❡♥❡♦✉s ❚▲❲❊ s❛♠♣❧❡s

❊♥❝r②♣t✐♦♥✿

C = Z + µ · h ✇❤❡r❡ Z ∈ Γℓ′

❍♦♠♦♠♦r♣❤✐❝ ♦♣❡r❛t✐♦♥s✿

▲❡t ❛♥❞ ▲✐♥❡❛r ❝♦♠❜✐♥❛t✐♦♥s✿ ❡♥❝r②♣ts ✭ ✮ ▼✉❧t✐♣❧✐❝❛t✐♦♥ ✿ ❡♥❝r②♣ts

✷✸ ✴ ✹✸

slide-65
SLIDE 65

❚●❙❲

P❛r❛♠❡t❡rs ▲❡t H = TN[X]k × TN[X] h = (h1, . . . , hl) ∈ Hℓ′ ❛ s✉♣❡r✲✐♥❝r❡❛s✐♥❣ ❣❡♥❡r❛t✐♥❣ ❢❛♠✐❧② ♦❢ H Dech t❤❡ ✧s♠❛❧❧✧ ❞❡❝♦♠♣♦s✐t✐♦♥ ❢✉♥❝t✐♦♥ ❢r♦♠ H → Rℓ′ ✭R = Z[X]/(XN + 1)✮ s✉❝❤ t❤❛t Dech(x) · h = x ❢♦r ❛❧❧ x ∈ H Γ = kerϕs ❞❡♥♦t❡s ❤♦♠♦❣❡♥❡♦✉s ❚▲❲❊ s❛♠♣❧❡s

❊♥❝r②♣t✐♦♥✿

C = Z + µ · h ✇❤❡r❡ Z ∈ Γℓ′

❍♦♠♦♠♦r♣❤✐❝ ♦♣❡r❛t✐♦♥s✿

▲❡t C1 = Z1 + µ1 · h ❛♥❞ C2 = Z2 + µ2 · h ▲✐♥❡❛r ❝♦♠❜✐♥❛t✐♦♥s✿ δ1C1 + δ2C2 ❡♥❝r②♣ts δ1µ1 + δ2µ2 ✭δi ∈ R✮ ▼✉❧t✐♣❧✐❝❛t✐♦♥ ✿ Dech(C1) · C2 ❡♥❝r②♣ts µ1µ2

✷✸ ✴ ✹✸

slide-66
SLIDE 66

❚♦② ❡①❛♠♣❧❡ ✭✇✐t❤♦✉t ♥♦✐s❡✮

ϕs = ·4

1 100Z/Z 1 4Z/Z

=

1 25Z/Z

Imϕs

( i s

  • m

)

P❛r❛♠❡t❡rs H =

1 100Z/Z = 1 4Z/Z ⊕ 1 25Z/Z ✭✐s ❛ Z✲♠♦❞✉❧❡✮

h = 1

100, 2 100, 5 100, 10 100, 20 100, 50 100

  • Dech✿ ❞❡❝♦♠♣♦s✐t✐♦♥ ✐♥ ❊✉r♦ ❝♦✐♥s

Γ = 1

4Z/Z ⊂ H✿ ♠♦❞✉❧♦ ♦❢ t❤❡ ❝♦❞❡

❙❛♠♣❧❡s

✷✹ ✴ ✹✸

slide-67
SLIDE 67

❚♦② ❡①❛♠♣❧❡ ✭✇✐t❤♦✉t ♥♦✐s❡✮

ϕs = ·4

1 100Z/Z 1 4Z/Z

=

1 25Z/Z

Imϕs

( i s

  • m

)

P❛r❛♠❡t❡rs H =

1 100Z/Z = 1 4Z/Z ⊕ 1 25Z/Z ✭✐s ❛ Z✲♠♦❞✉❧❡✮

h = 1

100, 2 100, 5 100, 10 100, 20 100, 50 100

  • Dech✿ ❞❡❝♦♠♣♦s✐t✐♦♥ ✐♥ ❊✉r♦ ❝♦✐♥s

Γ = 1

4Z/Z ⊂ H✿ ♠♦❞✉❧♦ ♦❢ t❤❡ ❝♦❞❡

❙❛♠♣❧❡s

C1 = 32 100, 14 100, 60 100, 45 100, 90 100, 100

  • =

1 4, 0 4, 1 4, 3 4, 2 4, 2 4

  • + 7 · h

C2 = 73 100, 21 100, 40 100, 5 100, 35 100, 50 100

  • =

3 4, 1 4, 2 4, 1 4, 3 4, 2 4

  • − 2 · h

✷✹ ✴ ✹✸

slide-68
SLIDE 68

❚♦② ❡①❛♠♣❧❡ ✭✇✐t❤♦✉t ♥♦✐s❡✮

▼✉❧t✐♣❧✐❝❛t✐♦♥✿ Dech(C1) · C2 =         1 1 1 2 1 1 1 1 2 2 1                 73/100 21/100 40/100 5/100 35/100 50/100         = 61 100, 47 100, 55 100, 10 100, 20 100, 0 100

  • ❱❡r✐✜❝❛t✐♦♥✿ ❞♦❡s ❡♥❝♦❞❡ 7 · (−2) = 11 mod 25

61 100, 47 100, 55 100, 10 100, 20 100, 0 100

  • =

2 4, 1 4, 0 4, 0 4, 0 4, 2 4

  • + 11 · h

✷✺ ✴ ✹✸

slide-69
SLIDE 69

❚♦② ❡①❛♠♣❧❡ ✭✇✐t❤♦✉t ♥♦✐s❡✮

▼✉❧t✐♣❧✐❝❛t✐♦♥✿ Dech(C1) · C2 =         1 1 1 2 1 1 1 1 2 2 1                 73/100 21/100 40/100 5/100 35/100 50/100         = 61 100, 47 100, 55 100, 10 100, 20 100, 0 100

  • ❱❡r✐✜❝❛t✐♦♥✿ ❞♦❡s ❡♥❝♦❞❡ 7 · (−2) = 11 mod 25

61 100, 47 100, 55 100, 10 100, 20 100, 0 100

  • =

2 4, 1 4, 0 4, 0 4, 0 4, 2 4

  • + 11 · h

✷✺ ✴ ✹✸

slide-70
SLIDE 70

❚▲❲❊ ❛♥❞ ❚●❙❲

Γ= ker ϕs

= ⊕

ϕs

H

TLWE

M

T

N[X]

i s

  • m

✷✻ ✴ ✹✸

slide-71
SLIDE 71

❚▲❲❊ ❛♥❞ ❚●❙❲

Γ= ker ϕs

= ⊕

ϕs

H

TLWE

M

T

N[X]

i s

  • m

Hℓ′

TGSW

Γℓ′

R · h R

✷✻ ✴ ✹✸

slide-72
SLIDE 72

❚▲❲❊ ❛♥❞ ❚●❙❲

Γ= ker ϕs

= ⊕

ϕs

H

TLWE

M

T

N[X]

i s

  • m

Hℓ′

TGSW

Γℓ′

R · h R

e · TGSW(A) is a TLWE of A · ϕs(e · h) ∀e ∈ Rℓ′,∀A ∈ R,∀b ∈ T

N[X]: ✷✻ ✴ ✹✸

slide-73
SLIDE 73

❚▲❲❊ ❛♥❞ ❚●❙❲

Γ= ker ϕs

= ⊕

ϕs

H

TLWE

M

T

N[X]

i s

  • m

Hℓ′

TGSW

Γℓ′

R · h R

e · TGSW(A) is a TLWE of A · ϕs(e · h) ∀e ∈ Rℓ′,∀A ∈ R,∀b ∈ T

N[X]:

= ⇒ Decomph(TLWE(b)) · TGSW(A) is a TLWE of A · b

✷✻ ✴ ✹✸

slide-74
SLIDE 74

❚♦② ❡①❛♠♣❧❡ ✭❲■❚❍ ♥♦✐s❡✮

P❛r❛♠❡t❡rs H =

1 100Z/Z = 1 4Z/Z ⊕ 1 25Z/Z ✭✐s ❛ Z✲♠♦❞✉❧❡✮

h = 1

100, 2 100, 5 100, 10 100, 20 100, 50 100

  • Dech✿ ❞❡❝♦♠♣♦s✐t✐♦♥ ✐♥ ❊✉r♦ ❝♦✐♥s

Γ = 1

4Z/Z ⊂ H✿ ♠♦❞✉❧♦ ♦❢ t❤❡ ❝♦❞❡

❙❛♠♣❧❡s

C1 = 31 100, 16 100, 63 100, 46 100, 89 100, 100

  • =

1 4, 0 4, 1 4, 3 4, 2 4, 2 4

  • +
  • − 1

100, 2 100, 3 100, 1 100, − 1 100, 1 100

  • + 7 · h

C2 = 71 100, 23 100, 37 100, 5 100, 33 100, 48 100

  • =

3 4, 1 4, 2 4, 1 4, 3 4, 2 4

  • +
  • − 2

100, 2 100, − 3 100, 100, − 2 100, − 2 100

  • − 2 · h

✷✼ ✴ ✹✸

slide-75
SLIDE 75

❚♦② ❡①❛♠♣❧❡ ✭❲■❚❍ ♥♦✐s❡✮

P❛r❛♠❡t❡rs H =

1 100Z/Z = 1 4Z/Z ⊕ 1 25Z/Z ✭✐s ❛ Z✲♠♦❞✉❧❡✮

h = 1

100, 2 100, 5 100, 10 100, 20 100, 50 100

  • Dech✿ ❞❡❝♦♠♣♦s✐t✐♦♥ ✐♥ ❊✉r♦ ❝♦✐♥s

Γ = 1

4Z/Z ⊂ H✿ ♠♦❞✉❧♦ ♦❢ t❤❡ ❝♦❞❡

❙❛♠♣❧❡s

C1 = 31 100, 16 100, 63 100, 46 100, 89 100, 100

  • =

1 4, 0 4, 1 4, 3 4, 2 4, 2 4

  • +
  • − 1

100, 2 100, 3 100, 1 100, − 1 100, 1 100

  • + 7 · h

C2 = 71 100, 23 100, 37 100, 5 100, 33 100, 48 100

  • =

3 4, 1 4, 2 4, 1 4, 3 4, 2 4

  • +
  • − 2

100, 2 100, − 3 100, 100, − 2 100, − 2 100

  • − 2 · h

✷✼ ✴ ✹✸

slide-76
SLIDE 76

❚♦② ❡①❛♠♣❧❡ ✭❲■❚❍ ♥♦✐s❡✮

▼✉❧t✐♣❧✐❝❛t✐♦♥✿ Dech(C1,1) · C2 = [ 1

1 1 0 ]

      

71/100 23/100 37/100 5/100 33/100 48/100

       Dech(C1,1) · C2 = 9 100

  • ❱❡r✐✜❝❛t✐♦♥✿ ❞♦❡s ❡♥❝♦❞❡ 7 · (−2) = 11 mod 25

9 100

  • =

4

2 100

  • + 11 · h1

✷✽ ✴ ✹✸

slide-77
SLIDE 77

Pr♦❞✉❝t

❊①t❡r♥❛❧ ♣r♦❞✉❝t ✭❢♦✉♥❞ ✐♥❞❡♣❡♥❞❡♥t❧② ❜② ❬❇P✶✻❪✮ ⊡: TGSW × TLWE − → TLWE (A, b) − → A ⊡ b = Dech,β,ǫ(b) · A (µA, µb) − → µA · µb ✇❤❡r❡ Dech,β,ǫ ✐s t❤❡ ❛♣♣r♦①✐♠❛t❡ ❣❛❞❣❡t ❞❡❝♦♠♣♦s✐t✐♦♥ ■♥t❡r♥❛❧ ♣r♦❞✉❝t ✭❝❧❛ss✐❝❛❧✮ ✳ ✳ ✳

✷✾ ✴ ✹✸

slide-78
SLIDE 78

Pr♦❞✉❝t

❊①t❡r♥❛❧ ♣r♦❞✉❝t ✭❢♦✉♥❞ ✐♥❞❡♣❡♥❞❡♥t❧② ❜② ❬❇P✶✻❪✮ ⊡: TGSW × TLWE − → TLWE (A, b) − → A ⊡ b = Dech,β,ǫ(b) · A (µA, µb) − → µA · µb ✇❤❡r❡ Dech,β,ǫ ✐s t❤❡ ❛♣♣r♦①✐♠❛t❡ ❣❛❞❣❡t ❞❡❝♦♠♣♦s✐t✐♦♥ ■♥t❡r♥❛❧ ♣r♦❞✉❝t ✭❝❧❛ss✐❝❛❧✮ ⊠: TGSW × TGSW − → TGSW (A, B) − → A ⊠ B =    A ⊡ b1 ✳ ✳ ✳ A ⊡ b(k+1)ℓ    (µA, µB) − → µA · µB

✷✾ ✴ ✹✸

slide-79
SLIDE 79

Pr♦❞✉❝t

µA T-LWE T-GSW µb µA · µb T-LWE ηA ηb µA1 ηb + O(ηA) ❊rr(A ⊡ b)∞ ≤ ℓ′NβηA + µA1 (1 + kN)ǫ + µA1 ηb ✇❤❡r❡ β ❛♥❞ ǫ ❛r❡ t❤❡ ♣❛r❛♠❡t❡rs ✉s❡❞ ✐♥ t❤❡ ❞❡❝♦♠♣♦s✐t✐♦♥ Dech,β,ǫ(b)✳

✸✵ ✴ ✹✸

slide-80
SLIDE 80

❚❛❜❧❡ ♦❢ ❝♦♥t❡♥ts

✶ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♣♣❧✐❝❛t✐♦♥s

✷ ❚▲❲❊

❚❤❡ r❡❛❧ t♦r✉s ▲❲❊ ❛♥❞ ❚▲❲❊

✸ ❚●❙❲ ❛♥❞ t❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t

❊♥❝r②♣t✐♦♥ ❛♥❞ ●❛❞❣❡t ❚▲❲❊ ❛♥❞ ❚●❙❲

✹ ❋❛st❡r ❇♦♦tstr❛♣♣✐♥❣

  • ❛t❡ ❜♦♦tstr❛♣♣✐♥❣

❙❡❝✉r✐t② ❛♥❛❧②s✐s

✺ ❈♦♥❝❧✉s✐♦♥

✸✶ ✴ ✹✸

slide-81
SLIDE 81

❋❛st❡r ❜♦♦tstr❛♣♣✐♥❣

❲❡ ❛♣♣❧✐❡❞ ♦✉r r❡s✉❧t t♦ t❤❡ ❢❛st ❜♦♦tstr❛♣♣✐♥❣ ♣r♦♣♦s❡❞ ❜② ❉✉❝❛s ❛♥❞ ▼✐❝❝✐❛♥❝✐♦ ✭❊✉r♦❝r②♣t ✷✵✶✺✮ ❬❉▼✶✺❪✿ ❤♦♠♦♠♦r♣❤✐❝ ◆❆◆❉ ❣❛t❡ ✇✐t❤ ❢❛st ❜♦♦tstr❛♣♣✐♥❣ ✐♥ ∼ 0.69 s❡❝♦♥❞s ❲❡ r❡♣❧❛❝❡❞ ❛❧❧ t❤❡ ✐♥t❡r♥❛❧ ♣r♦❞✉❝ts ✐♥ t❤❡ ❜♦♦tstr❛♣♣✐♥❣ ♣r♦❝❡❞✉r❡ ✇✐t❤ t❤❡ ❡①t❡r♥❛❧ ♦♥❡✳ ❘❡s✉❧t✿ ✭✇✐t❤ ❢✉rt❤❡r ♦♣t✐♠✐③❛t✐♦♥s✮ ✇❡ ❤❛❞ ❛ s♣❡❡❞✲✉♣ ♦❢ ❛ ❢❛❝t♦r ✭❜♦♦tstr❛♣♣✐♥❣ ✐♥ s❡❝♦♥❞s✮

✸✷ ✴ ✹✸

slide-82
SLIDE 82

❋❛st❡r ❜♦♦tstr❛♣♣✐♥❣

❲❡ ❛♣♣❧✐❡❞ ♦✉r r❡s✉❧t t♦ t❤❡ ❢❛st ❜♦♦tstr❛♣♣✐♥❣ ♣r♦♣♦s❡❞ ❜② ❉✉❝❛s ❛♥❞ ▼✐❝❝✐❛♥❝✐♦ ✭❊✉r♦❝r②♣t ✷✵✶✺✮ ❬❉▼✶✺❪✿ ❤♦♠♦♠♦r♣❤✐❝ ◆❆◆❉ ❣❛t❡ ✇✐t❤ ❢❛st ❜♦♦tstr❛♣♣✐♥❣ ✐♥ ∼ 0.69 s❡❝♦♥❞s ❲❡ r❡♣❧❛❝❡❞ ❛❧❧ t❤❡ ✐♥t❡r♥❛❧ ♣r♦❞✉❝ts ✐♥ t❤❡ ❜♦♦tstr❛♣♣✐♥❣ ♣r♦❝❡❞✉r❡ ✇✐t❤ t❤❡ ❡①t❡r♥❛❧ ♦♥❡✳ ❘❡s✉❧t✿ ✭✇✐t❤ ❢✉rt❤❡r ♦♣t✐♠✐③❛t✐♦♥s✮ ✇❡ ❤❛❞ ❛ s♣❡❡❞✲✉♣ ♦❢ ❛ ❢❛❝t♦r ∼ 12 ✭❜♦♦tstr❛♣♣✐♥❣ ✐♥ ∼ 0.052 s❡❝♦♥❞s✮

✸✷ ✴ ✹✸

slide-83
SLIDE 83

❇♦♦tstr❛♣♣✐♥❣

1 2 1 4 3 4

✸✸ ✴ ✹✸

slide-84
SLIDE 84

❇♦♦tstr❛♣♣✐♥❣

1 2 1 4 3 4

✸✸ ✴ ✹✸

slide-85
SLIDE 85

❇♦♦tstr❛♣♣✐♥❣

1 2 1 4 3 4

[Gentry09]-style bootstrap

✸✸ ✴ ✹✸

slide-86
SLIDE 86

❇♦♦tstr❛♣♣✐♥❣

1 2 1 4 3 4

[Gentry09]-style bootstrap

✸✸ ✴ ✹✸

slide-87
SLIDE 87

❇♦♦tstr❛♣♣✐♥❣

1 2 1 4 3 4

[DM15]-style bootstrap

✸✸ ✴ ✹✸

slide-88
SLIDE 88
  • ❛t❡ ❇♦♦tstr❛♣♣✐♥❣

false := LWE(− 1

8), noise< 1 16 1 2 1 4 3 4 1 8

− 1

8

✸✹ ✴ ✹✸

slide-89
SLIDE 89
  • ❛t❡ ❇♦♦tstr❛♣♣✐♥❣

true := LWE(+ 1

8), noise < 1 16 1 2 1 4 3 4 1 8

− 1

8

✸✹ ✴ ✹✸

slide-90
SLIDE 90
  • ❛t❡ ❇♦♦tstr❛♣♣✐♥❣

= + c1 c2

1 2 1 4 3 4 1 8

− 1

8

✸✹ ✴ ✹✸

slide-91
SLIDE 91
  • ❛t❡ ❇♦♦tstr❛♣♣✐♥❣

c1 c2 NAND( , ) : return false return true

1 2 1 4 3 4 1 8

− 1

8

✸✹ ✴ ✹✸

slide-92
SLIDE 92
  • ❛t❡ ❇♦♦tstr❛♣♣✐♥❣

c1 c2 NAND( , ) : return false return true

1 2 1 4 3 4 1 8

− 1

8

✸✹ ✴ ✹✸

slide-93
SLIDE 93
  • ❛t❡ ❇♦♦tstr❛♣♣✐♥❣

1 2 1 4 3 4

[DM15/BR15]-(revisited) [. . . ] v0 v1 v2 vi vi+1 v2N−1

✸✹ ✴ ✹✸

slide-94
SLIDE 94

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts

✭ ✮ ✇❤❡♥ ✐s ❦♥♦✇♥ ✭ ✮ ✇❤❡♥ ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② ❄

✶ ▼✉❧t✐♣❧② ❜② ✷ ❋♦r

♠✉❧t✐♣❧② ❜②

✇✐t❤ ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-95
SLIDE 95

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts

✭ ✮ ✇❤❡♥ ✐s ❦♥♦✇♥ ✭ ✮ ✇❤❡♥ ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② ❄

✶ ▼✉❧t✐♣❧② ❜② ✷ ❋♦r

♠✉❧t✐♣❧② ❜②

✇✐t❤ ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-96
SLIDE 96

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② p ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts c ∈ TLWE

✭ ✮ ✇❤❡♥ ✐s ❦♥♦✇♥ ✭ ✮ ✇❤❡♥ ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② ❄

✶ ▼✉❧t✐♣❧② ❜② ✷ ❋♦r

♠✉❧t✐♣❧② ❜②

✇✐t❤ ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-97
SLIDE 97

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② p ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts c ∈ TLWE

✭Xp · c✮ ✇❤❡♥ p ✐s ❦♥♦✇♥ ✭ ✮ ✇❤❡♥ ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② ❄

✶ ▼✉❧t✐♣❧② ❜② ✷ ❋♦r

♠✉❧t✐♣❧② ❜②

✇✐t❤ ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-98
SLIDE 98

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② p ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts c ∈ TLWE

✭Xp · c✮ ✇❤❡♥ p ✐s ❦♥♦✇♥ ✭TGSW(Xp) ⊡ c✮ ✇❤❡♥ p ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② ❄

✶ ▼✉❧t✐♣❧② ❜② ✷ ❋♦r

♠✉❧t✐♣❧② ❜②

✇✐t❤ ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-99
SLIDE 99

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② p ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts c ∈ TLWE

✭Xp · c✮ ✇❤❡♥ p ✐s ❦♥♦✇♥ ✭TGSW(Xp) ⊡ c✮ ✇❤❡♥ p ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② −ϕs(a, b) = −b + n

i=1 aisi❄

✶ ▼✉❧t✐♣❧② ❜② ✷ ❋♦r

♠✉❧t✐♣❧② ❜②

✇✐t❤ ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-100
SLIDE 100

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② p ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts c ∈ TLWE

✭Xp · c✮ ✇❤❡♥ p ✐s ❦♥♦✇♥ ✭TGSW(Xp) ⊡ c✮ ✇❤❡♥ p ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② −ϕs(a, b) = −b + n

i=1 aisi❄

✶ ▼✉❧t✐♣❧② ❜② X−b ✷ ❋♦r

♠✉❧t✐♣❧② ❜②

✇✐t❤ ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-101
SLIDE 101

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② p ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts c ∈ TLWE

✭Xp · c✮ ✇❤❡♥ p ✐s ❦♥♦✇♥ ✭TGSW(Xp) ⊡ c✮ ✇❤❡♥ p ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② −ϕs(a, b) = −b + n

i=1 aisi❄

✶ ▼✉❧t✐♣❧② ❜② X−b ✷ ❋♦r i ∈ [1, n] ♠✉❧t✐♣❧② ❜② TGSW(X−aisi)

✇✐t❤ ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-102
SLIDE 102

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② p ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts c ∈ TLWE

✭Xp · c✮ ✇❤❡♥ p ✐s ❦♥♦✇♥ ✭TGSW(Xp) ⊡ c✮ ✇❤❡♥ p ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② −ϕs(a, b) = −b + n

i=1 aisi❄

✶ ▼✉❧t✐♣❧② ❜② X−b ✷ ❋♦r i ∈ [1, n] ♠✉❧t✐♣❧② ❜② TGSW(X−aisi)

Xaisi = 1 + (Xai − 1) · si, ✇✐t❤ si ∈ {0, 1} ✱ ✇❤❡r❡ ❇❑

✸✺ ✴ ✹✸

slide-103
SLIDE 103

❇♦♦tstr❛♣♣✐♥❣ ❆❧❣♦r✐t❤♠ ✭❛♥✐♠❛t✐♦♥✮

❇♦♦tstr❛♣♣✐♥❣ ❛❧❣♦r✐t❤♠ ♦❢ (a, b)

✶ ❙t❛rt ❢r♦♠ ✭❛ tr✐✈✐❛❧✮ TLWE(v0 + v1X + · · · + vN−1XN−1)❛ ✷ ❘♦t❛t❡ ✐t ❜② p = −ϕs(a, b) ♣♦s✐t✐♦♥s ✸ ❊①tr❛❝t t❤❡ ❝♦♥st❛♥t t❡r♠ ✭✇❤✐❝❤ ❡♥❝r②♣ts vp✮

❛N ❝♦❡❢s ♠♦❞ XN + 1 ❝❛♥ ❜❡ ✈✐❡✇❡❞ ❛s 2N ❝♦❡❢s ♠♦❞ X2N − 1 s✳t✳ vN+i = −vi

❘♦t❛t❡ ❜② p ♣♦s✐t✐♦♥s t❤❡ ❝♦❡✣❝✐❡♥ts c ∈ TLWE

✭Xp · c✮ ✇❤❡♥ p ✐s ❦♥♦✇♥ ✭TGSW(Xp) ⊡ c✮ ✇❤❡♥ p ✐s ✉♥❦♥♦✇♥

❍♦✇ t♦ r♦t❛t❡ ❜② −ϕs(a, b) = −b + n

i=1 aisi❄

✶ ▼✉❧t✐♣❧② ❜② X−b ✷ ❋♦r i ∈ [1, n] ♠✉❧t✐♣❧② ❜② TGSW(X−aisi)

Xaisi = 1 + (Xai − 1) · si, ✇✐t❤ si ∈ {0, 1} TGSW(Xaisi) = h + (Xai − 1) · TGSW(si)✱ ✇❤❡r❡ ❇❑ = TGSW(si)

✸✺ ✴ ✹✸

slide-104
SLIDE 104

❙❡❝✉r✐t② ❛♥❛❧②s✐s

◆✉♠❡r✐❝❛❧ s❡❝✉r✐t② ❡st✐♠❛t❡s

❇❛s❡❞ ♦♥ ❬❆P❙✶✺❪✱❬▲P✶✶❪✱❬❉▼✶✺❪ r❡s✉❧ts

✶ ❈♦♥✈❡rt t❤❡ ✐♥st❛♥❝❡ t♦ ❛ ❧❛tt✐❝❡ ♣r♦❜❧❡♠

✇❡ t❡st❡❞✿ ❯♥✐q✉❡❙❱P✱ r❡❞ t♦ ❙■❙✱ ♠♦❞❙✇✐t❝❤✳✳✳

✷ ❆♣♣❧② t❤❡ ❜❡st ❤❡✉r✐st✐❝s ✸ ❖♣t✐♠✐③❡❞ ❛❧❧ ♥♦♥✲r❡❧❡✈❛♥t ♣❛r❛♠❡t❡rs✿

tr✐❛❧s

■♠♣♦rt❛♥t s❡❝✉r✐t② ♣❛r❛♠❡t❡rs

✶ ◆♦✐s❡ r❛t❡✿ ✷ ❊♥tr♦♣② ♦❢ t❤❡ s❡❝r❡t✿

❛♥❞ t❤❛t✬s ❛❧❧✦ ❡①♣r❡ss❡❞ s♦❧❡❧② ❛s ❛ ❢✉♥❝t✐♦♥ ♦❢

✸✻ ✴ ✹✸

slide-105
SLIDE 105

❙❡❝✉r✐t② ❛♥❛❧②s✐s

◆✉♠❡r✐❝❛❧ s❡❝✉r✐t② ❡st✐♠❛t❡s

❇❛s❡❞ ♦♥ ❬❆P❙✶✺❪✱❬▲P✶✶❪✱❬❉▼✶✺❪ r❡s✉❧ts

✶ ❈♦♥✈❡rt t❤❡ ✐♥st❛♥❝❡ t♦ ❛ ❧❛tt✐❝❡ ♣r♦❜❧❡♠

✔ ✇❡ t❡st❡❞✿ ❯♥✐q✉❡❙❱P✱ r❡❞ t♦ ❙■❙✱ ♠♦❞❙✇✐t❝❤✳✳✳

✷ ❆♣♣❧② t❤❡ ❜❡st ❤❡✉r✐st✐❝s ✸ ❖♣t✐♠✐③❡❞ ❛❧❧ ♥♦♥✲r❡❧❡✈❛♥t ♣❛r❛♠❡t❡rs✿ m, ε, q, tr✐❛❧s . . .

■♠♣♦rt❛♥t s❡❝✉r✐t② ♣❛r❛♠❡t❡rs

✶ ◆♦✐s❡ r❛t❡✿ ✷ ❊♥tr♦♣② ♦❢ t❤❡ s❡❝r❡t✿

❛♥❞ t❤❛t✬s ❛❧❧✦ ❡①♣r❡ss❡❞ s♦❧❡❧② ❛s ❛ ❢✉♥❝t✐♦♥ ♦❢

✸✻ ✴ ✹✸

slide-106
SLIDE 106

❙❡❝✉r✐t② ❛♥❛❧②s✐s

◆✉♠❡r✐❝❛❧ s❡❝✉r✐t② ❡st✐♠❛t❡s

❇❛s❡❞ ♦♥ ❬❆P❙✶✺❪✱❬▲P✶✶❪✱❬❉▼✶✺❪ r❡s✉❧ts

✶ ❈♦♥✈❡rt t❤❡ ✐♥st❛♥❝❡ t♦ ❛ ❧❛tt✐❝❡ ♣r♦❜❧❡♠

✔ ✇❡ t❡st❡❞✿ ❯♥✐q✉❡❙❱P✱ r❡❞ t♦ ❙■❙✱ ♠♦❞❙✇✐t❝❤✳✳✳

✷ ❆♣♣❧② t❤❡ ❜❡st ❤❡✉r✐st✐❝s ✸ ❖♣t✐♠✐③❡❞ ❛❧❧ ♥♦♥✲r❡❧❡✈❛♥t ♣❛r❛♠❡t❡rs✿ m, ε, q, tr✐❛❧s . . .

■♠♣♦rt❛♥t s❡❝✉r✐t② ♣❛r❛♠❡t❡rs

✶ ◆♦✐s❡ r❛t❡✿ α ✷ ❊♥tr♦♣② ♦❢ t❤❡ s❡❝r❡t✿ n

❛♥❞ t❤❛t✬s ❛❧❧✦ λ ❡①♣r❡ss❡❞ s♦❧❡❧② ❛s ❛ ❢✉♥❝t✐♦♥ ♦❢ (n, α)

✸✻ ✴ ✹✸

slide-107
SLIDE 107

❙❡❝✉r✐t② ♣❛r❛♠❡t❡r ✲ t❤❡ r❛✐♥❜♦✇

5 10 15 20 25 30 35 40 45 200 400 600 800 1000 log2(1/α) n Values of λ(n,α) 32 64 128 256 512 512 384 2 5 6 192 128 8 40

Switch Key

  • Boot. Key
  • Boot. Key [11]

✸✼ ✴ ✹✸

slide-108
SLIDE 108

❚❛❜❧❡ ♦❢ ❝♦♥t❡♥ts

✶ ❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥

❆♣♣❧✐❝❛t✐♦♥s

✷ ❚▲❲❊

❚❤❡ r❡❛❧ t♦r✉s ▲❲❊ ❛♥❞ ❚▲❲❊

✸ ❚●❙❲ ❛♥❞ t❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t

❊♥❝r②♣t✐♦♥ ❛♥❞ ●❛❞❣❡t ❚▲❲❊ ❛♥❞ ❚●❙❲

✹ ❋❛st❡r ❇♦♦tstr❛♣♣✐♥❣

  • ❛t❡ ❜♦♦tstr❛♣♣✐♥❣

❙❡❝✉r✐t② ❛♥❛❧②s✐s

✺ ❈♦♥❝❧✉s✐♦♥

✸✽ ✴ ✹✸

slide-109
SLIDE 109

❚❋❍❊ ✐♠♣❧❡♠❡♥t❛t✐♦♥

❤tt♣s✿✴✴t❢❤❡✳❣✐t❤✉❜✳✐♦✴t❢❤❡✴ ❇❡❢♦r❡✿ ✶ ❜♦♦tstr❛♣♣✐♥❣ ✐♥ ✺✷ ♠s ◆♦✇✿ ✶ ❜♦♦tstr❛♣♣✐♥❣ ✐♥ ✷✵ ♠s

✸✾ ✴ ✹✸

slide-110
SLIDE 110

❚❋❍❊ ✐♠♣❧❡♠❡♥t❛t✐♦♥

❤tt♣s✿✴✴t❢❤❡✳❣✐t❤✉❜✳✐♦✴t❢❤❡✴ ❇❡❢♦r❡✿ ✶ ❜♦♦tstr❛♣♣✐♥❣ ✐♥ ✺✷ ♠s ◆♦✇✿ ✶ ❜♦♦tstr❛♣♣✐♥❣ ✐♥ ✷✵ ♠s

✸✾ ✴ ✹✸

slide-111
SLIDE 111

❚❋❍❊ ✐♠♣❧❡♠❡♥t❛t✐♦♥

❤tt♣s✿✴✴t❢❤❡✳❣✐t❤✉❜✳✐♦✴t❢❤❡✴ ❇❡❢♦r❡✿ ✶ ❜♦♦tstr❛♣♣✐♥❣ ✐♥ ✺✷ ♠s ◆♦✇✿ ✶ ❜♦♦tstr❛♣♣✐♥❣ ✐♥ ✷✵ ♠s

✸✾ ✴ ✹✸

slide-112
SLIDE 112

❈♦♥❝❧✉s✐♦♥

❙✉♠♠❛r② ❈♦♥str✉❝t✐♦♥ ❛♥❞ ❛❜str❛❝t✐♦♥ ♦❢ ❚▲❲❊ ❛♥❞ ❚●❙❲ ❚❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t ⊡ : TGSW × TLWE → TLWE ❋❛st❡r ❜♦♦tstr❛♣♣✐♥❣ ▼♦r❡ ❲❡ ❝❛♥ ❛♣♣❧② ♦✉r r❡s✉❧ts t♦ ❧❡✈❡❧❡❞ ❍❊ s❝❤❡♠❡s ❲❡ ❝❛♥ ✐♠♣r♦✈❡ t❤✐s r❡s✉❧t ❛♥❞ ♠❛❦❡ ❋❍❊ ❢❛st❡r

❚❤❛♥❦ ②♦✉✦

♠✳s✳♥✳

✹✵ ✴ ✹✸

slide-113
SLIDE 113

❈♦♥❝❧✉s✐♦♥

❙✉♠♠❛r② ❈♦♥str✉❝t✐♦♥ ❛♥❞ ❛❜str❛❝t✐♦♥ ♦❢ ❚▲❲❊ ❛♥❞ ❚●❙❲ ❚❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t ⊡ : TGSW × TLWE → TLWE ❋❛st❡r ❜♦♦tstr❛♣♣✐♥❣ ▼♦r❡ ❲❡ ❝❛♥ ❛♣♣❧② ♦✉r r❡s✉❧ts t♦ ❧❡✈❡❧❡❞ ❍❊ s❝❤❡♠❡s ❲❡ ❝❛♥ ✐♠♣r♦✈❡ t❤✐s r❡s✉❧t ❛♥❞ ♠❛❦❡ ❋❍❊ ❢❛st❡r

❚❤❛♥❦ ②♦✉✦

♠✳s✳♥✳

✹✵ ✴ ✹✸

slide-114
SLIDE 114

❈♦♥❝❧✉s✐♦♥

❙✉♠♠❛r② ❈♦♥str✉❝t✐♦♥ ❛♥❞ ❛❜str❛❝t✐♦♥ ♦❢ ❚▲❲❊ ❛♥❞ ❚●❙❲ ❚❤❡ ❡①t❡r♥❛❧ ♣r♦❞✉❝t ⊡ : TGSW × TLWE → TLWE ❋❛st❡r ❜♦♦tstr❛♣♣✐♥❣ ▼♦r❡ ❲❡ ❝❛♥ ❛♣♣❧② ♦✉r r❡s✉❧ts t♦ ❧❡✈❡❧❡❞ ❍❊ s❝❤❡♠❡s ❲❡ ❝❛♥ ✐♠♣r♦✈❡ t❤✐s r❡s✉❧t ❛♥❞ ♠❛❦❡ ❋❍❊ ❢❛st❡r

❚❤❛♥❦ ②♦✉✦

♠✳s✳♥✳

✹✵ ✴ ✹✸

slide-115
SLIDE 115

❇✐❜❧✐♦❣r❛♣❤②

❬❆P❙✶✺❪ ❆❧❜r❡❝❤t✱ ▼✳❘✳✱ P❧❛②❡r✱ ❘✳✱ ❛♥❞ ❙❝♦tt✱ ❙✳✱ ✧❖♥ t❤❡ ❝♦♥❝r❡t❡ ❤❛r❞♥❡ss ♦❢ ❧❡❛r♥✐♥❣ ✇✐t❤ ❡rr♦rs✳✧ ❏♦✉r♥❛❧ ♦❢ ▼❛t❤❡♠❛t✐❝❛❧ ❈r②♣t♦❧♦❣② ✾✳✸ ✭✷✵✶✺✮✿ ✶✻✾✲✷✵✸✳ ❬❇●❱✶✷❪ ❇r❛❦❡rs❦✐✱ ❩✳✱ ●❡♥tr②✱ ❈✳✱ ❛♥❞ ❱❛✐❦✉♥t❛♥❛t❤❛♥✱ ❱✳ ✧✭▲❡✈❡❧❡❞✮ ❢✉❧❧② ❤♦♠♦♠♦r♣❤✐❝ ❡♥❝r②♣t✐♦♥ ✇✐t❤♦✉t ❜♦♦tstr❛♣♣✐♥❣✳✧ ■♥ Pr♦❝❡❡❞✐♥❣s ♦❢ t❤❡ ✸r❞ ■♥♥♦✈❛t✐♦♥s ✐♥ ❚❤❡♦r❡t✐❝❛❧ ❈♦♠♣✉t❡r ❙❝✐❡♥❝❡ ❈♦♥❢❡r❡♥❝❡ ✭♣♣✳ ✸✵✾✲✸✷✺✮✳ ❆❈▼ ✭✷✵✶✷✮✳ ❬❇▲P❘❙✶✸❪ ❇r❛❦❡rs❦✐✱ ❩✳✱ ▲❛♥❣❧♦✐s✱ ❆✳✱ P❡✐❦❡rt✱ ❈✳✱ ❘❡❣❡✈✱ ❖✳✱ ❛♥❞ ❙t❡❤❧é✱ ❉✳ ✧❈❧❛ss✐❝❛❧ ❤❛r❞♥❡ss ♦❢ ❧❡❛r♥✐♥❣ ✇✐t❤ ❡rr♦rs✳✧ ■♥ t❤❡ ♣r♦❝❡❡❞✐♥❣s ♦❢ ❙❚❖❈✬✶✸ ✭✷✵✶✸✮✳ ❬❇P✶✻❪✱ ❇r❛❦❡rs❦✐✱ ❩✳✱ ❛♥❞ P❡r❧♠❛♥✱ ❘✳ ✧▲❛tt✐❝❡✲❇❛s❡❞ ❋✉❧❧② ❉②♥❛♠✐❝ ▼✉❧t✐✲❑❡② ❋❍❊ ✇✐t❤ ❙❤♦rt ❈✐♣❤❡rt❡①ts✳✧ ■♥ t❤❡ ♣r♦❝❡❡❞✐♥❣s ♦❢ ❈❘❨P❚❖ ✷✵✶✻ ✭✷✵✶✻✮✳ ❬❇❘✶✺❪ ❇✐❛ss❡✱ ❏✲❋✳✱ ❘✉✐③✱ ▲✳✱ ✧❋❍❊❲ ✇✐t❤ ❊✣❝✐❡♥t ▼✉❧t✐❜✐t ❇♦♦tstr❛♣♣✐♥❣✳✧ ■♥ t❤❡ ♣r♦❝❡❡❞✐♥❣s ♦❢ ▲❛t✐♥❈r②♣t ✷✵✶✺ ✭✷✵✶✺✮✳

✹✶ ✴ ✹✸

slide-116
SLIDE 116

❇✐❜❧✐♦❣r❛♣❤②

❬❈❙✶✺❪ ❈❤❡♦♥✱ ❏✳❍✳✱ ❙t❡❤❧é✱ ❉✳✱ ✧❋✉❧❧② ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥ ♦✈❡r t❤❡ ■♥t❡❣❡rs ❘❡✈✐s✐t❡❞✳✧ ■♥ t❤❡ ♣r♦❝❡❡❞✐♥❣s ♦❢ ❊❯❘❖❈❘❨P❚✬✶✺✳ ❙♣r✐♥❣❡r✲❱❡r❧❛❣ ✭✷✵✶✺✮✳ ❬❈●●■✶✻❪ ❈❤✐❧❧♦tt✐✱ ■✳✱ ●❛♠❛✱ ◆✳✱ ●❡♦r❣✐❡✈❛✱ ▼✳✱ ❛♥❞ ■③❛❜❛❝❤è♥❡✱ ▼✳ ✧❆ ❍♦♠♦♠♦r♣❤✐❝ ▲❲❊ ❇❛s❡❞ ❊✲✈♦t✐♥❣ ❙❝❤❡♠❡✳✧ ■♥ ■♥t❡r♥❛t✐♦♥❛❧ ❲♦r❦s❤♦♣ ♦♥ P♦st✲◗✉❛♥t✉♠ ❈r②♣t♦❣r❛♣❤② ✭♣♣✳ ✷✹✺✲✷✻✺✮✳ ❙♣r✐♥❣❡r ■♥t❡r♥❛t✐♦♥❛❧ P✉❜❧✐s❤✐♥❣ ✭✷✵✶✻✮✳ ❬❉▼✶✺❪ ❉✉❝❛s✱ ▲✳✱ ▼✐❝❝✐❛♥❝✐♦✱ ❉✳✱ ✧❋❍❊❲✿ ❇♦♦tstr❛♣♣✐♥❣ ❍♦♠♦♠♦r♣❤✐❝ ❊♥❝r②♣t✐♦♥ ✐♥ ❧❡ss t❤❛♥ ❛ s❡❝♦♥❞✳✧ ■♥ t❤❡ ♣r♦❝❡❡❞✐♥❣s ♦❢ ❊❯❘❖❈❘❨P❚✬✶✺✳ ❙♣r✐♥❣❡r✲❱❡r❧❛❣ ✭✷✵✶✺✮✳ ❬●■◆❳✶✻❪ ●❛♠❛✱ ◆✳✱ ■③❛❜❛❝❤❡♥❡✱ ▼✳✱ ◆❣✉②❡♥✱ P✳◗✳✱ ❛♥❞ ❳✐❡✱ ❳✳✱ ✧❙tr✉❝t✉r❛❧ ▲❛tt✐❝❡ ❘❡❞✉❝t✐♦♥✿ ●❡♥❡r❛❧✐③❡❞ ❲♦rst✲❈❛s❡ t♦ ❆✈❡r❛❣❡✲❈❛s❡ ❘❡❞✉❝t✐♦♥s✳✧ ■♥ t❤❡ ♣r♦❝❡❡❞✐♥❣s ♦❢ ❊❯❘❖❈❘❨P❚✬✶✻✳ ❙♣r✐♥❣❡r✲❱❡r❧❛❣ ✭✷✵✶✻✮✳ ❬●❡♥✵✾❪ ●❡♥tr②✱ ❈✳✱ ✧❆ ❢✉❧❧② ❤♦♠♦♠♦r♣❤✐❝ ❡♥❝r②♣t✐♦♥ s❝❤❡♠❡ ❬P❤✳ ❉✳ t❤❡s✐s❪✳✧ ■♥t❡r♥❛t✐♦♥❛❧ ❏♦✉r♥❛❧ ♦❢ ❉✐str✐❜✉t❡❞ ❙❡♥s♦r ◆❡t✇♦r❦s✱ ❙t❛♥❢♦r❞ ❯♥✐✈❡rs✐t② ✭✷✵✵✾✮✳

✹✷ ✴ ✹✸

slide-117
SLIDE 117

❇✐❜❧✐♦❣r❛♣❤②

❬●❙❲✶✸❪ ●❡♥tr②✱ ❈✳✱ ❙❛❤❛✐✱ ❆✳✱ ❛♥❞ ❲❛t❡rs✱ ❇✳✱ ✧❍♦♠♦♠♦r♣❤✐❝ ❡♥❝r②♣t✐♦♥ ❢r♦♠ ❧❡❛r♥✐♥❣ ✇✐t❤ ❡rr♦rs✿ ❈♦♥❝❡♣t✉❛❧❧②✲s✐♠♣❧❡r✱ ❛s②♠♣t♦t✐❝❛❧❧②✲❢❛st❡r✱ ❛ttr✐❜✉t❡✲❜❛s❡❞✳✧ ❆❞✈❛♥❝❡s ✐♥ ❈r②♣t♦❧♦❣②✕❈❘❨P❚❖ ✷✵✶✸✳ ❙♣r✐♥❣❡r ❇❡r❧✐♥ ❍❡✐❞❡❧❜❡r❣✱ ✷✵✶✸✳ ✼✺✲✾✷ ✭✷✵✶✸✮✳ ❬▲P✶✶❪ ▲✐♥❞♥❡r✱ ❘✳✱ ❛♥❞ P❡✐❦❡rt✱ ❈✳✱ ✧❇❡tt❡r ❦❡② s✐③❡s ✭❛♥❞ ❛tt❛❝❦s✮ ❢♦r ▲❲❊✲❜❛s❡❞ ❡♥❝r②♣t✐♦♥✳✧ ❈r②♣t♦❣r❛♣❤❡rs✬ ❚r❛❝❦ ❛t t❤❡ ❘❙❆ ❈♦♥❢❡r❡♥❝❡✳ ❙♣r✐♥❣❡r ❇❡r❧✐♥ ❍❡✐❞❡❧❜❡r❣ ✭✷✵✶✶✮✳ ❬▲P❘✶✵❪ ▲②✉❜❛s❤❡✈s❦②✱ ❱✳✱ P❡✐❦❡rt✱ ❈✳✱ ❛♥❞ ❘❡❣❡✈✱ ❖✳✱ ✧❖♥ ■❞❡❛❧ ▲❛tt✐❝❡s ❛♥❞ ▲❡❛r♥✐♥❣ ✇✐t❤ ❊rr♦rs ♦✈❡r ❘✐♥❣s✳✧ ❆❞✈❛♥❝❡s ✐♥ ❈r②♣t♦❧♦❣②✕❊❯❘❖❈❘❨P❚ ✷✵✶✵ ✭✷✵✶✵✮✳ ❬❘❡❣✵✺❪ ❘❡❣❡✈✱ ❖✳✱ ✧❖♥ ❧❛tt✐❝❡s✱ ❧❡❛r♥✐♥❣ ✇✐t❤ ❡rr♦rs✱ r❛♥❞♦♠ ❧✐♥❡❛r ❝♦❞❡s✱ ❛♥❞ ❝r②♣t♦❣r❛♣❤②✳✧ ■♥ ❙❚❖❈✱ ♣♣✳✽✹✲✾✸ ✭✷✵✵✺✮✳

✹✸ ✴ ✹✸