We discuss the advantages and limitations of cyclotomic fields to have fast polynomial arithmetic within homomorphic encryption, and show how these limitations can be overcome by replacing cyclotomic fields by a family that we refer to as cyclo-multiquadratic. This family is of particular interest due to its arithmetic efficiency properties and to the fact that the Polynomial Learning with Errors (PLWE) and Ring Learning with Errors (RLWE) problems are equivalent for it. Likewise, we provide exact expressions for the condition number for any cyclotomic field, but under what we call the twisted power basis. As a tool for our result, we obtain refined polynomial upper bounds for the condition number of cyclotomic fields with up to 6 different primes dividing the conductor. From a more practical side, we also show that for this family, swapping between NTT and coefficient representations can be achieved at least twice faster than for the usual cyclotomic family.
翻译:我们讨论了分圆域在同态加密中实现快速多项式运算的优势与局限性,并展示如何通过将分圆域替换为我们称为"环-多二次域"的域族来克服这些局限性。该域族因其算术效率特性以及多项式带误差学习(PLWE)与环带误差学习(RLWE)问题在该域上等价而具有特殊意义。同时,我们给出了任意分圆域在所谓"扭幂基"下的条件数精确表达式。作为该结果的技术支撑,我们获得了对最多包含6个不同素数整除导子的分圆域的条件数多项式上界的精细改进。从更实际的角度,我们还证明了对于该域族,在NTT表示与系数表示之间进行切换的速度至少可比常规分圆域族快两倍。