TY - GEN
T1 - HERDS
T2 - 45th Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2026
AU - Xiang, Binwu
AU - Min, Seonhong
AU - Hwang, Intak
AU - Wang, Zhiwei
AU - He, Haoqi
AU - Wei, Yuanju
AU - Yang, Kang
AU - Zhang, Jiang
AU - Deng, Yi
AU - Yu, Yu
N1 - Publisher Copyright:
© International Association for Cryptologic Research 2026.
PY - 2026
Y1 - 2026
N2 - Multi-key fully homomorphic encryption (MK-FHE) enables secure computation over ciphertexts under different keys, but its practicality is hindered by inefficient bootstrapping. In this work, we propose HERDS, a new MK-FHE scheme with highly efficient bootstrapping. Our bootstrapping framework improves upon the best-known complexity, reducing it from O(dkn) to O(kn), and further to O(kn) under parallelization, where d is the gadget length (typically scaling with the number of parties k) and n is the LWE dimension. The framework consists of two main components: (i) a ciphertext conversion algorithm that transforms a multi-key LWE ciphertext into k vectorized RLWE ciphertexts via k optimized blind rotations and dk key-switching operations, and (ii) a hybrid accumulator that aggregates these into a single multi-key RLWE ciphertext. We implemented HERDS on both CPU and GPU platforms to demonstrate its practicality. For k=16, we achieve 3.3× and 7.2× improvements on CPU, compared to the state-of-the-art schemes by Kwak et al. (PKC 2024) and by Xiang et al. (ASIACRYPT 2024), respectively. We further achieve a 195× GPU acceleration, compared to our CPU runtime. As a byproduct, we design a new distributed-decryption protocol, which allows us to obtain a ciphertext with a small noise bound, and thus does not blow up the parameters.
AB - Multi-key fully homomorphic encryption (MK-FHE) enables secure computation over ciphertexts under different keys, but its practicality is hindered by inefficient bootstrapping. In this work, we propose HERDS, a new MK-FHE scheme with highly efficient bootstrapping. Our bootstrapping framework improves upon the best-known complexity, reducing it from O(dkn) to O(kn), and further to O(kn) under parallelization, where d is the gadget length (typically scaling with the number of parties k) and n is the LWE dimension. The framework consists of two main components: (i) a ciphertext conversion algorithm that transforms a multi-key LWE ciphertext into k vectorized RLWE ciphertexts via k optimized blind rotations and dk key-switching operations, and (ii) a hybrid accumulator that aggregates these into a single multi-key RLWE ciphertext. We implemented HERDS on both CPU and GPU platforms to demonstrate its practicality. For k=16, we achieve 3.3× and 7.2× improvements on CPU, compared to the state-of-the-art schemes by Kwak et al. (PKC 2024) and by Xiang et al. (ASIACRYPT 2024), respectively. We further achieve a 195× GPU acceleration, compared to our CPU runtime. As a byproduct, we design a new distributed-decryption protocol, which allows us to obtain a ciphertext with a small noise bound, and thus does not blow up the parameters.
KW - Blind Rotation
KW - Bootstrapping
KW - Hardware Accelerator
KW - MK-FHE
UR - https://www.scopus.com/pages/publications/105040165917
U2 - 10.1007/978-3-032-25327-9_8
DO - 10.1007/978-3-032-25327-9_8
M3 - 会议稿件
AN - SCOPUS:105040165917
SN - 9783032253262
T3 - Lecture Notes in Computer Science
SP - 214
EP - 242
BT - Advances in Cryptology – EUROCRYPT 2026 - 45th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Proceedings
A2 - Daemen, Joan
A2 - Thomé, Emmanuel
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 10 May 2026 through 14 May 2026
ER -