Overview
The arithmetic module provides homomorphic operations for computing on encrypted data without decryption. All operations preserve the encrypted values while allowing addition, subtraction, multiplication, and scalar operations.Addition and subtraction
ct_add
Adds two ciphertexts homomorphically.
const PubKey&
required
Public key
const Cipher&
required
First ciphertext operand
const Cipher&
required
Second ciphertext operand
Cipher
Ciphertext encrypting
dec(A) + dec(B)Description
Performs homomorphic addition by:- Fusing the layer graphs of both ciphertexts
- Combining edge sets with appropriate layer offset
- Adding constant terms:
c0 = A.c0 + B.c0 - Compacting edges if budget is exceeded
Both ciphertexts must have the same number of slots.
ct_sub
Subtracts one ciphertext from another.
const PubKey&
required
Public key
const Cipher&
required
Minuend ciphertext
const Cipher&
required
Subtrahend ciphertext
Cipher
Ciphertext encrypting
dec(A) - dec(B)Description
Computes homomorphic subtraction asct_add(pk, A, ct_neg(pk, B)).
See: arithmetic.hpp:190
ct_neg
Negates a ciphertext.
const PubKey&
required
Public key
const Cipher&
required
Ciphertext to negate
Cipher
Ciphertext encrypting
-dec(A)Description
Negates by scaling with-1.
See: arithmetic.hpp:161
Multiplication
ct_mul
Multiplies two ciphertexts homomorphically.
const PubKey&
required
Public key
const Cipher&
required
First ciphertext operand
const Cipher&
required
Second ciphertext operand
size_t
default:"8"
Number of repack edges per product layer (tuning parameter)
Cipher
Ciphertext encrypting
dec(A) * dec(B)Description
Performs homomorphic multiplication by:- Separating constant terms:
A = A_g + a0,B = B_g + b0 - Creating product layers for all pairs
(layer_a, layer_b) - Computing repacked edges:
g^B * (R_a * R_b) = target - Adding cross terms:
a0 * B_g + b0 * A_g - Setting constant term:
c0 = a0 * b0
|A.L| * |B.L| new product layers.
See: arithmetic.hpp:194
ct_square
Squares a ciphertext homomorphically.
const PubKey&
required
Public key
const Cipher&
required
Ciphertext to square
size_t
default:"8"
Number of repack edges per product layer
Cipher
Ciphertext encrypting
dec(A)^2Description
Computes homomorphic squaring more efficiently thanct_mul(pk, A, A, S) by:
- Only creating product layers for pairs
(i, j)wherei ≤ j - Doubling the contribution for off-diagonal pairs:
2 * R_i * R_j - Creating
|A.L| * (|A.L| + 1) / 2layers instead of|A.L|^2
Scalar operations
ct_mul_const (unsigned)
Multiplies a ciphertext by an unsigned constant.
const PubKey&
required
Public key
const Cipher&
required
Ciphertext operand
uint64_t
required
Unsigned scalar constant
Cipher
Ciphertext encrypting
k * dec(A)Description
Scales all edge weights and the constant term byk. This is a cheap operation that doesn’t create new layers or edges.
See: arithmetic.hpp:261
ct_mul_const (signed)
Multiplies a ciphertext by a signed constant.
const PubKey&
required
Public key
const Cipher&
required
Ciphertext operand
int64_t
required
Signed scalar constant
Cipher
Ciphertext encrypting
k * dec(A)Description
Scales the ciphertext by a signed integer, correctly handling negative values. See: arithmetic.hpp:265ct_div_const
Divides a ciphertext by a constant (field inversion).
const PubKey&
required
Public key
const Cipher&
required
Ciphertext operand
const Fp&
required
Field element divisor (must be non-zero)
Cipher
Ciphertext encrypting
dec(A) / k in the fieldDescription
Scales by the multiplicative inverse ofk in the field. Equivalent to ct_scale(pk, A, fp_inv(k)).
See: arithmetic.hpp:257
ct_add_const (unsigned)
Adds an unsigned constant to a ciphertext.
const PubKey&
required
Public key (unused, for API consistency)
const Cipher&
required
Ciphertext operand
uint64_t
required
Unsigned constant to add
Cipher
Ciphertext encrypting
dec(A) + kDescription
Adds a plaintext constant by updating thec0 term. No new edges or layers are created.
See: arithmetic.hpp:269
ct_add_const (signed)
Adds a signed constant to a ciphertext.
const PubKey&
required
Public key (unused)
const Cipher&
required
Ciphertext operand
int64_t
required
Signed constant to add
Cipher
Ciphertext encrypting
dec(A) + kct_sub_const (unsigned)
Subtracts an unsigned constant from a ciphertext.
const PubKey&
required
Public key
const Cipher&
required
Ciphertext operand
uint64_t
required
Unsigned constant to subtract
Cipher
Ciphertext encrypting
dec(A) - kct_sub_const (signed)
Subtracts a signed constant from a ciphertext.
const PubKey&
required
Public key
const Cipher&
required
Ciphertext operand
int64_t
required
Signed constant to subtract
Cipher
Ciphertext encrypting
dec(A) - kct_scale
Scales a ciphertext by a field element.
const PubKey&
required
Public key (unused)
const Cipher&
required
Ciphertext to scale
const Fp&
required
Field element scalar
Cipher
Ciphertext encrypting
s * dec(A)Description
Multiplies all edge weights and constant terms by the field elements. This is the most general scalar multiplication function.
See: arithmetic.hpp:152
Example usage
Performance considerations
Operation costs:
- Addition/subtraction: O(edges) - very fast
- Scalar operations: O(edges) - very fast
- Multiplication: O(layers^2) - expensive, increases depth
- Square: O(layers^2 / 2) - more efficient than general multiplication