Submitted:
08 January 2026
Posted:
08 January 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
- 1.
- A secret sharing-based bootstrapping key generation algorithm is proposed. The FINAL scheme lacks an asymmetric encryption variant, and existing NTRU-based blind rotation algorithms [20,21] employ symmetrically encrypted bootstrapping keys. To ensure compatibility between the proposed bootstrapping algorithm and NTRU-based blind rotation while maintaining low noise levels in bootstrapping keys, additive secret sharing is introduced in the offline phase before bootstrapping. parties within the same group collectively negotiate and generate bootstrapping keys through operations such as addition and multiplication of secret shares.
- 2.
- A multi-group hybrid product algorithm is proposed. To parallelize bootstrapping, the core steps of bootstrapping are divided into multiple subtasks by group. Each subtask independently performs blind rotation using the corresponding group bootstrapping key, and the outputs of the subtasks are aggregated using the multi-group hybrid product algorithm.
- 3.
- Secure parameter sets are determined and the effectiveness is verified through experiments. Since the FINAL scheme is based on NTRU, "overstretched" parameters render the scheme vulnerable to sublattice attacks. By analyzing the upper bound of noise, the parameters of the proposed scheme are ensured to remain within a secure range using LWE [22] and NTRU estimators [23]. Experiments are conducted under two different parameter sets with the number of groups ranging from 2 to 8, validating the effectiveness of the proposed scheme.
2. Related Work
2.1. Multi-Party Homomorphic Encryption Schemes
2.2. Multi-Key Homomorphic Encryption Schemes Based on Blind Rotation
3. Preliminaries
3.1. Notions
3.2. Hard Problems
- 1.
- Randomly sampled pairs ;
- 2.
- Pairs , where is uniformly sampled from , is the i-th element of , is uniformly sampled from , is the i-th element of , and e is sampled from .
- 1.
- Randomly sampled pairs ;
- 2.
- Pairs , where are uniformly sampled from , and e is sampled from .
- 1.
- A randomly sampled element ;
- 2.
- The element .
- 1.
- A randomly sampled vector ;
- 2.
- The vector .
3.3. Gadget Decomposition
3.4. FINAL Scheme
- FINAL.Setup(): Input a security parameter , generate security-compliant parameters including the NTRU polynomial modulus Q, polynomial degree N, Gadget decomposition base B, key distribution over R, and noise distribution over R. Output .
- FINAL.KeyGen(): Input the parameters generated by the Setup algorithm, select an invertible polynomial from , and output the NTRU key f.
- FINAL.ScalarEnc(m, f): Input a plaintext and the NTRU key f, randomly select noise , set as the scaling factor, and output the NTRU scalar ciphertext
- FINAL.VectorEnc(m, f): Input a plaintext and the NTRU key f, randomly select noise where , and output the NTRU vector ciphertext
3.5. XZD Blind Rotation
-
BRKGen(): Given an LWE secret key and an NTRU key , the algorithm outputs , where
- 1.
- , for , ,
- 2.
- .
- BREval(): Input an LWE ciphertext , a rotation polynomial r, the evaluation key generated by BRKGen, and the NTRU scaling factor . The algorithm computes and outputs
| Algorithm 1 BREval( (adapted from [20]). |
![]() |
3.6. Additive-Only Multi-Party RLWE-Based Homomorphic Encryption
- AHE.Setup(): Input a security parameter , output security-compliant public parameters including the RLWE ciphertext modulus Q, plaintext modulus t, polynomial degree N, secret key distribution over R, noise distribution over R, and a common reference polynomial . Output .
- AHE.SKeyGen(): Each party selects an RLWE secret key .
- AHE.PKeyGen(): Each party selects noise , computes , and sets .
- AHE.JointPKeyGen(): Input the public keys of all parties, compute , and output the joint RLWE public key .
- AHE.Enc(m): Input a plaintext , select noise , , randomly select a temporary secret polynomial , compute and , and output the ciphertext .
- AHE.Dec(): Input a ciphertext encrypted under the joint RLWE public key and the RLWE secret keys of all parties, compute .
- AHE.Add(): Input two multi-party RLWE ciphertexts and encrypting plaintexts under the same public key, compute and output .
- AHE.ScalarMult(): Input a scalar polynomial and a multi-party RLWE ciphertext , compute and output .
4. Basic Multi-Group LWE-Based Homomorphic Encryption without Bootstrapping
- MGHE.Setup(): Takes a security parameter as input, generates global parameters meeting security requirements, including LWE encryption modulus , LWE bootstrapping modulus q, LWE dimension n, LWE secret key distribution over , noise distribution over , and a common reference matrix . Outputs .
- MGHE.SKeyGen(): Parties in each group independently generate a private LWE secert key , and output the LWE secret key .
- MGHE.PKeyGen(): Party selects noise , computes , and sets .
- MGHE.JointPKeyGen(): Takes the LWE public keys of each party in a group , computes , and outputs the LWE joint public key .
- MGHE.Enc(): Takes a plaintext bit and the LWE joint public key of a group as input, randomly selects a temporary secret vector , noise , , computes , , and outputs the LWE ciphertext encrypting the plaintext m under the joint LWE public key .
- MGHE.ModulusSwitch(): Takes the LWE ciphertext generated by the MGHE.Enc algorithm and the LWE bootstrapping modulus q for bootstrapping, computes and outputs .
- MGHE.Dec(): Takes the multi-group LWE ciphertext and the LWE secret keys of each party in each group as input, computes and outputs .
- MGHE.NAND(): Takes two multi-group LWE ciphertexts and encrypted under the same set of public keys , which encrypt plaintext bits respectively. For , let and , computes , and outputs the ciphertext encrypting the plaintext m NAND .
5. Bootstrapping for Multi-Group LWE Ciphertext
5.1. Generating Polynomial Multiplication Triples
- TripleGen.Setup(): Successively executes AHE.Setup, AHE.SKeyGen, AHE.PKeyGen, and AHE.JointPKeyGen, outputs public parameters , secret keys of each party, and joint public key .
- TripleGen.EvalGen(): Takes the public parameters output by TripleGen.Setup, the secret keys of each party, and the joint public key as input, and outputs a random polynomial multiplication triple. The detailed specifications referred to Algorithm 2.
| Algorithm 2 TripleGen(). |
![]() |
5.2. Additive Secret Sharing over Polynomial Ring
- ASS.Split(s): Takes a secret belonging to as input. For , party randomly selects elements in , computes , and distributes the secret share of the secret s to party .
- ASS.Recover(): Each party broadcasts the share of the secret s. After collecting sent by the other parties, computes .
- ASS.Add(): Takes the secret shares of secrets x and y as input. For , party locally computes , and outputs the secret shares of the secret .
- ASS.ScalarMult(): Takes the secret shares of the secret x and a polynomial as input. For , party locally computes , and obtains the secret shares of the secret .
- ASS.Mult(): Takes the secret shares , of secrets x and y, and the secret shares , , of the multiplication triple as input. Each party locally computes , and broadcasts them. After receiving the broadcasts from other parties, party locally recovers the secrets and . For , locally computes ; for other parties , locally computes .
- ASS.Auto(): Takes the secret shares of the secret x and an automorphism as input. For , party locally computes , and obtains the secret shares of the secret .
5.3. Multi-Group Hybrid Product
-
MGHPKeyGen(): Takes the RLWE secret key of the j-th party in group G and the secret share of the joint NTRU key F as input, randomly selects a common reference polynomial vector , each party selects a secret polynomial from the noise distribution over the ring R and noise polynomial vectors . Denote and as the decomposition base and decomposition degree of the ciphertext modulus Q respectively, and as the corresponding decomposition vector. For , computeThen output .
-
MGHybridProd(): Takes the MGRLWE public keys , the output by the i-th group after executing MGHPKeyGen, the multi-group RLWE ciphertext encrypting the plaintext m, and the vector NTRU ciphertext encrypting the plaintext as input. For , let , where is the polynomial vector shared by multiple groups in MGHPKeyGen, computesthen updateOutputs the multi-group RLWE ciphertext encrypting the plaintext .
5.4. Other Core algorithms for Bootstrapping
- Enroll(): Takes the LWE secret key and its corresponding NTRU key of each party in a group as input, and outputs , which respectively denote the secret share of the joint NTRU key F, the secret share of (multiplicative inverse of F), the secret share of the secret key, and the secret share of the negative sum secret keys. The algorithm is presented as shown in Algorithm 3.
| Algorithm 3:. |
![]() |
- JBRKGen(): Takes , , , output by the Enroll algorithm and a set of multiplication triples as input, outputs the joint bootstrapping key . The details are as shown in Algorithm 4.
| Algorithm 4 JBRKGen(). |
![]() |
- SampleExt(): Takes the MGRLWE ciphertext as input, denotes as the j-th coefficient of the polynomial , sets and for , and outputs .
- ModSwitch(): Takes the MGLWE ciphertext , the original modulus Q and the new modulus q as input, computes and for , and outputs the new ciphertext .
- LKSKeyGen(): Takes the LWE secret keys and of party in the group as input, randomly selects a matrix within the group, randomly samples the noise for , computes , denotes , and outputs .
- LKeySwitch(): Takes the MGLWE ciphertext as well as the key switching key for the i-th group as input, denotes for , computes , , and outputs .
5.5. Parallelizable Multi-Group Ciphertext Bootstrapping Algorithm
- 1.
- Set of multiplication triples: TripleGen.
- 2.
-
Secret shares generated by Enroll algorithm of parties in group :Enroll.
- 3.
- Joint bootstrapping key of group : JBRKGen.
- 4.
- Multi-group hybrid product key of group : MGHPKeyGen.
- 5.
- LWE key switching key of group : LKSKeyGen.
| Algorithm 5. |
![]() |
6. Noise Analysis
7. Parameters and Implementation
7.1. Security Model and Security Analysis
7.2. Parameter Selection
7.3. Experimental Results
8. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Author 1, T. The title of the cited article. Journal Abbreviation 2008, 10, 142–149.
- Rivest, R. L.; Shamir, A.; Adleman, L. A method for obtaining digital signatures and public-key cryptosystems. Communications of the ACM 1978, 21, 120–126. [Google Scholar] [CrossRef]
- Paillier, P. Public-key cryptosystems based on composite degree residuosity classes. In Proceedings of the International Conference on the Theory and Applications of Cryptographic Techniques, Prague, Czech Republic, May 2–6, 1999; pp. 223-–238. [Google Scholar]
- Gentry, C. Fully homomorphic encryption using ideal lattices. In Proceedings of the forty-first annual ACM symposium on Theory of computing, Bethesda, MD, USA, May 31 – June 2, 2009; pp. 169–178. [Google Scholar]
- Gentry, C.; Halevi, S.; Smart, N. P. Better bootstrapping in fully homomorphic encryption. In Proceedings of the International Workshop on Public Key Cryptography, Darmstadt, Germany, May 21–23, 2012; pp. 1–16. [Google Scholar]
- Halevi, S.; Shoup, V. Bootstrapping for HElib. Journal of Cryptology 2021, 34. [Google Scholar] [CrossRef]
- Chen, H.; Han, K. Homomorphiclowerdigits removal andimprovedFHEbootstrapping. In Proceedings of the 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel Aviv, Israel, April 29 – May 3, 2018; pp. 315–337. [Google Scholar]
- Kim, J.; Seo, J.; Song, Y. Simpler and faster BFV bootstrapping for arbitrary plaintext modulus from CKKS. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, UT, USA, October 14–18, 2024; pp. 2535–2546. [Google Scholar]
- Bae, Y.; Cheon, J. H.; Kim, J.; Stehlé, D. Bootstrapping bits with CKKS. In Proceedings of the 43rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Zurich, Switzerland, May 26–-30, 2024; pp. 94–-123. [Google Scholar]
- Chillotti, I.; Gama, N.; Georgieva, M. Faster fully homomorphic encryption: Bootstrapping in less than 0.1 seconds. In Proceedings of the 22nd International Conference on the Theory and Application of Cryptology and Information Security, Hanoi, Vietnam, December 4–8, 2016; pp. 3-–33. [Google Scholar]
- Chillotti, I.; Gama, N.; Georgieva, M.; Izabachène, M. TFHE: fast fully homomorphic encryption over the torus. Journal of Cryptology 2020, 33, 34–91. [Google Scholar] [CrossRef]
- Bonte, C.; Iliashenko, I.; Park, J.; Pereira, H. V. L. FINAL: faster FHE instantiated with NTRU and LWE. In Proceedings of the 28th International Conference on the Theory and Application of Cryptology and Information Security, Taipei, Taiwan, December 5-–9, 2022; pp. 188-–215. [Google Scholar]
- Boneh, D.; Gennaro, R.; Goldfeder, S.; Jain, A. Threshold cryptosystems from threshold fully homomorphic encryption. In Proceedings of the 38th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 19–-23, 2018; pp. 565-–596. [Google Scholar]
- Mouchet, C.; Bertrand, E.; Hubaux, J. P. An efficient threshold access-structure for rlwe-based multiparty homomorphic encryption. Journal of Cryptology 2023, 36. [Google Scholar] [CrossRef]
- Park, J. Homomorphic encryption for multiple users with less communications. IEEE Access 2021, 9, 135915–135926. [Google Scholar] [CrossRef]
- López-Alt, A.; Tromer, E.; Vaikuntanathan, V. On-the-fly multiparty computation on the cloud via multikey fully homomorphic encryption. In Proceedings of the forty-fourth annual ACM symposium on Theory of computing, New York, USA, May 19–22, 2012; pp. 1219–1234. [Google Scholar]
- Chen, H.; Dai, W.; Kim, M.; Song, Y. Efficient multi-key homomorphic encryption with packed ciphertexts with application to oblivious neural network inference. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, London, UK, November 11–15, 2019; pp. 395–412. [Google Scholar]
- Chen, H.; Chillotti, I.; Song, Y. Multi-key homomorphic encryption from TFHE. In Proceedings of the 25th International Conference on the Theory and Application of Cryptology and Information Security, Kobe, Japan, December 8–-12, 2019; pp. 446–-472. [Google Scholar]
- Kwak, H.; Lee, D.; Song, Y.; Wagh, S. A general framework of homomorphic encryption for multiple parties with non-interactive key-aggregation. In Proceedings of the 22nd International Conference, ACNS 2024, Abu Dhabi, United Arab Emirates, March 5–-8, 2024; pp. 403–-430. [Google Scholar]
- Xiang, B.; Zhang, J.; Deng, Y.; Dai, Y.; Feng, D. Fast blind rotation for bootstrapping FHEs. In Proceedings of the 43rd Annual International Cryptology Conference, Santa Barbara, CA, USA, August 20-–24, 2023; pp. 3-–36. [Google Scholar]
- Li, Z.; Lu, X.; Wang, Z.; Wang, R.; Liu, Y.; Zheng, Y.; Zhao, L.; Wang, K.; Hou, R. Faster NTRU-Based Bootstrapping in Less Than 4 Ms. TCHES 2024, 2024, 418–451. [Google Scholar] [CrossRef]
- Albrecht, M. R.; Player, R.; Scott, S. On the concrete hardness of learning with errors. Journal of Mathematical Cryptology 2015, 9, 169–203. [Google Scholar] [CrossRef]
- Ducas, L.; van Woerden, W. NTRU fatigue: how stretched is overstretched? In Proceedings of the 27th International Conference on the Theory and Application of Cryptology and Information Security, Singapore, December 6–-10, 2021; pp. 3-–32. [Google Scholar]
- Brakerski, Z.; Gentry, C.; Vaikuntanathan, V. (Leveled) fully homomorphic encryption without bootstrapping. ACM Transactions on Computation Theory 2014, 6, 1–36. [Google Scholar] [CrossRef]
- Fan, J.; Vercauteren, F. Somewhat practical fully homomorphic encryption. Cryptology ePrint Archive, Paper 2012/144, 2012. Available online: https://eprint.iacr.org/2012/144 (accessed on January 8, 2026).
- Cheon, J. H.; Kim, A.; Kim, M.; Song, Y. Homomorphic encryption for arithmetic of approximate numbers. In Proceedings of the 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3–7, 2017; pp. 409–-437. [Google Scholar]
- Ducas, L.; Micciancio, D. FHEW: bootstrapping homomorphic encryption in less than a second. In Proceedings of the 34th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Sofia, Bulgaria, April 26–30, 2015; pp. 617-–640. [Google Scholar]
- Asharov, G.; Jain, A.; López-Alt, A.; Tromer, E. Multiparty computation with low communication, computation and interaction via threshold FHE. In Proceedings of the 31st Annual International Conference on the Theory and Applications of Cryptographic Techniques, Cambridge, UK, April 15–19, 2012; pp. 483-–501. [Google Scholar]
- Lee, Y.; Micciancio, D.; Kim, A.; Choi, R.; Deryabin, M. Efficient FHEW bootstrapping with small evaluation keys, and applications to threshold homomorphic encryption. In Proceedings of the 42nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Lyon, France, April 23–27, 2023; pp. 227-–256. [Google Scholar]
- Park, J.; Rovira, S. Efficient TFHE bootstrapping in the multiparty setting. IEEE Access 2023, 11, 118625–118638. [Google Scholar] [CrossRef]
- Kwak, H.; Min, S.; Song, Y. Towards practical multi-key TFHE: parallelizable, key-compatible, quasi-linear complexity. In Proceedings of the 27th IACR International Conference on Practice and Theory of Public-Key Cryptography, Sydney, NSW, Australia, April 15–-17, 2024; pp. 354–-385. [Google Scholar]
- Xu, K.; Tan, B. H. M.; Wang, L. P.; Aung, K. M. M. Multi-key fully homomorphic encryption from NTRU and (R) LWE with faster bootstrapping. Theoretical Computer Science 2023, 968, 114026. [Google Scholar] [CrossRef]
- Kim, J.; Lee, C. A polynomial time algorithm for breaking NTRU encryption with multiple keys. Designs, Codes and Cryptography 2023, 91, 2779–2789. [Google Scholar] [CrossRef]
- Park, J.; Van Leeuwen, B.; Zajonc, O. FINALLY: A multi-key FHE scheme based on NTRU and LWE. Cryptology ePrint Archive, Paper 2024/1505, 2024. Available online: https://eprint.iacr.org/2024/1505 (accessed on January 8, 2026).
- Regev, O. On lattices, learning with errors, random linear codes, and cryptography. Journal of the ACM 2009, 56, 1–40. [Google Scholar] [CrossRef]
- Lyubashevsky, V.; Peikert, C.; Regev, O. On ideal lattices and learning with errors over rings. Journal of the ACM 2013, 60, 1–35. [Google Scholar] [CrossRef]
- Genise, N.; Gentry, C.; Halevi, S.; Li, B. Homomorphic encryption for finite automata. In Proceedings of the 25th International Conference on the Theory and Application of Cryptology and Information Security, Kobe, Japan, December 8-–12, 2019; pp. 473-–502. [Google Scholar]
- Albrecht, M.; Bai, S.; Ducas, L. A subfield lattice attack on overstretched NTRU assumptions: Cryptanalysis of some FHE and graded encoding schemes. In Proceedings of the 36th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 14–18, 2016; pp. 153–-178. [Google Scholar]
- Alperin-Sheriff, J.; Peikert, C. Faster bootstrapping with polynomial error. In Proceedings of the 34th Annual Cryptology Conference, Santa Barbara, CA, USA, August 17–21, 2014; pp. 297–-314. [Google Scholar]
- Mouchet, C.; Troncoso-Pastoriza, J. Multiparty homomorphic encryption from ring-learning-with-errors. Proceedings on Privacy Enhancing Technologies 2021, 2021, 291–311. [Google Scholar] [CrossRef]
- Kraitsberg, M.; Lindell, Y.; Osheter, V.; Smart, N. P. Adding distributed decryption and key generation to a ring-LWE based CCA encryption scheme. In Proceedings of the 24th Australasian Conference, ACISP 2019, Christchurch, New Zealand, July 3–-5, 2019; pp. 192-–210. [Google Scholar]
- Beaver, D. Efficient multiparty protocols using circuit randomization. In Proceedings of the 11th Annual International Cryptology Conference on Advances in Cryptology, Berlin, Heidelberg, 1991; pp. 420–432. [Google Scholar]
- Keller, M.; Orsini, E.; Scholl, P. MASCOT: faster malicious arithmetic secure computation with oblivious transfer. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria, October 24–28, 2016; pp. 830–842. [Google Scholar]
- Keller, M.; Pastro, V.; Rotaru, D. Overdrive: Making SPDZ great again. In Proceedings of the 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel Aviv, Israel, April 29 – May 3, 2018; pp. 158–-189. [Google Scholar]
- Keller, M.; Sun, K. Secure quantized training for deep learning. In Proceedings of the 39th International Conference on Machine Learning, 2022; pp. 10912–10938. [Google Scholar]
- Escudero, D. An introduction to secret-sharing-based secure multiparty computation. Cryptology ePrint Archive, Paper 2022/062, 2022. Available online: https://eprint.iacr.org/2022/062 (accessed on January 8, 2026).


| Set | q | n | Q | N | Estimate Security | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| I | (2, 15) | 4096 | 1024 | 3 | 600 | 32 | 10 | 4096 | 100 | |||
| II | (4, 7) | 4096 | 1024 | 3 | 600 | 32 | 10 | 4096 | 100 | |||
| III | (8, 7) | 4096 | 1024 | 3 | 600 | 16 | 13 | 4096 | 100 |
| Set | q | n | Q | N | Estimate Security | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| I’ | (2, 25) | 4096 | 1024 | 3 | 600 | 512 | 7 | 8192 | 128 | |||
| II’ | (4, 10) | 4096 | 1024 | 3 | 600 | 512 | 7 | 8192 | 128 | |||
| III’ | (8, 8) | 4096 | 1024 | 3 | 600 | 256 | 8 | 8192 | 128 |
| Set | k | Serialized (s) | Parallelized (s) |
|---|---|---|---|
| I | 2 | 42.58 | 1.87 |
| II | 3 | 50.37 | 1.91 |
| 4 | 82.06 | 2.31 | |
| III | 5 | 146.79 | 4.18 |
| 6 | 174.12 | 4.84 | |
| 7 | 205.59 | 5.70 | |
| 8 | 223.56 | 6.13 |
| Set | k | Serialized (s) | Parallelized (s) |
|---|---|---|---|
| I’ | 2 | 47.36 | 2.58 |
| II’ | 3 | 84.34 | 2.76 |
| 4 | 113.50 | 2.87 | |
| III’ | 5 | 158.14 | 4.35 |
| 6 | 193.99 | 5.16 | |
| 7 | 222.93 | 5.96 | |
| 8 | 253.63 | 6.60 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).




