client.rs 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176
  1. use std::collections::HashMap;
  2. use crate::{poly::*, params::*, discrete_gaussian::*, gadget::*, arith::*};
  3. pub struct PublicParameters<'a> {
  4. v_packing: Vec<PolyMatrixNTT<'a>>, // Ws
  5. v_expansion_left: Vec<PolyMatrixNTT<'a>>,
  6. v_expansion_right: Vec<PolyMatrixNTT<'a>>,
  7. v_conversion: PolyMatrixNTT<'a>, // V
  8. }
  9. impl<'a> PublicParameters<'a> {
  10. fn init(params: &'a Params) -> Self {
  11. PublicParameters {
  12. v_packing: Vec::new(),
  13. v_expansion_left: Vec::new(),
  14. v_expansion_right: Vec::new(),
  15. v_conversion: PolyMatrixNTT::zero(params, 2, 2 * params.m_conv())
  16. }
  17. }
  18. }
  19. pub struct Client<'a> {
  20. params: &'a Params,
  21. sk_gsw: PolyMatrixRaw<'a>,
  22. sk_reg: PolyMatrixRaw<'a>,
  23. sk_gsw_full: PolyMatrixRaw<'a>,
  24. sk_reg_full: PolyMatrixRaw<'a>,
  25. dg: DiscreteGaussian,
  26. }
  27. fn matrix_with_identity<'a> (p: &PolyMatrixRaw<'a>) -> PolyMatrixRaw<'a> {
  28. assert_eq!(p.cols, 1);
  29. let mut r = PolyMatrixRaw::zero(p.params, p.rows, p.rows + 1);
  30. r.copy_into(p, 0, 0);
  31. r.copy_into(&PolyMatrixRaw::identity(p.params, p.rows, p.rows), 0, 1);
  32. r
  33. }
  34. impl<'a> Client<'a> {
  35. pub fn init(params: &'a Params) -> Self {
  36. let sk_gsw_dims = params.get_sk_gsw();
  37. let sk_reg_dims = params.get_sk_reg();
  38. let sk_gsw = PolyMatrixRaw::zero(params, sk_gsw_dims.0, sk_gsw_dims.1);
  39. let sk_reg = PolyMatrixRaw::zero(params, sk_reg_dims.0, sk_reg_dims.1);
  40. let sk_gsw_full = matrix_with_identity(&sk_gsw);
  41. let sk_reg_full = matrix_with_identity(&sk_reg);
  42. let dg = DiscreteGaussian::init(params);
  43. Self {
  44. params,
  45. sk_gsw,
  46. sk_reg,
  47. sk_gsw_full,
  48. sk_reg_full,
  49. dg,
  50. }
  51. }
  52. fn get_fresh_gsw_public_key(&mut self, m: usize) -> PolyMatrixRaw<'a> {
  53. let params = self.params;
  54. let n = params.n;
  55. let a = PolyMatrixRaw::random(params, 1, m);
  56. let e = PolyMatrixRaw::noise(params, n, m, &mut self.dg);
  57. let a_inv = -&a;
  58. let b_p = &self.sk_gsw.ntt() * &a.ntt();
  59. let b = &e.ntt() + &b_p;
  60. let p = stack(&a_inv, &b.raw());
  61. p
  62. }
  63. fn get_regev_sample(&mut self) -> PolyMatrixNTT<'a> {
  64. let params = self.params;
  65. let a = PolyMatrixRaw::random(params, 1, 1);
  66. let e = PolyMatrixRaw::noise(params, 1, 1, &mut self.dg);
  67. let b_p = &self.sk_reg.ntt() * &a.ntt();
  68. let b = &e.ntt() + &b_p;
  69. let mut p = PolyMatrixNTT::zero(params, 2, 1);
  70. p.copy_into(&(-&a).ntt(), 0, 0);
  71. p.copy_into(&b, 1, 0);
  72. p
  73. }
  74. fn get_fresh_reg_public_key(&mut self, m: usize) -> PolyMatrixNTT<'a> {
  75. let params = self.params;
  76. let mut p = PolyMatrixNTT::zero(params, 2, m);
  77. for i in 0..m {
  78. p.copy_into(&self.get_regev_sample(), 0, i);
  79. }
  80. p
  81. }
  82. fn encrypt_matrix_gsw(&mut self, ag: PolyMatrixNTT<'a>) -> PolyMatrixNTT<'a> {
  83. let mx = ag.cols;
  84. let p = self.get_fresh_gsw_public_key(mx);
  85. let res = &(p.ntt()) + &(ag.pad_top(1));
  86. res
  87. }
  88. fn encrypt_matrix_reg(&mut self, a: PolyMatrixNTT<'a>) -> PolyMatrixNTT<'a> {
  89. let m = a.cols;
  90. let p = self.get_fresh_reg_public_key(m);
  91. &p + &a.pad_top(1)
  92. }
  93. fn generate_expansion_params(&mut self, num_exp: usize, m_exp: usize) -> Vec<PolyMatrixNTT<'a>> {
  94. // MatPoly G_exp = buildGadget(1, m_exp);
  95. // MatPoly G_exp_nttd = to_ntt(G_exp);
  96. let params = self.params;
  97. let g_exp = build_gadget(params, 1, m_exp);
  98. let g_exp_ntt = g_exp.ntt();
  99. let mut res = Vec::new();
  100. for i in 0..num_exp {
  101. let t = (params.poly_len / (1 << i)) + 1;
  102. let tau_sk_reg = automorph_alloc(&self.sk_reg, t);
  103. // MatPoly W_exp_i = encryptSimpleRegevMatrix(s0, multiply(tau_s0, G_exp_nttd));
  104. let prod = &tau_sk_reg.ntt() * &g_exp_ntt;
  105. let w_exp_i = self.encrypt_matrix_reg(prod);
  106. res.push(w_exp_i);
  107. }
  108. res
  109. }
  110. pub fn generate_keys(&mut self) -> PublicParameters {
  111. let params = self.params;
  112. self.dg.sample_matrix(&mut self.sk_gsw);
  113. self.dg.sample_matrix(&mut self.sk_reg);
  114. self.sk_gsw_full = matrix_with_identity(&self.sk_gsw);
  115. self.sk_reg_full = matrix_with_identity(&self.sk_reg);
  116. let sk_reg_ntt = to_ntt_alloc(&self.sk_reg);
  117. let m_conv = params.m_conv();
  118. let mut pp = PublicParameters::init(params);
  119. // Params for packing
  120. let gadget_conv = build_gadget(params, 1, m_conv);
  121. let gadget_conv_ntt = to_ntt_alloc(&gadget_conv);
  122. for i in 0..params.n {
  123. let scaled = scalar_multiply_alloc(&sk_reg_ntt, &gadget_conv_ntt);
  124. let mut ag = PolyMatrixNTT::zero(params, params.n, m_conv);
  125. ag.copy_into(&scaled, i, 0);
  126. let w = self.encrypt_matrix_gsw(ag);
  127. pp.v_packing.push(w);
  128. }
  129. // Params for expansion
  130. let further_dims = 1usize << params.db_dim_2;
  131. let num_expanded = 1usize << params.db_dim_1;
  132. let num_bits_to_gen = params.t_gsw * further_dims + num_expanded;
  133. let g = log2(num_bits_to_gen as u64) as usize;
  134. let stop_round = log2((params.t_gsw * further_dims) as u64) as usize;
  135. pp.v_expansion_left = self.generate_expansion_params(g, params.t_exp_left);
  136. pp.v_expansion_right = self.generate_expansion_params(stop_round + 1, params.t_exp_right);
  137. // Params for converison
  138. let g_conv = build_gadget(params, 2, 2 * m_conv);
  139. let sk_reg_squared_ntt = &self.sk_reg.ntt() * &self.sk_reg.ntt();
  140. pp.v_conversion = PolyMatrixNTT::zero(params, 2, 2 * m_conv);
  141. for i in 0..2*m_conv {
  142. if i % 2 == 0 {
  143. let val = g_conv.get_poly(0, i)[0];
  144. let sigma = &sk_reg_squared_ntt * &single_poly(params, val).ntt();
  145. let ct = self.encrypt_matrix_reg(sigma);
  146. pp.v_conversion.copy_into(&ct, 0, i);
  147. }
  148. }
  149. pp
  150. }
  151. // fn generate_query(&self) -> Query<'a, Params>;
  152. }