High-level overview
The encryption scheme consists of:- Syndrome graph construction: Build a random k-uniform hypergraph
- Noise generation: Use PRF to generate structured noise from LPN
- Layer-edge representation: Express ciphertexts as computational graphs
- Decryption via syndrome evaluation: Recover plaintext by evaluating the hypergraph
Key parameters
Frominclude/pvac/core/types.hpp:36-70:
These parameters provide 128-bit security based on LPN hardness with noise rate τ = 1/8.Security analysis:
- Information-theoretic bound: 2226 bits
- Classical security: 200+ bits
- Quantum security: 100+ bits
Ciphertext structure
A ciphertext is a computational graph with layers and hypergraph edges:Layers
Layers represent computation nodes:include/pvac/core/types.hpp:91-101.
- BASE layers: Created during fresh encryption
- PROD layers: Created during homomorphic multiplication
Edges
Edges encode the hypergraph structure:include/pvac/core/types.hpp:103-114.
Each edge contributes
sign * w[slot] * g^idx to the encrypted value, where the syndrome s provides LPN-based security.Encryption algorithm
Fresh encryption
Encrypting a valuev at depth d:
synth function from include/pvac/ops/encrypt.hpp:559-602:
Encryption steps
1. Noise budget computation
include/pvac/ops/encrypt.hpp:194-214.
2. PRF-based randomness
The scheme uses pseudorandom functions based on LPN:include/pvac/crypto/lpn.hpp:263-268.
Each prf_R_core call:
- Generates LPN matrix rows using AES-CTR
- Computes dot product with secret key
- Adds noise with rate τ = 1/8
- Applies Toeplitz hash to extract 127 bits
- Maps to nonzero field element
Using three independent samples (with domain separation) increases security margin.
3. Hypergraph edge construction
Three types of edges encode the value: Signature edges (K=8 edges) encode the main value:include/pvac/ops/encrypt.hpp:352-372.
2-tuple edges add structured noise:
include/pvac/ops/encrypt.hpp:388-401.
3-tuple edges add even more noise:
Similar construction with 3 edges that sum to the delta value.
Syndrome vectors
Each edge has a syndrome vectors of length m_bits = 8192:
His a randomm_bits × n_bitsbinary matrix (8192 × 16384)xis a random sparse binary vector with weightx_col_wt = 128Hhas column weighth_col_wt = 192
The syndrome provides LPN-based security. Without the secret key, recovering the plaintext from syndromes is as hard as solving LPN.
Ciphertext size
Fresh ciphertext
For a fresh encryption at depth 0:- 1 layer: 40 bytes
- ~200 edges: each ~250 bytes (1024-bit syndrome + weights)
- Total: ~42 KB
Growth with depth
From
benchmarks/README.md:88-97.
Code example
Next steps
Homomorphic operations
Learn how to compute on encrypted data
Security
Understand the LPN-based security