pir.cpp 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285
  1. #include "pir.hpp"
  2. using namespace std;
  3. using namespace seal;
  4. using namespace seal::util;
  5. vector<uint64_t> get_dimensions(uint64_t plaintext_num, uint32_t d) {
  6. assert(d > 0);
  7. assert(plaintext_num > 0);
  8. vector<uint64_t> dimensions(d);
  9. for (uint32_t i = 0; i < d; i++) {
  10. dimensions[i] = std::max((uint32_t) 2, (uint32_t) floor(pow(plaintext_num, 1.0/d)));
  11. }
  12. uint32_t product = 1;
  13. uint32_t j = 0;
  14. // if plaintext_num is not a d-power
  15. if ((double) dimensions[0] != pow(plaintext_num, 1.0 / d)) {
  16. while (product < plaintext_num && j < d) {
  17. product = 1;
  18. dimensions[j++]++;
  19. for (uint32_t i = 0; i < d; i++) {
  20. product *= dimensions[i];
  21. }
  22. }
  23. }
  24. return dimensions;
  25. }
  26. void gen_params(uint64_t ele_num, uint64_t ele_size, uint32_t N, uint32_t logt,
  27. uint32_t d, EncryptionParameters &params,
  28. PirParams &pir_params) {
  29. // Determine the maximum size of each dimension
  30. // plain modulus = a power of 2 plus 1
  31. uint64_t plain_mod = (static_cast<uint64_t>(1) << logt) + 1;
  32. uint64_t plaintext_num = plaintexts_per_db(logt, N, ele_num, ele_size);
  33. #ifdef DEBUG
  34. cout << "log(plain mod) before expand = " << logt << endl;
  35. cout << "number of FV plaintexts = " << plaintext_num << endl;
  36. #endif
  37. vector<SmallModulus> coeff_mod_array;
  38. uint32_t logq = 0;
  39. for (uint32_t i = 0; i < 1; i++) {
  40. coeff_mod_array.emplace_back(SmallModulus());
  41. coeff_mod_array[i] = small_mods_60bit(i);
  42. logq += coeff_mod_array[i].bit_count();
  43. }
  44. params.set_poly_modulus_degree(N);
  45. params.set_coeff_modulus(coeff_mod_array);
  46. params.set_plain_modulus(plain_mod);
  47. vector<uint64_t> nvec = get_dimensions(plaintext_num, d);
  48. uint32_t expansion_ratio = 0;
  49. for (uint32_t i = 0; i < params.coeff_modulus().size(); ++i) {
  50. double logqi = log2(params.coeff_modulus()[i].value());
  51. expansion_ratio += ceil(logqi / logt);
  52. }
  53. pir_params.d = d;
  54. pir_params.dbc = 6;
  55. pir_params.n = plaintext_num;
  56. pir_params.nvec = nvec;
  57. pir_params.expansion_ratio = expansion_ratio << 1;
  58. }
  59. void update_params(uint64_t ele_num, uint64_t ele_size, uint32_t d,
  60. const EncryptionParameters &old_params, EncryptionParameters &expanded_params,
  61. PirParams &pir_params) {
  62. uint32_t logt = ceil(log2(old_params.plain_modulus().value()));
  63. uint32_t N = old_params.poly_modulus_degree();
  64. // Determine the maximum size of each dimension
  65. uint32_t logtp = plainmod_after_expansion(logt, N, d, ele_num, ele_size);
  66. uint64_t expanded_plain_mod = static_cast<uint64_t>(1) << logtp;
  67. uint64_t plaintext_num = plaintexts_per_db(logtp, N, ele_num, ele_size);
  68. #ifdef DEBUG
  69. cout << "log(plain mod) before expand = " << logt << endl;
  70. cout << "log(plain mod) after expand = " << logtp << endl;
  71. cout << "number of FV plaintexts = " << plaintext_num << endl;
  72. #endif
  73. expanded_params.set_poly_modulus_degree(old_params.poly_modulus_degree());
  74. expanded_params.set_coeff_modulus(old_params.coeff_modulus());
  75. expanded_params.set_plain_modulus(expanded_plain_mod);
  76. // Assumes dimension of database is 2
  77. vector<uint64_t> nvec = get_dimensions(plaintext_num, d);
  78. uint32_t expansion_ratio = 0;
  79. for (uint32_t i = 0; i < old_params.coeff_modulus().size(); ++i) {
  80. double logqi = log2(old_params.coeff_modulus()[i].value());
  81. expansion_ratio += ceil(logqi / logtp);
  82. }
  83. pir_params.d = d;
  84. pir_params.dbc = 6;
  85. pir_params.n = plaintext_num;
  86. pir_params.nvec = nvec;
  87. pir_params.expansion_ratio = expansion_ratio << 1;
  88. }
  89. uint32_t plainmod_after_expansion(uint32_t logt, uint32_t N, uint32_t d,
  90. uint64_t ele_num, uint64_t ele_size) {
  91. // Goal: find max logtp such that logtp + ceil(log(ceil(d_root(n)))) <= logt
  92. // where n = ceil(ele_num / floor(N*logtp / ele_size *8))
  93. for (uint32_t logtp = logt; logtp >= 2; logtp--) {
  94. uint64_t n = plaintexts_per_db(logtp, N, ele_num, ele_size);
  95. if (logtp == logt && n == 1) {
  96. return logtp - 1;
  97. }
  98. if ((double)logtp + ceil(log2(ceil(pow(n, 1.0/(double)d)))) <= logt) {
  99. return logtp;
  100. }
  101. }
  102. assert(0); // this should never happen
  103. return logt;
  104. }
  105. // Number of coefficients needed to represent a database element
  106. uint64_t coefficients_per_element(uint32_t logtp, uint64_t ele_size) {
  107. return ceil(8 * ele_size / (double)logtp);
  108. }
  109. // Number of database elements that can fit in a single FV plaintext
  110. uint64_t elements_per_ptxt(uint32_t logtp, uint64_t N, uint64_t ele_size) {
  111. uint64_t coeff_per_ele = coefficients_per_element(logtp, ele_size);
  112. uint64_t ele_per_ptxt = N / coeff_per_ele;
  113. assert(ele_per_ptxt > 0);
  114. return ele_per_ptxt;
  115. }
  116. // Number of FV plaintexts needed to represent the database
  117. uint64_t plaintexts_per_db(uint32_t logtp, uint64_t N, uint64_t ele_num, uint64_t ele_size) {
  118. uint64_t ele_per_ptxt = elements_per_ptxt(logtp, N, ele_size);
  119. return ceil((double)ele_num / ele_per_ptxt);
  120. }
  121. vector<uint64_t> bytes_to_coeffs(uint32_t limit, const uint8_t *bytes, uint64_t size) {
  122. uint64_t size_out = coefficients_per_element(limit, size);
  123. vector<uint64_t> output(size_out);
  124. uint32_t room = limit;
  125. uint64_t *target = &output[0];
  126. for (uint32_t i = 0; i < size; i++) {
  127. uint8_t src = bytes[i];
  128. uint32_t rest = 8;
  129. while (rest) {
  130. if (room == 0) {
  131. target++;
  132. room = limit;
  133. }
  134. uint32_t shift = rest;
  135. if (room < rest) {
  136. shift = room;
  137. }
  138. *target = *target << shift;
  139. *target = *target | (src >> (8 - shift));
  140. src = src << shift;
  141. room -= shift;
  142. rest -= shift;
  143. }
  144. }
  145. *target = *target << room;
  146. return output;
  147. }
  148. void coeffs_to_bytes(uint32_t limit, const Plaintext &coeffs, uint8_t *output, uint32_t size_out) {
  149. uint32_t room = 8;
  150. uint32_t j = 0;
  151. uint8_t *target = output;
  152. for (uint32_t i = 0; i < coeffs.coeff_count(); i++) {
  153. uint64_t src = coeffs[i];
  154. uint32_t rest = limit;
  155. while (rest && j < size_out) {
  156. uint32_t shift = rest;
  157. if (room < rest) {
  158. shift = room;
  159. }
  160. target[j] = target[j] << shift;
  161. target[j] = target[j] | (src >> (limit - shift));
  162. src = src << shift;
  163. room -= shift;
  164. rest -= shift;
  165. if (room == 0) {
  166. j++;
  167. room = 8;
  168. }
  169. }
  170. }
  171. }
  172. void vector_to_plaintext(const vector<uint64_t> &coeffs, Plaintext &plain) {
  173. uint32_t coeff_count = coeffs.size();
  174. plain.resize(coeff_count);
  175. util::set_uint_uint(coeffs.data(), coeff_count, plain.data());
  176. }
  177. vector<uint64_t> compute_indices(uint64_t desiredIndex, vector<uint64_t> Nvec) {
  178. uint32_t num = Nvec.size();
  179. uint64_t product = 1;
  180. for (uint32_t i = 0; i < num; i++) {
  181. product *= Nvec[i];
  182. }
  183. uint64_t j = desiredIndex;
  184. vector<uint64_t> result;
  185. for (uint32_t i = 0; i < num; i++) {
  186. product /= Nvec[i];
  187. uint64_t ji = j / product;
  188. result.push_back(ji);
  189. j -= ji * product;
  190. }
  191. return result;
  192. }
  193. inline Ciphertext deserialize_ciphertext(string s) {
  194. Ciphertext c;
  195. std::istringstream input(s);
  196. c.unsafe_load(input);
  197. return c;
  198. }
  199. vector<Ciphertext> deserialize_ciphertexts(uint32_t count, string s, uint32_t len_ciphertext) {
  200. vector<Ciphertext> c;
  201. for (uint32_t i = 0; i < count; i++) {
  202. c.push_back(deserialize_ciphertext(s.substr(i * len_ciphertext, len_ciphertext)));
  203. }
  204. return c;
  205. }
  206. inline string serialize_ciphertext(Ciphertext c) {
  207. std::ostringstream output;
  208. c.save(output);
  209. return output.str();
  210. }
  211. string serialize_ciphertexts(vector<Ciphertext> c) {
  212. string s;
  213. for (uint32_t i = 0; i < c.size(); i++) {
  214. s.append(serialize_ciphertext(c[i]));
  215. }
  216. return s;
  217. }
  218. string serialize_galoiskeys(GaloisKeys g) {
  219. std::ostringstream output;
  220. g.save(output);
  221. return output.str();
  222. }
  223. GaloisKeys *deserialize_galoiskeys(string s) {
  224. GaloisKeys *g = new GaloisKeys();
  225. std::istringstream input(s);
  226. g->unsafe_load(input);
  227. return g;
  228. }