F1: A Fast and Programmable Accelerator for Fully Homomorphic Encryption
Nikola Samardzic, Axel Feldmann, Aleksandar Krastev, Srinivas Devadas, Ronald G. Dreslinski, Christopher Peikert, Daniel Sánchez
Abstract
Fully Homomorphic Encryption (FHE) allows computing on encrypted data, enabling secure offloading of computation to untrusted servers. Though it provides ideal security, FHE is expensive when executed in software, 4 to 5 orders of magnitude slower than computing on unencrypted data. These overheads are a major barrier to FHE's widespread adoption.
We present F1, the first FHE accelerator that is programmable, i.e., capable of executing full FHE programs. F1 builds on an indepth architectural analysis of the characteristics of FHE computations that reveals acceleration opportunities. F1 is a wide-vector processor with novel functional units deeply specialized to FHE primitives, such as modular arithmetic, number-theoretic transforms, and structured permutations. This organization provides so much compute throughput that data movement becomes the key bottleneck. Thus, F1 is primarily designed to minimize data movement. Hardware provides an explicitly managed memory hierarchy and mechanisms to decouple data movement from execution. A novel compiler leverages these mechanisms to maximize reuse and schedule off-chip and on-chip data movement.
We evaluate F1 using cycle-accurate simulation and RTL synthesis. F1 is the first system to accelerate complete FHE programs, and outperforms state-of-the-art software implementations by gmean 5,400× and by up to 17,000×. These speedups counter most of FHE's overheads and enable new applications, like real-time private deep learning in the cloud.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 21bdd300-ac25-4fe8-93ca-dbab6f9bf328Cited by top-tier papers52
- CraterLake: a hardware accelerator for efficient unbounded computation on encrypted dataNikola Samardzic, Axel Feldmann, Aleksandar Krastev, Nathan Manohar et al.ISCA 2022 · 205 citations
- BTS: an accelerator for bootstrappable fully homomorphic encryptionSangpyo Kim, Jongmin Kim, Michael Jaemin Kim, Wonkyung Jung et al.ISCA 2022 · 184 citations
- ARK: Fully Homomorphic Encryption Accelerator with Runtime Data Generation and Inter-Operation Key ReuseJongmin Kim, Gwangho Lee, Sangpyo Kim, Gina Sohn et al.MICRO 2022 · 160 citations
- SPIRAL: Fast, High-Rate Single-Server PIR via FHE CompositionSamir Jordan Menon, David J. WuS&P 2022 · 153 citations
- BOLT: Privacy-Preserving, Accurate and Efficient Inference for TransformersQi Pang, Jinhao Zhu, Helen Möllering, Wenting Zheng et al.S&P 2024 · 149 citations
Builds on4
- Searching for MobileNetV3Andrew Howard, Ruoming Pang, Hartwig Adam, Quoc V. Le et al.ICCV 2019 · 9,163 citations
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- HEAX: An Architecture for Computing on Encrypted DataM. Sadegh Riazi, Kim Laine, Blake Pelton, Wei DaiASPLOS 2020 · 244 citations
- EVA: an encrypted vector arithmetic language and compiler for efficient homomorphic computationRoshan Dathathri, Blagovesta Kostova, Olli Saarikivi, Wei Dai et al.PLDI 2020 · 117 citations
Related papers
- A Tensor Compiler with Automatic Data Packing for Simple and Efficient Fully Homomorphic EncryptionAleksandar Krastev, Nikola Samardzic, Simon Langowski, Srinivas Devadas et al.PLDI 2024 · 23 citations
- Falcon: Algorithm-Hardware Co-Design for Efficient Fully Homomorphic Encryption AcceleratorLiang Kong, Xianglong Deng, Guang Fan, Shengyu Fan et al.ASPLOS 2026
- Coyote: A Compiler for Vectorizing Encrypted Arithmetic CircuitsRaghav Malik, Kabir Sheth, Milind KulkarniASPLOS 2023 · 22 citations
- GME: GPU-based Microarchitectural Extensions to Accelerate Homomorphic EncryptionKaustubh Shivdikar, Yuhui Bao, Rashmi Agrawal, Michael Tian Shen et al.MICRO 2023 · 46 citations
- FAB: An FPGA-based Accelerator for Bootstrappable Fully Homomorphic EncryptionRashmi Agrawal, Leo de Castro, Guowei Yang, Chiraag Juvekar et al.HPCA 2023 · 136 citations
