Skip to content

Add generation and compression of evaluation keys at a specified level (issue #413) - #1292

Draft
pascoec wants to merge 3 commits into
devfrom
issue413
Draft

pascoec wants to merge 3 commits into
devfrom
issue413

Conversation

@pascoec

@pascoec pascoec commented Sep 4, 2026 •

Copy link
Copy Markdown
Collaborator

Implements #413: evaluation keys can now be generated with fewer RNS limbs — sized to the
ciphertexts they will actually touch — and existing keys can be compressed in place.

Draft. The core capability is complete and fully tested. Before marking ready for
review, we plan to integrate it with the bootstrapping/FBT key generation paths (see the
checklist at the bottom) so the savings apply to the largest key sets OpenFHE produces.

What this adds

API (all new arguments default to 0 = current behavior; BGV and CKKS, BV and HYBRID
key switching; BFV throws for levels > 0 per the issue):

cc->EvalRotateKeyGen(sk, {1, -1, 8}, levels);        // also EvalAtIndex/EvalAutomorphismKeyGen
cc->EvalMultKeyGen(sk, levels);                      // also EvalMultKeysGen
cc->EvalSumKeyGen(sk, levels);                       // also EvalSumRows/EvalSumColsKeyGen
cc->KeySwitchGen(sk1, sk2, levels);
auto small = cc->CompressEvalKey(evalKey, levels);   // drop limbs from an existing key

Potential Additions

  • BFV support
  • Bootstrapping integration: split FindBootstrapRotationIndices by transform stage inside ckksrns-fhe and generate the SlotsToCoeffs-only rotation keys at their stage's level (StC runs near the bottom of the modulus chain). Estimated ~60% off the StC subset, roughly a third of the whole bootstrapping key set; the CtS keys must stay (near) full-size since they run right after the modulus raise. Per-stage levels are derivable internally from the level budget — no user-facing API change.
  • StC-first bootstrapping and CKKS FBT: in these flavors the StC transform runs on the depleted input ciphertext, so its keys can approach the size floor (a single digit over a few limbs). Apply the same per-stage generation there.
  • Scheme switching (CKKS↔FHEW): the switching and rotation keys generated by EvalCKKStoFHEWKeyGen/EvalSchemeSwitchingKeyGen are applied at a fixed reduced level near the bottom of the chain — natural candidates for the levels argument.
  • Documentation updates (readthedocs keyswitch/bootstrapping pages).

@pascoec pascoec added this to the Release 1.6.0 milestone Sep 4, 2026
@pascoec
pascoec requested a review from yspolyakov September 4, 2026 21:21
@pascoec pascoec self-assigned this Sep 4, 2026
@pascoec pascoec added the optimization Improves performance label Sep 4, 2026
@pascoec
pascoec marked this pull request as draft September 4, 2026 21:23
@pascoec pascoec linked an issue Sep 4, 2026 that may be closed by this pull request
@pascoec pascoec modified the milestones: Release 1.6.0, Release 1.6.1 Sep 15, 2026
…l (issue #413)

Adds a  argument (default 0) to KeySwitchGen, EvalMultKeyGen(s),
EvalAutomorphismKeyGen, EvalAtIndexKeyGen/EvalRotateKeyGen, and
EvalSum(Rows/Cols)KeyGen that drops the given number of RNS limbs from the
generated keys, and a CompressEvalKey function that removes limbs from an
existing key. Supported for BGV and CKKS with both BV and HYBRID key
switching; BFV throws for levels > 0. The old cryptocontext-level
Set/GetKeyGenLevel is deprecated in favor of the per-call argument.

- Key-switching keys are generated over the reduced basis Q_l (BV) or
  Q_l*P (HYBRID), with the digit count reduced to match; a reduced key at
  a given level is byte-identical to a full key compressed to that level.
- The key-switching cores now derive tower offsets from the key itself
  instead of assuming context-sized keys, so full, reduced, and compressed
  keys share one code path; applying a key to a ciphertext with more limbs
  than the key supports throws an informative error.
- The automorphism key map keeps the key with the most limbs on duplicate
  indices, and key generation regenerates only indices whose existing key
  is smaller than requested (via a new GetNumEvalKeyTowers).
- Adds ILDCRTParams constructors for a leading-towers prefix and for the
  concatenation of two bases (e.g. Q_l*P), sharing the component
  parameters; converts fifteen hand-rolled moduli/roots basis
  constructions across pke and core to use them.
- Adds unit tests (rotation/relinearization/summation keys at a level,
  compression, key-map retention, and error paths for CKKS/BGV x
  BV/HYBRID) and a CKKS bootstrapping example demonstrating reduced
  application keys alongside full bootstrapping keys (65% smaller keys,
  3x faster keygen, unchanged rotation time and precision).
…ocument the levels API

- SerializeReducedKeys verifies that keys generated at a level and keys compressed with
  CompressEvalKey survive BINARY serialization and still key-switch correctly at their
  level, for CKKS/BGV with both BV and HYBRID key switching.
- Documents the levels argument and CompressEvalKey in the keyswitch README.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

optimization Improves performance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add functionality for creating automorphism keys at a specified level

1 participant