Documentation Index
Fetch the complete documentation index at: https://mintlify.com/octra-labs/pvac_hfhe_cpp/llms.txt
Use this file to discover all available pages before exploring further.
Overview
Recryption (bootstrapping) allows refreshing the noise in a ciphertext without changing its encrypted value. This enables computation of arbitrary-depth circuits by periodically refreshing ciphertexts during evaluation.Evaluation key
make_evalkey
Creates an evaluation key for bootstrapping operations.
Public key
Secret key
Number of zero ciphertexts to pre-generate for the pool
Expected circuit depth for noise budget planning
Evaluation key containing a pool of zero encryptions and an encryption of 1
Description
Generates an evaluation key used for recryption operations. The evaluation key contains:- zero_pool: A vector of
pool_sizezero ciphertexts with noise budget for depthdepth_hint - enc_one: An encryption of the value 1
Larger pool sizes provide more randomness options but increase key size. A pool size of 8-16 is typically sufficient.
Recryption
ct_recrypt
Refreshes a ciphertext by balancing its sigma vector density.
Public key
Evaluation key containing zero pool
Ciphertext to refresh
Refreshed ciphertext with balanced noise
Description
Refreshes the ciphertext’s noise without changing the encrypted value by:- Checking if sigma density is unbalanced (outside [0.495, 0.505])
- If unbalanced, adding a random zero ciphertext from the pool
- Applying UBK (universal balancing key) operations
- Repeating up to 8 iterations or until balanced
- Compacting edges and layers
Sigma density checking
sigma_needs_balance
Checks if a ciphertext’s sigma density requires rebalancing.
Public key
Ciphertext to check
true if sigma density is outside the balanced range [0.495, 0.505]Description
Computes the sigma vector density usingsigma_density(pk, C) and returns true if the density is less than 0.495 or greater than 0.505.
A balanced sigma density (near 0.5) indicates well-distributed noise, which is important for security and correctness.
See: recrypt.hpp:21
Implementation details
Noise balancing algorithm
The recryption algorithm uses an iterative approach:- Selects a random zero ciphertext from the pool
- Adds it to the current result (adding zero doesn’t change the value)
- Applies UBK transformations
- Checks and enforces edge budget
- Sigma density is balanced (in [0.495, 0.505]), or
- 8 iterations have been performed
UBK operations
Theubk_apply function (defined elsewhere) performs transformations on the ciphertext that help balance the sigma vectors while preserving the encrypted value.
Example usage
When to use recryption
Recryption should be used when:- Deep circuits: After multiple multiplications, ciphertexts grow large
- Unbalanced noise: When
sigma_needs_balancereturns true - Performance: Large ciphertexts slow down operations
- Memory: Edge count approaches
pk.prm.edge_budget
Recryption is relatively expensive compared to basic operations. Use it strategically rather than after every operation.
Performance considerations
Cost factors:
- Recryption cost: O(edges * iterations)
- Typical iterations: 2-4 for moderately unbalanced ciphertexts
- Zero pool generation: One-time cost at key generation
- Pool size: Minimal impact on recryption speed
Advanced topics
Choosing pool size
The zero pool size affects:- Randomness: Larger pools provide more diverse zero ciphertexts
- Key size: Each zero ciphertext adds to the evaluation key size
- Security: More randomness can improve noise distribution
- Small circuits (depth ≤ 5): pool_size = 4-8
- Medium circuits (depth ≤ 15): pool_size = 8-16
- Large circuits (depth > 15): pool_size = 16-32
Depth hint selection
The depth hint determines the noise budget for zero ciphertexts:- Set it to the expected maximum depth of your circuit
- Too low: Zero ciphertexts may not provide enough noise refresh
- Too high: Wastes noise budget, larger ciphertexts