惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog RSS Feed
J
Java Code Geeks
H
Help Net Security
Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
Microsoft Security Blog
Microsoft Security Blog
宝玉的分享
宝玉的分享
Stack Overflow Blog
Stack Overflow Blog
D
DataBreaches.Net
The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
U
Unit 42
博客园 - 三生石上(FineUI控件)
Last Week in AI
Last Week in AI
M
MIT News - Artificial intelligence
WordPress大学
WordPress大学
小众软件
小众软件
博客园 - 叶小钗
D
Docker
量子位
P
Proofpoint News Feed
博客园_首页
T
Tailwind CSS Blog
F
Fortinet All Blogs

Cryptology ePrint Archive

Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning High-Throughput Side-Channel-Protected Stream Cipher Hardware for 6G Systems Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX Zeal: PIR for Non-Cooperative Databases VEIL: Lightweight Zero-Knowledge for Hash-Based Multilinear Proof Systems Witness-Indistinguishable Arguments of Knowledge and One-Way Functions The many faces of Schnorr: a touch-up Open Problems in List Decoding and Correlated Agreement Compressed Key Exchange Protocol from Orientations of Large Discriminant Using AVX-512 SPLASH: SPeculative Leakage-Adaptive Secure Hardware An Efficient Identity-Based Blind Signature Scheme from SM9 Efficient Batch Threshold Encryption Using Partial Fraction Techniques A note on the Unsuitability of LIGA for Linkable Ring Signatures: The perils of non-commutativity Verification Facade: Masquerading Insecure Cryptographic Implementations as Verified Code Cryptographic Implications of Worst-Case Hardness of Time-Bounded Kolmogorov Complexity Efficient Merkle-Tree Consistent Accumulator FLOSS: Fast Linear Online Secret-Shared Shuffling Which Privacy Blanket is Optimal in the Shuffle Model? Applications of Bruhat-Chevalley-Renner Decomposition to Metric-Aware Code-Based Cryptography
Bootstrapping over Free $\mathcal{R}$-Module
2025-09-25 · via Cryptology ePrint Archive

Paper 2025/1753

Bootstrapping over Free $\mathcal{R}$-Module

, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS; School of Cybersecurity, UCAS

Jikang Bai, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS; School of Cybersecurity, UCAS

Yijian Liu, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS; School of Cybersecurity, UCAS

Xinxuan Zhang, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS; School of Cybersecurity, UCAS

Xianhui Lu, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS; School of Cybersecurity, UCAS

Lutan Zhao, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS; School of Cybersecurity, UCAS

Kunpeng Wang, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS; School of Cybersecurity, UCAS

Rui Hou, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS; School of Cybersecurity, UCAS

Abstract

FHEW/TFHE bootstrapping suffers from a structural rigidity: the accumulator's ring dimension $N$ is limited by the input ciphertext modulus $q$ (typically $q \le 2N$), and thus the message space $t$. This coupling forces $N$ to grow with $t$, leading to inflated parameters and thereby high computational costs. In this work, we overcome this limitation by replacing the ring structure with a free $\mathcal{R}_N$-module $\bigoplus_{i=0}^{\tau-1}\mathcal{R}_N \cdot X^i$. This generalization decouples $N$ from $q$ through a flexible parameter $\tau$. We prove that computation in this extended algebra efficiently reduces to base-ring operations, enabling a new bootstrapping algorithm with improvements in both performance and precision. Theoretically, our approach reduces the asymptotic complexity of standard FHEW/TFHE bootstrapping from quadratic $\tilde{O}(t^2)$ to quasi-linear $\tilde{O}(t)$ in the message space $t$. Compared with prior Extended Bootstrapping methods over discrete cyclotomic ring [PKC'23, TCC'25, Asiacrypt'25], our framework constitutes an algebraic generalization that enables more flexible parameter selection. Experimental results demonstrate that our method achieves speedups of 1.40$\times$--2.77$\times$ over the state-of-the-art sorted extended bootstrapping [Asiacrypt'25].

Note: Add comparisons with Extended Bootstrapping [PKC23] and Sorted Bootstrapping [ASIACRYPT25].

BibTeX

@misc{cryptoeprint:2025/1753,
      author = {Ruida Wang and Jikang Bai and Yijian Liu and Xinxuan Zhang and Xianhui Lu and Lutan Zhao and Kunpeng Wang and Rui Hou},
      title = {Bootstrapping over Free $\mathcal{R}$-Module},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1753},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1753}
}