- Merged (PR #619): Removed unqualified calls to
std::move. - Merged (PR #651): Fixed filename typos in native examples.
- Merged (PR #662) and (PR #666): Fixed broken links in README.md.
- Merged (PR #669): Removed extra semicolons that caused compiler warnings.
- Merged (PR #688): Fixed incorrect version numbers in native/tests/CMakeLists.txt.
- Merged (PR #695): Fixed incorrect version numbers in native/examples/CMakeLists.txt
- Fixed detection of intrinsics on M1 Macs (PR #597).
- Fixed old dependency version numbers in README.md (PR #596).
- Fixed release date typo in README.md.
- The BGV scheme now keeps ciphertexts in NTT form. BGV ciphertext multiplication is much faster than version 4.0.0.
- When a BGV ciphertext saved by previous versions is loaded in the current version, it is automatically converted to NTT form.
- Increased
SEAL_COEFF_MOD_COUNT_MAX, the maximum number of primes that define the coefficient modulus, from 64 to 256.
- Fixed typos (PR #590).
- Added $schema to cgmanifest.json (PR #558).
- Fixed typos (PR #512).
- Fixed typos (PR #530).
- Fixed typos (PR #509).
- Added missing
constqualifiers (PR #556). - Added vcpkg installation instructions (PR #562).
- Fixed an issue in specific environments where allocation fails without throwing
std::bad_alloc. - Fixed comments (C++) and C/.NET wrapper implementation of an exception thrown by
invariant_noise_budget.
- Added new public methods
mod_reduce_xxx(...)(native) andModReduceXxx(...)(dotnet) to the classEvaluator.
- Added BGV scheme (PR 283). Thanks, Alibaba Gemini Lab!
- Added a new example "BGV basics" to native and dotnet.
- Loading objects serialized by Microsoft SEAL v3.4+ are supported.
- Updated versions of dependencies: GoogleTest from 1.10.0 to 1.11.0 and GoogleBenchmark from 1.5.2 to 1.6.0.
- Fixed an ambiguous comment (PR 375).
- Added
seal::scheme_type::bgv. - Added a new public method
parms_id()(native) to the classEncryptionParameters. - Added a new public method
Create(...)(native and dotnet) with three inputs in the classCoeffModulus. - Added a new public method
correction_factor()(native) orCorrectionFactor()(dotnet) to the classCiphertext. - Removed the friendship of the class
EncryptionParametersto the classSEALContext.
native/bench/bgv.cppis added.- Examples are renamed and extended.
- All output files including downloaded thirdparty dependencies and Visual Studio project and solution files will be created in the build directory (PR 427).
- Reduced
util::try_minimal_primitive_rootsearch iterations by half (PR 430). Thanks, zirconium-n! - Updated .Net SDK version to 6.0.x and supported Visual Studio version to 17 2022.
- Added
SEAL_AVOID_BRANCHINGoption to eleminate branching in critical functions when Microsoft SEAL is built with maliciously inserted compiler flags.
- Removed exceptions in
KeyGenerator::CreateGaloisKeyswhen inputs do not include steps so that even whenEncryptionParameterQualifiers::using_batchingis false Galois automorphisms are still available.
dotnet/SEALNet.slnis removed.dotnet/SEALNet.sln.inis added.
- Fixed a bug when Intel HEXL is used (Issue 411) (PR 414).
- Fixed an abnormal benchmark case due to AVX512 transitions when Intel HEXL is used (PR 416).
- Fixed compiler and linker errors in downstream projects when Microsoft SEAL is built with
SEAL_BUILD_DEPS=ONandSEAL_USE_INTEL_HEXL=ON. - Updated CMake minimum requirement to 3.13.
native/src/seal/util/intel_seal_ext.his removed.native/src/seal/util/intel_seal_ext.cppis removed.
- Improved the performance of
Evaluator::multiply,Evaluator::multiply_inplace, andEvaluator::squarein the BFV scheme for default parameters with degree4096or higher. - Improved the performance of decryption (PR 363).
- Updated to HEXL version 1.2.1 (PR 375).
- Added more benchmark cases (PR 379).
constmethods inSEALContextandSEALContext::ContextDataclasses that used to return a pointer or reference now have a preceedingconstqualifier.
- Fixed failed tests on PowerPC architecture (Issue 360).
- Fixed an error when loading seeded ciphertexts serialized by v3.4.x from v3.5.0+.
- Fixed failed tests on ARM64 architecture (Issue 347).
- Improved HEXL NTT integration (PR 349).
- Improved CKKS ciphertext multiplication (PR 346).
- Improved CKKS ciphertext square (PR 353), except that with GNU G++ compiler and
1024degree there is a huge penalty in execution time. Users should switch from GNU G++ in this specific parameter setting if CKKS square is used.
- Updated the dependency Intel HEXL to v1.1.0 (PR 332).
- Integrated more optimizations from Intel HEXL to Microsoft SEAL.
- Intel HEXL now uses Microsoft SEAL's memory pool, so that memory allocation reported by Microsoft SEAL is more accurate.
- Fixed typos in comments (PR 328).
- Fixed a bug in
DWTHandler(Issue 330). - Fixed failing tests when
SEAL_USE_ZLIB=OFFandSEAL_USE_ZTD=OFF(PR 332). - Fixed shared library build when
SEAL_USE_HEXL=ON(PR 332). - Added missing
constqualifiers to several members ofBatchEncoderandEvaluator(PR 334).
- Enabled AddressSanitizer and LeakSanitizer when building Microsoft SEAL tests in Debug mode on Unix-like systems, based on (PR 318).
- Fixed
alloc-dealloc-mismatchissues resolved by (PR 318). - Fixed wrong descriptions in serializable.h and Serializable.cs reported in (Issue 316).
- Added support to build Microsoft SEAL out of the box with emscripten (PR 306).
- Added support to build Microsoft SEAL with Intel HEXL as an optional dependency (PR 312).
- Improved the error message when attempting to configure with
BUILD_SHARED_LIBS=ONandSEAL_BUILD_SEAL_C=ON(Issue 284). - Added
seal::random_bytesfunction in randomgen.h. - Removed redundant
is_metadata_valid_forinvocations reported in (Issue 313). - Minor bug fixes
- Merged pull request (PR 282) with typo and minor bug fixes.
- Fixed an issue (Issue 278) in finding ZLIB header files when building SEAL with
BUILD_SHARED_LIBS=ON. - Fixed a member variable initialization order bug in SafeByteBuffer.
- Added benchmarks that depend on Google Benchmark in native/bench.
- Changed low-level code that reduces the runtime difference among code generated by msvc, gcc, and clang.
- Using ARM64 intrinsics for better performance (PR 269).
- Fixed a bug reported in (Issue 248) and (Issue 249): in in-place Zstandard compression the input buffer head location was not correctly updated, resulting in huge memory use.
- Fixed an issue with CMake system where a shared Zstandard was not correctly handled (it is not supported).
- Fixed an issue with CMake system where
BUILD_SHARED_LIBS=ONandSEAL_BUILD_DEPS=ONresulted in Zstandard header files not being visible to the build (Issue 242).
- Fixed issues with CMake system overwriting existing
FETCHCONTENT_BASE_DIR(Issue 242). - Corrected mistakes and typos in README.md.
- Added support for Zstandard compression as a much more efficient alternative to ZLIB. The performance improvement is around 20–30x.
- Added support for iOS in the NuGet package of Microsoft SEAL.
- The build system is unified for all platforms.
There is no longer a Visual Studio solution file (
seal.sln) for Windows. There is a separate solution file for the dotnet library (dotnet/SEALNet.sln). - Added support for Shake256 (FIPS-202) XOF for pseudo-random number generation in addition to the default Blake2xb (faster).
- Microsoft SEAL 3.6 is backwards compatible with 3.4 and 3.5 when deserializing, but it does not support serializing in the old formats.
- All C++
enumlabels are consistently in lowercase. Most importantly,scheme_type::BFVandscheme_type::CKKSare changed toscheme_type::bfvandscheme_type::ckks. - Changed
seal::SEAL_BYTEtoseal::seal_byte; all uppercase names are used only for preprocessor macros. - Removed
BatchEncoderAPI for encoding and decodingPlaintextobjects inplace. This is because aPlaintextobject with slot-data written into the coefficients is (confusingly) not valid to be used for encryption. - Removed
IntegerEncoderandBigUIntclasses.IntegerEncoderresults in inefficient homomorphic evaluation and lacks sane correctness properties, so it was basically impossible to use in real applications. TheBigUIntclass was only used by theIntegerEncoder. - All
Encryptor::encryptvariants have now two overloads: one that takes aCiphertextout-parameter, and one that returns aSerializable<Ciphertext>. - Changed the names of the public key generation functions to clearly express that a new key is created each time, e.g.,
KeyGenerator::create_public_key. - Removed the
KeyGenerator::relin_keys_localandKeyGenerator::galois_keys_localfunctions. These were poorly named and have been replaced with overloads ofKeyGenerator::create_relin_keysandKeyGenerator::create_galois_keysthat take an out-parameter of typeRelinKeysorGaloisKeys. - Renamed
IntArraytoDynArray(dynamic array) and removed unnecessary limitations on the object type template parameter. - Added public API for modular reduction to the
Modulusclass. - Added API for creating
DynArrayandPlaintextobjects from agsl::span<std::uint64_t>(C++) orIEnumerable<ulong>(C#).
- Added
std::hashimplementation forEncryptionParameters(in addition toparms_id_type) so it is possible to create e.g.std::unordered_mapofEncryptionParameters. - Added API to
UniformRandomGeneratorFactoryto find whether the factory uses a default seed and to retrieve that seed. - Added const overloads for
DynArray::beginandDynArray::end. - Added a
Shake256PRNGandShake256PRNGFactoryclasses. RenamedBlakePRNGclass toBlake2xbPRNG, andBlakePRNGFactoryclass toBlake2xbPRNGFactory. - Added a serializable
UniformRandomGeneratorInfoclass that represents the type of an extendable output function and a seed value. - Added native/src/seal/version.h defining a struct
SEALVersion. This is used internally to route deserialization logic to correct functions depending on loadedSEALHeaderversion.
SEAL_BUILD_DEPScontrols whether dependencies are downloaded and built into Microsoft SEAL or searched from the system.- Only a shared library will be built when
BUILD_SHARED_LIBSis set toON. Previously a static library was always built. - Encryption error is sampled from a Centered Binomial Distribution (CBD) by default unless
SEAL_USE_GAUSSIAN_NOISEis set toON. Sampling from a CBD is constant-time and faster than sampling from a Gaussian distribution, which is why it is used by many of the NIST PQC finalists. SEAL_DEFAULT_PRNGcontrols which XOF is used for pseudo-random number generation. The available values areBlake2xb(default) andShake256.
- The pkg-config system has been improved.
All files related to pkg-config have been moved to pkgconfig/.
CMake creates now also a pkg-config file
seal_shared.pcfor compiling against a shared Microsoft SEAL ifBUILD_SHARED_LIBSis set toON. - Added
.pre-commit-config.yaml(check out pre-commit if you are not familiar with this tool). - Added
seal::util::DWTHandlerandseal::util::Arithmeticclass templates that unify the implementation of FFT (used byCKKSEncoder) and NTT (used by polynomial arithmetic). - The performance of encoding and decoding in CKKS are improved.
- The performance of randomness generation for ciphertexts and keys (RLWE samples) is improved.
native/src/seal/intarray.hto native/src/seal/dynarray.hdotnet/src/SEALNet.csprojto dotnet/src/SEALNet.csproj.indotnet/tests/SEALNetTest.csprojto dotnet/tests/SEALNetTest.csproj.indotnet/examples/SEALNetExamples.csprojto dotnet/examples/SEALNetExamples.csproj.in
- native/src/seal/util/dwthandler.h
- native/src/seal/util/fips202.h
- native/src/seal/util/fips202.c
- native/src/seal/version.h
- dotnet/SEALNet.sln
- .pre-commit-config.yaml
dotnet/src/BigUInt.csdotnet/src/IntegerEncoder.csdotnet/tests/BigUIntTests.csdotnet/tests/IntegerEncoderTests.csnative/examples/SEALExamples.vcxprojnative/examples/SEALExamples.vcxproj.filtersnative/src/CMakeConfig.cmdnative/src/SEAL_C.vcxprojnative/src/SEAL_C.vcxproj.filtersnative/src/SEAL.vcxprojnative/src/SEAL.vcxproj.filtersnative/src/seal/biguint.hnative/src/seal/biguint.cppnative/src/seal/intencoder.hnative/src/seal/intencoder.cppnative/tests/packages.confignative/tests/SEALTest.vcxprojnative/tests/SEALTest.vcxproj.filtersnative/tests/seal/biguint.cppnative/tests/seal/intencoder.cppthirdparty/SEAL.sln
- Fixed (Issue 216).
- Fixed (Issue 210).
- The bug fixed in (PR 209) also affects Android. Changed version to 3.5.8 where this is fixed.
- Fixed an omission in input validation in decryption: the size of the ciphertext was not checked to be non-zero.
- In Windows switch to using
RtlGenRandomif the BCrypt API fails. - Improved performance in serialization: data clearing memory pools were always used before, but now are only used for the secret key.
- Use native APIs for memory clearing, when available, instead of for-loop.
- Fixed a bug where setting a PRNG factory to use a constant seed did not result in deterministic ciphertexts or public keys. The problem was that the specified PRNG factory was not used to sample the uniform part of the RLWE sample(s), but instead a fresh (secure) PRNG was always created and used.
- Fixed a bug where the
parms_idof aPlaintextwas not cleared correctly before resizing inDecryptor::bfv_decrypt. As a result, a plaintext in NTT form could not be used as the destination for decrypting a BFV ciphertext.
- Merged pull request (Issue 190) to replace global statics with function-local statics to avoid creating these objects unless they are actually used.
- Fixed (Issue 188).
- Added a struct
seal::util::MultiplyUIntModOperandin native/src/seal/util/uintarithsmallmod.h. This struct handles precomputation data for Barrett style modular multiplication. - Added new overloads for modular arithmetic in native/src/seal/util/uintarithsmallmod.h where one operand is replaced by a
MultiplyUIntModOperandinstance for improved performance when the same operand is used repeatedly. - Changed the name of
seal::util::barrett_reduce_63toseal::util::barrett_reduce_64; the name was misleading and only referred to the size of the modulus. - Added
seal::util::StrideIterin native/src/seal/util/iterator.h. - Added macros
SEAL_ALLOCATE_GET_PTR_ITERandSEAL_ALLOCATE_GET_STRIDE_ITERin native/src/seal/util/defines.h.
- Significant performance improvements from merging pull request (PR 185) and implementing other improvements of the same style (see above).
- Removed a lot of old and unused code.
std::void_twas introduced only in C++17; switched to using a custom implementation (Issue 180).- Fixed two independent bugs in
native/src/CMakeConfig.cmd: The first prevented SEAL to be built in a directory with spaces in the path due to missing quotation marks. Another issue caused MSVC to fail when building SEAL for multiple architectures. RNSBase::decompose_arrayhad incorrect semantics that causedEvaluator::multiply_plain_normalandEvaluator::transform_to_ntt_inplace(forPlaintext) to behave incorrectly for some plaintexts.
- Added pkg-config support (PR 181).
seal::util::PtrIter<T *>now dereferences correctly toT &instead ofT *. This results in simpler code, where insideSEAL_ITERATElambda functions dereferences ofseal::util::PtrIter<T *>do not need to be dereferenced a second time, as was particularly common when iterating overModulusIterandNTTTablesItertypes.seal::util::IterTuplenow dereferences to anstd::tupleof dereferences of its component iterators, so it is no longer possible to directly pass a dereferencedseal::util::IterTupleto an inner lambda function in nestedSEAL_ITERATEcalls. Instead, the outer lambda function parameter should be wrapped inside another call toseal::util::iterbefore passed on to the innerSEAL_ITERATEto produce an appropriateseal::util::IterTuple.
- Fixed a bug in
seal::util::IterTuple<...>where a part of thevalue_typewas constructed incorrectly. - Fixed a bug in
Evaluator::mod_switch_drop_to_nextthat caused non-inplace modulus switching to fail (Issue 179). Thanks s0l0ist!
- Merged pull request PR 178 to fix a lambda capture issue when building on GCC 7.5.
- Fixed issue where SEAL.vcxproj could not be compiled with MSBuild outside the solution (Issue 171).
- SEAL 3.5.1 required CMake 3.13 instead of 3.12; this has now been fixed and 3.12 works again (Issue 167).
- Fixed issue in NuSpec file that made local NuGet package generation fail.
- Fixed issue in NuSpec where XML documentation was not included into the package.
- Huge improvements to SEAL iterators, including
seal::util::iterandseal::util::reverse_iterfunctions that can create any type of iterator from appropriate parameters. - Added
seal::util::SeqIter<T>iterator for iterating a sequence of numbers for convenient iteration indexing. - Switched functions in
seal/util/polyarithsmallmod.*to use iterators; this is to reduce the layers of iteration in higher level code. - Added macro
SEAL_ITERATEthat should be used instead offor_each_n.
- Added note in README.md about known performance issues when compiling with GNU G++ compared to Clang++ (Issue 173).
- Merged pull requests that improve the performance of keyswitching (PR 177) and rescale (PR 176) in CKKS.
Changed version to 3.5.1. The two hotfixes below are included.
- Fixed a critical bug (Issue 166) in
Evaluator::multiply_plain_inplace. Thanks s0l0ist!
- Switched to using Microsoft GSL v3.0.1 and fixed minor GSL related issues in
CMakeLists.txt. - Fixed some typos in README.md.
- Fixes bugs in ADO pipelines files.
- Microsoft SEAL officially supports Android (Xamarin.Android) on ARM64.
- Microsoft SEAL is a CMake project (UNIX-like systems only):
- There is now a top-level
CMakeLists.txtthat builds all native components. - The following CMake targets are created:
SEAL::seal(static library),SEAL::seal_shared(shared library; optional),SEAL::sealc(C export library; optional). - Examples and unit tests are built if enabled through CMake (see README.md).
- ZLIB is downloaded and compiled by CMake and automatically included in the library.
- Microsoft GSL is downloaded by CMake. Its header files are copied to
native/src/gsland installed with Microsoft SEAL. - Google Test is downloaded and compiled by CMake.
- There is now a top-level
- Improved serialization:
Serialization::SEALHeaderlayout has been changed. SEAL 3.4 objects can still be loaded by SEAL 3.5, and the headers are automatically converted to SEAL 3.5 format.Serialization::SEALHeadercaptures version number information.- Added examples for serialization.
- The seeded versions of
Encryptor's symmetric-key encryption andKeyGenerator'sRelinKeysandGaloisKeysgeneration now outputSerializableobjects. See more details in API Changes below.
We have created a set of C++ iterators that easily allows looping over polynomials in a ciphertext, over RNS components in a polynomial, and over coefficients in an RNS component.
There are also a few other iterators that can come in handy.
Currently Evaluator fully utilizes these, and in the future the rest of the library will as well.
The iterators are primarily intended to be used with std::for_each_n to simplify existing code and help with code correctness.
Please see native/src/seal/util/iterator.h for guidance on how to use these.
We have also completely rewritten the RNS tools that were previously in the util::BaseConverter class.
This functionality is now split between two classes: util::BaseConverter whose sole purpose is to perform the FastBConv computation of [BEHZ16] and util::RNSTool that handles almost everything else.
RNS bases are now represented by the new util::RNSBase class.
The following changes are explained in C++ syntax and are introduced to .NET wrappers similarly:
- New generic class
SerializablewrapsCiphertext,RelinKeys, andGaloisKeysobjects to provide a more flexible approach to the functionality provided in release 3.4 byKeyGenerator::[relin|galois]_keys_saveandEncryptor::encrypt_[zero_]symmetric_savefunctions. Specifically, these functions have been removed and replaced with overloads ofKeyGenerator::[relin|galois]_keysandEncryptor::encrypt_[zero_]symmetricthat returnSerializableobjects. TheKeyGenerator::[relin|galois]_keysmethods in release 3.4 are renamed toKeyGenerator::[relin|galois]_keys_local. TheSerializableobjects cannot be used directly by the API, and are only intended to be serialized, which activates the compression functionalities introduced earlier in release 3.4. SmallModulusclass is renamed toModulus, and is relocated to native/src/seal/modulus.h.*coeff_mod_count*methods are renamed to*coeff_modulus_size*, which applies to many classes.parameter_error_nameandparameter_error_messagemethods are added toEncryptionParameterQualifiersandSEALContextclasses to explain why anEncryptionParametersobject is invalid.- The data members and layout of
Serialization::SEALHeaderhave changed.
The following changes are specific to C++:
- New bounds in native/src/seal/util/defines.h:
SEAL_POLY_MOD_DEGREE_MAXis increased to 131072; values bigger than 32768 require the security check to be disabled by passingsec_level_type::nonetoSEALContext::Create.SEAL_COEFF_MOD_COUNT_MAXis increased to 64.SEAL_MOD_BIT_COUNT_MAXandSEAL_MOD_BIT_COUNT_MINare added and set to 61 and 2, respectively.SEAL_INTERNAL_MOD_BIT_COUNTis added and set to 61.
EncryptionParameterQualifiersnow has an error codeparameter_errorthat interprets the reason why anEncryptionParameterobject is invalid.bool parameters_set()is added to replace the previousbool parameters_setmember.
The following changes are specific to .NET:
- Version numbers are retrievable in .NET through
SEALVersionclass.
- Releases are now listed on releases page.
- The native library can serialize (save and load) objects larger than 4 GB. Please be aware that compressed serialization requires an additional temporary buffer roughly the size of the object to be allocated, and the streambuffer for the output stream may consume some non-trivial amount of memory as well. In the .NET library, objects are limited to 2 GB, and loading an object larger than 2 GB will throw an exception. (Issue 142)
- Larger-than-suggested parameters are supported for expert users.
To enable that, please adjust
SEAL_POLY_MOD_DEGREE_MAXandSEAL_COEFF_MOD_COUNT_MAXin native/src/seal/util/defines.h. (Issue 150, Issue 84) - Serialization now clearly indicates an insufficient buffer size error. (Issue 117)
- Unsupported compression mode now throws
std::invalid_argument(native) orArgumentException(.NET). - There is now a
.clang-formatfor automated formatting of C++ (.cppand.h) files. Executetools/scripts/clang-format-all.shfor easy formatting (UNIX-like systems only). This is compatible with clang-format-9 and above. Formatting for C# is not yet supported. (Issue 93) - The C export library previously in
dotnet/native/is moved to native/src/seal/c/ and renamed to SEAL_C to support building of wrapper libraries in languages like .NET, Java, Python, etc. - The .NET wrapper library targets .NET Standard 2.0, but the .NET example and test projects use C# 8.0 and require .NET Core 3.x. Therefore, Visual Studio 2017 is no longer supported for building the .NET example and test projects.
- Fixed issue when compiling in FreeBSD. (PR 113)
- A bug in the [BEHZ16]-style RNS operations is fixed; proper unit tests are added.
- Performance of methods in
Evaluatorare in general improved. (PR 148) This is compiler-dependent, however, and currently Clang seems to produce the fastest running code for Microsoft SEAL.
Renamed files and directories:
- dotnet/examples/7_Performance.cs was previously
dotnet/examples/6_Performance.cs - native/examples/7_performance.cpp was previously
native/examples/6_performance.cpp - native/src/seal/c/ was previously
dotnet/native/sealnet. - native/src/seal/util/ntt.h was previously
native/src/seal/util/smallntt.h. - native/src/seal/util/ntt.cpp was previously
native/src/seal/util/smallntt.cpp. - native/tests/seal/util/ntt.cpp was previously
native/tests/seal/util/smallntt.cpp.
New files:
- android/
- dotnet/examples/6_Serialization.cs
- dotnet/src/Serializable.cs
- dotnet/src/Version.cs
- dotnet/tests/SerializationTests.cs
- native/examples/6_serialization.cpp
- native/src/seal/c/version.h
- native/src/seal/c/version.cpp
- native/src/seal/util/galois.h
- native/src/seal/util/galois.cpp
- native/src/seal/util/hash.cpp
- native/src/seal/util/iterator.h
- native/src/seal/util/rns.h
- native/src/seal/util/rns.cpp
- native/src/seal/util/streambuf.h
- native/src/seal/util/streambuf.cpp
- native/src/seal/serializable.h
- native/tests/seal/util/iterator.cpp
- native/tests/seal/util/galois.cpp
- native/tests/seal/util/rns.cpp
Removed files:
dotnet/src/SmallModulus.csis merged to dotnet/src/ModulusTests.cs.dotnet/tests/SmallModulusTests.csis merged to dotnet/tests/ModulusTests.cs.native/src/seal/util/baseconverter.hnative/src/seal/util/baseconverter.cppnative/src/seal/smallmodulus.his merged to native/src/seal/modulus.h.native/src/seal/smallmodulus.cppis merged to native/src/seal/modulus.cpp.native/src/seal/c/smallmodulus.his merged to native/src/seal/c/modulus.h.native/src/seal/c/smallmodulus.cppis merged to native/src/seal/c/modulus.cpp.native/tests/seal/smallmodulus.cppis merged to native/tests/seal/modulus.cpp.native/tests/seal/util/baseconverter.cpp
- Fixed a concurrency issue in SEALNet: the
unordered_mapstoringSEALContextpointers was not locked appropriately on construction and destruction of newSEALContextobjects. - Fixed a few typos in examples (PR 71).
- Added include guard to config.h.in.
- Fixed issues with
SEALNet.targetsfile andSEALNet.nuspec.in. - Updated
README.mdwith information about existing multi-platform NuGet package.
- Fixed bug in .NET serialization code where an incorrect number of bytes was written when using ZLIB compression.
- Fixed an issue with .NET functions
Encryptor.EncryptSymmetric..., where asymmetric encryption was done instead of symmetric encryption. - Prevented
KeyGenerator::galois_keysandKeyGenerator::relin_keysfrom being called when the encryption parameters do not support keyswitching. - Fixed a bug in
Decryptor::invariant_noise_budgetwhere the computed noise budget waslog(plain_modulus)bits smaller than it was supposed to be. - Removed support for Microsoft GSL
gsl::multi_span, as it was recently deprecated in GSL.
- Fixed bug reported in Issue 66 on GitHub.
- CMake does version matching now (correctly) only on major and minor version, not patch version, so writing
find_package(SEAL 3.4)works correctly and selects the newest version3.4.xit can find.
This patch fixes a few issues with ZLIB support on Windows. Specifically,
- Fixed a mistake in
native/src/CMakeConfig.cmdwhere the CMake library search path suffix was incorrect. - Switched to using a static version of ZLIB on Windows.
- Corrected instructions in README.md for enabling ZLIB support on Windows.
- Microsoft SEAL can use ZLIB, a data compression library, to automatically compress data that is serialized. This applies to every serializable object in Microsoft SEAL. This feature must be enabled by the user. See more explanation of the compression mechanism in README.md. Microsoft SEAL does not redistribute ZLIB.
- AES-128 is replaced with the BLAKE2 family of hash functions in the pseudorandom number generator, as BLAKE2 provides better cross-platform support. Microsoft SEAL redistributes the reference implementation of BLAKE2 with light modifications to silence some misleading warnings in Visual Studio. The reference implementation of BLAKE2 is licensed under CC0 1.0 Universal; see license boilerplates in files native/src/seal/util/blake*.
- The serialization functionality has been completely rewritten to make it more safe and robust.
Every serialized Microsoft SEAL object starts with a 16-byte
Serialization::SEALHeaderstruct, and then includes the data for the object member variables. Every serializable object can now also be directly serialized into a memory buffer instead of a C++ stream. This improves serialization for .NET and makes it much easier to wrap the serialization functionality in other languages, e.g., Java. Unfortunately, old serialized Microsoft SEAL objects are incompatible with the new format. - A ciphertext encrypted with a secret key, for example, a keyswitching key, has one component generated by the PRNG. By using a seeded PRNG, this component can be replaced with the random seed used by the PRNG to reduce data size. After transmitted to another party with Microsoft SEAL, the component can be restored (regenerated) with the same seed. The security of using seeded PRNG is enhanced by switching to BLAKE2 hash function with a 512-bit seed.
Encryptornow can be constructed with a secret key. This enables symmetric key encryption which has methods that serialize ciphertexts (compressed with a seed) to a C++ stream or a memory buffer.- The CMake system has been improved. For example, multiple versions of Microsoft SEAL can now be installed on the same system easily, as the default installation directory and library filename now depend on the version of Microsoft SEAL. Examples and unit tests can now be built without installing the library. README.md has been updated to reflect these changes.
Encryptor::encryptoperations in the BFV scheme are modified. Each coefficient of a plaintext message is first multiplied with the ciphertext modulus, then divided by the plaintext modulus, and rounded to the nearest integer. In comparison with the previous method, where each coefficient of a plaintext message is multiplied with the flooring of the coefficient modulus divided by the plaintext modulus, the new method reduces the noise introduced in encryption, increases a noise budget of a fresh encryption, slightly slows down encryption, and has no impact on the security at all.- Merged PR 62 that uses a non-adjacent form (NAF) decomposition of random rotations to perform them in a minimal way from power-of-two rotations in both directions.
- This improves performance of random rotations.
In all classes with save and load methods:
- Replaced the old
savewith two new methods that saves to either a C++ stream or a memory buffer. Optionally, a compression mode can be chosen when saving an object. - Replaced the old
loadwith two new methods that loads from either a C++ stream or a memory buffer. - Added a method
save_sizeto get an upper bound on the size of the object as if it was written to an output stream. To save to a buffer, the user must ensure that the buffer has at least size equal to what thesave_sizemember function returns. - New
saveandloadmethods rely on theSerializationclass declared inserialization.h. This class unifies the serialization functionality for all serializable Microsoft SEAL classes.
In class Ciphertext:
- Added a method
int_arrayfor read-only access to the underlyingIntArrayobject. - Removed methods
uint64_count_capacityanduint64_countthat can now be accessed in a more descriptive manner through theint_arrayreturn value.
In class CKKSEncoder: added support for gsl::span type of input.
In class SEALContext::ContextData: added method coeff_mod_plain_modulus for read-only access to the non-RNS version of upper_half_increment.
In class EncryptionParameters: an EncryptionParameters object can be constructed without scheme_type which by default is set to scheme_type::none.
In class Encryptor:
- An
Encryptorobject can now be constructed with a secret key to enable symmetric key encryption. - Added methods
encrypt_symmetricandencrypt_zero_symmetricthat generate aCiphertextusing the secret key. - Added methods
encrypt_symmetric_saveandencrypt_zero_symmetric_savethat directly serialize the resultingCiphertextto a C++ stream or a memory buffer. The resultingCiphertextno long exists after serilization. In these methods, the second polynomial of a ciphertext is generated by the PRNG and is replaced with the random seed used.
In class KeyGenerator:
- Added methods
relin_keys_saveandgalois_keys_savethat generate and directly serialize keys to a C++ stream or a memory buffer. The resulting keys no long exist after serilization. In these methods, half of the polynomials in keys are generated by the PRNG and is replaced with the random seed used. - Methods
galois_keysandgalois_keys_savethrow an exception ifEncryptionParametersdo not support batching in the BFV scheme.
In class Plaintext: added a method int_array for read-only access to the underlying IntArray object.
In class UniformRandomGenerator and UniformRandomGeneratorFactory: redesigned for users to implement their own random number generators more easily.
In file valcheck.h: validity checks are partitioned into finer methods; the is_valid_for(...) functions will validate all aspects fo the Microsoft SEAL ojects.
New classes BlakePRNG and BlakePRNGFactory: uses Blake2 family of hash functions for PRNG.
New class Serialization:
- Gives a uniform serialization in Microsoft SEAL to save objects to a C++ stream or a memory buffer.
- Can be configured to use ZLIB compression.
New files:
- native/src/seal/util/rlwe.h
- native/src/seal/util/blake2.h
- native/src/seal/util/blake2-impl.h
- native/src/seal/util/blake2b.c
- native/src/seal/util/blake2xb.c
- native/src/seal/util/croots.cpp
- native/src/seal/util/croots.h
- native/src/seal/util/scalingvariant.cpp
- native/src/seal/util/scalingvariant.h
- native/src/seal/util/ztools.cpp
- native/src/seal/util/ztools.h
- native/src/seal/serialization.cpp
- native/src/seal/serialization.h
- native/tests/seal/serialization.cpp
- dotnet/native/sealnet/serialization_wrapper.cpp
- dotnet/native/sealnet/serialization_wrapper.h
Removed files:
API changes are mostly identical in terms of functionality to those in C++ native, except only the IsValidFor variant of the validity check functions is available in .NET, the more granular checks are not exposed.
New files:
- Function
encrypt_zero_asymmetricin native/src/seal/util/rlwe.h handles the conditionis_ntt_form == falsecorrectly. - Invariant noise calculation in BFV is now correct when the plaintext modulus is large and ciphertexts are fresh (reported in issue 59).
- Fixed comments in native/src/seal/util/smallntt.cpp as reported in issue 56.
- Fixed an error in examples as reported in issue 61.
GaloisKeyscan no longer be created with encryption parameters that do not support batching.- Security issues in deserialization were resolved.
- Switched to using RNS rounding instead of RNS flooring to fix the CKKS accuracy issue reported in issue 52.
- Added support for QUIET option in CMake (
find_package(seal QUIET)). - Using
[[nodiscard]]attribute when compiling as C++17. - Fixed a bug in
Evaluator::multiply_manywhere the input vector was changed.
- A bug was fixed that introduced significant extra inaccuracy in CKKS when compiled on Linux, at least with some versions of glibc; Windows and macOS were not affected.
- A bug was fixed where, on 32-bit platforms, some versions of GCC resolved the util::reverse_bits function to the incorrect overload.
In this version, we have significantly improved the usability of the CKKS scheme in Microsoft SEAL and many of these improvements apply to the BFV scheme as well. Homomorphic operations that are based on key switching, i.e., relinearization and rotation, do not consume any noise budget (BFV) or impact accuracy (CKKS). The implementations of these operations are significantly simplified and unified, and no longer use bit decomposition, so decomposition bit count is gone. Moreover, fresh ciphertexts now have lower noise. These changes have an effect on the API and it will be especially worthwhile for users of older versions of the library to study the examples and comments in native/examples/3_levels.cpp (C++) or dotnet/examples/3_Levels.cs (C#).
The setup of EncryptionParameters has been made both easier and safer (see API Changes below).
The examples in native/examples/ and dotnet/examples/ have been redesigned to better teach the multiple technical concepts required to use Microsoft SEAL correctly and efficiently, and more compactly demonstrate the API.
Deleted header files:
native/defaultparameters.h
New header files:
- native/src/seal/kswitchkeys.h: new base class for
RelinKeysandGaloisKeys) - native/src/seal/modulus.h: static helper functions for parameter selection
- native/src/seal/valcheck.h: object validity check functionality
- native/src/seal/util/rlwe.h
In class SEALContext:
- Replaced
context_data(parms_id_type)withget_context_data(parms_id_type). - Removed
context_data(). - Added
key_context_data(),key_parms_id(),first_context_data(), andlast_context_data(). - Added
using_keyswitching()that indicates whether key switching is supported in thisSEALContext. Create(...)in C++, and constructor in C#, now accepts an optional security level based on HomomorphicEncryption.org security standard, causing it to enforce the specified security level. By default a 128-bit security level is used.- Added
prev_context_data()method to classContextData(doubly linked modulus switching chain). - In C#
SEALContextnow has a public constructor.
Parameter selection:
- Removed the
DefaultParamsclass. - Default
coeff_modulusfor the BFV scheme are now accessed through the functionCoeffModulus::BFVDefault(...). These moduli are not recommended for the CKKS scheme. - Customized
coeff_modulusfor the CKKS scheme can be created usingCoeffModulus::Create(...)which takes thepoly_modulus_degreeand a vector of bit-lengths of the prime factors as arguments. It samples suitable primes close to 2^bit_length and returns a vector ofSmallModuluselements. PlainModulus::Batching(...)can be used to sample a prime forplain_modulusthat supportsBatchEncoderfor the BFV scheme.
Other important changes:
- Removed
size_capacityfunction and data members fromCiphertextclass. - Moved all validation methods such as
is_valid_forandis_metadata_valid_fortovalcheck.h. - Removed argument
decomposition_bit_countfrom methodsrelin_keys(...)andgalois_keys(...)in classKeyGenerator. - It is no longer possible to create more than one relinearization key. This is to simplify the API and reduce confusion. We have never seen a real use-case where more relinearization keys would be a good idea.
- Added methods to generate an encryption of zero to
Encryptor. - Added comparison methods and primality check for
SmallModulus. - Classes
RelinKeysandGaloisKeysare now derived from a common base classKSwitchKeys. - GoogleTest framework is now included as a Git submodule.
- Numerous bugs have been fixed, particularly in the .NET wrappers.