Conversation
…l (issue #413) Adds a argument (default 0) to KeySwitchGen, EvalMultKeyGen(s), EvalAutomorphismKeyGen, EvalAtIndexKeyGen/EvalRotateKeyGen, and EvalSum(Rows/Cols)KeyGen that drops the given number of RNS limbs from the generated keys, and a CompressEvalKey function that removes limbs from an existing key. Supported for BGV and CKKS with both BV and HYBRID key switching; BFV throws for levels > 0. The old cryptocontext-level Set/GetKeyGenLevel is deprecated in favor of the per-call argument. - Key-switching keys are generated over the reduced basis Q_l (BV) or Q_l*P (HYBRID), with the digit count reduced to match; a reduced key at a given level is byte-identical to a full key compressed to that level. - The key-switching cores now derive tower offsets from the key itself instead of assuming context-sized keys, so full, reduced, and compressed keys share one code path; applying a key to a ciphertext with more limbs than the key supports throws an informative error. - The automorphism key map keeps the key with the most limbs on duplicate indices, and key generation regenerates only indices whose existing key is smaller than requested (via a new GetNumEvalKeyTowers). - Adds ILDCRTParams constructors for a leading-towers prefix and for the concatenation of two bases (e.g. Q_l*P), sharing the component parameters; converts fifteen hand-rolled moduli/roots basis constructions across pke and core to use them. - Adds unit tests (rotation/relinearization/summation keys at a level, compression, key-map retention, and error paths for CKKS/BGV x BV/HYBRID) and a CKKS bootstrapping example demonstrating reduced application keys alongside full bootstrapping keys (65% smaller keys, 3x faster keygen, unchanged rotation time and precision).
…ocument the levels API - SerializeReducedKeys verifies that keys generated at a level and keys compressed with CompressEvalKey survive BINARY serialization and still key-switch correctly at their level, for CKKS/BGV with both BV and HYBRID key switching. - Documents the levels argument and CompressEvalKey in the keyswitch README.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements #413: evaluation keys can now be generated with fewer RNS limbs — sized to the
ciphertexts they will actually touch — and existing keys can be compressed in place.
What this adds
API (all new arguments default to 0 = current behavior; BGV and CKKS, BV and HYBRID
key switching; BFV throws for
levels > 0per the issue):Potential Additions