Skip to main content
PVAC-HFHE uses a novel hypergraph-based encryption scheme secured by the Learning Parity with Noise (LPN) assumption.

High-level overview

The encryption scheme consists of:
  1. Syndrome graph construction: Build a random k-uniform hypergraph
  2. Noise generation: Use PRF to generate structured noise from LPN
  3. Layer-edge representation: Express ciphertexts as computational graphs
  4. Decryption via syndrome evaluation: Recover plaintext by evaluating the hypergraph

Key parameters

From include/pvac/core/types.hpp:36-70:
These parameters provide 128-bit security based on LPN hardness with noise rate τ = 1/8.Security analysis:
  • Information-theoretic bound: 2226 bits
  • Classical security: 200+ bits
  • Quantum security: 100+ bits

Ciphertext structure

A ciphertext is a computational graph with layers and hypergraph edges:

Layers

Layers represent computation nodes:
From include/pvac/core/types.hpp:91-101.
  • BASE layers: Created during fresh encryption
  • PROD layers: Created during homomorphic multiplication

Edges

Edges encode the hypergraph structure:
From include/pvac/core/types.hpp:103-114.
Each edge contributes sign * w[slot] * g^idx to the encrypted value, where the syndrome s provides LPN-based security.

Encryption algorithm

Fresh encryption

Encrypting a value v at depth d:
The synth function from include/pvac/ops/encrypt.hpp:559-602:

Encryption steps

1. Noise budget computation

From include/pvac/ops/encrypt.hpp:194-214.
Noise budget grows linearly with depth: budget(d) = 120 + 16*d bits. This allows deeper circuits while maintaining security.

2. PRF-based randomness

The scheme uses pseudorandom functions based on LPN:
From include/pvac/crypto/lpn.hpp:263-268. Each prf_R_core call:
  1. Generates LPN matrix rows using AES-CTR
  2. Computes dot product with secret key
  3. Adds noise with rate τ = 1/8
  4. Applies Toeplitz hash to extract 127 bits
  5. Maps to nonzero field element
Using three independent samples (with domain separation) increases security margin.

3. Hypergraph edge construction

Three types of edges encode the value: Signature edges (K=8 edges) encode the main value:
From include/pvac/ops/encrypt.hpp:352-372. 2-tuple edges add structured noise:
From include/pvac/ops/encrypt.hpp:388-401. 3-tuple edges add even more noise: Similar construction with 3 edges that sum to the delta value.

Syndrome vectors

Each edge has a syndrome vector s of length m_bits = 8192:
The syndrome is computed as:
where:
  • H is a random m_bits × n_bits binary matrix (8192 × 16384)
  • x is a random sparse binary vector with weight x_col_wt = 128
  • H has column weight h_col_wt = 192
The syndrome provides LPN-based security. Without the secret key, recovering the plaintext from syndromes is as hard as solving LPN.

Ciphertext size

Fresh ciphertext

For a fresh encryption at depth 0:
Typically:
  • 1 layer: 40 bytes
  • ~200 edges: each ~250 bytes (1024-bit syndrome + weights)
  • Total: ~42 KB

Growth with depth

From benchmarks/README.md:88-97.
Ciphertext size grows exponentially with multiplicative depth in this PoC. Production implementations would use recryption/bootstrapping.

Code example

Next steps

Homomorphic operations

Learn how to compute on encrypted data

Security

Understand the LPN-based security