Skip to main content
PVAC-HFHE supports homomorphic addition, subtraction, and multiplication, allowing computation on encrypted data without decryption.

Overview

Homomorphic operations preserve the algebraic structure:
The server can compute on ciphertexts without knowing the plaintext values or secret key.
All operations are exact (no approximation errors) and work over the 127-bit prime field F_p.

Addition

Addition is extremely fast: simply concatenate the layer graphs and edge lists.
From include/pvac/ops/arithmetic.hpp:165-188:

Why addition is fast

Addition doesn’t create new layers or multiply edges. It just:
  1. Merges layer lists (adjusting PROD layer parent indices)
  2. Concatenates edge lists (adjusting layer IDs)
  3. Adds constant terms
Performance:
  • Time: 0.012 ms (12 microseconds)
  • Ciphertext growth: None (just concatenation)
  • Noise growth: Linear
Addition is 10-87× faster than RLWE schemes (BFV/BGV/CKKS) because it requires no polynomial operations.

Example

Subtraction

Subtraction is addition with negation:
Negation scales all edge weights and constants by -1:
From include/pvac/ops/arithmetic.hpp:152-163. Performance: Same as addition (~0.012 ms).

Multiplication

Multiplication creates new PROD layers representing cross-products of parent layers.
The parameter S controls the number of edges per product layer (default: 8). From include/pvac/ops/arithmetic.hpp:194-225:

Multiplication algorithm

Given A = a0 + g_A and B = b0 + g_B where a0, b0 are constants and g_A, g_B are graph parts:
Steps:
  1. Product layers: For each pair (la, lb) where la ∈ layers(A) and lb ∈ layers(B), create a PROD layer:
From include/pvac/ops/arithmetic.hpp:90-94.
  1. Repack edges: For each PROD layer, create S new edges that encode the product value:
Choose s-1 random edges, then solve for the last edge’s weight to match the target sum. From include/pvac/ops/arithmetic.hpp:55-88.
  1. Add cross terms: Scale B’s edges by a0 and A’s edges by b0.
  2. Compute constant: c0 = a0 * b0.

Why multiplication is more expensive

  • Layer growth: |L_C| = |L_A| + |L_B| + |L_A| × |L_B|
  • Edge growth: New edges for each product layer
  • Compaction: May trigger edge merging if budget exceeded
Performance:
  • Time: 2.47 ms
  • vs BFV: 2.9× faster (shallow), 7.4× faster (leveled)
  • vs CKKS: 14.3× faster
From benchmarks/README.md:42-50, PVAC-HFHE multiplication is significantly faster than RLWE schemes for scalar operations.

Example

Squaring

Squaring is optimized compared to generic multiplication:
From include/pvac/ops/arithmetic.hpp:227-255:
Optimization: Only creates LA*(LA+1)/2 PROD layers instead of LA², exploiting symmetry.

Constant operations

Operations with public constants are much faster:

Addition with constant

From include/pvac/ops/arithmetic.hpp:269-275. Free operation: Only updates constant term, no layer/edge changes.

Multiplication by constant

From include/pvac/ops/arithmetic.hpp:261-263. Fast operation: Scales all edge weights, no new layers.

Division by constant

From include/pvac/ops/arithmetic.hpp:257-259. Requires field inversion of the constant.

Depth and noise growth

Multiplicative depth

The depth of a ciphertext is the longest path of multiplications from fresh encryptions:
  • Fresh encryption: depth 0
  • Addition/subtraction: max(depth(A), depth(B))
  • Multiplication: depth(A) + depth(B) + 1

Noise budget

Noise grows with depth:
Default parameters:
  • Base: 120 bits
  • Growth: 16 bits per depth
  • At depth 5: 120 + 16*5 = 200 bits
When noise budget is exhausted, decryption will fail. The PoC supports depth up to ~5 before ciphertext size becomes impractical.

Performance comparison

From benchmarks/README.md:42-72:

Scalar multiplication

Scalar addition

PVAC-HFHE excels at shallow circuits (depth 1-2) with scalar operations, significantly outperforming RLWE schemes.

Ciphertext management

Edge budget

When ciphertext edges exceed the budget (default: 1,200,000), automatic compaction triggers:

Compaction

Merges edges pointing to the same (layer, index, sign):
From include/pvac/ops/encrypt.hpp:658-660. Also removes unused layers:

Code examples

Polynomial evaluation

Dot product

Next steps

Security

Understand the LPN-based security model

API reference

Explore the complete API