HERMES: Efficient Ring Packing Using MLWE Ciphertexts and Application to Transciphering
Youngjin Bae, Jung Hee Cheon, Jaehyung Kim, Jai Hyun Park, Damien Stehlé
Abstract
Most of the current fully homomorphic encryption (FHE) schemes are based on either the learning-with-errors (LWE) problem or on its ring variant (RLWE) for storing plaintexts. During the homomorphic computation of FHE schemes, RLWE formats provide high throughput when considering several messages, and LWE formats provide a low latency when there are only a few messages. Efficient conversion can bridge the advantages of each format. However, converting LWE formats into RLWE format, which is called ring packing, has been a challenging problem.
We propose an efficient solution for ring packing for FHE. The main improvement of this work is twofold. First, we accelerate the existing ring packing methods by using bootstrapping and ring switching techniques, achieving practical runtimes. Second, we propose a new method for efficient ring packing, HERMES, by using ciphertexts in Module-LWE (MLWE) formats, to also reduce the memory. To this end, we generalize the tools of LWE and RLWE formats for MLWE formats.
On a single-thread implementation, HERMES consumes s for the ring packing of LWE-format ciphertexts into an RLWE-format ciphertext. This gives x higher throughput compared to the state-of-the-art ring packing for FHE, PEGASUS [S&P'21], which takes s for packing LWE ciphertexts with similar homomorphic capacity. We also illustrate the efficiency of HERMES by using it for transciphering from LWE symmetric encryption to CKKS fully homomorphic encryption, significantly outperforming the recent proposals HERA [Asiacrypt'21] and Rubato [Eurocrypt'22].
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b6428db3-592d-42c6-8d07-d3597b5f2d25Cited by top-tier papers8
- NSHEDB: Noise-Sensitive Homomorphic Encrypted Database Query EngineBoram Jung, Hung-Wei Tseng, Yuliang LiSIGMOD 2026 · 2 citations
- Ajax: Fast Threshold Fully Homomorphic Encryption without Noise FloodingZhenkai Hu, Haofei Liang, Xiao Wang, Xiang Xie et al.USENIX Security 2026
- Grafting: Decoupled Scale Factors and Modulus in RNS-CKKSJung Hee Cheon, Hyeongmin Choe, Minsik Kang, Jaehyung Kim et al.CCS 2025
- SPIRIT: Batch Hintless Single-Server PIR via Stateful Ciphertext ConversionZhou Zhang, Ran Mao, Zian Zhao, Haowen Pan et al.USENIX Security 2026
- BatchBoot: Fast Batched Bootstrapping for TFHE scheme and Practical ApplicationsZhihao Li, Hongyu Wang, Yuan Zhao, Lichun Li et al.USENIX Security 2026
Related papers
- SHIP: A Shallow and Highly Parallelizable CKKS Bootstrapping AlgorithmJung Hee Cheon, Guillaume Hanrot, Jongmin Kim, Damien StehléEUROCRYPT 2025 · 8 citations
- HERDS: Multi-key Fully Homomorphic Encryption with Sublinear BootstrappingBinwu Xiang, Seonhong Min, Intak Hwang, Zhiwei Wang et al.EUROCRYPT 2026 · 1 citation
- DPad-HE: Towards Hardware-friendly Homomorphic Evaluation using 4-Directional ManipulationWenxu Tang, Fangyu Zheng, Guang Fan, Tian Zhou et al.CCS 2024 · 1 citation
- Two-Tier Data Packing in RLWE-based Homomorphic Encryption for Secure Federated LearningYufei Zhou, Peijia Zheng, Xiaochun Cao, Jiwu HuangCCS 2024 · 3 citations
- High-Precision Exact FHE Made Simple, General, and FastChris Peikert, Doron Zarchy, Guy ZyskindCRYPTO 2026 · 8 citations
