{"catalogVersion":"he-dossier-v4-contribution-cards","constructions":[{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"composite_residuosity","assumption_id":"HE-ASSUMPTION-DECISIONAL-COMPOSITE-RESIDUOSITY","assumption_name":"Decisional Composite Residuosity","authors":["Pascal Paillier"],"base_signature":null,"block_size":null,"bootstrapping":"not applicable","capabilities":["additive-homomorphism","exact"],"ciphertext_security":null,"circuit_class":"additive circuits only","client_storage":null,"communication":null,"construction_family":"additive_phe","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"modular exponentiation"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact modular arithmetic","ggm_file":null,"id":"he_paillier99","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"no lattice noise budget","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"none in the base construction","paper_title":"Public-Key Cryptosystems Based on Composite Degree Residuosity Classes","paper_url":"https://link.springer.com/chapter/10.1007/3-540-48910-X_16","parallelizable":null,"plaintext_space":"integers modulo n","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"PHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"two residues modulo n-squared"}},"statefulness":null,"summary":"Reference PHE row used to distinguish one-operation homomorphism from SHE, LHE, and FHE.","supported_gates":"unbounded additions; plaintext-scalar multiplication","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"bibliographic_reviewed","work_id":"HE-PAPER-1999-PAILLIER","year":1999},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"ideal_lattice","assumption_id":"HE-ASSUMPTION-IDEAL-LATTICE-HARDNESS-PLUS-SQUASHING-RELATED-ASSUMPTIONS","assumption_name":"Ideal-lattice hardness plus squashing-related assumptions","authors":["Craig Gentry"],"base_signature":null,"block_size":null,"bootstrapping":"homomorphic evaluation of augmented decryption","capabilities":["first-fhe","bootstrapping"],"ciphertext_security":null,"circuit_class":"unbounded circuits after bootstrap","client_storage":null,"communication":null,"construction_family":"ideal_lattice","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"squashed decryption circuit"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact","ggm_file":null,"id":"he_gentry09","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"somewhat-HE noise budget plus squashing","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"later variants only","paper_title":"Fully Homomorphic Encryption Using Ideal Lattices","paper_url":"https://crypto.stanford.edu/craig/craig-thesis.pdf","parallelizable":null,"plaintext_space":"bits and ring elements","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"FHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"polynomial; historically impractical"}},"statefulness":null,"summary":"Blueprint record rather than a recommended modern implementation.","supported_gates":"addition and multiplication; arbitrary circuits after bootstrap","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"HE-PAPER-2009-GENTRY","year":2009},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"agcd","assumption_id":"HE-ASSUMPTION-APPROXIMATE-GCD-WITH-AUXILIARY-ASSUMPTIONS-IN-THE-ORIGINAL-FULL-SCHEME","assumption_name":"Approximate GCD with auxiliary assumptions in the original full scheme","authors":["Marten van Dijk","Craig Gentry","Shai Halevi","Vinod Vaikuntanathan"],"base_signature":null,"block_size":null,"bootstrapping":"Gentry-style squashed decryption","capabilities":["integer-fhe","bootstrapping"],"ciphertext_security":null,"circuit_class":"unbounded Boolean circuits after bootstrap","client_storage":null,"communication":null,"construction_family":"integer_agcd","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"reduction modulo secret integer"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact bits","ggm_file":null,"id":"he_dghv10","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"approximate multiples; noise grows under multiplication","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"none in the base scheme","paper_title":"Fully Homomorphic Encryption over the Integers","paper_url":"https://eprint.iacr.org/2009/616","parallelizable":null,"plaintext_space":"bits","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"FHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"very large integers"}},"statefulness":null,"summary":"Conceptually simple first-generation branch; retained for lineage rather than Pareto efficiency.","supported_gates":"XOR and AND through integer addition and multiplication","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"abstract_reviewed","work_id":"HE-PAPER-2010-DGHV","year":2010},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lwe","assumption_id":"HE-ASSUMPTION-LEARNING-WITH-ERRORS","assumption_name":"Learning With Errors","authors":["Zvika Brakerski","Vinod Vaikuntanathan"],"base_signature":null,"block_size":null,"bootstrapping":"required for unbounded depth","capabilities":["relinearization","key-switching","standard-lwe"],"ciphertext_security":null,"circuit_class":"bounded depth before refresh; unbounded after refresh","client_storage":null,"communication":null,"construction_family":"lwe_relinearization","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"LWE inner product"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact modular arithmetic","ggm_file":null,"id":"he_bv11","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"relinearization and dimension-modulus reduction","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"not the core contribution","paper_title":"Efficient Fully Homomorphic Encryption from (Standard) LWE","paper_url":"https://eprint.iacr.org/2011/344","parallelizable":null,"plaintext_space":"bits or small modular plaintexts","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"FHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_with_refresh_assumption","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"short LWE ciphertext after relinearization"}},"statefulness":null,"summary":"Key ancestor for BGV/BFV-style ciphertext dimension control.","supported_gates":"addition and multiplication","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"abstract_reviewed","work_id":"HE-PAPER-2011-BV","year":2011},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"rlwe","assumption_id":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","assumption_name":"Ring Learning With Errors","authors":["Junfeng Fan","Frederik Vercauteren"],"base_signature":null,"block_size":null,"bootstrapping":"optional and not part of the basic leveled record","capabilities":["packing","relinearization","exact","rns-friendly"],"ciphertext_security":null,"circuit_class":"predetermined-depth arithmetic circuits","client_storage":null,"communication":null,"construction_family":"bfv","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"ring product and scaled rounding"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact modular arithmetic","ggm_file":null,"id":"he_bfv12","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"relinearization and modulus management; RNS in modern variants","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"SIMD when the plaintext ring splits","paper_title":"Somewhat Practical Fully Homomorphic Encryption","paper_url":"https://eprint.iacr.org/2012/144","parallelizable":null,"plaintext_space":"exact integers modulo t","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"LHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_leveled","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"two ring elements after relinearization"}},"statefulness":null,"summary":"Standard exact-arithmetic counterpart to CKKS in many libraries.","supported_gates":"packed modular addition and multiplication","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"abstract_reviewed","work_id":"HE-PAPER-2012-FV","year":2012},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lwe_rlwe","assumption_id":"HE-ASSUMPTION-LWE-OR-RING-LWE","assumption_name":"LWE or Ring-LWE","authors":["Zvika Brakerski","Craig Gentry","Vinod Vaikuntanathan"],"base_signature":null,"block_size":null,"bootstrapping":"optional for unbounded FHE","capabilities":["packing","modulus-switching","key-switching","exact"],"ciphertext_security":null,"circuit_class":"predetermined-depth arithmetic circuits","client_storage":null,"communication":null,"construction_family":"bgv","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"ring inner product and rounding"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact modular arithmetic","ggm_file":null,"id":"he_bgv12","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"modulus switching chain plus key switching","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"SIMD via CRT plaintext slots","paper_title":"Fully Homomorphic Encryption without Bootstrapping","paper_url":"https://eprint.iacr.org/2011/277","parallelizable":null,"plaintext_space":"exact modular integers and packed slots","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"LHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_leveled","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"small constant number of ring elements"}},"statefulness":null,"summary":"Main exact packed leveled-HE reference family.","supported_gates":"additions and multiplications to a parameterized depth","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"abstract_reviewed","work_id":"HE-PAPER-2012-BGV","year":2012},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lwe","assumption_id":"HE-ASSUMPTION-CLASSICAL-GAPSVP-VIA-LWE","assumption_name":"Classical GapSVP via LWE","authors":["Zvika Brakerski"],"base_signature":null,"block_size":null,"bootstrapping":"available for unbounded depth","capabilities":["single-modulus","tensoring","exact"],"ciphertext_security":null,"circuit_class":"predetermined-depth arithmetic circuits","client_storage":null,"communication":null,"construction_family":"scale_invariant_lwe","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"LWE decryption"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact modular arithmetic","ggm_file":null,"id":"he_scaleinv12","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"tensoring with linear multiplicative noise growth","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"not the primary contribution","paper_title":"Fully Homomorphic Encryption without Modulus Switching from Classical GapSVP","paper_url":"https://eprint.iacr.org/2012/078","parallelizable":null,"plaintext_space":"exact modular plaintexts","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"LHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_leveled","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"LWE ciphertext"}},"statefulness":null,"summary":"Alternative noise invariant showing that modulus switching is not conceptually necessary.","supported_gates":"addition and multiplication","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"abstract_reviewed","work_id":"HE-PAPER-2012-BRAKERSKI","year":2012},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lwe","assumption_id":"HE-ASSUMPTION-LEARNING-WITH-ERRORS","assumption_name":"Learning With Errors","authors":["Craig Gentry","Amit Sahai","Brent Waters"],"base_signature":null,"block_size":null,"bootstrapping":"supported through homomorphic decryption","capabilities":["approximate-eigenvector","external-product-ancestor"],"ciphertext_security":null,"circuit_class":"general circuits after refresh","client_storage":null,"communication":null,"construction_family":"gsw","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"approximate eigenvector test"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact modular plaintext","ggm_file":null,"id":"he_gsw13","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"gadget decomposition and asymmetric noise growth","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"ring variants and descendants","paper_title":"Homomorphic Encryption from Learning with Errors: Conceptually-Simpler, Asymptotically-Faster, Attribute-Based","paper_url":"https://eprint.iacr.org/2013/340","parallelizable":null,"plaintext_space":"bits or small modular plaintexts","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"FHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_with_refresh_assumption","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"matrix ciphertext"}},"statefulness":null,"summary":"Conceptual ancestor of RingGSW, FHEW, and TFHE external products.","supported_gates":"direct addition and multiplication of GSW ciphertexts","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"abstract_reviewed","work_id":"HE-PAPER-2013-GSW","year":2013},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lwe_rlwe","assumption_id":"HE-ASSUMPTION-STANDARD-LATTICE-PROBLEMS-VIA-LWE-RLWE","assumption_name":"Standard lattice problems via LWE/RLWE","authors":["Léo Ducas","Daniele Micciancio"],"base_signature":null,"block_size":null,"bootstrapping":"subsecond LWE/RLWE gate bootstrap in the paper","capabilities":["gate-bootstrapping","boolean"],"ciphertext_security":null,"circuit_class":"unbounded Boolean circuits","client_storage":null,"communication":null,"construction_family":"fhew_tfhe","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"LWE phase and rounding"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact bits with quantified decryption failure","ggm_file":null,"id":"he_fhew15","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"bootstrap after a gate","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"limited in the base design","paper_title":"FHEW: Bootstrapping Homomorphic Encryption in Less Than a Second","paper_url":"https://eprint.iacr.org/2014/816","parallelizable":null,"plaintext_space":"bits","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"FHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_with_evaluation_keys","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"LWE ciphertext"},"MPK":{"asymptotic":"large bootstrapping key"}},"statefulness":null,"summary":"First widely cited subsecond gate-refresh point.","supported_gates":"refreshed Boolean gates","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"HE-PAPER-2015-FHEW","year":2015},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lwe_rlwe","assumption_id":"HE-ASSUMPTION-LEARNING-WITH-ERRORS-AND-RING-VARIANTS","assumption_name":"Learning With Errors and ring variants","authors":["Ilaria Chillotti","Nicolas Gama","Mariya Georgieva","Malika Izabachène"],"base_signature":null,"block_size":null,"bootstrapping":"external-product gate bootstrap below 0.1 seconds in the paper","capabilities":["gate-bootstrapping","external-product","boolean"],"ciphertext_security":null,"circuit_class":"unbounded Boolean circuits","client_storage":null,"communication":null,"construction_family":"fhew_tfhe","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"torus LWE phase decoding"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"exact discrete messages with failure probability","ggm_file":null,"id":"he_tfhe16","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"bootstrapping resets noise after nonlinear gates","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"limited in base gate mode","paper_title":"Faster Fully Homomorphic Encryption: Bootstrapping in Less Than 0.1 Seconds","paper_url":"https://eprint.iacr.org/2016/870","parallelizable":null,"plaintext_space":"bits and small torus messages","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"FHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"secret_or_public_key","security_model":"standard_with_evaluation_keys","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"compact LWE ciphertext"},"MPK":{"asymptotic":"bootstrapping and switching keys"}},"statefulness":null,"summary":"Base TFHE record; circuit and programmable bootstrapping are tracked as later results.","supported_gates":"Boolean gates and functions through blind rotation descendants","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"HE-PAPER-2016-TFHE","year":2016},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"rlwe","assumption_id":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","assumption_name":"Ring Learning With Errors","authors":["Jung Hee Cheon","Andrey Kim","Miran Kim","Yongsoo Song"],"base_signature":null,"block_size":null,"bootstrapping":"not in the base construction","capabilities":["packing","approximate","rescaling","numerical"],"ciphertext_security":null,"circuit_class":"predetermined-depth numerical circuits","client_storage":null,"communication":null,"construction_family":"ckks","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"ring decryption and approximate decoding"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"approximate with an explicit precision budget","ggm_file":null,"id":"he_ckks17","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"rescaling and modulus chain","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"native SIMD complex slots","paper_title":"Homomorphic Encryption for Arithmetic of Approximate Numbers","paper_url":"https://eprint.iacr.org/2016/421","parallelizable":null,"plaintext_space":"packed approximate real or complex numbers","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"LHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_leveled","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"two ring elements after relinearization"}},"statefulness":null,"summary":"Base numerical HE record; returned precision is part of correctness.","supported_gates":"approximate addition and multiplication with rescaling","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"HE-PAPER-2017-CKKS","year":2017},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"rlwe","assumption_id":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","assumption_name":"Ring Learning With Errors","authors":["Jung Hee Cheon","Kyoohyung Han","Andrey Kim","Miran Kim","Yongsoo Song"],"base_signature":null,"block_size":null,"bootstrapping":"homomorphic transforms and scaled-sine modular reduction","capabilities":["packing","approximate","bootstrapping","numerical"],"ciphertext_security":null,"circuit_class":"unbounded numerical circuits with periodic bootstrap","client_storage":null,"communication":null,"construction_family":"ckks","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"approximate CKKS decoding"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"approximate; refresh returns bounded precision","ggm_file":null,"id":"he_ckks_boot18","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"rescaling plus approximate modular-reduction refresh","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"native SIMD complex slots","paper_title":"Bootstrapping for Approximate Homomorphic Encryption","paper_url":"https://eprint.iacr.org/2018/153","parallelizable":null,"plaintext_space":"packed approximate real or complex numbers","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"FHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_with_evaluation_keys","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"packed ring ciphertext"},"MPK":{"asymptotic":"rotation and bootstrap keys"}},"statefulness":null,"summary":"First CKKS FHE refresh record; later high-precision and RNS works refine its cost and output quality.","supported_gates":"unbounded approximate arithmetic through refresh","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"HE-PAPER-2018-CKKS-BOOT","year":2018},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"rlwe","assumption_id":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","assumption_name":"Ring Learning With Errors","authors":["Jung Hee Cheon","Kyoohyung Han","Andrey Kim","Miran Kim","Yongsoo Song"],"base_signature":null,"block_size":null,"bootstrapping":"compatible with later RNS bootstrap implementations","capabilities":["packing","approximate","rns","ntt","numerical"],"ciphertext_security":null,"circuit_class":"predetermined-depth numerical circuits","client_storage":null,"communication":null,"construction_family":"ckks","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"RNS ring decryption and approximate decoding"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":"approximate with an explicit precision budget","ggm_file":null,"id":"he_rns_ckks18","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":"RNS rescaling and approximate modulus switching","nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":"native SIMD complex slots","paper_title":"A Full RNS Variant of Approximate Homomorphic Encryption","paper_url":"https://eprint.iacr.org/2018/931","parallelizable":null,"plaintext_space":"packed approximate real or complex numbers","policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"LHE","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard_leveled","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"CT":{"asymptotic":"two RNS ring elements after relinearization"}},"statefulness":null,"summary":"Implementation-oriented CKKS record separating the RNS representation advance from the first CKKS semantics.","supported_gates":"approximate addition and multiplication using word-size RNS kernels","tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"HE-PAPER-2018-RNS-CKKS","year":2018}],"edges":[{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-01EF7B25337CE6","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-GHS-AES-2012","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0221A9725436D6","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-TFHE-8BIT","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-04A025127E7300","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-TFHE-2016","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-04F832559D5620","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-002","target":"HE-OP-003","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-077E5F39BB4EF3","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BGV","target":"HE-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-08816A0B866886","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-HP-CKKS-2020","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-08A19EEBC5207C","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-SIMD-PACKING-2012","target":"he_bgv12","type":"OPTIMIZES"},{"evidenceLocator":"Abstract","evidenceUrl":"https://eprint.iacr.org/2018/931.pdf","id":"HE-REL-08FDECD10AB582","note":"Full-RNS arithmetic turns the CKKS construction into word-size RNS and NTT kernels.","resultId":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","reviewStatus":"primary_source_checked","source":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","target":"HE-OPT-CKKS-FULL-RNS-2018","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-09C0CA3E256FC5","note":"","resultId":null,"reviewStatus":"reported","source":"HE-WORKLOAD-GATE-BOOTSTRAP","target":"HE-PAPER-2015-FHEW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0ADE56BC56B9EC","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-005-01","target":"HE-OP-005","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0B26413F3671C9","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-HP-CKKS-2020","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0B5785BF1F5EDD","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2016-TFHE","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0C7A743AB4E684","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-CKKS-BOOT-2018","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0CC109A6E3AB94","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-FHEW-2015","target":"he_fhew15","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0D97619DEC8636","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-CKKS","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0F5D209106C398","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-TFHE-2016","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-0F8E685187A27C","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-SV-SIMD","target":"HE-OP-006","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-1063B4900C2BCA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-TFHE-2016","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-109BD826A860B6","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-002","target":"HE-PAPER-2020-HP-CKKS","type":"GROUNDED_IN"},{"evidenceLocator":"Abstract and performance section","evidenceUrl":"https://eprint.iacr.org/2016/870.pdf","id":"HE-REL-10F6577CFA64E5","note":"The sub-0.1-second TFHE gate-refresh claim is bounded by the separate source-reported benchmark object and its parameter and workload context.","resultId":"HE-RESULT-2016-TFHE-SUB-TENTH-SECOND-GATE-REFRESH","reviewStatus":"primary_source_checked","source":"HE-RESULT-2016-TFHE-SUB-TENTH-SECOND-GATE-REFRESH","target":"HE-BENCH-TFHE-2016","type":"CONTEXTUALIZED_BY_MEASUREMENT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-111D884D3974F3","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-TFHE-2016","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-11CA7EC947E768","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-SIMD-PACKING-2012","target":"he_bfv12","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-130FCD08491903","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-HP-CKKS-2020","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-14B3E19E98C285","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-GHS-AES-BOOT-2012","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"Sections 5, 7, and 8; Appendix A","evidenceUrl":"https://eprint.iacr.org/2024/1201.pdf","id":"HE-REL-169D873F32E92A","note":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","resultId":"HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE","reviewStatus":"section_checked","source":"HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE","target":"HE-IMPL-TFHE-PROCESSOR-2024","type":"DOCUMENTED_BY_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-16AC348E278D39","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-006-03","target":"HE-OP-006","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-17362388F30422","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2024-TFHE-PROCESSOR","target":"HE-OP-005","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-1772C08535E646","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_bfv12","target":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-180EBF9C987205","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-003","target":"HE-OP-001","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-18B8E4266C644D","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-TFHE-CB","target":"HE-OP-005","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-19039C5C4852AE","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-FHEW-2015","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"Abstract and performance section","evidenceUrl":"https://eprint.iacr.org/2016/870.pdf","id":"HE-REL-1910A77B69F7A1","note":"The TFHE measurement is attached to the reported prototype, parameter record, and single-gate refresh workload.","resultId":null,"reviewStatus":"primary_source_checked","source":"HE-IMPL-TFHE-2016","target":"HE-BENCH-TFHE-2016","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-19C24DF77DDB11","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-GHS-AES-2012","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"Implementation and performance sections","evidenceUrl":"https://eprint.iacr.org/2016/870.pdf","id":"HE-REL-1AC4DFC6E6B772","note":"The TFHE realization implements the LWE–RingGSW external-product bootstrap kernel measured by the paper.","resultId":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","reviewStatus":"primary_source_checked","source":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","target":"HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE","type":"REALIZED_AS_PROTOTYPE"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-1AEA5E2C8F4A8E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-1CE5C6C873F5B8","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-004-01","target":"HE-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"Abstract and introduction","evidenceUrl":"https://eprint.iacr.org/2014/816.pdf","id":"HE-REL-1DF607EA314563","note":"FHEW specializes the original refresh blueprint into subsecond bootstrapped Boolean operations.","resultId":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","reviewStatus":"primary_source_checked","source":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","target":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Implementation and performance sections","evidenceUrl":"https://eprint.iacr.org/2014/816.pdf","id":"HE-REL-1E39B0A5555A13","note":"The FHEW gate-bootstrap result is realized by the research prototype underlying the paper's reported binary-gate measurement.","resultId":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","reviewStatus":"primary_source_checked","source":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","target":"HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE","type":"REALIZED_AS_PROTOTYPE"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2086D09C4598C9","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-FHEW-2015","target":"HE-PAPER-2015-FHEW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-209CC40A83EB09","note":"","resultId":null,"reviewStatus":"reported","source":"HE-PARAM-HP-CKKS-2020","target":"he_ckks_boot18","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-20B2D3B49D46C1","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-CKKS-REFRESH","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"Implementation description and evaluation","evidenceUrl":"https://eprint.iacr.org/2018/931.pdf","id":"HE-REL-210775FA472469","note":"The full-RNS contribution is realized as word-size RNS and NTT-friendly CKKS kernels in the paper's implementation pattern.","resultId":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","reviewStatus":"primary_source_checked","source":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","target":"HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS","type":"REALIZED_AS_PROTOTYPE"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-211E853500F9D8","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-ROUTE-002","target":"HE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2191A83E0B1557","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2016-TFHE","target":"HE-RESULT-2016-TFHE-SUB-TENTH-SECOND-GATE-REFRESH","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2214D7F0F3E053","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-004","target":"HE-PAPER-2011-BV","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-222B995FB924C8","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2024-TFHE-PROCESSOR","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"Sections 3–5 and paper bibliography entries for TFHE","evidenceUrl":"https://eprint.iacr.org/2024/1201.pdf","id":"HE-REL-225118B67D0D1F","note":"The processor work builds its word interface over the TFHE bootstrap family and systematizes functional lookup patterns into more than fifty encrypted 8-bit instructions.","resultId":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","reviewStatus":"section_checked","source":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","target":"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2406A159A474D5","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-006-02","target":"HE-OP-006","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-255D5708D77F40","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-PARAM-GHS-AES-BOOT-2012","target":"he_bgv12","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-25E1D83434577E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-001","target":"HE-OP-001","type":"ADVANCES"},{"evidenceLocator":"Introduction and implementation setting; exact section locator pending local PDF audit","evidenceUrl":"https://eprint.iacr.org/2020/1549.pdf","id":"HE-REL-265069741C92BE","note":"High-precision CKKS bootstrapping relies on the modern RNS implementation line while optimizing the approximation and depth of modular reduction.","resultId":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","reviewStatus":"abstract_checked","source":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","target":"HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP","type":"COMBINES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-273CEE4EFBB918","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-2012","target":"he_bgv12","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-275BE48D1E2C4A","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-HP-CKKS-2020","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-27733E7B93BBF1","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_ckks17","target":"HE-PAPER-2017-CKKS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-27DBE194411B73","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-004-02","target":"HE-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-288964F83ADEDE","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-002-03","target":"HE-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-28CACCDFB66A00","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-003-03","target":"HE-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-28FDAA2DD1D3A2","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-FV","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"Implementation and performance sections","evidenceUrl":"https://eprint.iacr.org/2016/870.pdf","id":"HE-REL-2997C7E1045517","note":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","resultId":"HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE","reviewStatus":"primary_source_checked","source":"HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE","target":"HE-IMPL-TFHE-2016","type":"DOCUMENTED_BY_IMPLEMENTATION"},{"evidenceLocator":"Abstract and implementation results","evidenceUrl":"https://eprint.iacr.org/2014/816.pdf","id":"HE-REL-2BAD0C1531838F","note":"The FHEW benchmark records the prototype's reported roughly half-second refreshed binary operation.","resultId":null,"reviewStatus":"primary_source_checked","source":"HE-IMPL-FHEW-2015","target":"HE-BENCH-FHEW-2015","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2C9CBA3D8FA8EC","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-PARAM-GHS-AES-2012","target":"HE-PAPER-2012-GHS-AES","type":"DESCRIBED_IN"},{"evidenceLocator":"Implementation and evaluation sections; exact row pending","evidenceUrl":"https://eprint.iacr.org/2020/1549.pdf","id":"HE-REL-2CA4FD2992231B","note":"The high-precision benchmark measures the optimized approximation under its own precision and parameter profile.","resultId":null,"reviewStatus":"primary_source_checked","source":"HE-OPT-CKKS-HIGH-PRECISION-2020","target":"HE-BENCH-HP-CKKS-2020","type":"BENCHMARKS"},{"evidenceLocator":"Abstract and introduction","evidenceUrl":"https://eprint.iacr.org/2016/870.pdf","id":"HE-REL-2E3D6D4C5E2B94","note":"TFHE rewrites FHEW through an LWE–RingGSW external product, reducing reported refresh time and bootstrapping-key size.","resultId":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","reviewStatus":"primary_source_checked","source":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","target":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2E62279797E9C2","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-FHEW-2015","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2E6F85159DAE91","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-002","target":"HE-PAPER-2018-CKKS-BOOT","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2ED6FBA75E0680","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-CKKS-REFRESH","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-2ED78D90FCB988","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2011-BV","target":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-311A64F728CDC4","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-31477B4945DAFE","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BRAKERSKI","target":"HE-RESULT-2012-BRAKERSKI-SCALE-INVARIANT-FHE-WITH-LINEAR-NOISE-GROWTH","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-32C8C83C732B60","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2015-FHEW","target":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-32FE4885C74192","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-ROUTE-006","target":"HE-OP-006","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-346087ABDCA116","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-005-03","target":"HE-OP-005","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-3630DFEF5CE5D3","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_scaleinv12","target":"HE-ASSUMPTION-CLASSICAL-GAPSVP-VIA-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-36AE50BE659008","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-TFHE-2016","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-371BE33D437218","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-003","target":"HE-PAPER-2009-GENTRY","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-375F616D1C06DE","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-1999-PAILLIER","target":"HE-RESULT-1999-PAILLIER-PRACTICAL-ADDITIVELY-HOMOMORPHIC-PUBLIC-KEY-ENCRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"Sections 1 and 4; HElib implementation description","evidenceUrl":"https://eprint.iacr.org/2012/099.pdf","id":"HE-REL-37795CCB796A0A","note":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","resultId":"HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE","reviewStatus":"section_checked","source":"HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE","target":"HE-IMPL-GHS-AES-2012","type":"DOCUMENTED_BY_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-37BDB3851AEA18","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-CKKS-BOOT-2018","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"Section 4; Algorithm 6; Theorem 4.1","evidenceUrl":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","id":"HE-REL-392FDA2A66BACC","note":"The follow-up extends the TFHE ciphertext stack with a circuit bootstrap that turns an LWE-encrypted bit into a low-noise RingGSW ciphertext for later leveled circuits.","resultId":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","reviewStatus":"theorem_checked","source":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","target":"HE-RESULT-2017-TFHE-CB-TFHE-CIRCUIT-BOOTSTRAPPING-AND-PACKED-OPERATIONS","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-394795B7F3ABE2","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-PARAM-TFHE-PROCESSOR-2024","target":"HE-PAPER-2024-TFHE-PROCESSOR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-39669DDEA79712","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2010-DGHV","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-3A2339836567BE","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BGV","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"Section 3, Leveled Homomorphic Circuits","evidenceUrl":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","id":"HE-REL-3A342891437E8D","note":"The follow-up adds packed TRLWE lookup and automata evaluation paths alongside the original TFHE gate-bootstrap line.","resultId":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","reviewStatus":"section_checked","source":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","target":"HE-RESULT-2017-TFHE-CB-TFHE-PACKED-LEVELED-OPERATIONS","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-3AD623D0A5A1C6","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-RNS-CKKS","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-3B58F9E2C2EF0C","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-004","target":"HE-OP-003","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-3E70C84EC1566C","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-002","target":"HE-OP-004","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-3F158E7E5F4DFC","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-CKKS-BOOT-2018","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-3F9E6DB8AFD727","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-CKKS-FULL-RNS-2018","target":"he_rns_ckks18","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-406600ED173884","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-TFHE-PROCESSOR-2024","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-41910DEB9D63F3","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-002","target":"HE-OP-006","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-41DE53069DD4CA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2016-TFHE","target":"HE-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-430EF73B33C61E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-004","target":"HE-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-436967000E095F","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2009-GENTRY","target":"HE-OP-004","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-437A180FFE8869","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-GHS-AES-2012","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-443DD31502CC64","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2015-FHEW","target":"HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-446B5D434C9B8F","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_gentry09","target":"HE-ASSUMPTION-IDEAL-LATTICE-HARDNESS-PLUS-SQUASHING-RELATED-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-454E1E8AD77757","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-IMPL-GHS-AES-2012","target":"he_bgv12","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-45C7BD9F2B1068","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-FHEW-2015","target":"HE-IMPL-FHEW-2015","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4601D33C076C88","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-004","target":"HE-OP-006","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4644F91A7EB8D8","note":"","resultId":null,"reviewStatus":"reported","source":"HE-PARAM-CKKS-BOOT-2018","target":"he_ckks_boot18","type":"PARAMETERIZES"},{"evidenceLocator":"Abstract and introduction; exact section locator pending local PDF audit","evidenceUrl":"https://eprint.iacr.org/2009/616.pdf","id":"HE-REL-469A85DA837F69","note":"DGHV retains Gentry's somewhat-HE-to-bootstrapping blueprint while replacing ideal-lattice arithmetic with approximate multiples of a hidden integer.","resultId":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","reviewStatus":"abstract_checked","source":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","target":"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD","type":"CHANGES_ASSUMPTION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-46E19348EB3AC5","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-CKKS-BOOT-2018","target":"HE-IMPL-CKKS-BOOT-2018","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-46F62B2D9355FC","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-CKKS","target":"HE-OP-003","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-46F78750C5BC6E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-FHEW-2015","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-479B0C97F15F41","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-2016","target":"HE-PARAM-TFHE-2016","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-488338FE64E483","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-PARAM-TFHE-PROCESSOR-2024","target":"he_tfhe16","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-48D506D59D9FB2","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2024-TFHE-PROCESSOR","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"Sections 5, 7, and 8; Appendix A","evidenceUrl":"https://eprint.iacr.org/2024/1201.pdf","id":"HE-REL-4A5543B957DF1D","note":"The encrypted 8-bit instruction abstraction is realized by the paper-described processor prototype used for system-level evaluation.","resultId":"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING","reviewStatus":"section_checked","source":"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING","target":"HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE","type":"REALIZED_AS_PROTOTYPE"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4A771F17923AD9","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_bv11","target":"HE-PAPER-2011-BV","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4CFD39A85D12F6","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_tfhe16","target":"HE-ASSUMPTION-LEARNING-WITH-ERRORS-AND-RING-VARIANTS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4D1F1F127E87D9","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-PARAM-GHS-AES-2012","target":"he_bgv12","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4D31EEEACF0BF3","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-006-01","target":"HE-OP-006","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"GSW Section 1.2 and Section 3","evidenceUrl":"https://eprint.iacr.org/2013/340.pdf","id":"HE-REL-4D3A3AB8FB9436","note":"GSW retains LWE security but replaces relinearized vector ciphertext multiplication with an approximate-eigenvector matrix representation.","resultId":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","reviewStatus":"section_checked","source":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","target":"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","type":"CHANGES_CIPHERTEXT_REPRESENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4DE95ECD8AC651","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-TFHE-PROCESSOR-2024","target":"HE-PAPER-2024-TFHE-PROCESSOR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4E8478766C3AAB","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-001-03","target":"HE-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-4FAC0C1CF11805","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2011-BV","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-50006D25BF8F10","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-FHEW-2015","target":"HE-PAPER-2015-FHEW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-500F3D589ED4AE","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-RNS-CKKS-2018","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5055455EDE6DC6","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-CKKS-BOOT","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5086375E10F3D0","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_ckks_boot18","target":"HE-PAPER-2018-CKKS-BOOT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5105E2DE4C06A1","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-CKKS-FULL-RNS-2018","target":"HE-PAPER-2018-RNS-CKKS","type":"DESCRIBED_IN"},{"evidenceLocator":"Construction overview; exact section locator pending local PDF audit","evidenceUrl":"https://eprint.iacr.org/2014/816.pdf","id":"HE-REL-5203BA398DCDDC","note":"FHEW uses GSW-type ciphertext operations as part of its fast gate-bootstrapping construction.","resultId":"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","reviewStatus":"abstract_checked","source":"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","target":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","type":"BUILDS_ON_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5234D0432FDC70","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-GATE-BOOTSTRAP","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5326D3B373C2A0","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2011-BV","target":"HE-OP-004","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-54B5CAC48B88B2","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-001","target":"HE-PAPER-2016-TFHE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-54B896CFDE7198","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-WORKLOAD-TFHE-8BIT","target":"HE-PAPER-2024-TFHE-PROCESSOR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-54E6B3028DBC1D","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-GHS-AES-2012","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-551A48E319D478","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-TFHE-PROCESSOR-2024","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-55B16DC8435C3C","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-CKKS-BOOT-2018","target":"HE-WORKLOAD-CKKS-REFRESH","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-55B9E205C41066","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_gsw13","target":"HE-ASSUMPTION-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-55C5C78A86C623","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-001","target":"HE-OP-003","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-56363C9AECD306","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BGV","target":"HE-OP-003","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-568E56027AAED8","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-TFHE-PROCESSOR-2024","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-56EAD00FC13724","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-CKKS-BOOT-2018","target":"he_ckks_boot18","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-573BC10CAAC180","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-004-03","target":"HE-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-57B99403B40252","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-004","target":"HE-PAPER-2009-GENTRY","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-587D633634311C","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-003-02","target":"HE-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-59B0C299C32DA3","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_rns_ckks18","target":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5A73C7C18BDA8A","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_paillier99","target":"HE-PAPER-1999-PAILLIER","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5A81897BE79F50","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-001","target":"HE-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5C4A9726DEEAD2","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-005","target":"HE-PAPER-2017-TFHE-CB","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5D197E20A93158","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_fhew15","target":"HE-PAPER-2015-FHEW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5DFC0660A98238","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-FHEW-2015","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5E286DA1E465A0","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-PROCESSOR-2024","target":"HE-PAPER-2024-TFHE-PROCESSOR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5EEC45B9E9B589","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-PROCESSOR-2024","target":"HE-WORKLOAD-TFHE-8BIT","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5FC1DB013BA7EB","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_ckks_boot18","target":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-5FC403F4117E7C","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-2016","target":"HE-PAPER-2016-TFHE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-6006F08CC08D9E","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-CKKS-BOOT-2018","target":"HE-PAPER-2018-CKKS-BOOT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-617777CC005748","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2016-TFHE","target":"HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-62E2AE92EBC8CC","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-TFHE-2016","target":"he_tfhe16","type":"IMPLEMENTS"},{"evidenceLocator":"Abstract and introduction","evidenceUrl":"https://eprint.iacr.org/2016/870.pdf","id":"HE-REL-636715C9A6894C","note":"TFHE changes the concrete FHEW bootstrap path through an LWE–RingGSW external product.","resultId":null,"reviewStatus":"primary_source_checked","source":"HE-IMPL-FHEW-2015","target":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-638C6E2C1F1204","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-BOOT-2012","target":"HE-IMPL-GHS-AES-2012","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"Implementation evaluation; exact benchmark row pending","evidenceUrl":"https://eprint.iacr.org/2012/099.pdf","id":"HE-REL-639DE2C4363F87","note":"The end-to-end AES measurement evaluates the paper's CRT, packing, key-switching, and modulus-planning pipeline.","resultId":null,"reviewStatus":"abstract_checked","source":"HE-OPT-BGV-AES-PIPELINE-2012","target":"HE-BENCH-GHS-AES-2012","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-643138EDFFCE00","note":"","resultId":null,"reviewStatus":"reported","source":"HE-PARAM-FHEW-2015","target":"HE-PAPER-2015-FHEW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-647A6D5625071B","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-004","target":"HE-OP-005","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-649E2F2879481A","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2024-TFHE-PROCESSOR","target":"HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-654660C8E4D6DC","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-RNS-CKKS-2018","target":"he_rns_ckks18","type":"IMPLEMENTS"},{"evidenceLocator":"Abstract; exact section locator pending local PDF audit","evidenceUrl":"https://eprint.iacr.org/2012/078.pdf","id":"HE-REL-6556686B4DEB7F","note":"Brakerski replaces quadratic multiplication-noise growth and modulus switching with tensoring that gives a scale-invariant single-modulus scheme.","resultId":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","reviewStatus":"abstract_checked","source":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","target":"HE-RESULT-2012-BRAKERSKI-SCALE-INVARIANT-FHE-WITH-LINEAR-NOISE-GROWTH","type":"CHANGES_NOISE_MECHANISM"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-65F1E62B5DF5EA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2013-GSW","target":"HE-RESULT-2013-GSW-MULTIPLICATION-WITHOUT-RELINEARIZATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-680C34826D12D1","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-2012","target":"HE-WORKLOAD-AES-2012","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-69C9E4B3840D28","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-TFHE-PROCESSOR-2024","target":"he_tfhe16","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-6B354421E81CC3","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-003-01","target":"HE-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-6B3AE9FF14EB1A","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-SV-SIMD","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"Abstract, comparison with previous schemes; exact section locator pending local PDF audit","evidenceUrl":"https://eprint.iacr.org/2011/344.pdf","id":"HE-REL-6C777674B67738","note":"BV moves somewhat homomorphic encryption from integer and ideal assumptions to standard LWE and replaces squashing with relinearization and dimension-modulus reduction.","resultId":"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD","reviewStatus":"abstract_checked","source":"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD","target":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","type":"CHANGES_ASSUMPTION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-6CBEA5D8A6A312","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-TFHE-PROCESSOR-2024","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-6D5DB55CD341E5","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-CKKS-BOOT","target":"HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-6E25EA7A9C2E66","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-GHS-AES","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-6E2E70B0C94FA7","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_bgv12","target":"HE-ASSUMPTION-LWE-OR-RING-LWE","type":"RELIES_ON"},{"evidenceLocator":"BGV Sections 1.2 and 3; Theorem 3","evidenceUrl":"https://eprint.iacr.org/2011/277.pdf","id":"HE-REL-6F20A53A991C83","note":"BGV builds on BV noise-management techniques and introduces a modulus-chain approach yielding leveled FHE without bootstrapping.","resultId":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","reviewStatus":"theorem_checked","source":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","target":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-6FDE6CE5714E32","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-ROUTE-001","target":"HE-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-70D660719FCF8C","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2013-GSW","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7226095D3FEB75","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2013-GSW","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7417AA5CE7B464","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-2016","target":"he_tfhe16","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-746B8F02F3A476","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-002-02","target":"HE-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-74E5287A1E4E77","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2009-GENTRY","target":"HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-75028B2962BFB7","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-GHS-AES","target":"HE-OP-006","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7566845B2E92F9","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2016-TFHE","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-758D98BD2060C8","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-CKKS-BOOT-2018","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-75C847FC08696A","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-001","target":"HE-OP-006","type":"ADVANCES"},{"evidenceLocator":"GHS Sections 1 and 3–4","evidenceUrl":"https://eprint.iacr.org/2012/099.pdf","id":"HE-REL-76735ADA9F34F0","note":"The AES evaluation uses SIMD packing to amortize many AES blocks inside one homomorphic computation.","resultId":"HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION","reviewStatus":"section_checked","source":"HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION","target":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","type":"BUILDS_ON_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-76D8C9E27578AF","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-TFHE-2016","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-77AE99EB1F99AA","note":"","resultId":null,"reviewStatus":"reported","source":"HE-WORKLOAD-CKKS-REFRESH","target":"HE-PAPER-2018-CKKS-BOOT","type":"DESCRIBED_IN"},{"evidenceLocator":"Introduction and construction overview; exact section locator pending local PDF audit","evidenceUrl":"https://eprint.iacr.org/2016/421.pdf","id":"HE-REL-77DADC02C51CBD","note":"CKKS retains packed RLWE ciphertext arithmetic and relinearization while replacing exact modular plaintext semantics with approximate numerical encoding and rescaling.","resultId":"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION","reviewStatus":"abstract_checked","source":"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION","target":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-78346DC9DCED47","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-CKKS","target":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-790D1C7DC837CA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-1978-RAD","target":"HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7955D0D38A2403","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-CKKS-BOOT-2018","target":"HE-PAPER-2018-CKKS-BOOT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-79B1E15DA53FBB","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BRAKERSKI","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7A3A4A8092CE02","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_dghv10","target":"HE-PAPER-2010-DGHV","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7A54543C0D83A8","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016","target":"he_fhew15","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7CC6B5D76787D4","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2010-DGHV","target":"HE-OP-004","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7D3B50C4701B05","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OPT-BGV-AES-PIPELINE-2012","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7E122C71B9BE61","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-BGV-AES-PIPELINE-2012","target":"HE-PAPER-2012-GHS-AES","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7EC889A8124056","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2015-FHEW","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"System evaluation; exact row pending","evidenceUrl":"https://eprint.iacr.org/2024/1201.pdf","id":"HE-REL-7F5E9AED119C8C","note":"The processor evaluation measures instruction- and program-level behavior rather than treating gate latency as the whole system result.","resultId":null,"reviewStatus":"abstract_checked","source":"HE-IMPL-TFHE-PROCESSOR-2024","target":"HE-BENCH-TFHE-PROCESSOR-2024","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-7FFAB78D251539","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-FV","target":"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-807F88F847F213","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OPT-CKKS-FULL-RNS-2018","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-81548DBC49D0F0","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-HP-CKKS-2020","target":"HE-PAPER-2020-HP-CKKS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-81765C250C1AAA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2009-GENTRY","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-819726903DDADB","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-GHS-AES-2012","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-81EF02973ECD29","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_bgv12","target":"HE-PAPER-2012-BGV","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-84BF80C9C442A4","note":"","resultId":null,"reviewStatus":"reported","source":"HE-PARAM-CKKS-BOOT-2018","target":"HE-PAPER-2018-CKKS-BOOT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-85E7D6113A0E35","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-TFHE-2016","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-85F14804BE3CD4","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OPT-BGV-AES-PIPELINE-2012","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-8626119020F528","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_rns_ckks18","target":"HE-PAPER-2018-RNS-CKKS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-862CDE5E3F17D4","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-GHS-AES","target":"HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-87ACBF0B52A620","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-001","target":"HE-PAPER-2009-GENTRY","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-88E6AA1B0F91FA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-004","target":"HE-PAPER-2010-DGHV","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-89822B0C65FBA3","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2020-HP-CKKS","target":"HE-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-89AC9B94DC73E5","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-005","target":"HE-PAPER-2013-GSW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-8BA75B6D98AADF","note":"","resultId":null,"reviewStatus":"reported","source":"HE-PARAM-FHEW-2015","target":"he_fhew15","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-8EF916267AC4CB","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_dghv10","target":"HE-ASSUMPTION-APPROXIMATE-GCD-WITH-AUXILIARY-ASSUMPTIONS-IN-THE-ORIGINAL-FULL-SCHEME","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-8F1788F2F743C0","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-RNS-CKKS","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-8F984A0899905C","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2009-GENTRY","target":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-8FE44CC81129F7","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-005-02","target":"HE-OP-005","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-92A8A6B6942B40","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-HP-CKKS-2020","target":"HE-WORKLOAD-CKKS-REFRESH","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-93DF262034BDB0","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-FHEW-2015","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-946C968E108794","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BGV","target":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-95256CA313817E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-CKKS","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-954650C54F093B","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-PROCESSOR-2024","target":"he_tfhe16","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-95672E25363A8C","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-2012","target":"HE-PARAM-GHS-AES-2012","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-95714694B8635C","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-CKKS-BOOT-2018","target":"HE-PARAM-CKKS-BOOT-2018","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-966D0F6C48B60E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-CKKS-BOOT","target":"HE-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9742E39B4263E6","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2024-TFHE-PROCESSOR","target":"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-97D516FFE477DE","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-002-01","target":"HE-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"Section 4.4, implementation using bootstrapping; Table 1","evidenceUrl":"https://eprint.iacr.org/2012/099.pdf","id":"HE-REL-97F3431FC9D850","note":"The separate bootstrapped AES observation binds the same pipeline to its 23-level parameter regime, two recryptions, historical laptop, and reported memory.","resultId":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","reviewStatus":"section_checked","source":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","target":"HE-BENCH-GHS-AES-BOOT-2012","type":"CONTEXTUALIZED_BY_MEASUREMENT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9876C62684563A","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2016-TFHE","target":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-99CC9A630212AC","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OPT-CKKS-FULL-RNS-2018","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9A9EBD495872F6","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-TFHE-CB","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9C2A410FDF02A4","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-GATE-BOOTSTRAP","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9D9E13D2D57CD1","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-TFHE-8BIT","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9DB4BF90AE0398","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-TFHE-2016","target":"HE-PAPER-2016-TFHE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9ECEDDD9F73C88","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-CKKS-HIGH-PRECISION-2020","target":"HE-PAPER-2020-HP-CKKS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9F1E4A62BBEC38","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-FHEW-2015","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-9FEA007427A170","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-CKKS-FULL-RNS-2018","target":"he_ckks17","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A0129EC0EF093D","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-GATE-BOOTSTRAP","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"Implementation and performance sections","evidenceUrl":"https://eprint.iacr.org/2014/816.pdf","id":"HE-REL-A06BAD42147A72","note":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","resultId":"HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE","reviewStatus":"primary_source_checked","source":"HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE","target":"HE-IMPL-FHEW-2015","type":"DOCUMENTED_BY_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A0D79E3373569D","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-2016","target":"HE-WORKLOAD-GATE-BOOTSTRAP","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A0FCD4526A5EE8","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-FHEW-2015","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A191D457131010","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_scaleinv12","target":"HE-PAPER-2012-BRAKERSKI","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A1AD0CA39E571B","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2016-TFHE","target":"HE-OP-005","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A44D4CBA1F1BEB","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-RNS-CKKS","target":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","type":"HAS_RESULT"},{"evidenceLocator":"Abstract and introduction","evidenceUrl":"https://eprint.iacr.org/2016/421.pdf","id":"HE-REL-A492DC3D84799A","note":"CKKS reinterprets modulus reduction as rescaling approximate plaintext and error together, changing the correctness semantics from exact modular arithmetic to controlled approximation.","resultId":"HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT","reviewStatus":"primary_source_checked","source":"HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT","target":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","type":"CHANGES_CORRECTNESS_SEMANTICS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A50CBB129945CB","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-005","target":"HE-PAPER-2024-TFHE-PROCESSOR","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A520F863D52C73","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-001-01","target":"HE-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A545239E5C55BA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-ROUTE-005","target":"HE-OP-005","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A6F656D07FE904","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-SIMD-PACKING-2012","target":"HE-PAPER-2012-SV-SIMD","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A7BFF2CFAD3386","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-001","target":"HE-OP-003","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-A91D050A51C4BA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-001","target":"HE-PAPER-2015-FHEW","type":"GROUNDED_IN"},{"evidenceLocator":"Abstract and introduction","evidenceUrl":"https://eprint.iacr.org/2018/153.pdf","id":"HE-REL-A9BA73982569B0","note":"The bootstrapping paper turns leveled CKKS into FHE by approximately evaluating modular reduction in the decryption circuit.","resultId":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","reviewStatus":"primary_source_checked","source":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","target":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-AA66CC48FC01DD","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-RNS-CKKS","target":"HE-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-AB54270C3A0A6F","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-PROCESSOR-2024","target":"HE-PARAM-TFHE-PROCESSOR-2024","type":"EVALUATED_WITH"},{"evidenceLocator":"Introduction and definition of FHE; exact cross-reference pending PDF audit","evidenceUrl":"https://crypto.stanford.edu/craig/craig-thesis.pdf","id":"HE-REL-AC3C7C4B7E780E","note":"Gentry resolves the general computation goal posed by the privacy-homomorphism program by giving the first construction for arbitrary circuits.","resultId":"HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM","reviewStatus":"primary_source_checked","source":"HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM","target":"HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION","type":"GENERALIZES"},{"evidenceLocator":"GHS Sections 1–3 and its BGV instantiation discussion","evidenceUrl":"https://eprint.iacr.org/2012/099.pdf","id":"HE-REL-ADDB525CD0F959","note":"The AES implementation instantiates BGV-style modulus switching, key switching, CRT representation, and leveled evaluation.","resultId":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","reviewStatus":"section_checked","source":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","target":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","type":"BUILDS_ON_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B2BBF15EFDC787","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-BOOT-2012","target":"he_bgv12","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B3415E99A976BA","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-2012","target":"HE-PAPER-2012-GHS-AES","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B3AEAD74AEFDAA","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_bfv12","target":"HE-PAPER-2012-FV","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B47FC6CA425E1C","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-RNS-CKKS-2018","target":"he_ckks17","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B5FA6A62FF220B","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-006","target":"HE-PAPER-2018-RNS-CKKS","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B7D41A776DC25D","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BGV","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B80245AB141965","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-FHEW-2015","target":"he_fhew15","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B9CFA5F1A58139","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-2016","target":"HE-IMPL-TFHE-2016","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-B9D26BC1F80C08","note":"","resultId":null,"reviewStatus":"reported","source":"HE-IMPL-RNS-CKKS-2018","target":"HE-PAPER-2018-RNS-CKKS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-BA7298631DBCD6","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-TFHE-CB","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-BB6B8D300F0738","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-GHS-AES-BOOT-2012","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-BC824CAA396EAF","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-006","target":"HE-PAPER-2024-TFHE-PROCESSOR","type":"GROUNDED_IN"},{"evidenceLocator":"BGV Sections 1.2 and 3; Theorem 3","evidenceUrl":"https://eprint.iacr.org/2011/277.pdf","id":"HE-REL-BD0D8E0BC98998","note":"BGV eliminates online bootstrapping for circuits of a predetermined depth by using depth-dependent parameters and a modulus chain; depth-independent FHE still uses bootstrapping. This is a scoped evaluation-cost trade-off.","resultId":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","reviewStatus":"theorem_checked","source":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","target":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-BD9BC80CDED300","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-FHEW-2015","target":"HE-PARAM-FHEW-2015","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-BE42C39FB97BB9","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_paillier99","target":"HE-ASSUMPTION-DECISIONAL-COMPOSITE-RESIDUOSITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-BEF1868CA6B0E9","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BGV","target":"HE-OP-004","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-BFB0A2039BCF3B","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-AES-2012","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C064A4EDA36B3F","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-002","target":"HE-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C088706E19CF19","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-RNS-CKKS","target":"HE-OP-006","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C10BAB902F52F9","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-2012","target":"HE-IMPL-GHS-AES-2012","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C1119FE2203B83","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_gsw13","target":"HE-PAPER-2013-GSW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C11D3CA8F3CCCB","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_fhew15","target":"HE-ASSUMPTION-STANDARD-LATTICE-PROBLEMS-VIA-LWE-RLWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C1E512880BC393","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-003","target":"HE-OP-002","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C340E0644B8982","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-BGV","target":"HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C44845FD59AFF9","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-SV-SIMD","target":"HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C450BE38C03A49","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-003","target":"HE-PAPER-2012-BGV","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C4BF4B1F4F9568","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-HP-CKKS-2020","target":"HE-PARAM-HP-CKKS-2020","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C4ED20CCBE08AB","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-GHS-AES-BOOT-2012","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C500E4D18F9675","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2015-FHEW","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C52160DD0ED2CC","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-TFHE-2016","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C7B5560295F9B9","note":"","resultId":null,"reviewStatus":"source_derived","source":"HE-MILESTONE-001-02","target":"HE-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C84F4598A5211F","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-TFHE-PROCESSOR-2024","target":"HE-IMPL-TFHE-PROCESSOR-2024","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C92AAEAE3ADFA3","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2013-GSW","target":"HE-OP-004","type":"APPROACHES"},{"evidenceLocator":"Evaluation section; exact row pending","evidenceUrl":"https://eprint.iacr.org/2018/153.pdf","id":"HE-REL-C935B4C23A1D41","note":"The benchmark anchors the first packed CKKS refresh claim to its prototype and parameter regime.","resultId":null,"reviewStatus":"primary_source_checked","source":"HE-IMPL-CKKS-BOOT-2018","target":"HE-BENCH-CKKS-BOOT-2018","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C98C0526D0EEB5","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-006","target":"HE-PAPER-2012-GHS-AES","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-C9AA49350D4177","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-PARAM-GHS-AES-BOOT-2012","target":"HE-PAPER-2012-GHS-AES","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-CA85628BDBB4B5","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-GHS-AES","target":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-CAB5D92893E54C","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2010-DGHV","target":"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-CB53305148102D","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-BOOT-2012","target":"HE-PAPER-2012-GHS-AES","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-CB5AF1A3C0D02F","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2020-HP-CKKS","target":"HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP","type":"HAS_RESULT"},{"evidenceLocator":"Introduction and implementation setting","evidenceUrl":"https://eprint.iacr.org/2020/1549.pdf","id":"HE-REL-CD40BC3E297AED","note":"The high-precision line retains modern RNS implementation machinery while improving approximate modular reduction.","resultId":null,"reviewStatus":"primary_source_checked","source":"HE-OPT-CKKS-FULL-RNS-2018","target":"HE-OPT-CKKS-HIGH-PRECISION-2020","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-CE76A24ED57F39","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OP-002","target":"HE-PAPER-2017-CKKS","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-CF10C20967CB4E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-002","target":"HE-OP-002","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-CF11D5B0980390","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OPT-SIMD-PACKING-2012","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-CFD4A0F3976AC7","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-001","target":"HE-OP-005","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-D2F1A911AD0AE5","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BARRIER-004","target":"HE-OP-002","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-D2FD5AFDC4B447","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_tfhe16","target":"HE-PAPER-2016-TFHE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-D380630EAC839C","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-RNS-CKKS-2018","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-D3A972B339695E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-TFHE-2016","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-D417DD16AA228F","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-FHEW-2015","target":"HE-WORKLOAD-GATE-BOOTSTRAP","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"Abstract","evidenceUrl":"https://eprint.iacr.org/2018/931.pdf","id":"HE-REL-D4CA379E7E411D","note":"Full-RNS CKKS replaces multiprecision core arithmetic with word-size RNS/NTT operations and approximate RNS modulus switching.","resultId":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","reviewStatus":"primary_source_checked","source":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","target":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Bootstrapping evaluation section; exact artifact locator pending","evidenceUrl":"https://eprint.iacr.org/2018/153.pdf","id":"HE-REL-D4D4D8ADCE4F57","note":"The first CKKS bootstrap is realized by the paper-described packed refresh prototype evaluating approximate modular reduction.","resultId":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","reviewStatus":"primary_source_checked","source":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","target":"HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE","type":"REALIZED_AS_PROTOTYPE"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-D4EB347614B21E","note":"","resultId":null,"reviewStatus":"reported","source":"HE-PARAM-TFHE-2016","target":"HE-PAPER-2016-TFHE","type":"DESCRIBED_IN"},{"evidenceLocator":"Bootstrapping evaluation section; exact artifact locator pending","evidenceUrl":"https://eprint.iacr.org/2018/153.pdf","id":"HE-REL-D573AEDEF65DD7","note":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","resultId":"HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE","reviewStatus":"primary_source_checked","source":"HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE","target":"HE-IMPL-CKKS-BOOT-2018","type":"DOCUMENTED_BY_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-D9CB0BE74FEE72","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-OPT-CKKS-HIGH-PRECISION-2020","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-DB0BB322BCB8AD","note":"","resultId":null,"reviewStatus":"section_checked","source":"HE-IMPL-GHS-AES-2012","target":"HE-PAPER-2012-GHS-AES","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-DBBC4DE939254D","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-003","target":"HE-OP-006","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-DD608F04AD1C0B","note":"","resultId":null,"reviewStatus":"reported","source":"HE-WORKLOAD-AES-2012","target":"HE-PAPER-2012-GHS-AES","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-DD8A0149C7B7E1","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-CKKS-BOOT-2018","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-DDAF6FC0F977A8","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-IMPL-TFHE-PROCESSOR-2024","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-DE2FC880B41713","note":"","resultId":null,"reviewStatus":"reported","source":"HE-PARAM-TFHE-2016","target":"he_tfhe16","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-DFBEAB9E86EB3F","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2011-BV","target":"HE-OP-004","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E061FA5C2EB644","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-ROUTE-004","target":"HE-OP-004","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E4BEAF273248C5","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-TFHE-CB","target":"HE-RESULT-2017-TFHE-CB-TFHE-PACKED-LEVELED-OPERATIONS","type":"HAS_RESULT"},{"evidenceLocator":"Section 4.4, non-bootstrapping implementation; Table 1","evidenceUrl":"https://eprint.iacr.org/2012/099.pdf","id":"HE-REL-E578B577FE2F73","note":"The historical end-to-end AES claim is bounded by the separate parameter, workload, hardware, and source-reported measurement record.","resultId":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","reviewStatus":"section_checked","source":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","target":"HE-BENCH-GHS-AES-2012","type":"CONTEXTUALIZED_BY_MEASUREMENT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E5E74AA30EF87F","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-TRACK-003","target":"HE-OP-005","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E6961840278A06","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-BOOT-2012","target":"HE-PARAM-GHS-AES-BOOT-2012","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E6DB1A94C8046B","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-CKKS-HIGH-PRECISION-2020","target":"he_ckks_boot18","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E779D8C6279681","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2011-BV","target":"HE-RESULT-2011-BV-DIMENSION-MODULUS-REDUCTION-WITHOUT-SQUASHING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E792FD348C26FB","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016","target":"HE-PAPER-2016-TFHE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E7A5759E73C6F0","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-CKKS-BOOT-2018","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E7FED056C6B00F","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-1978-RAD","target":"HE-OP-004","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E8C7FEED1451CD","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-BGV-AES-PIPELINE-2012","target":"he_bgv12","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E8CA4FB9D691BE","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-GHS-AES","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-E96D19ED5B573E","note":"","resultId":null,"reviewStatus":"source_declared","source":"he_gentry09","target":"HE-PAPER-2009-GENTRY","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-EB24523F8A7BEF","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2013-GSW","target":"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","type":"HAS_RESULT"},{"evidenceLocator":"Sections 1 and 4; HElib implementation description","evidenceUrl":"https://eprint.iacr.org/2012/099.pdf","id":"HE-REL-EC33A1997405F4","note":"The end-to-end AES contribution is realized by the paper-described packed-BGV prototype combining CRT, slots, key switching, and modulus planning.","resultId":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","reviewStatus":"section_checked","source":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","target":"HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE","type":"REALIZED_AS_PROTOTYPE"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-ED74EA1A41F337","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2015-FHEW","target":"HE-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-EE4EEF12D001CA","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-CKKS-BOOT-2018","target":"he_ckks_boot18","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-EEB0ED645A239A","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-HP-CKKS-2020","target":"HE-IMPL-CKKS-BOOT-2018","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-EF55D02FD1F983","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-CKKS-BOOT","target":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F00F17A4BEE667","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2012-FV","target":"HE-OP-006","type":"TARGETS"},{"evidenceLocator":"Introduction and construction overview; exact section locator pending local PDF audit","evidenceUrl":"https://eprint.iacr.org/2012/144.pdf","id":"HE-REL-F06E3C6B03304C","note":"FV specializes the relinearized LWE/RLWE arithmetic line into a practical ring-based exact modular construction.","resultId":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","reviewStatus":"abstract_checked","source":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","target":"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F131F94DD6E139","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_bv11","target":"HE-ASSUMPTION-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F34AA150EADF0E","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-GHS-AES-BOOT-2012","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F50247A7DEC500","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2017-TFHE-CB","target":"HE-RESULT-2017-TFHE-CB-TFHE-CIRCUIT-BOOTSTRAPPING-AND-PACKED-OPERATIONS","type":"HAS_RESULT"},{"evidenceLocator":"Abstract and introduction","evidenceUrl":"https://eprint.iacr.org/2020/1549.pdf","id":"HE-REL-F5F43C83DAF1C6","note":"The high-precision work replaces indirect modular-reduction approximations with a direct error-variance-minimizing polynomial design.","resultId":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","reviewStatus":"primary_source_checked","source":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","target":"HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Implementation description and evaluation","evidenceUrl":"https://eprint.iacr.org/2018/931.pdf","id":"HE-REL-F6F2CD38E264B5","note":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","resultId":"HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS","reviewStatus":"primary_source_checked","source":"HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS","target":"HE-IMPL-RNS-CKKS-2018","type":"DOCUMENTED_BY_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F6FCA8CA5A9162","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2020-HP-CKKS","target":"HE-OP-002","type":"TARGETS"},{"evidenceLocator":"Abstract and implementation results","evidenceUrl":"https://eprint.iacr.org/2014/816.pdf","id":"HE-REL-F738B700A8E2A2","note":"The roughly half-second FHEW gate-bootstrap claim is recorded as a contextual observation tied to the paper's prototype, parameters, and workload.","resultId":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","reviewStatus":"primary_source_checked","source":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","target":"HE-BENCH-FHEW-2015","type":"CONTEXTUALIZED_BY_MEASUREMENT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F75B5F70A1F141","note":"","resultId":null,"reviewStatus":"reported","source":"HE-PARAM-HP-CKKS-2020","target":"HE-PAPER-2020-HP-CKKS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F8211ACE381008","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-WORKLOAD-AES-2012","target":"HE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F891CFD8AB81B0","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-CKKS-HIGH-PRECISION-2020","target":"he_rns_ckks18","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-F932A2C908ED13","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PARAM-TFHE-PROCESSOR-2024","target":"HE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-FB3AA6800DBF01","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"he_ckks17","target":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-FC39F520A6FC31","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-HP-CKKS-2020","target":"he_ckks_boot18","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-FC808728A3EED3","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-ROUTE-003","target":"HE-OP-003","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-FC852EC1E4EB99","note":"","resultId":null,"reviewStatus":"reported","source":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016","target":"he_tfhe16","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-FCC07B184579BA","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-PAPER-2018-RNS-CKKS","target":"HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-FECA93B75C5AD5","note":"","resultId":null,"reviewStatus":"reported","source":"HE-BENCH-GHS-AES-BOOT-2012","target":"HE-WORKLOAD-AES-2012","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"","evidenceUrl":"","id":"HE-REL-FF4D057AC1DE3C","note":"","resultId":null,"reviewStatus":"source_declared","source":"HE-BENCH-FHEW-2015","target":"HE-OP-001","type":"TARGETS"}],"nodes":[{"evidence":"scheme_declared","id":"HE-ASSUMPTION-APPROXIMATE-GCD-WITH-AUXILIARY-ASSUMPTIONS-IN-THE-ORIGINAL-FULL-SCHEME","keywords":["agcd"],"metadata":{"family":"agcd","name":"Approximate GCD with auxiliary assumptions in the original full scheme"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"agcd","summary":"Assumption used by one or more HE construction records: Approximate GCD with auxiliary assumptions in the original full scheme.","title":"Approximate GCD with auxiliary assumptions in the original full scheme","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-APPROXIMATE-GCD-WITH-AUXILIARY-ASSUMPTIONS-IN-THE-ORIGINAL-FULL-SCHEME"},{"evidence":"scheme_declared","id":"HE-ASSUMPTION-CLASSICAL-GAPSVP-VIA-LWE","keywords":["lwe"],"metadata":{"family":"lwe","name":"Classical GapSVP via LWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lwe","summary":"Assumption used by one or more HE construction records: Classical GapSVP via LWE.","title":"Classical GapSVP via LWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-CLASSICAL-GAPSVP-VIA-LWE"},{"evidence":"scheme_declared","id":"HE-ASSUMPTION-DECISIONAL-COMPOSITE-RESIDUOSITY","keywords":["composite_residuosity"],"metadata":{"family":"composite_residuosity","name":"Decisional Composite Residuosity"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"composite_residuosity","summary":"Assumption used by one or more HE construction records: Decisional Composite Residuosity.","title":"Decisional Composite Residuosity","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-DECISIONAL-COMPOSITE-RESIDUOSITY"},{"evidence":"scheme_declared","id":"HE-ASSUMPTION-IDEAL-LATTICE-HARDNESS-PLUS-SQUASHING-RELATED-ASSUMPTIONS","keywords":["ideal_lattice"],"metadata":{"family":"ideal_lattice","name":"Ideal-lattice hardness plus squashing-related assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"ideal_lattice","summary":"Assumption used by one or more HE construction records: Ideal-lattice hardness plus squashing-related assumptions.","title":"Ideal-lattice hardness plus squashing-related assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-IDEAL-LATTICE-HARDNESS-PLUS-SQUASHING-RELATED-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"HE-ASSUMPTION-LEARNING-WITH-ERRORS","keywords":["lwe"],"metadata":{"family":"lwe","name":"Learning With Errors"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lwe","summary":"Assumption used by one or more HE construction records: Learning With Errors.","title":"Learning With Errors","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-LEARNING-WITH-ERRORS"},{"evidence":"scheme_declared","id":"HE-ASSUMPTION-LEARNING-WITH-ERRORS-AND-RING-VARIANTS","keywords":["lwe_rlwe"],"metadata":{"family":"lwe_rlwe","name":"Learning With Errors and ring variants"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lwe_rlwe","summary":"Assumption used by one or more HE construction records: Learning With Errors and ring variants.","title":"Learning With Errors and ring variants","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-LEARNING-WITH-ERRORS-AND-RING-VARIANTS"},{"evidence":"scheme_declared","id":"HE-ASSUMPTION-LWE-OR-RING-LWE","keywords":["lwe_rlwe"],"metadata":{"family":"lwe_rlwe","name":"LWE or Ring-LWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lwe_rlwe","summary":"Assumption used by one or more HE construction records: LWE or Ring-LWE.","title":"LWE or Ring-LWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-LWE-OR-RING-LWE"},{"evidence":"scheme_declared","id":"HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS","keywords":["rlwe"],"metadata":{"family":"rlwe","name":"Ring Learning With Errors"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"rlwe","summary":"Assumption used by one or more HE construction records: Ring Learning With Errors.","title":"Ring Learning With Errors","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-RING-LEARNING-WITH-ERRORS"},{"evidence":"scheme_declared","id":"HE-ASSUMPTION-STANDARD-LATTICE-PROBLEMS-VIA-LWE-RLWE","keywords":["lwe_rlwe"],"metadata":{"family":"lwe_rlwe","name":"Standard lattice problems via LWE/RLWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lwe_rlwe","summary":"Assumption used by one or more HE construction records: Standard lattice problems via LWE/RLWE.","title":"Standard lattice problems via LWE/RLWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ASSUMPTION-STANDARD-LATTICE-PROBLEMS-VIA-LWE-RLWE"},{"evidence":"literature_consensus","id":"HE-BARRIER-001","keywords":["noise-growth","depth","correctness"],"metadata":{"dossier_type":"barrier","evidence":"literature_consensus","id":"HE-BARRIER-001","keywords":["noise-growth","depth","correctness"],"status":"structural_constraint","targets":["HE-OP-001","HE-OP-003","HE-OP-005"],"title":"Noise growth couples circuit depth to parameters or refresh"},"primaryUrl":null,"sections":[{"content":"Homomorphic multiplication and ciphertext conversion increase error. Without refresh, supported depth must be budgeted into the modulus and dimension; with refresh, the decryption circuit becomes part of the workload.","heading":"Statement and scope"},{"content":"This is not an impossibility of FHE. It explains why every construction pays through larger parameters, restricted depth, approximation, or bootstrapping.","heading":"What it excludes"}],"status":"structural_constraint","subtitle":"","summary":"Homomorphic multiplication and ciphertext conversion increase error. Without refresh, supported depth must be budgeted into the modulus and dimension; with refresh, the decryption circuit becomes part of the workload.","title":"Noise growth couples circuit depth to parameters or refresh","type":"barrier","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-BARRIER-001"},{"evidence":"literature_consensus","id":"HE-BARRIER-002","keywords":["bootstrapping-key","circular-security","memory"],"metadata":{"dossier_type":"barrier","evidence":"literature_consensus","id":"HE-BARRIER-002","keywords":["bootstrapping-key","circular-security","memory"],"status":"assumption_and_resource_constraint","targets":["HE-OP-001","HE-OP-004"],"title":"Bootstrapping evaluation material creates KDM and memory obligations"},"primaryUrl":null,"sections":[{"content":"Refreshing normally requires encrypted secret-key-related material plus large decomposition or transform keys. Security and memory must therefore be analyzed together rather than hiding the evaluation key behind asymptotic notation.","heading":"Statement and scope"},{"content":"Leveled HE can avoid refresh for bounded-depth workloads, but that does not answer the unbounded-FHE assumption question.","heading":"What it excludes"}],"status":"assumption_and_resource_constraint","subtitle":"","summary":"Refreshing normally requires encrypted secret-key-related material plus large decomposition or transform keys. Security and memory must therefore be analyzed together rather than hiding the evaluation key behind asymptotic notation.","title":"Bootstrapping evaluation material creates KDM and memory obligations","type":"barrier","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-BARRIER-002"},{"evidence":"literature_consensus","id":"HE-BARRIER-003","keywords":["ckks","approximation-error","failure-probability"],"metadata":{"dossier_type":"barrier","evidence":"literature_consensus","id":"HE-BARRIER-003","keywords":["ckks","approximation-error","failure-probability"],"status":"semantic_constraint","targets":["HE-OP-002"],"title":"CKKS correctness is a precision distribution, not exact equality"},"primaryUrl":null,"sections":[{"content":"Encryption noise, rescaling error, polynomial approximation, and input magnitude jointly determine CKKS output quality. A decrypted value being close is not meaningful without an explicit error and failure model.","heading":"Statement and scope"},{"content":"It does not make CKKS unsuitable; it requires applications and libraries to treat precision as part of the cryptographic contract.","heading":"What it excludes"}],"status":"semantic_constraint","subtitle":"","summary":"Encryption noise, rescaling error, polynomial approximation, and input magnitude jointly determine CKKS output quality. A decrypted value being close is not meaningful without an explicit error and failure model.","title":"CKKS correctness is a precision distribution, not exact equality","type":"barrier","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-BARRIER-003"},{"evidence":"implementation_consensus","id":"HE-BARRIER-004","keywords":["memory","rotations","key-switching","data-movement"],"metadata":{"dossier_type":"barrier","evidence":"implementation_consensus","id":"HE-BARRIER-004","keywords":["memory","rotations","key-switching","data-movement"],"status":"systems_constraint","targets":["HE-OP-001","HE-OP-002","HE-OP-003","HE-OP-005","HE-OP-006"],"title":"Key switching, rotations, transforms, and memory traffic dominate many workloads"},"primaryUrl":null,"sections":[{"content":"Arithmetic gate counts alone often fail to predict HE performance. Evaluation-key movement, NTTs, rotations, repacking, and cache behavior can dominate latency and energy.","heading":"Statement and scope"},{"content":"Asymptotic scheme comparisons without an implementation and packing model cannot be treated as portable performance rankings.","heading":"What it excludes"}],"status":"systems_constraint","subtitle":"","summary":"Arithmetic gate counts alone often fail to predict HE performance. Evaluation-key movement, NTTs, rotations, repacking, and cache behavior can dominate latency and energy.","title":"Key switching, rotations, transforms, and memory traffic dominate many workloads","type":"barrier","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-BARRIER-004"},{"evidence":"primary_source_checked","id":"HE-BENCH-FHEW-2015","keywords":["benchmark","fhew","latency","reported"],"metadata":{"construction_id":"he_fhew15","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"personal-computer setting reported in the paper","id":"HE-BENCH-FHEW-2015","implementation_id":"HE-IMPL-FHEW-2015","keywords":["benchmark","fhew","latency","reported"],"maps_to":["HE-OP-001","HE-OP-005","HE-OP-006"],"metrics":{"evaluation_key_bytes":"large bootstrapping key; exact extraction pending","failure_probability":"paper-specific; not normalized","latency":"roughly half a second per refreshed binary gate","peak_memory":"not normalized","precision_bits":"not applicable","throughput":"not normalized"},"paper_id":"HE-PAPER-2015-FHEW","parameter_set_id":"HE-PARAM-FHEW-2015","source_locator":"abstract and implementation results","status":"reported","title":"FHEW subsecond single-gate bootstrap","workload_id":"HE-WORKLOAD-GATE-BOOTSTRAP","year":2015},"primaryUrl":null,"sections":[{"content":"The claim marks a major historical latency change. It is not presented as a modern cross-library score until security, hardware, key memory, and failure settings are normalized.","heading":"Interpretation"}],"status":"reported","subtitle":"2015","summary":"The claim marks a major historical latency change. It is not presented as a modern cross-library score until security, hardware, key memory, and failure settings are normalized.","title":"FHEW subsecond single-gate bootstrap","type":"benchmark_run","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-BENCH-FHEW-2015"},{"evidence":"primary_source_checked","id":"HE-BENCH-GHS-AES-2012","keywords":["benchmark","aes","bgv","reported"],"metadata":{"comparable":false,"construction_id":"he_bgv12","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"Lenovo X230, Intel Core i5-3320M at 2.6 GHz, Ubuntu 14.04 VM, 4 GB RAM, g++ 4.9.2","id":"HE-BENCH-GHS-AES-2012","implementation_id":"HE-IMPL-GHS-AES-2012","keywords":["benchmark","aes","bgv","reported"],"maps_to":["HE-OP-001","HE-OP-006"],"metrics":{"evaluation_key_bytes":"not normalized","failure_probability":"exact-arithmetic correctness under HE-PARAM-GHS-AES-2012; failure bound not separately normalized","latency":"252 seconds for one packed AES encryption over 120 blocks","peak_memory":"not normalized","precision_bits":"not applicable","throughput":"2 seconds per AES block as reported"},"paper_id":"HE-PAPER-2012-GHS-AES","parameter_set_id":"HE-PARAM-GHS-AES-2012","source_locator":"Section 4.4, non-bootstrapping implementation; Table 1","status":"reported","title":"GHS non-bootstrapped packed AES evaluation","workload_id":"HE-WORKLOAD-AES-2012","year":2015},"primaryUrl":null,"sections":[{"content":"January 2015 end-to-end workload result for one explicit non-bootstrapped parameter regime. It is not backdated to the 2012 paper or ranked against later libraries because the security analysis, VM, packing, and software revision are not normalized.","heading":"Interpretation"}],"status":"reported","subtitle":"2015","summary":"January 2015 end-to-end workload result for one explicit non-bootstrapped parameter regime. It is not backdated to the 2012 paper or ranked against later libraries because the security analysis, VM, packing, and software revision are not normalized.","title":"GHS non-bootstrapped packed AES evaluation","type":"benchmark_run","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-BENCH-GHS-AES-2012"},{"evidence":"primary_source_checked","id":"HE-BENCH-GHS-AES-BOOT-2012","keywords":["benchmark","aes","bgv","bootstrapping","reported"],"metadata":{"comparable":false,"construction_id":"he_bgv12","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"Lenovo X230, Intel Core i5-3320M at 2.6 GHz, Ubuntu 14.04 VM, 4 GB RAM, g++ 4.9.2","id":"HE-BENCH-GHS-AES-BOOT-2012","implementation_id":"HE-IMPL-GHS-AES-2012","keywords":["benchmark","aes","bgv","bootstrapping","reported"],"maps_to":["HE-OP-001","HE-OP-006"],"metrics":{"evaluation_key_bytes":"not normalized","failure_probability":"exact-arithmetic correctness under HE-PARAM-GHS-AES-BOOT-2012; failure bound not separately normalized","latency":"1050 seconds for one packed AES encryption over 180 blocks, including 823 seconds in two recryptions","peak_memory":"3.7 GB","precision_bits":"not applicable","throughput":"5.8 seconds per AES block as reported"},"paper_id":"HE-PAPER-2012-GHS-AES","parameter_set_id":"HE-PARAM-GHS-AES-BOOT-2012","source_locator":"Section 4.4, implementation using bootstrapping; Table 1","status":"reported","title":"GHS bootstrapped packed AES evaluation","workload_id":"HE-WORKLOAD-AES-2012","year":2015},"primaryUrl":null,"sections":[{"content":"This is a separate January 2015 bootstrapped run, not an alternative metric on the non-bootstrapped record and not a 2012 measurement. Its recryption share and memory explain the system bottleneck; the row is not eligible for cross-library ranking.","heading":"Interpretation"}],"status":"reported","subtitle":"2015","summary":"This is a separate January 2015 bootstrapped run, not an alternative metric on the non-bootstrapped record and not a 2012 measurement. Its recryption share and memory explain the system bottleneck; the row is not eligible for cross-library ranking.","title":"GHS bootstrapped packed AES evaluation","type":"benchmark_run","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-BENCH-GHS-AES-BOOT-2012"},{"evidence":"primary_source_checked","id":"HE-BENCH-TFHE-2016","keywords":["benchmark","tfhe","latency","reported"],"metadata":{"construction_id":"he_tfhe16","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"paper-reported CPU setting","id":"HE-BENCH-TFHE-2016","implementation_id":"HE-IMPL-TFHE-2016","keywords":["benchmark","tfhe","latency","reported"],"maps_to":["HE-OP-001","HE-OP-005","HE-OP-006"],"metrics":{"evaluation_key_bytes":"reduced relative to the cited FHEW setting; exact extraction pending","failure_probability":"paper-specific; not normalized","latency":"less than 0.1 seconds per reported refresh setting","peak_memory":"not normalized","precision_bits":"not applicable","throughput":"not normalized"},"paper_id":"HE-PAPER-2016-TFHE","parameter_set_id":"HE-PARAM-TFHE-2016","source_locator":"abstract and performance section","status":"reported","title":"TFHE sub-tenth-second gate bootstrap","workload_id":"HE-WORKLOAD-GATE-BOOTSTRAP","year":2016},"primaryUrl":null,"sections":[{"content":"Reported historical gate-refresh latency. The database preserves “reported” rather than silently treating it as reproduced or hardware-normalized.","heading":"Interpretation"}],"status":"reported","subtitle":"2016","summary":"Reported historical gate-refresh latency. The database preserves “reported” rather than silently treating it as reproduced or hardware-normalized.","title":"TFHE sub-tenth-second gate bootstrap","type":"benchmark_run","venue":null,"year":2016,"sourcePath":"data/he-catalog.json#HE-BENCH-TFHE-2016"},{"evidence":"primary_source_checked","id":"HE-BENCH-CKKS-BOOT-2018","keywords":["benchmark","ckks","bootstrapping","reported"],"metadata":{"construction_id":"he_ckks_boot18","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"paper-reported platform; structured extraction pending","id":"HE-BENCH-CKKS-BOOT-2018","implementation_id":"HE-IMPL-CKKS-BOOT-2018","keywords":["benchmark","ckks","bootstrapping","reported"],"maps_to":["HE-OP-002","HE-OP-006"],"metrics":{"evaluation_key_bytes":"not normalized","failure_probability":"not normalized","latency":"reported packed refresh; exact table extraction pending","peak_memory":"not normalized","precision_bits":"limited returned precision in the initial construction; exact record pending","throughput":"packed slots; not normalized"},"paper_id":"HE-PAPER-2018-CKKS-BOOT","parameter_set_id":"HE-PARAM-CKKS-BOOT-2018","source_locator":"evaluation section; exact benchmark row pending","status":"reported","title":"First packed CKKS refresh demonstration","workload_id":"HE-WORKLOAD-CKKS-REFRESH","year":2018},"primaryUrl":null,"sections":[{"content":"Proof-of-feasibility measurement for packed approximate refresh. Precision, slots, latency, and failure are one inseparable benchmark profile.","heading":"Interpretation"}],"status":"reported","subtitle":"2018","summary":"Proof-of-feasibility measurement for packed approximate refresh. Precision, slots, latency, and failure are one inseparable benchmark profile.","title":"First packed CKKS refresh demonstration","type":"benchmark_run","venue":null,"year":2018,"sourcePath":"data/he-catalog.json#HE-BENCH-CKKS-BOOT-2018"},{"evidence":"primary_source_checked","id":"HE-BENCH-HP-CKKS-2020","keywords":["benchmark","ckks","precision","reported"],"metadata":{"construction_id":"he_ckks_boot18","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"paper-reported platform; structured extraction pending","id":"HE-BENCH-HP-CKKS-2020","implementation_id":"HE-IMPL-CKKS-BOOT-2018","keywords":["benchmark","ckks","precision","reported"],"maps_to":["HE-OP-002","HE-OP-006"],"metrics":{"evaluation_key_bytes":"not normalized","failure_probability":"approximation setting reported; not normalized","latency":"reported; exact parameter-matched row pending","peak_memory":"not normalized","precision_bits":"high-precision target; exact parameter-matched value pending","throughput":"packed slots; not normalized"},"paper_id":"HE-PAPER-2020-HP-CKKS","parameter_set_id":"HE-PARAM-HP-CKKS-2020","source_locator":"implementation and evaluation sections; exact row pending","status":"reported","title":"High-precision CKKS bootstrap evaluation","workload_id":"HE-WORKLOAD-CKKS-REFRESH","year":2020},"primaryUrl":null,"sections":[{"content":"Measurement associated with an improved modular-reduction approximation. No latency-only ranking is permitted without the matching returned precision and parameter record.","heading":"Interpretation"}],"status":"reported","subtitle":"2020","summary":"Measurement associated with an improved modular-reduction approximation. No latency-only ranking is permitted without the matching returned precision and parameter record.","title":"High-precision CKKS bootstrap evaluation","type":"benchmark_run","venue":null,"year":2020,"sourcePath":"data/he-catalog.json#HE-BENCH-HP-CKKS-2020"},{"evidence":"primary_source_checked","id":"HE-BENCH-TFHE-PROCESSOR-2024","keywords":["benchmark","tfhe","processor","reported"],"metadata":{"comparable":false,"construction_id":"he_tfhe16","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"12th Gen Intel Core i7-12700H laptop, 64 GiB RAM, Ubuntu 22.04.2 LTS, single core","id":"HE-BENCH-TFHE-PROCESSOR-2024","implementation_id":"HE-IMPL-TFHE-PROCESSOR-2024","keywords":["benchmark","tfhe","processor","reported"],"maps_to":["HE-OP-005","HE-OP-006"],"metrics":{"evaluation_key_bytes":"not normalized","failure_probability":"bound to HE-PARAM-TFHE-PROCESSOR-2024; paper-specific coordinates are not collapsed","latency":"Table 4 reports 493 ms ADD, 725 ms MUL, and 7.711 s DIV; Table 6 reports 5.66 s SquaresSum on five inputs and 15.42 s for the sigmoid-neuron workload","peak_memory":"not normalized","precision_bits":"not applicable","throughput":"program and instruction observations only; no common cross-system throughput unit"},"paper_id":"HE-PAPER-2024-TFHE-PROCESSOR","parameter_set_id":"HE-PARAM-TFHE-PROCESSOR-2024","source_locator":"Sections 7–9, Tables 4, 6, 8, and 9","status":"reported","title":"Encrypted 8-bit TFHE processor evaluation","workload_id":"HE-WORKLOAD-TFHE-8BIT","year":2024},"primaryUrl":null,"sections":[{"content":"System-level measurement for encrypted word operations. It belongs in a separate workload class from a single gate bootstrap or packed CKKS arithmetic.","heading":"Interpretation"}],"status":"reported","subtitle":"2024","summary":"System-level measurement for encrypted word operations. It belongs in a separate workload class from a single gate bootstrap or packed CKKS arithmetic.","title":"Encrypted 8-bit TFHE processor evaluation","type":"benchmark_run","venue":null,"year":2024,"sourcePath":"data/he-catalog.json#HE-BENCH-TFHE-PROCESSOR-2024"},{"evidence":"bibliographic_reviewed","id":"he_paillier99","keywords":["phe","additive_phe","additive-homomorphism","exact"],"metadata":{"assumption":{"family":"composite_residuosity","name":"Decisional Composite Residuosity"},"bootstrapping":"not applicable","capabilities":["additive-homomorphism","exact"],"circuit_class":"additive circuits only","construction_family":"additive_phe","decrypt_cost":{"primary":"modular exponentiation"},"dossier_type":"construction","exactness":"exact modular arithmetic","id":"he_paillier99","name":"Paillier additive homomorphic encryption","noise_management":"no lattice noise budget","packing":"none in the base construction","plaintext_space":"integers modulo n","primitive":"PHE","security":{"mode":"public-key","model":"standard","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"two residues modulo n-squared"}},"supported_gates":"unbounded additions; plaintext-scalar multiplication","verification":{"status":"bibliographic_reviewed"},"work_id":"HE-PAPER-1999-PAILLIER","year":1999},"primaryUrl":"https://link.springer.com/chapter/10.1007/3-540-48910-X_16","sections":[{"content":"Reference PHE row used to distinguish one-operation homomorphism from SHE, LHE, and FHE.","heading":"Construction note"}],"status":"bibliographic_reviewed","subtitle":"PHE · 1999","summary":"Reference PHE row used to distinguish one-operation homomorphism from SHE, LHE, and FHE.","title":"Paillier additive homomorphic encryption","type":"construction","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/he-catalog.json#he_paillier99"},{"evidence":"primary_source_reviewed","id":"he_gentry09","keywords":["fhe","ideal_lattice","first-fhe","bootstrapping"],"metadata":{"assumption":{"family":"ideal_lattice","name":"Ideal-lattice hardness plus squashing-related assumptions"},"bootstrapping":"homomorphic evaluation of augmented decryption","capabilities":["first-fhe","bootstrapping"],"circuit_class":"unbounded circuits after bootstrap","construction_family":"ideal_lattice","decrypt_cost":{"primary":"squashed decryption circuit"},"dossier_type":"construction","exactness":"exact","id":"he_gentry09","name":"Gentry ideal-lattice FHE","noise_management":"somewhat-HE noise budget plus squashing","packing":"later variants only","plaintext_space":"bits and ring elements","primitive":"FHE","security":{"mode":"public-key","model":"standard","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"polynomial; historically impractical"}},"supported_gates":"addition and multiplication; arbitrary circuits after bootstrap","verification":{"status":"primary_source_reviewed"},"work_id":"HE-PAPER-2009-GENTRY","year":2009},"primaryUrl":"https://crypto.stanford.edu/craig/craig-thesis.pdf","sections":[{"content":"Blueprint record rather than a recommended modern implementation.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"FHE · 2009","summary":"Blueprint record rather than a recommended modern implementation.","title":"Gentry ideal-lattice FHE","type":"construction","venue":"STOC 2009","year":2009,"sourcePath":"data/he-catalog.json#he_gentry09"},{"evidence":"abstract_reviewed","id":"he_dghv10","keywords":["fhe","integer_agcd","integer-fhe","bootstrapping"],"metadata":{"assumption":{"family":"agcd","name":"Approximate GCD with auxiliary assumptions in the original full scheme"},"bootstrapping":"Gentry-style squashed decryption","capabilities":["integer-fhe","bootstrapping"],"circuit_class":"unbounded Boolean circuits after bootstrap","construction_family":"integer_agcd","decrypt_cost":{"primary":"reduction modulo secret integer"},"dossier_type":"construction","exactness":"exact bits","id":"he_dghv10","name":"DGHV integer FHE","noise_management":"approximate multiples; noise grows under multiplication","packing":"none in the base scheme","plaintext_space":"bits","primitive":"FHE","security":{"mode":"public-key","model":"standard","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"very large integers"}},"supported_gates":"XOR and AND through integer addition and multiplication","verification":{"status":"abstract_reviewed"},"work_id":"HE-PAPER-2010-DGHV","year":2010},"primaryUrl":"https://eprint.iacr.org/2009/616","sections":[{"content":"Conceptually simple first-generation branch; retained for lineage rather than Pareto efficiency.","heading":"Construction note"}],"status":"abstract_reviewed","subtitle":"FHE · 2010","summary":"Conceptually simple first-generation branch; retained for lineage rather than Pareto efficiency.","title":"DGHV integer FHE","type":"construction","venue":"EUROCRYPT 2010","year":2010,"sourcePath":"data/he-catalog.json#he_dghv10"},{"evidence":"abstract_reviewed","id":"he_bv11","keywords":["fhe","lwe_relinearization","relinearization","key-switching","standard-lwe"],"metadata":{"assumption":{"family":"lwe","name":"Learning With Errors"},"bootstrapping":"required for unbounded depth","capabilities":["relinearization","key-switching","standard-lwe"],"circuit_class":"bounded depth before refresh; unbounded after refresh","construction_family":"lwe_relinearization","decrypt_cost":{"primary":"LWE inner product"},"dossier_type":"construction","exactness":"exact modular arithmetic","id":"he_bv11","name":"Brakerski–Vaikuntanathan LWE FHE","noise_management":"relinearization and dimension-modulus reduction","packing":"not the core contribution","plaintext_space":"bits or small modular plaintexts","primitive":"FHE","security":{"mode":"public-key","model":"standard_with_refresh_assumption","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"short LWE ciphertext after relinearization"}},"supported_gates":"addition and multiplication","verification":{"status":"abstract_reviewed"},"work_id":"HE-PAPER-2011-BV","year":2011},"primaryUrl":"https://eprint.iacr.org/2011/344","sections":[{"content":"Key ancestor for BGV/BFV-style ciphertext dimension control.","heading":"Construction note"}],"status":"abstract_reviewed","subtitle":"FHE · 2011","summary":"Key ancestor for BGV/BFV-style ciphertext dimension control.","title":"Brakerski–Vaikuntanathan LWE FHE","type":"construction","venue":"FOCS 2011","year":2011,"sourcePath":"data/he-catalog.json#he_bv11"},{"evidence":"abstract_reviewed","id":"he_bfv12","keywords":["lhe","bfv","packing","relinearization","exact","rns-friendly"],"metadata":{"assumption":{"family":"rlwe","name":"Ring Learning With Errors"},"bootstrapping":"optional and not part of the basic leveled record","capabilities":["packing","relinearization","exact","rns-friendly"],"circuit_class":"predetermined-depth arithmetic circuits","construction_family":"bfv","decrypt_cost":{"primary":"ring product and scaled rounding"},"dossier_type":"construction","exactness":"exact modular arithmetic","id":"he_bfv12","name":"Fan–Vercauteren / BFV exact HE","noise_management":"relinearization and modulus management; RNS in modern variants","packing":"SIMD when the plaintext ring splits","plaintext_space":"exact integers modulo t","primitive":"LHE","security":{"mode":"public-key","model":"standard_leveled","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"two ring elements after relinearization"}},"supported_gates":"packed modular addition and multiplication","verification":{"status":"abstract_reviewed"},"work_id":"HE-PAPER-2012-FV","year":2012},"primaryUrl":"https://eprint.iacr.org/2012/144","sections":[{"content":"Standard exact-arithmetic counterpart to CKKS in many libraries.","heading":"Construction note"}],"status":"abstract_reviewed","subtitle":"LHE · 2012","summary":"Standard exact-arithmetic counterpart to CKKS in many libraries.","title":"Fan–Vercauteren / BFV exact HE","type":"construction","venue":"IACR ePrint 2012/144","year":2012,"sourcePath":"data/he-catalog.json#he_bfv12"},{"evidence":"abstract_reviewed","id":"he_bgv12","keywords":["lhe","bgv","packing","modulus-switching","key-switching","exact"],"metadata":{"assumption":{"family":"lwe_rlwe","name":"LWE or Ring-LWE"},"bootstrapping":"optional for unbounded FHE","capabilities":["packing","modulus-switching","key-switching","exact"],"circuit_class":"predetermined-depth arithmetic circuits","construction_family":"bgv","decrypt_cost":{"primary":"ring inner product and rounding"},"dossier_type":"construction","exactness":"exact modular arithmetic","id":"he_bgv12","name":"BGV leveled homomorphic encryption","noise_management":"modulus switching chain plus key switching","packing":"SIMD via CRT plaintext slots","plaintext_space":"exact modular integers and packed slots","primitive":"LHE","security":{"mode":"public-key","model":"standard_leveled","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"small constant number of ring elements"}},"supported_gates":"additions and multiplications to a parameterized depth","verification":{"status":"abstract_reviewed"},"work_id":"HE-PAPER-2012-BGV","year":2012},"primaryUrl":"https://eprint.iacr.org/2011/277","sections":[{"content":"Main exact packed leveled-HE reference family.","heading":"Construction note"}],"status":"abstract_reviewed","subtitle":"LHE · 2012","summary":"Main exact packed leveled-HE reference family.","title":"BGV leveled homomorphic encryption","type":"construction","venue":"ITCS 2012","year":2012,"sourcePath":"data/he-catalog.json#he_bgv12"},{"evidence":"abstract_reviewed","id":"he_scaleinv12","keywords":["lhe","scale_invariant_lwe","single-modulus","tensoring","exact"],"metadata":{"assumption":{"family":"lwe","name":"Classical GapSVP via LWE"},"bootstrapping":"available for unbounded depth","capabilities":["single-modulus","tensoring","exact"],"circuit_class":"predetermined-depth arithmetic circuits","construction_family":"scale_invariant_lwe","decrypt_cost":{"primary":"LWE decryption"},"dossier_type":"construction","exactness":"exact modular arithmetic","id":"he_scaleinv12","name":"Brakerski scale-invariant FHE","noise_management":"tensoring with linear multiplicative noise growth","packing":"not the primary contribution","plaintext_space":"exact modular plaintexts","primitive":"LHE","security":{"mode":"public-key","model":"standard_leveled","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"LWE ciphertext"}},"supported_gates":"addition and multiplication","verification":{"status":"abstract_reviewed"},"work_id":"HE-PAPER-2012-BRAKERSKI","year":2012},"primaryUrl":"https://eprint.iacr.org/2012/078","sections":[{"content":"Alternative noise invariant showing that modulus switching is not conceptually necessary.","heading":"Construction note"}],"status":"abstract_reviewed","subtitle":"LHE · 2012","summary":"Alternative noise invariant showing that modulus switching is not conceptually necessary.","title":"Brakerski scale-invariant FHE","type":"construction","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/he-catalog.json#he_scaleinv12"},{"evidence":"abstract_reviewed","id":"he_gsw13","keywords":["fhe","gsw","approximate-eigenvector","external-product-ancestor"],"metadata":{"assumption":{"family":"lwe","name":"Learning With Errors"},"bootstrapping":"supported through homomorphic decryption","capabilities":["approximate-eigenvector","external-product-ancestor"],"circuit_class":"general circuits after refresh","construction_family":"gsw","decrypt_cost":{"primary":"approximate eigenvector test"},"dossier_type":"construction","exactness":"exact modular plaintext","id":"he_gsw13","name":"GSW approximate-eigenvector FHE","noise_management":"gadget decomposition and asymmetric noise growth","packing":"ring variants and descendants","plaintext_space":"bits or small modular plaintexts","primitive":"FHE","security":{"mode":"public-key","model":"standard_with_refresh_assumption","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"matrix ciphertext"}},"supported_gates":"direct addition and multiplication of GSW ciphertexts","verification":{"status":"abstract_reviewed"},"work_id":"HE-PAPER-2013-GSW","year":2013},"primaryUrl":"https://eprint.iacr.org/2013/340","sections":[{"content":"Conceptual ancestor of RingGSW, FHEW, and TFHE external products.","heading":"Construction note"}],"status":"abstract_reviewed","subtitle":"FHE · 2013","summary":"Conceptual ancestor of RingGSW, FHEW, and TFHE external products.","title":"GSW approximate-eigenvector FHE","type":"construction","venue":"CRYPTO 2013","year":2013,"sourcePath":"data/he-catalog.json#he_gsw13"},{"evidence":"primary_source_reviewed","id":"he_fhew15","keywords":["fhe","fhew_tfhe","gate-bootstrapping","boolean"],"metadata":{"assumption":{"family":"lwe_rlwe","name":"Standard lattice problems via LWE/RLWE"},"bootstrapping":"subsecond LWE/RLWE gate bootstrap in the paper","capabilities":["gate-bootstrapping","boolean"],"circuit_class":"unbounded Boolean circuits","construction_family":"fhew_tfhe","decrypt_cost":{"primary":"LWE phase and rounding"},"dossier_type":"construction","exactness":"exact bits with quantified decryption failure","id":"he_fhew15","name":"FHEW gate-bootstrapped FHE","noise_management":"bootstrap after a gate","packing":"limited in the base design","plaintext_space":"bits","primitive":"FHE","security":{"mode":"public-key","model":"standard_with_evaluation_keys","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"LWE ciphertext"},"MPK":{"asymptotic":"large bootstrapping key"}},"supported_gates":"refreshed Boolean gates","verification":{"status":"primary_source_reviewed"},"work_id":"HE-PAPER-2015-FHEW","year":2015},"primaryUrl":"https://eprint.iacr.org/2014/816","sections":[{"content":"First widely cited subsecond gate-refresh point.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"FHE · 2015","summary":"First widely cited subsecond gate-refresh point.","title":"FHEW gate-bootstrapped FHE","type":"construction","venue":"EUROCRYPT 2015","year":2015,"sourcePath":"data/he-catalog.json#he_fhew15"},{"evidence":"primary_source_reviewed","id":"he_tfhe16","keywords":["fhe","fhew_tfhe","gate-bootstrapping","external-product","boolean"],"metadata":{"assumption":{"family":"lwe_rlwe","name":"Learning With Errors and ring variants"},"bootstrapping":"external-product gate bootstrap below 0.1 seconds in the paper","capabilities":["gate-bootstrapping","external-product","boolean"],"circuit_class":"unbounded Boolean circuits","construction_family":"fhew_tfhe","decrypt_cost":{"primary":"torus LWE phase decoding"},"dossier_type":"construction","exactness":"exact discrete messages with failure probability","id":"he_tfhe16","name":"TFHE fast gate bootstrapping","noise_management":"bootstrapping resets noise after nonlinear gates","packing":"limited in base gate mode","plaintext_space":"bits and small torus messages","primitive":"FHE","security":{"mode":"secret_or_public_key","model":"standard_with_evaluation_keys","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"compact LWE ciphertext"},"MPK":{"asymptotic":"bootstrapping and switching keys"}},"supported_gates":"Boolean gates and functions through blind rotation descendants","verification":{"status":"primary_source_reviewed"},"work_id":"HE-PAPER-2016-TFHE","year":2016},"primaryUrl":"https://eprint.iacr.org/2016/870","sections":[{"content":"Base TFHE record; circuit and programmable bootstrapping are tracked as later results.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"FHE · 2016","summary":"Base TFHE record; circuit and programmable bootstrapping are tracked as later results.","title":"TFHE fast gate bootstrapping","type":"construction","venue":"ASIACRYPT 2016","year":2016,"sourcePath":"data/he-catalog.json#he_tfhe16"},{"evidence":"primary_source_reviewed","id":"he_ckks17","keywords":["lhe","ckks","packing","approximate","rescaling","numerical"],"metadata":{"assumption":{"family":"rlwe","name":"Ring Learning With Errors"},"bootstrapping":"not in the base construction","capabilities":["packing","approximate","rescaling","numerical"],"circuit_class":"predetermined-depth numerical circuits","construction_family":"ckks","decrypt_cost":{"primary":"ring decryption and approximate decoding"},"dossier_type":"construction","exactness":"approximate with an explicit precision budget","id":"he_ckks17","name":"CKKS approximate leveled HE","noise_management":"rescaling and modulus chain","packing":"native SIMD complex slots","plaintext_space":"packed approximate real or complex numbers","primitive":"LHE","security":{"mode":"public-key","model":"standard_leveled","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"two ring elements after relinearization"}},"supported_gates":"approximate addition and multiplication with rescaling","verification":{"status":"primary_source_reviewed"},"work_id":"HE-PAPER-2017-CKKS","year":2017},"primaryUrl":"https://eprint.iacr.org/2016/421","sections":[{"content":"Base numerical HE record; returned precision is part of correctness.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"LHE · 2017","summary":"Base numerical HE record; returned precision is part of correctness.","title":"CKKS approximate leveled HE","type":"construction","venue":"ASIACRYPT 2017","year":2017,"sourcePath":"data/he-catalog.json#he_ckks17"},{"evidence":"primary_source_reviewed","id":"he_ckks_boot18","keywords":["fhe","ckks","packing","approximate","bootstrapping","numerical"],"metadata":{"assumption":{"family":"rlwe","name":"Ring Learning With Errors"},"bootstrapping":"homomorphic transforms and scaled-sine modular reduction","capabilities":["packing","approximate","bootstrapping","numerical"],"circuit_class":"unbounded numerical circuits with periodic bootstrap","construction_family":"ckks","decrypt_cost":{"primary":"approximate CKKS decoding"},"dossier_type":"construction","exactness":"approximate; refresh returns bounded precision","id":"he_ckks_boot18","name":"Bootstrapped CKKS","noise_management":"rescaling plus approximate modular-reduction refresh","packing":"native SIMD complex slots","plaintext_space":"packed approximate real or complex numbers","primitive":"FHE","security":{"mode":"public-key","model":"standard_with_evaluation_keys","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"packed ring ciphertext"},"MPK":{"asymptotic":"rotation and bootstrap keys"}},"supported_gates":"unbounded approximate arithmetic through refresh","verification":{"status":"primary_source_reviewed"},"work_id":"HE-PAPER-2018-CKKS-BOOT","year":2018},"primaryUrl":"https://eprint.iacr.org/2018/153","sections":[{"content":"First CKKS FHE refresh record; later high-precision and RNS works refine its cost and output quality.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"FHE · 2018","summary":"First CKKS FHE refresh record; later high-precision and RNS works refine its cost and output quality.","title":"Bootstrapped CKKS","type":"construction","venue":"EUROCRYPT 2018","year":2018,"sourcePath":"data/he-catalog.json#he_ckks_boot18"},{"evidence":"primary_source_reviewed","id":"he_rns_ckks18","keywords":["lhe","ckks","packing","approximate","rns","ntt","numerical"],"metadata":{"assumption":{"family":"rlwe","name":"Ring Learning With Errors"},"bootstrapping":"compatible with later RNS bootstrap implementations","capabilities":["packing","approximate","rns","ntt","numerical"],"circuit_class":"predetermined-depth numerical circuits","construction_family":"ckks","decrypt_cost":{"primary":"RNS ring decryption and approximate decoding"},"dossier_type":"construction","exactness":"approximate with an explicit precision budget","id":"he_rns_ckks18","name":"Full-RNS CKKS","noise_management":"RNS rescaling and approximate modulus switching","packing":"native SIMD complex slots","plaintext_space":"packed approximate real or complex numbers","primitive":"LHE","security":{"mode":"public-key","model":"standard_leveled","notion":"IND-CPA"},"sizes":{"CT":{"asymptotic":"two RNS ring elements after relinearization"}},"supported_gates":"approximate addition and multiplication using word-size RNS kernels","verification":{"status":"primary_source_reviewed"},"work_id":"HE-PAPER-2018-RNS-CKKS","year":2018},"primaryUrl":"https://eprint.iacr.org/2018/931","sections":[{"content":"Implementation-oriented CKKS record separating the RNS representation advance from the first CKKS semantics.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"LHE · 2018","summary":"Implementation-oriented CKKS record separating the RNS representation advance from the first CKKS semantics.","title":"Full-RNS CKKS","type":"construction","venue":"SAC 2018","year":2018,"sourcePath":"data/he-catalog.json#he_rns_ckks18"},{"evidence":"primary_source_checked","id":"HE-IMPL-FHEW-2015","keywords":["implementation","fhew","bootstrapping"],"metadata":{"artifact_type":"research prototype","availability":"paper artifact lineage","backend":"LWE and ring-GSW gate bootstrapping","construction_ids":["he_fhew15"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-IMPL-FHEW-2015","keywords":["implementation","fhew","bootstrapping"],"language":"C++ prototype","maps_to":["HE-OP-001","HE-OP-005","HE-OP-006"],"paper_id":"HE-PAPER-2015-FHEW","status":"reported","title":"FHEW gate-bootstrapping prototype","year":2015},"primaryUrl":null,"sections":[{"content":"Prototype used to demonstrate subsecond refresh of a binary gate. It is recorded separately from the FHEW construction so later implementations can reproduce or replace the artifact without changing the construction record.","heading":"Scope"}],"status":"reported","subtitle":"2015","summary":"Prototype used to demonstrate subsecond refresh of a binary gate. It is recorded separately from the FHEW construction so later implementations can reproduce or replace the artifact without changing the construction record.","title":"FHEW gate-bootstrapping prototype","type":"implementation","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-IMPL-FHEW-2015"},{"evidence":"primary_source_checked","id":"HE-IMPL-GHS-AES-2012","keywords":["implementation","bgv","aes","simd"],"metadata":{"artifact_type":"research prototype","availability":"public HElib lineage; exact historical revision not pinned","backend":"packed exact RLWE arithmetic","construction_ids":["he_bgv12"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"section_checked","id":"HE-IMPL-GHS-AES-2012","keywords":["implementation","bgv","aes","simd"],"language":"C++ over NTL and GMP","maps_to":["HE-OP-001","HE-OP-006"],"paper_id":"HE-PAPER-2012-GHS-AES","status":"reported","title":"Updated HElib packed-BGV implementation for homomorphic AES","year":2015},"primaryUrl":null,"sections":[{"content":"January 2015 updated implementation of packed leveled evaluation for the AES circuit, combining CRT representation, SIMD slots, key switching, and circuit-specific planning.","heading":"Scope"},{"content":"The updated report identifies HElib and its C++/NTL/GMP stack, but this record does not yet pin the exact historical revision or reproduce the Ubuntu 14.04 build. Its 2015 measurements are not attributed to the 2012 conference version, and the two parameter regimes remain separate benchmark records.","heading":"Evidence boundary"}],"status":"reported","subtitle":"2015","summary":"January 2015 updated implementation of packed leveled evaluation for the AES circuit, combining CRT representation, SIMD slots, key switching, and circuit-specific planning.","title":"Updated HElib packed-BGV implementation for homomorphic AES","type":"implementation","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-IMPL-GHS-AES-2012"},{"evidence":"primary_source_checked","id":"HE-IMPL-TFHE-2016","keywords":["implementation","tfhe","external-product","bootstrapping"],"metadata":{"artifact_type":"research prototype","availability":"paper artifact lineage","backend":"LWE–RingGSW external products","construction_ids":["he_tfhe16"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-IMPL-TFHE-2016","keywords":["implementation","tfhe","external-product","bootstrapping"],"language":"C++ prototype","maps_to":["HE-OP-001","HE-OP-005","HE-OP-006"],"paper_id":"HE-PAPER-2016-TFHE","status":"reported","title":"TFHE fast gate-bootstrapping prototype","year":2016},"primaryUrl":null,"sections":[{"content":"Prototype implementation associated with the reported sub-tenth-second TFHE refresh result. The record distinguishes executable engineering choices from the underlying TFHE construction.","heading":"Scope"}],"status":"reported","subtitle":"2016","summary":"Prototype implementation associated with the reported sub-tenth-second TFHE refresh result. The record distinguishes executable engineering choices from the underlying TFHE construction.","title":"TFHE fast gate-bootstrapping prototype","type":"implementation","venue":null,"year":2016,"sourcePath":"data/he-catalog.json#HE-IMPL-TFHE-2016"},{"evidence":"primary_source_checked","id":"HE-IMPL-CKKS-BOOT-2018","keywords":["implementation","ckks","bootstrapping","approximate"],"metadata":{"artifact_type":"research prototype","availability":"paper-described prototype","backend":"packed RLWE approximate arithmetic","construction_ids":["he_ckks_boot18"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-IMPL-CKKS-BOOT-2018","keywords":["implementation","ckks","bootstrapping","approximate"],"language":"not normalized","maps_to":["HE-OP-002","HE-OP-006"],"paper_id":"HE-PAPER-2018-CKKS-BOOT","status":"reported","title":"First packed CKKS bootstrapping prototype","year":2018},"primaryUrl":null,"sections":[{"content":"Prototype demonstrating refresh in CKKS's native packed approximate representation. Exact artifact and build details remain to be audited from the local PDF and associated code record.","heading":"Scope"}],"status":"reported","subtitle":"2018","summary":"Prototype demonstrating refresh in CKKS's native packed approximate representation. Exact artifact and build details remain to be audited from the local PDF and associated code record.","title":"First packed CKKS bootstrapping prototype","type":"implementation","venue":null,"year":2018,"sourcePath":"data/he-catalog.json#HE-IMPL-CKKS-BOOT-2018"},{"evidence":"primary_source_checked","id":"HE-IMPL-RNS-CKKS-2018","keywords":["implementation","ckks","rns","ntt"],"metadata":{"artifact_type":"research implementation pattern","availability":"paper-described implementation","backend":"RNS and NTT word-size kernels","construction_ids":["he_rns_ckks18","he_ckks17"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-IMPL-RNS-CKKS-2018","keywords":["implementation","ckks","rns","ntt"],"language":"not normalized","maps_to":["HE-OP-002","HE-OP-006"],"paper_id":"HE-PAPER-2018-RNS-CKKS","status":"reported","title":"Full-RNS CKKS word-arithmetic implementation","year":2018},"primaryUrl":null,"sections":[{"content":"Implementation pattern replacing multiprecision core arithmetic with full-RNS, word-size operations. It records the practical realization separately from the CKKS construction and the RNS optimization result.","heading":"Scope"}],"status":"reported","subtitle":"2018","summary":"Implementation pattern replacing multiprecision core arithmetic with full-RNS, word-size operations. It records the practical realization separately from the CKKS construction and the RNS optimization result.","title":"Full-RNS CKKS word-arithmetic implementation","type":"implementation","venue":null,"year":2018,"sourcePath":"data/he-catalog.json#HE-IMPL-RNS-CKKS-2018"},{"evidence":"primary_source_checked","id":"HE-IMPL-TFHE-PROCESSOR-2024","keywords":["implementation","tfhe","processor","word-arithmetic"],"metadata":{"artifact_type":"processor abstraction prototype","availability":"paper-described prototype","backend":"programmable bootstrapping and lookup tables","construction_ids":["he_tfhe16"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-IMPL-TFHE-PROCESSOR-2024","keywords":["implementation","tfhe","processor","word-arithmetic"],"language":"not normalized","maps_to":["HE-OP-005","HE-OP-006"],"paper_id":"HE-PAPER-2024-TFHE-PROCESSOR","status":"reported","title":"General-purpose encrypted 8-bit TFHE processor prototype","year":2024},"primaryUrl":null,"sections":[{"content":"Prototype systematizing programmable bootstrapping into reusable encrypted word instructions. It is not treated as a new HE construction and is not ranked against packed arithmetic implementations.","heading":"Scope"},{"content":"The paper states that the instruction set was fully implemented over TFHElib, but this record does not yet bind an immutable repository revision or independently reproduced build.","heading":"Version boundary"}],"status":"reported","subtitle":"2024","summary":"Prototype systematizing programmable bootstrapping into reusable encrypted word instructions. It is not treated as a new HE construction and is not ranked against packed arithmetic implementations.","title":"General-purpose encrypted 8-bit TFHE processor prototype","type":"implementation","venue":null,"year":2024,"sourcePath":"data/he-catalog.json#HE-IMPL-TFHE-PROCESSOR-2024"},{"evidence":"source_derived","id":"HE-MILESTONE-001-01","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":1,"parent_problem_id":"HE-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-001","summary":"Sub-10 ms exact refresh with published 128-bit parameters on a commodity CPU.","title":"Sub-10 ms exact refresh with published 128-bit parameters on a commodity CPU.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-001-01"},{"evidence":"source_derived","id":"HE-MILESTONE-001-02","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":2,"parent_problem_id":"HE-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-001","summary":"Evaluation keys small enough to remain cache-resident for a useful word-level program.","title":"Evaluation keys small enough to remain cache-resident for a useful word-level program.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-001-02"},{"evidence":"source_derived","id":"HE-MILESTONE-001-03","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":3,"parent_problem_id":"HE-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-001","summary":"Reproducible failure probability and parameter estimates across two independent libraries.","title":"Reproducible failure probability and parameter estimates across two independent libraries.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-001-03"},{"evidence":"source_derived","id":"HE-MILESTONE-002-01","keywords":["weaker-target","shared"],"metadata":{"frontier_track":"shared","order":1,"parent_problem_id":"HE-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-002","summary":"Return at least 40 reliable precision bits with a machine-checkable error budget.","title":"Return at least 40 reliable precision bits with a machine-checkable error budget.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-002-01"},{"evidence":"source_derived","id":"HE-MILESTONE-002-02","keywords":["weaker-target","construction"],"metadata":{"frontier_track":"construction","order":2,"parent_problem_id":"HE-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-002","summary":"Reduce transform and modular-reduction depth without sparse-secret shortcuts.","title":"Reduce transform and modular-reduction depth without sparse-secret shortcuts.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-002-02"},{"evidence":"source_derived","id":"HE-MILESTONE-002-03","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":3,"parent_problem_id":"HE-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-002","summary":"Publish comparable latency, throughput, memory, and failure probability together.","title":"Publish comparable latency, throughput, memory, and failure probability together.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-002-03"},{"evidence":"source_derived","id":"HE-MILESTONE-003-01","keywords":["weaker-target","construction"],"metadata":{"frontier_track":"construction","order":1,"parent_problem_id":"HE-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-003","summary":"Circuit privacy without large noise flooding for a standardized packed scheme.","title":"Circuit privacy without large noise flooding for a standardized packed scheme.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-003-01"},{"evidence":"source_derived","id":"HE-MILESTONE-003-02","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":2,"parent_problem_id":"HE-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-003","summary":"Efficient proof or authentication of correct homomorphic evaluation.","title":"Efficient proof or authentication of correct homomorphic evaluation.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-003-02"},{"evidence":"source_derived","id":"HE-MILESTONE-003-03","keywords":["weaker-target","construction"],"metadata":{"frontier_track":"construction","order":3,"parent_problem_id":"HE-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-003","summary":"Clear composition theorem covering key switching and bootstrapping artifacts.","title":"Clear composition theorem covering key switching and bootstrapping artifacts.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-003-03"},{"evidence":"source_derived","id":"HE-MILESTONE-004-01","keywords":["weaker-target","construction"],"metadata":{"frontier_track":"construction","order":1,"parent_problem_id":"HE-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-004","summary":"Leveled HE with a refresh interface whose evaluation material avoids same-key cycles.","title":"Leveled HE with a refresh interface whose evaluation material avoids same-key cycles.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-004-01"},{"evidence":"source_derived","id":"HE-MILESTONE-004-02","keywords":["weaker-target","construction"],"metadata":{"frontier_track":"construction","order":2,"parent_problem_id":"HE-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-004","summary":"A modular reduction from a standard KDM notion sufficient for practical bootstrapping.","title":"A modular reduction from a standard KDM notion sufficient for practical bootstrapping.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-004-02"},{"evidence":"source_derived","id":"HE-MILESTONE-004-03","keywords":["weaker-target","construction"],"metadata":{"frontier_track":"construction","order":3,"parent_problem_id":"HE-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-004","summary":"A construction separating refresh correctness from circular-security evidence.","title":"A construction separating refresh correctness from circular-security evidence.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-004-03"},{"evidence":"source_derived","id":"HE-MILESTONE-005-01","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":1,"parent_problem_id":"HE-OP-005"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-005","summary":"SIMD-compatible programmable lookup with useful slot count.","title":"SIMD-compatible programmable lookup with useful slot count.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-005-01"},{"evidence":"source_derived","id":"HE-MILESTONE-005-02","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":2,"parent_problem_id":"HE-OP-005"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-005","summary":"Word-level comparisons and division without compiling every bit gate.","title":"Word-level comparisons and division without compiling every bit gate.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-005-02"},{"evidence":"source_derived","id":"HE-MILESTONE-005-03","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":3,"parent_problem_id":"HE-OP-005"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-005","summary":"Compiler cost model that chooses arithmetic, lookup, and ciphertext conversion automatically.","title":"Compiler cost model that chooses arithmetic, lookup, and ciphertext conversion automatically.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-005-03"},{"evidence":"source_derived","id":"HE-MILESTONE-006-01","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":1,"parent_problem_id":"HE-OP-006"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-006","summary":"A shared benchmark manifest that records circuits, packing, keys, precision, and security.","title":"A shared benchmark manifest that records circuits, packing, keys, precision, and security.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-006-01"},{"evidence":"source_derived","id":"HE-MILESTONE-006-02","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":2,"parent_problem_id":"HE-OP-006"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-006","summary":"Cross-library reproduction of one BGV/BFV, CKKS, and TFHE workload.","title":"Cross-library reproduction of one BGV/BFV, CKKS, and TFHE workload.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-006-02"},{"evidence":"source_derived","id":"HE-MILESTONE-006-03","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":3,"parent_problem_id":"HE-OP-006"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward HE-OP-006","summary":"Parameter files tied to a named estimator version and attack model.","title":"Parameter files tied to a named estimator version and attack model.","type":"milestone","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-MILESTONE-006-03"},{"evidence":"normalized_from_literature","id":"HE-OP-001","keywords":["exact-fhe","bootstrapping","latency","key-size"],"metadata":{"acceptance":{"performance_evidence":"latency, throughput, key memory, and ciphertext size together","reproducibility":"independent reproduction on commodity hardware","security_baseline":"declared 128-bit parameters and failure model"},"barriers":["HE-BARRIER-001","HE-BARRIER-002","HE-BARRIER-004"],"closest_results":["HE-PAPER-2012-BGV","HE-PAPER-2015-FHEW","HE-PAPER-2016-TFHE"],"dossier_type":"open_problem","evidence":"normalized_from_literature","id":"HE-OP-001","keywords":["exact-fhe","bootstrapping","latency","key-size"],"milestone_tracks":["practical","practical","practical"],"milestones":["Sub-10 ms exact refresh with published 128-bit parameters on a commodity CPU.","Evaluation keys small enough to remain cache-resident for a useful word-level program.","Reproducible failure probability and parameter estimates across two independent libraries."],"profile":{"assumption":"standard LWE or RLWE","expressivity":"exact Boolean and modular arithmetic","security":"IND-CPA with explicit refresh assumptions","setup":"reusable public evaluation material","size":"low-latency bootstrap with compact keys"},"provenance":["HE-PAPER-2009-GENTRY","HE-PAPER-2015-FHEW","HE-PAPER-2016-TFHE"],"routes":["HE-ROUTE-001"],"status":"open","title":"Practical exact FHE with cheap refresh and compact evaluation keys"},"primaryUrl":null,"sections":[{"content":"Construct exact, indefinitely composable HE whose refresh latency, evaluation-key memory, and ciphertext expansion are simultaneously practical under clearly stated standard lattice assumptions and reproducible 128-bit parameters.","heading":"Current normalized statement"},{"content":"Existing families optimize different corners: packed RLWE amortizes arithmetic, while FHEW/TFHE refreshes small messages quickly. No single construction dominates latency, throughput, memory, packing, and assumption cleanliness.","heading":"Why it remains open"},{"content":"Sub-10 ms exact refresh with published 128-bit parameters on a commodity CPU. Evaluation keys small enough to remain cache-resident for a useful word-level program. Reproducible failure probability and parameter estimates across two independent libraries.","heading":"Variants and partial targets"}],"status":"open","subtitle":"","summary":"Construct exact, indefinitely composable HE whose refresh latency, evaluation-key memory, and ciphertext expansion are simultaneously practical under clearly stated standard lattice assumptions and reproducible 128-bit parameters.","title":"Practical exact FHE with cheap refresh and compact evaluation keys","type":"open_problem","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-OP-001"},{"evidence":"normalized_from_literature","id":"HE-OP-002","keywords":["ckks","approximate-fhe","bootstrapping","precision"],"metadata":{"acceptance":{"performance_evidence":"latency paired with returned precision and failure probability","reproducibility":"parameter-matched implementation and error certificate","security_baseline":"RLWE parameters with explicit secret distribution"},"barriers":["HE-BARRIER-003","HE-BARRIER-004"],"closest_results":["HE-PAPER-2018-CKKS-BOOT","HE-PAPER-2018-RNS-CKKS","HE-PAPER-2020-HP-CKKS"],"dossier_type":"open_problem","evidence":"normalized_from_literature","id":"HE-OP-002","keywords":["ckks","approximate-fhe","bootstrapping","precision"],"milestone_tracks":["shared","construction","practical"],"milestones":["Return at least 40 reliable precision bits with a machine-checkable error budget.","Reduce transform and modular-reduction depth without sparse-secret shortcuts.","Publish comparable latency, throughput, memory, and failure probability together."],"profile":{"assumption":"RLWE with explicit secret distribution","expressivity":"approximate real and complex arithmetic","security":"IND-CPA plus quantified decryption failure","setup":"packed RLWE evaluation keys","size":"high returned precision per unit latency and memory"},"provenance":["HE-PAPER-2017-CKKS","HE-PAPER-2018-CKKS-BOOT","HE-PAPER-2020-HP-CKKS"],"routes":["HE-ROUTE-002"],"status":"open","title":"High-precision CKKS bootstrapping with certified end-to-end error"},"primaryUrl":null,"sections":[{"content":"Refresh packed CKKS ciphertexts while returning high precision, low failure probability, and a composable error certificate at substantially lower latency and key memory.","heading":"Current normalized statement"},{"content":"Bootstrapping requires approximate transforms and modular reduction; approximation range, multiplicative depth, scale, secret distribution, and security parameters interact.","heading":"Why it remains open"},{"content":"Return at least 40 reliable precision bits with a machine-checkable error budget. Reduce transform and modular-reduction depth without sparse-secret shortcuts. Publish comparable latency, throughput, memory, and failure probability together.","heading":"Variants and partial targets"}],"status":"open","subtitle":"","summary":"Refresh packed CKKS ciphertexts while returning high precision, low failure probability, and a composable error certificate at substantially lower latency and key memory.","title":"High-precision CKKS bootstrapping with certified end-to-end error","type":"open_problem","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-OP-002"},{"evidence":"repository_normalization","id":"HE-OP-003","keywords":["circuit-privacy","malicious-evaluator","verifiability"],"metadata":{"acceptance":{"performance_evidence":"overhead over an otherwise identical HE evaluation","reproducibility":"auditable malicious-evaluation test vectors","security_baseline":"composable circuit-privacy and robustness definition"},"barriers":["HE-BARRIER-001","HE-BARRIER-004"],"closest_results":["HE-PAPER-2012-BGV","HE-PAPER-2017-CKKS"],"dossier_type":"open_problem","evidence":"repository_normalization","id":"HE-OP-003","keywords":["circuit-privacy","malicious-evaluator","verifiability"],"milestone_tracks":["construction","practical","construction"],"milestones":["Circuit privacy without large noise flooding for a standardized packed scheme.","Efficient proof or authentication of correct homomorphic evaluation.","Clear composition theorem covering key switching and bootstrapping artifacts."],"profile":{"assumption":"standard lattice assumptions","expressivity":"general arithmetic or Boolean circuits","security":"circuit privacy and robust result validation","setup":"public evaluation with auditable keys","size":"modest overhead beyond ordinary evaluation"},"provenance":["HE-PAPER-2009-GENTRY","HE-PAPER-2012-BGV"],"routes":["HE-ROUTE-003"],"status":"open","title":"Practical circuit privacy and maliciously robust evaluation"},"primaryUrl":null,"sections":[{"content":"Hide evaluator-side circuit information where required and detect malformed or incomplete evaluation without erasing the performance gains of modern packed HE.","heading":"Current normalized statement"},{"content":"Circuit privacy without large noise flooding for a standardized packed scheme. Efficient proof or authentication of correct homomorphic evaluation. Clear composition theorem covering key switching and bootstrapping artifacts.","heading":"Variants and partial targets"}],"status":"open","subtitle":"","summary":"Hide evaluator-side circuit information where required and detect malformed or incomplete evaluation without erasing the performance gains of modern packed HE.","title":"Practical circuit privacy and maliciously robust evaluation","type":"open_problem","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-OP-003"},{"evidence":"repository_normalization","id":"HE-OP-004","keywords":["circular-security","kdm","standard-lwe","foundations"],"metadata":{"acceptance":{"performance_evidence":"explicit cost of removing same-key cycles","reproducibility":"machine-checkable dependency and assumption audit","security_baseline":"reduction from a standard falsifiable assumption"},"barriers":["HE-BARRIER-002"],"closest_results":["HE-PAPER-2011-BV","HE-PAPER-2012-BGV","HE-PAPER-2013-GSW"],"dossier_type":"open_problem","evidence":"repository_normalization","id":"HE-OP-004","keywords":["circular-security","kdm","standard-lwe","foundations"],"milestone_tracks":["construction","construction","construction"],"milestones":["Leveled HE with a refresh interface whose evaluation material avoids same-key cycles.","A modular reduction from a standard KDM notion sufficient for practical bootstrapping.","A construction separating refresh correctness from circular-security evidence."],"profile":{"assumption":"standard LWE without ad hoc KDM assumptions","expressivity":"unbounded general circuits","security":"standard-model IND-CPA with explicit reductions","setup":"public evaluation without secret-key cycles","size":"polynomial and compact"},"provenance":["HE-PAPER-2009-GENTRY","HE-PAPER-2010-DGHV","HE-PAPER-2011-BV"],"routes":["HE-ROUTE-004"],"status":"open","title":"Unbounded FHE from clean standard assumptions without circular-security gaps"},"primaryUrl":null,"sections":[{"content":"Obtain genuinely unbounded FHE from standard, falsifiable lattice assumptions while avoiding an unproven same-key circular-security step in the bootstrapping key.","heading":"Current normalized statement"},{"content":"This is a foundational target, not a claim that deployed leveled HE is insecure. Many applications avoid bootstrapping or work under an explicit circular-security assumption.","heading":"Scope caution"},{"content":"Leveled HE with a refresh interface whose evaluation material avoids same-key cycles. A modular reduction from a standard KDM notion sufficient for practical bootstrapping. A construction separating refresh correctness from circular-security evidence.","heading":"Variants and partial targets"}],"status":"open","subtitle":"","summary":"Obtain genuinely unbounded FHE from standard, falsifiable lattice assumptions while avoiding an unproven same-key circular-security step in the bootstrapping key.","title":"Unbounded FHE from clean standard assumptions without circular-security gaps","type":"open_problem","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-OP-004"},{"evidence":"normalized_from_literature","id":"HE-OP-005","keywords":["programmable-bootstrapping","lookup","nonlinear","control-flow"],"metadata":{"acceptance":{"performance_evidence":"program-level cost, not only single-gate latency","reproducibility":"shared word-level workload and compiler manifest","security_baseline":"explicit lookup and conversion failure bounds"},"barriers":["HE-BARRIER-001","HE-BARRIER-004"],"closest_results":["HE-PAPER-2016-TFHE","HE-PAPER-2017-TFHE-CB","HE-PAPER-2024-TFHE-PROCESSOR"],"dossier_type":"open_problem","evidence":"normalized_from_literature","id":"HE-OP-005","keywords":["programmable-bootstrapping","lookup","nonlinear","control-flow"],"milestone_tracks":["practical","practical","practical"],"milestones":["SIMD-compatible programmable lookup with useful slot count.","Word-level comparisons and division without compiling every bit gate.","Compiler cost model that chooses arithmetic, lookup, and ciphertext conversion automatically."],"profile":{"assumption":"LWE and ring variants","expressivity":"comparisons, lookup, branches, division","security":"explicit failure bounds","setup":"reusable functional-bootstrap keys","size":"high packed throughput without Booleanization"},"provenance":["HE-PAPER-2013-GSW","HE-PAPER-2017-TFHE-CB","HE-PAPER-2024-TFHE-PROCESSOR"],"routes":["HE-ROUTE-005"],"status":"open","title":"Packed nonlinear functions and encrypted control flow without gate explosion"},"primaryUrl":null,"sections":[{"content":"Evaluate comparisons, lookup tables, rounding, and data-dependent control over packed encrypted words without expanding the computation into an impractical Boolean circuit.","heading":"Current normalized statement"},{"content":"SIMD-compatible programmable lookup with useful slot count. Word-level comparisons and division without compiling every bit gate. Compiler cost model that chooses arithmetic, lookup, and ciphertext conversion automatically.","heading":"Variants and partial targets"}],"status":"open","subtitle":"","summary":"Evaluate comparisons, lookup tables, rounding, and data-dependent control over packed encrypted words without expanding the computation into an impractical Boolean circuit.","title":"Packed nonlinear functions and encrypted control flow without gate explosion","type":"open_problem","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-OP-005"},{"evidence":"repository_normalization","id":"HE-OP-006","keywords":["standardization","benchmarking","parameters","implementations"],"metadata":{"acceptance":{"performance_evidence":"matched workload, hardware, parameters, and packing","reproducibility":"cross-library reproduced status rather than reported only","security_baseline":"named estimator version and attack model"},"barriers":["HE-BARRIER-004"],"closest_results":["HE-PAPER-2012-SV-SIMD","HE-PAPER-2012-GHS-AES","HE-PAPER-2018-RNS-CKKS"],"dossier_type":"open_problem","evidence":"repository_normalization","id":"HE-OP-006","keywords":["standardization","benchmarking","parameters","implementations"],"milestone_tracks":["practical","practical","practical"],"milestones":["A shared benchmark manifest that records circuits, packing, keys, precision, and security.","Cross-library reproduction of one BGV/BFV, CKKS, and TFHE workload.","Parameter files tied to a named estimator version and attack model."],"profile":{"assumption":"declared LWE or RLWE distribution","expressivity":"exact, approximate, and lookup workloads","security":"versioned estimator and failure model","setup":"reproducible parameter generator","size":"comparable latency, throughput, memory, and key footprint"},"provenance":["HE-PAPER-2012-GHS-AES","HE-PAPER-2018-RNS-CKKS","HE-PAPER-2024-TFHE-PROCESSOR"],"routes":["HE-ROUTE-006"],"status":"open","title":"Portable HE parameters and performance claims across implementations"},"primaryUrl":null,"sections":[{"content":"Make a published HE result portable: another implementation should be able to reconstruct its security parameters, packing layout, failure model, precision target, and full cost profile.","heading":"Current normalized statement"},{"content":"A shared benchmark manifest that records circuits, packing, keys, precision, and security. Cross-library reproduction of one BGV/BFV, CKKS, and TFHE workload. Parameter files tied to a named estimator version and attack model.","heading":"Variants and partial targets"}],"status":"open","subtitle":"","summary":"Make a published HE result portable: another implementation should be able to reconstruct its security parameters, packing layout, failure model, precision target, and full cost profile.","title":"Portable HE parameters and performance claims across implementations","type":"open_problem","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-OP-006"},{"evidence":"abstract_checked","id":"HE-OPT-BGV-AES-PIPELINE-2012","keywords":["optimization","aes","crt","key-switching"],"metadata":{"category":"circuit-and-representation","construction_ids":["he_bgv12"],"dossier_type":"optimization","evidence":"abstract_checked","evidence_status":"reported","id":"HE-OPT-BGV-AES-PIPELINE-2012","keywords":["optimization","aes","crt","key-switching"],"maps_to":["HE-OP-001","HE-OP-006"],"paper_id":"HE-PAPER-2012-GHS-AES","scope":"end-to-end packed AES evaluation","status":"published","title":"CRT, packing, and key-switching pipeline for AES","year":2012},"primaryUrl":null,"sections":[{"content":"Circuit-specific composition of CRT arithmetic, packing, relinearization or key switching, and modulus planning for an end-to-end AES workload.","heading":"Optimization"}],"status":"published","subtitle":"2012","summary":"Circuit-specific composition of CRT arithmetic, packing, relinearization or key switching, and modulus planning for an end-to-end AES workload.","title":"CRT, packing, and key-switching pipeline for AES","type":"optimization","venue":null,"year":2012,"sourcePath":"data/he-catalog.json#HE-OPT-BGV-AES-PIPELINE-2012"},{"evidence":"primary_source_checked","id":"HE-OPT-SIMD-PACKING-2012","keywords":["optimization","simd","packing","throughput"],"metadata":{"category":"representation","construction_ids":["he_bgv12","he_bfv12"],"dossier_type":"optimization","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-OPT-SIMD-PACKING-2012","keywords":["optimization","simd","packing","throughput"],"maps_to":["HE-OP-006"],"paper_id":"HE-PAPER-2012-SV-SIMD","scope":"throughput per ciphertext slot","status":"published","title":"Ciphertext slot packing and parallel recryption","year":2012},"primaryUrl":null,"sections":[{"content":"Algebraic plaintext slots let one ciphertext carry many values that receive the same circuit. The optimization changes the relevant metric from latency per ciphertext to amortized throughput per slot.","heading":"Optimization"}],"status":"published","subtitle":"2012","summary":"Algebraic plaintext slots let one ciphertext carry many values that receive the same circuit. The optimization changes the relevant metric from latency per ciphertext to amortized throughput per slot.","title":"Ciphertext slot packing and parallel recryption","type":"optimization","venue":null,"year":2012,"sourcePath":"data/he-catalog.json#HE-OPT-SIMD-PACKING-2012"},{"evidence":"primary_source_checked","id":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016","keywords":["optimization","tfhe","external-product","latency"],"metadata":{"category":"bootstrapping-kernel","construction_ids":["he_tfhe16","he_fhew15"],"dossier_type":"optimization","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016","keywords":["optimization","tfhe","external-product","latency"],"maps_to":["HE-OP-001","HE-OP-005"],"paper_id":"HE-PAPER-2016-TFHE","scope":"single-gate refresh latency and evaluation-key footprint","status":"published","title":"TFHE external-product bootstrapping path","year":2016},"primaryUrl":null,"sections":[{"content":"Reformulates the FHEW line using an external product between GSW-type and LWE ciphertexts, changing the concrete bootstrapping kernel and reported cost profile.","heading":"Optimization"}],"status":"published","subtitle":"2016","summary":"Reformulates the FHEW line using an external product between GSW-type and LWE ciphertexts, changing the concrete bootstrapping kernel and reported cost profile.","title":"TFHE external-product bootstrapping path","type":"optimization","venue":null,"year":2016,"sourcePath":"data/he-catalog.json#HE-OPT-TFHE-EXTERNAL-PRODUCT-2016"},{"evidence":"primary_source_checked","id":"HE-OPT-CKKS-FULL-RNS-2018","keywords":["optimization","ckks","rns","ntt"],"metadata":{"category":"representation-and-kernels","construction_ids":["he_ckks17","he_rns_ckks18"],"dossier_type":"optimization","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-OPT-CKKS-FULL-RNS-2018","keywords":["optimization","ckks","rns","ntt"],"maps_to":["HE-OP-002","HE-OP-006"],"paper_id":"HE-PAPER-2018-RNS-CKKS","scope":"word-size modulus switching and polynomial arithmetic","status":"published","title":"Full-RNS CKKS arithmetic","year":2018},"primaryUrl":null,"sections":[{"content":"Moves CKKS core arithmetic into an RNS representation suitable for word-size operations and NTT kernels. This is an implementation optimization, not a change to the approximate-arithmetic objective.","heading":"Optimization"}],"status":"published","subtitle":"2018","summary":"Moves CKKS core arithmetic into an RNS representation suitable for word-size operations and NTT kernels. This is an implementation optimization, not a change to the approximate-arithmetic objective.","title":"Full-RNS CKKS arithmetic","type":"optimization","venue":null,"year":2018,"sourcePath":"data/he-catalog.json#HE-OPT-CKKS-FULL-RNS-2018"},{"evidence":"primary_source_checked","id":"HE-OPT-CKKS-HIGH-PRECISION-2020","keywords":["optimization","ckks","precision","bootstrapping"],"metadata":{"category":"approximation-and-depth","construction_ids":["he_ckks_boot18","he_rns_ckks18"],"dossier_type":"optimization","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-OPT-CKKS-HIGH-PRECISION-2020","keywords":["optimization","ckks","precision","bootstrapping"],"maps_to":["HE-OP-002"],"paper_id":"HE-PAPER-2020-HP-CKKS","scope":"returned precision versus multiplicative depth","status":"published","title":"Error-variance-minimized CKKS modular reduction","year":2020},"primaryUrl":null,"sections":[{"content":"Directly approximates modular reduction while minimizing error variance and multiplicative depth. Comparisons require matching parameter, precision, failure, and hardware records.","heading":"Optimization"}],"status":"published","subtitle":"2020","summary":"Directly approximates modular reduction while minimizing error variance and multiplicative depth. Comparisons require matching parameter, precision, failure, and hardware records.","title":"Error-variance-minimized CKKS modular reduction","type":"optimization","venue":null,"year":2020,"sourcePath":"data/he-catalog.json#HE-OPT-CKKS-HIGH-PRECISION-2020"},{"evidence":"primary_source_checked","id":"HE-PAPER-1978-RAD","keywords":["foundations","partial-homomorphism","historical"],"metadata":{"authors":["Ronald L. Rivest","Leonard Adleman","Michael L. Dertouzos"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-1978-RAD","keywords":["foundations","partial-homomorphism","historical"],"maps_to":["HE-OP-004"],"primary_url":"https://people.csail.mit.edu/rivest/pubs/RAD78.pdf","status":"published","title":"On Data Banks and Privacy Homomorphisms","venue":"Foundations of Secure Computation","year":1978},"primaryUrl":"https://people.csail.mit.edu/rivest/pubs/RAD78.pdf","sections":[{"content":"The paper articulated the privacy-homomorphism program: store encrypted data while permitting useful transformations without first decrypting it.","heading":"Atomic claims"},{"content":"It supplied the question and terminology that later PHE, SHE, LHE, and FHE constructions made precise.","heading":"Historical role"},{"content":"The proposed examples did not provide the modern security and generality eventually required of fully homomorphic encryption.","heading":"Limitation"}],"status":"published","subtitle":"Ronald L. Rivest, Leonard Adleman, Michael L. Dertouzos · 1978","summary":"The paper articulated the privacy-homomorphism program: store encrypted data while permitting useful transformations without first decrypting it.","title":"On Data Banks and Privacy Homomorphisms","type":"paper","venue":"Foundations of Secure Computation","year":1978,"sourcePath":"data/he-catalog.json#HE-PAPER-1978-RAD"},{"evidence":"primary_source_checked","id":"HE-PAPER-1999-PAILLIER","keywords":["phe","additive","composite-residuosity","roots"],"metadata":{"authors":["Pascal Paillier"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-1999-PAILLIER","keywords":["phe","additive","composite-residuosity","roots"],"primary_url":"https://link.springer.com/chapter/10.1007/3-540-48910-X_16","status":"published","title":"Public-Key Cryptosystems Based on Composite Degree Residuosity Classes","venue":"EUROCRYPT 1999","year":1999},"primaryUrl":"https://link.springer.com/chapter/10.1007/3-540-48910-X_16","sections":[{"content":"Paillier encryption supports addition of plaintexts through multiplication of ciphertexts, giving a canonical additively homomorphic public-key scheme.","heading":"Atomic claims"},{"content":"It is a clean reference point for partial homomorphism: one algebraic operation is unbounded, but arbitrary mixed addition-and-multiplication circuits are not supported.","heading":"Historical role"},{"content":"The scheme is not somewhat or fully homomorphic for general arithmetic circuits.","heading":"Limitation"}],"status":"published","subtitle":"Pascal Paillier · 1999","summary":"Paillier encryption supports addition of plaintexts through multiplication of ciphertexts, giving a canonical additively homomorphic public-key scheme.","title":"Public-Key Cryptosystems Based on Composite Degree Residuosity Classes","type":"paper","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/he-catalog.json#HE-PAPER-1999-PAILLIER"},{"evidence":"primary_source_checked","id":"HE-PAPER-2009-GENTRY","keywords":["fhe","ideal-lattice","bootstrapping","first-generation"],"metadata":{"authors":["Craig Gentry"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2009-GENTRY","keywords":["fhe","ideal-lattice","bootstrapping","first-generation"],"maps_to":["HE-OP-001","HE-OP-004"],"primary_url":"https://crypto.stanford.edu/craig/craig-thesis.pdf","status":"published","title":"Fully Homomorphic Encryption Using Ideal Lattices","venue":"STOC 2009","year":2009},"primaryUrl":"https://crypto.stanford.edu/craig/craig-thesis.pdf","sections":[{"content":"Gentry gave the first construction supporting evaluation of arbitrary circuits on ciphertexts and isolated bootstrappability: homomorphically evaluating a suitably augmented decryption circuit refreshes ciphertexts and lifts bounded homomorphism to FHE.","heading":"Atomic claims"},{"content":"The work established the enduring blueprint of a noise-limited scheme, decryption-circuit simplification, and bootstrapping.","heading":"Historical role"},{"content":"The ideal-lattice construction and its squashing machinery were far from practical and used assumptions later work sought to simplify.","heading":"Limitation"}],"status":"published","subtitle":"Craig Gentry · 2009","summary":"Gentry gave the first construction supporting evaluation of arbitrary circuits on ciphertexts and isolated bootstrappability: homomorphically evaluating a suitably augmented decryption circuit refreshes ciphertexts and lifts bounded homomorphism to FHE.","title":"Fully Homomorphic Encryption Using Ideal Lattices","type":"paper","venue":"STOC 2009","year":2009,"sourcePath":"data/he-catalog.json#HE-PAPER-2009-GENTRY"},{"evidence":"abstract_checked","id":"HE-PAPER-2010-DGHV","keywords":["fhe","integer-fhe","agcd","bootstrapping","first-generation"],"metadata":{"authors":["Marten van Dijk","Craig Gentry","Shai Halevi","Vinod Vaikuntanathan"],"dossier_type":"paper","evidence":"abstract_checked","id":"HE-PAPER-2010-DGHV","keywords":["fhe","integer-fhe","agcd","bootstrapping","first-generation"],"maps_to":["HE-OP-001","HE-OP-004"],"primary_url":"https://eprint.iacr.org/2009/616","status":"published","title":"Fully Homomorphic Encryption over the Integers","venue":"EUROCRYPT 2010","year":2010},"primaryUrl":"https://eprint.iacr.org/2009/616","sections":[{"content":"DGHV replaced ideal-lattice machinery with elementary modular arithmetic over approximate multiples of a secret integer, while retaining Gentry's bootstrapping route to FHE.","heading":"Atomic claims"},{"content":"It separated the bootstrapping idea from the original ideal-lattice instantiation and made the noise-growth mechanism especially transparent.","heading":"Historical role"},{"content":"Ciphertexts and public keys were very large, and the full construction used extra hardness assumptions and circular-security-style evaluation material.","heading":"Limitation"}],"status":"published","subtitle":"Marten van Dijk, Craig Gentry, Shai Halevi et al. · 2010","summary":"DGHV replaced ideal-lattice machinery with elementary modular arithmetic over approximate multiples of a secret integer, while retaining Gentry's bootstrapping route to FHE.","title":"Fully Homomorphic Encryption over the Integers","type":"paper","venue":"EUROCRYPT 2010","year":2010,"sourcePath":"data/he-catalog.json#HE-PAPER-2010-DGHV"},{"evidence":"abstract_checked","id":"HE-PAPER-2011-BV","keywords":["fhe","she","lwe","relinearization","key-switching"],"metadata":{"authors":["Zvika Brakerski","Vinod Vaikuntanathan"],"dossier_type":"paper","evidence":"abstract_checked","id":"HE-PAPER-2011-BV","keywords":["fhe","she","lwe","relinearization","key-switching"],"maps_to":["HE-OP-001","HE-OP-004"],"primary_url":"https://eprint.iacr.org/2011/344","status":"published","title":"Efficient Fully Homomorphic Encryption from (Standard) LWE","venue":"FOCS 2011","year":2011},"primaryUrl":"https://eprint.iacr.org/2011/344","sections":[{"content":"The paper based somewhat homomorphic encryption on standard LWE, introduced relinearization to control ciphertext dimension after multiplication, and avoided the earlier squashing paradigm through dimension-modulus reduction.","heading":"Atomic claims"},{"content":"It moved the main FHE line to standard lattice assumptions and introduced techniques inherited by the BGV/BFV family.","heading":"Historical role"},{"content":"The unbounded FHE upgrade still requires bootstrapping and evaluation material whose security needs separate treatment; the practical leveled setting remained the dominant use case.","heading":"Limitation"}],"status":"published","subtitle":"Zvika Brakerski, Vinod Vaikuntanathan · 2011","summary":"The paper based somewhat homomorphic encryption on standard LWE, introduced relinearization to control ciphertext dimension after multiplication, and avoided the earlier squashing paradigm through dimension-modulus reduction.","title":"Efficient Fully Homomorphic Encryption from (Standard) LWE","type":"paper","venue":"FOCS 2011","year":2011,"sourcePath":"data/he-catalog.json#HE-PAPER-2011-BV"},{"evidence":"primary_source_checked","id":"HE-PAPER-2012-BGV","keywords":["lhe","fhe","bgv","lwe","rlwe","modulus-switching","packing"],"metadata":{"authors":["Zvika Brakerski","Craig Gentry","Vinod Vaikuntanathan"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2012-BGV","keywords":["lhe","fhe","bgv","lwe","rlwe","modulus-switching","packing"],"maps_to":["HE-OP-001","HE-OP-006"],"primary_url":"https://eprint.iacr.org/2011/277","status":"published","title":"Fully Homomorphic Encryption without Bootstrapping","venue":"ITCS 2012","year":2012},"primaryUrl":"https://eprint.iacr.org/2011/277","sections":[{"content":"BGV introduced a leveled FHE approach that evaluates any predetermined polynomial-size circuit without bootstrapping. It applies the modulus-switching technique from the preceding BV line iteratively along a depth-indexed modulus chain; a bootstrapped variant makes per-gate cost independent of depth.","heading":"Atomic claims"},{"content":"It made leveled HE a first-class target rather than merely an unfinished FHE and became a principal basis for exact packed arithmetic implementations.","heading":"Historical role"},{"content":"Parameters and evaluation keys depend on the supported depth in leveled mode; unbounded evaluation still needs refresh and circular-security-related machinery.","heading":"Limitation"}],"status":"published","subtitle":"Zvika Brakerski, Craig Gentry, Vinod Vaikuntanathan · 2012","summary":"BGV introduced a leveled FHE approach that evaluates any predetermined polynomial-size circuit without bootstrapping. It applies the modulus-switching technique from the preceding BV line iteratively along a depth-indexed modulus chain; a bootstrapped variant makes per-gate cost independent of depth.","title":"Fully Homomorphic Encryption without Bootstrapping","type":"paper","venue":"ITCS 2012","year":2012,"sourcePath":"data/he-catalog.json#HE-PAPER-2012-BGV"},{"evidence":"abstract_checked","id":"HE-PAPER-2012-BRAKERSKI","keywords":["lhe","fhe","lwe","scale-invariant","tensoring"],"metadata":{"authors":["Zvika Brakerski"],"dossier_type":"paper","evidence":"abstract_checked","id":"HE-PAPER-2012-BRAKERSKI","keywords":["lhe","fhe","lwe","scale-invariant","tensoring"],"maps_to":["HE-OP-001"],"primary_url":"https://eprint.iacr.org/2012/078","status":"published","title":"Fully Homomorphic Encryption without Modulus Switching from Classical GapSVP","venue":"CRYPTO 2012","year":2012},"primaryUrl":"https://eprint.iacr.org/2012/078","sections":[{"content":"The paper introduced a tensoring technique whose multiplication noise grows linearly rather than quadratically and obtained a scale-invariant LWE-based scheme using one modulus instead of a modulus-switching chain.","heading":"Atomic claims"},{"content":"It exposed a second major design axis for noise management: control the multiplication invariant rather than switch moduli after every level.","heading":"Historical role"},{"content":"The construction is primarily a conceptual and asymptotic simplification; practical exact-arithmetic libraries largely followed BGV/BFV-style RNS and modulus-chain techniques.","heading":"Limitation"}],"status":"published","subtitle":"Zvika Brakerski · 2012","summary":"The paper introduced a tensoring technique whose multiplication noise grows linearly rather than quadratically and obtained a scale-invariant LWE-based scheme using one modulus instead of a modulus-switching chain.","title":"Fully Homomorphic Encryption without Modulus Switching from Classical GapSVP","type":"paper","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/he-catalog.json#HE-PAPER-2012-BRAKERSKI"},{"evidence":"abstract_checked","id":"HE-PAPER-2012-FV","keywords":["she","lhe","bfv","rlwe","exact-arithmetic","batching"],"metadata":{"authors":["Junfeng Fan","Frederik Vercauteren"],"dossier_type":"paper","evidence":"abstract_checked","id":"HE-PAPER-2012-FV","keywords":["she","lhe","bfv","rlwe","exact-arithmetic","batching"],"maps_to":["HE-OP-001","HE-OP-006"],"primary_url":"https://eprint.iacr.org/2012/144","status":"published","title":"Somewhat Practical Fully Homomorphic Encryption","venue":"IACR ePrint 2012/144","year":2012},"primaryUrl":"https://eprint.iacr.org/2012/144","sections":[{"content":"Fan and Vercauteren presented an RLWE-based somewhat homomorphic construction with practical ciphertext multiplication and relinearization, now commonly represented by the BFV family for exact modular arithmetic.","heading":"Atomic claims"},{"content":"BFV became, with BGV, a standard exact-arithmetic design point in libraries and security standards.","heading":"Historical role"},{"content":"The base scheme is depth bounded; unbounded FHE requires bootstrapping, and concrete efficiency depends heavily on RNS representation, packing, and parameter selection added by later work.","heading":"Limitation"}],"status":"published","subtitle":"Junfeng Fan, Frederik Vercauteren · 2012","summary":"Fan and Vercauteren presented an RLWE-based somewhat homomorphic construction with practical ciphertext multiplication and relinearization, now commonly represented by the BFV family for exact modular arithmetic.","title":"Somewhat Practical Fully Homomorphic Encryption","type":"paper","venue":"IACR ePrint 2012/144","year":2012,"sourcePath":"data/he-catalog.json#HE-PAPER-2012-FV"},{"evidence":"primary_source_checked","id":"HE-PAPER-2012-GHS-AES","keywords":["lhe","fhe","bgv","implementation","simd","transciphering"],"metadata":{"authors":["Craig Gentry","Shai Halevi","Nigel P. Smart"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2012-GHS-AES","keywords":["lhe","fhe","bgv","implementation","simd","transciphering"],"maps_to":["HE-OP-001","HE-OP-006"],"primary_url":"https://eprint.iacr.org/2012/099","status":"published","title":"Homomorphic Evaluation of the AES Circuit","venue":"CRYPTO 2012","version_note":"CRYPTO 2012 early version; the cited ePrint is the January 3, 2015 updated implementation report","year":2012},"primaryUrl":"https://eprint.iacr.org/2012/099","sections":[{"content":"The 2012 work demonstrated an end-to-end homomorphic evaluation of AES. The cited 2015 updated report realizes refined non-bootstrapped and bootstrapped HElib pipelines with CRT representation, packing, and key-switching optimizations.","heading":"Atomic claims"},{"content":"It connected construction-level advances to a recognizable large circuit and clarified where memory, rotations, key switching, and bootstrapping dominate real systems.","heading":"Historical role"},{"content":"The 2015 implementation measurements must not be backdated to the 2012 publication. Both regimes remained expensive and circuit-specific and did not eliminate careful compilation or parameter planning.","heading":"Limitation"}],"status":"published","subtitle":"Craig Gentry, Shai Halevi, Nigel P. Smart · 2012","summary":"The 2012 work demonstrated an end-to-end homomorphic evaluation of AES. The cited 2015 updated report realizes refined non-bootstrapped and bootstrapped HElib pipelines with CRT representation, packing, and key-switching optimizations.","title":"Homomorphic Evaluation of the AES Circuit","type":"paper","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/he-catalog.json#HE-PAPER-2012-GHS-AES"},{"evidence":"primary_source_checked","id":"HE-PAPER-2012-SV-SIMD","keywords":["fhe","she","batching","simd","ideal-lattice"],"metadata":{"authors":["Nigel P. Smart","Frederik Vercauteren"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2012-SV-SIMD","keywords":["fhe","she","batching","simd","ideal-lattice"],"maps_to":["HE-OP-006"],"primary_url":"https://eprint.iacr.org/2011/133","status":"published","title":"Fully Homomorphic SIMD Operations","venue":"Designs, Codes and Cryptography","year":2012},"primaryUrl":"https://eprint.iacr.org/2011/133","sections":[{"content":"The paper showed how algebraic plaintext slots support SIMD evaluation of many data elements in one ciphertext and how parallel recryption can amortize bootstrapping work.","heading":"Atomic claims"},{"content":"Packing changed the relevant cost metric from latency per ciphertext to throughput per slot and became central to BGV, BFV, and CKKS implementations.","heading":"Historical role"},{"content":"Slots share the same circuit shape; rotations, repacking, and data-dependent access remain expensive and require evaluation keys or additional transformations.","heading":"Limitation"}],"status":"published","subtitle":"Nigel P. Smart, Frederik Vercauteren · 2012","summary":"The paper showed how algebraic plaintext slots support SIMD evaluation of many data elements in one ciphertext and how parallel recryption can amortize bootstrapping work.","title":"Fully Homomorphic SIMD Operations","type":"paper","venue":"Designs, Codes and Cryptography","year":2012,"sourcePath":"data/he-catalog.json#HE-PAPER-2012-SV-SIMD"},{"evidence":"primary_source_checked","id":"HE-PAPER-2013-GSW","keywords":["fhe","gsw","lwe","gate-bootstrap","approximate-eigenvector"],"metadata":{"authors":["Craig Gentry","Amit Sahai","Brent Waters"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2013-GSW","keywords":["fhe","gsw","lwe","gate-bootstrap","approximate-eigenvector"],"maps_to":["HE-OP-001","HE-OP-005"],"primary_url":"https://eprint.iacr.org/2013/340","status":"published","title":"Homomorphic Encryption from Learning with Errors: Conceptually-Simpler, Asymptotically-Faster, Attribute-Based","venue":"CRYPTO 2013","year":2013},"primaryUrl":"https://eprint.iacr.org/2013/340","sections":[{"content":"GSW represented ciphertexts as approximate eigenvectors, enabling a conceptually direct multiplication rule and avoiding the relinearization structure used by earlier LWE schemes.","heading":"Atomic claims"},{"content":"Its matrix/external-product viewpoint became the algebraic core of fast gate-bootstrapping systems including FHEW and TFHE.","heading":"Historical role"},{"content":"Raw GSW ciphertexts are large; practical descendants rely on ring variants, decomposition, switching between ciphertext types, and specialized bootstrapping procedures.","heading":"Limitation"}],"status":"published","subtitle":"Craig Gentry, Amit Sahai, Brent Waters · 2013","summary":"GSW represented ciphertexts as approximate eigenvectors, enabling a conceptually direct multiplication rule and avoiding the relinearization structure used by earlier LWE schemes.","title":"Homomorphic Encryption from Learning with Errors: Conceptually-Simpler, Asymptotically-Faster, Attribute-Based","type":"paper","venue":"CRYPTO 2013","year":2013,"sourcePath":"data/he-catalog.json#HE-PAPER-2013-GSW"},{"evidence":"primary_source_checked","id":"HE-PAPER-2015-FHEW","keywords":["fhe","fhew","lwe","rlwe","gate-bootstrap"],"metadata":{"authors":["Léo Ducas","Daniele Micciancio"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2015-FHEW","keywords":["fhe","fhew","lwe","rlwe","gate-bootstrap"],"maps_to":["HE-OP-001","HE-OP-005"],"primary_url":"https://eprint.iacr.org/2014/816","status":"published","title":"FHEW: Bootstrapping Homomorphic Encryption in Less Than a Second","venue":"EUROCRYPT 2015","year":2015},"primaryUrl":"https://eprint.iacr.org/2014/816","sections":[{"content":"FHEW introduced a method that combines homomorphic evaluation of a simple bit operation with ciphertext refresh in roughly half a second on a personal computer.","heading":"Atomic claims"},{"content":"It shifted the bootstrapping target from refreshing large packed arithmetic circuits to rapidly evaluating and refreshing individual Boolean gates.","heading":"Historical role"},{"content":"The bootstrapping key was large and throughput for word arithmetic or packed workloads required additional representations and circuit-level strategies.","heading":"Limitation"}],"status":"published","subtitle":"Léo Ducas, Daniele Micciancio · 2015","summary":"FHEW introduced a method that combines homomorphic evaluation of a simple bit operation with ciphertext refresh in roughly half a second on a personal computer.","title":"FHEW: Bootstrapping Homomorphic Encryption in Less Than a Second","type":"paper","venue":"EUROCRYPT 2015","year":2015,"sourcePath":"data/he-catalog.json#HE-PAPER-2015-FHEW"},{"evidence":"primary_source_checked","id":"HE-PAPER-2016-TFHE","keywords":["fhe","tfhe","gsw","lwe","gate-bootstrap","external-product"],"metadata":{"authors":["Ilaria Chillotti","Nicolas Gama","Mariya Georgieva","Malika Izabachène"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2016-TFHE","keywords":["fhe","tfhe","gsw","lwe","gate-bootstrap","external-product"],"maps_to":["HE-OP-001","HE-OP-005"],"primary_url":"https://eprint.iacr.org/2016/870","status":"published","title":"Faster Fully Homomorphic Encryption: Bootstrapping in Less Than 0.1 Seconds","venue":"ASIACRYPT 2016","year":2016},"primaryUrl":"https://eprint.iacr.org/2016/870","sections":[{"content":"TFHE recast FHEW bootstrapping using an external product between GSW-type and LWE ciphertexts, reducing bootstrapping below 0.1 seconds and shrinking the evaluation key in the reported setting.","heading":"Atomic claims"},{"content":"It established the fast gate-by-gate branch of practical FHE and the ciphertext-type switching pattern behind programmable bootstrapping.","heading":"Historical role"},{"content":"Boolean-gate latency, packing, key size, and conversion to efficient word arithmetic remain distinct engineering and cryptographic constraints.","heading":"Limitation"}],"status":"published","subtitle":"Ilaria Chillotti, Nicolas Gama, Mariya Georgieva et al. · 2016","summary":"TFHE recast FHEW bootstrapping using an external product between GSW-type and LWE ciphertexts, reducing bootstrapping below 0.1 seconds and shrinking the evaluation key in the reported setting.","title":"Faster Fully Homomorphic Encryption: Bootstrapping in Less Than 0.1 Seconds","type":"paper","venue":"ASIACRYPT 2016","year":2016,"sourcePath":"data/he-catalog.json#HE-PAPER-2016-TFHE"},{"evidence":"primary_source_checked","id":"HE-PAPER-2017-CKKS","keywords":["lhe","ckks","rlwe","approximate-arithmetic","rescaling","packing"],"metadata":{"authors":["Jung Hee Cheon","Andrey Kim","Miran Kim","Yongsoo Song"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2017-CKKS","keywords":["lhe","ckks","rlwe","approximate-arithmetic","rescaling","packing"],"maps_to":["HE-OP-002","HE-OP-006"],"primary_url":"https://eprint.iacr.org/2016/421","status":"published","title":"Homomorphic Encryption for Arithmetic of Approximate Numbers","venue":"ASIACRYPT 2017","year":2017},"primaryUrl":"https://eprint.iacr.org/2016/421","sections":[{"content":"CKKS treats encryption noise and rescaling roundoff as part of a controlled approximate computation, supporting packed real or complex arithmetic with a rescaling operation that reduces plaintext scale and ciphertext modulus together.","heading":"Atomic claims"},{"content":"It created the dominant HE branch for numerical workloads where approximate outputs are meaningful.","heading":"Historical role"},{"content":"Correctness is a precision statement rather than exact equality; scale planning, approximation error, and bootstrapped modular reduction require explicit analysis.","heading":"Limitation"}],"status":"published","subtitle":"Jung Hee Cheon, Andrey Kim, Miran Kim et al. · 2017","summary":"CKKS treats encryption noise and rescaling roundoff as part of a controlled approximate computation, supporting packed real or complex arithmetic with a rescaling operation that reduces plaintext scale and ciphertext modulus together.","title":"Homomorphic Encryption for Arithmetic of Approximate Numbers","type":"paper","venue":"ASIACRYPT 2017","year":2017,"sourcePath":"data/he-catalog.json#HE-PAPER-2017-CKKS"},{"evidence":"primary_source_checked","id":"HE-PAPER-2017-TFHE-CB","keywords":["fhe","tfhe","packing","circuit-bootstrap","programmable-bootstrap"],"metadata":{"authors":["Ilaria Chillotti","Nicolas Gama","Mariya Georgieva","Malika Izabachène"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2017-TFHE-CB","keywords":["fhe","tfhe","packing","circuit-bootstrap","programmable-bootstrap"],"maps_to":["HE-OP-005","HE-OP-006"],"primary_url":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","status":"published","title":"Faster Packed Homomorphic Operations and Efficient Circuit Bootstrapping for TFHE","venue":"ASIACRYPT 2017","year":2017},"primaryUrl":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","sections":[{"content":"The paper makes two distinct contributions: packed leveled-circuit techniques for lookup and automata workloads, and circuit bootstrapping that converts LWE ciphertexts into low-noise RingGSW ciphertexts suitable for later leveled circuits.","heading":"Atomic claims"},{"content":"It broadened TFHE from a fast Boolean-gate engine toward functional and programmable bootstrapping.","heading":"Historical role"},{"content":"Ciphertext conversion, memory traffic, bootstrapping keys, and limited native SIMD still distinguish the TFHE branch from packed RLWE arithmetic.","heading":"Limitation"}],"status":"published","subtitle":"Ilaria Chillotti, Nicolas Gama, Mariya Georgieva et al. · 2017","summary":"The paper makes two distinct contributions: packed leveled-circuit techniques for lookup and automata workloads, and circuit bootstrapping that converts LWE ciphertexts into low-noise RingGSW ciphertexts suitable for later leveled circuits.","title":"Faster Packed Homomorphic Operations and Efficient Circuit Bootstrapping for TFHE","type":"paper","venue":"ASIACRYPT 2017","year":2017,"sourcePath":"data/he-catalog.json#HE-PAPER-2017-TFHE-CB"},{"evidence":"primary_source_checked","id":"HE-PAPER-2018-CKKS-BOOT","keywords":["fhe","ckks","rlwe","approximate-arithmetic","bootstrapping"],"metadata":{"authors":["Jung Hee Cheon","Kyoohyung Han","Andrey Kim","Miran Kim","Yongsoo Song"],"citation_key":"CHKKS18a","dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2018-CKKS-BOOT","keywords":["fhe","ckks","rlwe","approximate-arithmetic","bootstrapping"],"maps_to":["HE-OP-002"],"primary_url":"https://eprint.iacr.org/2018/153","status":"published","title":"Bootstrapping for Approximate Homomorphic Encryption","venue":"EUROCRYPT 2018","year":2018},"primaryUrl":"https://eprint.iacr.org/2018/153","sections":[{"content":"The paper extended CKKS from leveled approximate HE to FHE by approximating modular reduction in the decryption circuit and demonstrated refresh of packed ciphertexts.","heading":"Atomic claims"},{"content":"It showed that approximate arithmetic can bootstrap in its native packed representation instead of switching to bitwise gates.","heading":"Historical role"},{"content":"The initial refresh was expensive and returned limited precision; polynomial approximation, transforms, and error control became the central optimization targets.","heading":"Limitation"}],"status":"published","subtitle":"Jung Hee Cheon, Kyoohyung Han, Andrey Kim et al. · 2018","summary":"The paper extended CKKS from leveled approximate HE to FHE by approximating modular reduction in the decryption circuit and demonstrated refresh of packed ciphertexts.","title":"Bootstrapping for Approximate Homomorphic Encryption","type":"paper","venue":"EUROCRYPT 2018","year":2018,"sourcePath":"data/he-catalog.json#HE-PAPER-2018-CKKS-BOOT"},{"evidence":"primary_source_checked","id":"HE-PAPER-2018-RNS-CKKS","keywords":["lhe","ckks","rlwe","rns","ntt","approximate-arithmetic"],"metadata":{"authors":["Jung Hee Cheon","Kyoohyung Han","Andrey Kim","Miran Kim","Yongsoo Song"],"citation_key":"CHKKS18b","dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2018-RNS-CKKS","keywords":["lhe","ckks","rlwe","rns","ntt","approximate-arithmetic"],"maps_to":["HE-OP-002","HE-OP-006"],"primary_url":"https://eprint.iacr.org/2018/931","status":"published","title":"A Full RNS Variant of Approximate Homomorphic Encryption","venue":"SAC 2018","year":2018},"primaryUrl":"https://eprint.iacr.org/2018/931","sections":[{"content":"The work redesigned approximate HE around a full residue-number-system representation, enabling modulus switching and core operations with word-size arithmetic and NTT-friendly components.","heading":"Atomic claims"},{"content":"It converted CKKS from a conceptually efficient scheme into the RNS implementation pattern used by modern libraries.","heading":"Historical role"},{"content":"RNS representation improves kernels but does not by itself solve bootstrapping depth, certified precision, key memory, or data-movement costs.","heading":"Limitation"}],"status":"published","subtitle":"Jung Hee Cheon, Kyoohyung Han, Andrey Kim et al. · 2018","summary":"The work redesigned approximate HE around a full residue-number-system representation, enabling modulus switching and core operations with word-size arithmetic and NTT-friendly components.","title":"A Full RNS Variant of Approximate Homomorphic Encryption","type":"paper","venue":"SAC 2018","year":2018,"sourcePath":"data/he-catalog.json#HE-PAPER-2018-RNS-CKKS"},{"evidence":"primary_source_checked","id":"HE-PAPER-2020-HP-CKKS","keywords":["fhe","ckks","bootstrapping","high-precision","approximate-arithmetic"],"metadata":{"authors":["Yongwoo Lee","Joon-Woo Lee","Young-Sik Kim","Yongjune Kim","Jong-Seon No","HyungChul Kang"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2020-HP-CKKS","keywords":["fhe","ckks","bootstrapping","high-precision","approximate-arithmetic"],"maps_to":["HE-OP-002"],"primary_url":"https://eprint.iacr.org/2020/1549","status":"published","title":"High-Precision Bootstrapping for Approximate Homomorphic Encryption by Error Variance Minimization","venue":"EUROCRYPT 2022","year":2020},"primaryUrl":"https://eprint.iacr.org/2020/1549","sections":[{"content":"The paper proposed a direct polynomial approximation of modular reduction designed to minimize error variance and multiplicative depth for high-precision CKKS bootstrapping.","heading":"Atomic claims"},{"content":"It sharpened the frontier metric from merely achieving CKKS refresh to returning many reliable precision bits at practical cost.","heading":"Historical role"},{"content":"Precision, depth, runtime, memory, and failure probability remain coupled; reported performance is sensitive to parameters and approximation range.","heading":"Limitation"}],"status":"published","subtitle":"Yongwoo Lee, Joon-Woo Lee, Young-Sik Kim et al. · 2020","summary":"The paper proposed a direct polynomial approximation of modular reduction designed to minimize error variance and multiplicative depth for high-precision CKKS bootstrapping.","title":"High-Precision Bootstrapping for Approximate Homomorphic Encryption by Error Variance Minimization","type":"paper","venue":"EUROCRYPT 2022","year":2020,"sourcePath":"data/he-catalog.json#HE-PAPER-2020-HP-CKKS"},{"evidence":"primary_source_checked","id":"HE-PAPER-2024-TFHE-PROCESSOR","keywords":["fhe","tfhe","programmable-bootstrap","lookup-table","word-arithmetic"],"metadata":{"authors":["Daphné Trama","Pierre-Emmanuel Clet","Aymen Boudguiga","Renaud Sirdey","Nicolas Ye"],"dossier_type":"paper","evidence":"primary_source_checked","id":"HE-PAPER-2024-TFHE-PROCESSOR","keywords":["fhe","tfhe","programmable-bootstrap","lookup-table","word-arithmetic"],"maps_to":["HE-OP-005","HE-OP-006"],"primary_url":"https://eprint.iacr.org/2024/1201","status":"published","title":"Designing a General-Purpose 8-bit (T)FHE Processor Abstraction","venue":"TCHES 2025","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/1201","sections":[{"content":"The paper systematizes programmable bootstrapping and lookup-table dereferencing into more than fifty encrypted 8-bit instructions, represented as two basis-16 digits, and composes them into program-level workloads.","heading":"Atomic claims"},{"content":"It demonstrates how the TFHE line is climbing from Boolean gates toward reusable word-level instruction semantics.","heading":"Historical role"},{"content":"The processor abstraction does not remove the cost of bootstrapping, memory movement, or encrypted control flow. Its basis-16 parameters target roughly 128-bit security but expose a paper-specific failure regime that is not interchangeable with a 2^-128 correctness target.","heading":"Limitation"}],"status":"published","subtitle":"Daphné Trama, Pierre-Emmanuel Clet, Aymen Boudguiga et al. · 2024","summary":"The paper systematizes programmable bootstrapping and lookup-table dereferencing into more than fifty encrypted 8-bit instructions, represented as two basis-16 digits, and composes them into program-level workloads.","title":"Designing a General-Purpose 8-bit (T)FHE Processor Abstraction","type":"paper","venue":"TCHES 2025","year":2024,"sourcePath":"data/he-catalog.json#HE-PAPER-2024-TFHE-PROCESSOR"},{"evidence":"primary_source_checked","id":"HE-PARAM-FHEW-2015","keywords":["parameters","fhew","bootstrapping"],"metadata":{"construction_id":"he_fhew15","dossier_type":"parameter_set","estimator":"original paper methodology","evidence":"primary_source_checked","evidence_status":"reported","failure_model":"paper-reported gate-bootstrap correctness","id":"HE-PARAM-FHEW-2015","keywords":["parameters","fhew","bootstrapping"],"maps_to":["HE-OP-001","HE-OP-006"],"paper_id":"HE-PAPER-2015-FHEW","security_bits":"paper-reported setting; not cross-estimator normalized","status":"reported","title":"FHEW reported gate-bootstrap parameters","year":2015},"primaryUrl":null,"sections":[{"content":"This record anchors the FHEW benchmark to its own reported parameter regime. It is not labeled “128-bit equivalent” until a named modern estimator reproduces that claim.","heading":"Reproducibility boundary"}],"status":"reported","subtitle":"2015","summary":"This record anchors the FHEW benchmark to its own reported parameter regime. It is not labeled “128-bit equivalent” until a named modern estimator reproduces that claim.","title":"FHEW reported gate-bootstrap parameters","type":"parameter_set","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-PARAM-FHEW-2015"},{"evidence":"primary_source_checked","id":"HE-PARAM-GHS-AES-2012","keywords":["parameters","bgv","aes","audit-pending"],"metadata":{"construction_id":"he_bgv12","dossier_type":"parameter_set","estimator":"HElib parameter derivation described by the paper; not cross-estimator normalized","evidence":"primary_source_checked","evidence_status":"section_checked","failure_model":"exact-arithmetic 40-level setting with m = 53261, phi(m) = 46080, and 1920 slots","id":"HE-PARAM-GHS-AES-2012","keywords":["parameters","bgv","aes","audit-pending"],"maps_to":["HE-OP-006"],"paper_id":"HE-PAPER-2012-GHS-AES","security_bits":"paper-specific historical estimate; exact bit claim not stated for this row","status":"reported","title":"GHS non-bootstrapped packed-AES parameters","year":2015},"primaryUrl":null,"sections":[{"content":"This parameter object covers only the non-bootstrapped 40-level experiment in the January 2015 update. It must not be reused for the paper's separate bootstrapped run, backdated to the 2012 version, or interpreted as a current security recommendation.","heading":"Reproducibility boundary"}],"status":"reported","subtitle":"2015","summary":"This parameter object covers only the non-bootstrapped 40-level experiment in the January 2015 update. It must not be reused for the paper's separate bootstrapped run, backdated to the 2012 version, or interpreted as a current security recommendation.","title":"GHS non-bootstrapped packed-AES parameters","type":"parameter_set","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-PARAM-GHS-AES-2012"},{"evidence":"primary_source_checked","id":"HE-PARAM-GHS-AES-BOOT-2012","keywords":["parameters","bgv","aes","bootstrapping"],"metadata":{"construction_id":"he_bgv12","dossier_type":"parameter_set","estimator":"paper-specific derivation in Appendix C; not cross-estimator normalized","evidence":"primary_source_checked","evidence_status":"section_checked","failure_model":"23-level setting with m = 28679, phi(m) = 23040, and 960 slots; two recryptions in the reported AES encryption run","id":"HE-PARAM-GHS-AES-BOOT-2012","keywords":["parameters","bgv","aes","bootstrapping"],"maps_to":["HE-OP-001","HE-OP-006"],"paper_id":"HE-PAPER-2012-GHS-AES","security_bits":"123-bit paper estimate","status":"reported","title":"GHS bootstrapped packed-AES parameters","year":2015},"primaryUrl":null,"sections":[{"content":"This object records the January 2015 update's bootstrapped regime separately from the 40-level non-bootstrapped run. The 123-bit estimate is historical and is neither backdated to 2012 nor silently converted to a current estimator result.","heading":"Reproducibility boundary"}],"status":"reported","subtitle":"2015","summary":"This object records the January 2015 update's bootstrapped regime separately from the 40-level non-bootstrapped run. The 123-bit estimate is historical and is neither backdated to 2012 nor silently converted to a current estimator result.","title":"GHS bootstrapped packed-AES parameters","type":"parameter_set","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-PARAM-GHS-AES-BOOT-2012"},{"evidence":"primary_source_checked","id":"HE-PARAM-TFHE-2016","keywords":["parameters","tfhe","bootstrapping"],"metadata":{"construction_id":"he_tfhe16","dossier_type":"parameter_set","estimator":"original paper methodology","evidence":"primary_source_checked","evidence_status":"reported","failure_model":"paper-reported decryption and bootstrap failure setting","id":"HE-PARAM-TFHE-2016","keywords":["parameters","tfhe","bootstrapping"],"maps_to":["HE-OP-001","HE-OP-005","HE-OP-006"],"paper_id":"HE-PAPER-2016-TFHE","security_bits":"paper-reported setting; not cross-estimator normalized","status":"reported","title":"TFHE reported fast-bootstrap parameters","year":2016},"primaryUrl":null,"sections":[{"content":"Parameter record for the original fast TFHE experiment. It preserves the historical claim while marking estimator normalization as future audit work.","heading":"Reproducibility boundary"}],"status":"reported","subtitle":"2016","summary":"Parameter record for the original fast TFHE experiment. It preserves the historical claim while marking estimator normalization as future audit work.","title":"TFHE reported fast-bootstrap parameters","type":"parameter_set","venue":null,"year":2016,"sourcePath":"data/he-catalog.json#HE-PARAM-TFHE-2016"},{"evidence":"primary_source_checked","id":"HE-PARAM-CKKS-BOOT-2018","keywords":["parameters","ckks","precision","bootstrapping"],"metadata":{"construction_id":"he_ckks_boot18","dossier_type":"parameter_set","estimator":"not yet normalized","evidence":"primary_source_checked","evidence_status":"reported","failure_model":"approximate correctness and returned precision","id":"HE-PARAM-CKKS-BOOT-2018","keywords":["parameters","ckks","precision","bootstrapping"],"maps_to":["HE-OP-002","HE-OP-006"],"paper_id":"HE-PAPER-2018-CKKS-BOOT","security_bits":"paper-specific RLWE setting","status":"reported","title":"First CKKS bootstrap parameter regime","year":2018},"primaryUrl":null,"sections":[{"content":"The record keeps ring dimension, modulus chain, secret distribution, scale, slots, precision, and failure probability conceptually together. Exact values remain pending structured PDF extraction.","heading":"Reproducibility boundary"}],"status":"reported","subtitle":"2018","summary":"The record keeps ring dimension, modulus chain, secret distribution, scale, slots, precision, and failure probability conceptually together. Exact values remain pending structured PDF extraction.","title":"First CKKS bootstrap parameter regime","type":"parameter_set","venue":null,"year":2018,"sourcePath":"data/he-catalog.json#HE-PARAM-CKKS-BOOT-2018"},{"evidence":"primary_source_checked","id":"HE-PARAM-HP-CKKS-2020","keywords":["parameters","ckks","high-precision"],"metadata":{"construction_id":"he_ckks_boot18","dossier_type":"parameter_set","estimator":"not yet normalized","evidence":"primary_source_checked","evidence_status":"reported","failure_model":"returned precision and approximation error variance","id":"HE-PARAM-HP-CKKS-2020","keywords":["parameters","ckks","high-precision"],"maps_to":["HE-OP-002","HE-OP-006"],"paper_id":"HE-PAPER-2020-HP-CKKS","security_bits":"paper-specific RLWE setting","status":"reported","title":"High-precision CKKS bootstrap parameter regime","year":2020},"primaryUrl":null,"sections":[{"content":"Parameter record for high-precision modular-reduction experiments. It must remain paired with the relevant precision target and approximation interval.","heading":"Reproducibility boundary"}],"status":"reported","subtitle":"2020","summary":"Parameter record for high-precision modular-reduction experiments. It must remain paired with the relevant precision target and approximation interval.","title":"High-precision CKKS bootstrap parameter regime","type":"parameter_set","venue":null,"year":2020,"sourcePath":"data/he-catalog.json#HE-PARAM-HP-CKKS-2020"},{"evidence":"primary_source_checked","id":"HE-PARAM-TFHE-PROCESSOR-2024","keywords":["parameters","tfhe","basis-16","failure-probability"],"metadata":{"construction_id":"he_tfhe16","dossier_type":"parameter_set","estimator":"paper-specific parameter analysis; not cross-estimator normalized","evidence":"primary_source_checked","evidence_status":"section_checked","failure_model":"Table 2 reports basis-16 MVB error epsilon = 2^-23; Section 10 separately discusses a 2^-40 bootstrap-error regime and the unresolved cost of a 2^-128 target","id":"HE-PARAM-TFHE-PROCESSOR-2024","keywords":["parameters","tfhe","basis-16","failure-probability"],"maps_to":["HE-OP-005","HE-OP-006"],"paper_id":"HE-PAPER-2024-TFHE-PROCESSOR","security_bits":"approximately 128 bits in the paper's analysis","status":"reported","title":"Basis-16 parameters for the encrypted 8-bit TFHE processor","year":2024},"primaryUrl":null,"sections":[{"content":"This record preserves the paper's basis-16 coordinates and the fact that its error figures refer to different operations or accounting boundaries. They must not be collapsed into one stronger failure guarantee; a lower failure target may require different polynomial degree, modulus, and decomposition basis.","heading":"Reproducibility boundary"}],"status":"reported","subtitle":"2024","summary":"This record preserves the paper's basis-16 coordinates and the fact that its error figures refer to different operations or accounting boundaries. They must not be collapsed into one stronger failure guarantee; a lower failure target may require different polynomial degree, modulus, and decomposition basis.","title":"Basis-16 parameters for the encrypted 8-bit TFHE processor","type":"parameter_set","venue":null,"year":2024,"sourcePath":"data/he-catalog.json#HE-PARAM-TFHE-PROCESSOR-2024"},{"evidence":"repository_scope","id":"HE-TRACK-001","keywords":["bgv","bfv","exact-arithmetic"],"metadata":{"dossier_type":"research_track","evidence":"repository_scope","id":"HE-TRACK-001","keywords":["bgv","bfv","exact-arithmetic"],"status":"active","targets":["HE-OP-001","HE-OP-003","HE-OP-006"],"title":"Exact packed arithmetic track"},"primaryUrl":null,"sections":[{"content":"BGV and BFV are the main exact packed-arithmetic reference families; the track compares depth planning, RNS kernels, refresh, and integrity without mixing them with approximate semantics.","heading":"Current claim"}],"status":"active","subtitle":"","summary":"BGV and BFV are the main exact packed-arithmetic reference families; the track compares depth planning, RNS kernels, refresh, and integrity without mixing them with approximate semantics.","title":"Exact packed arithmetic track","type":"research_track","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-TRACK-001"},{"evidence":"repository_scope","id":"HE-TRACK-002","keywords":["ckks","approximate-arithmetic"],"metadata":{"dossier_type":"research_track","evidence":"repository_scope","id":"HE-TRACK-002","keywords":["ckks","approximate-arithmetic"],"status":"active","targets":["HE-OP-002","HE-OP-003","HE-OP-006"],"title":"Approximate numerical HE track"},"primaryUrl":null,"sections":[{"content":"CKKS is evaluated as an approximate numerical primitive whose precision, scale, packing, transforms, and bootstrap failure model are first-class fields.","heading":"Current claim"}],"status":"active","subtitle":"","summary":"CKKS is evaluated as an approximate numerical primitive whose precision, scale, packing, transforms, and bootstrap failure model are first-class fields.","title":"Approximate numerical HE track","type":"research_track","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-TRACK-002"},{"evidence":"repository_scope","id":"HE-TRACK-003","keywords":["fhew","tfhe","programmable-bootstrapping"],"metadata":{"dossier_type":"research_track","evidence":"repository_scope","id":"HE-TRACK-003","keywords":["fhew","tfhe","programmable-bootstrapping"],"status":"active","targets":["HE-OP-001","HE-OP-005","HE-OP-006"],"title":"Gate and programmable bootstrapping track"},"primaryUrl":null,"sections":[{"content":"FHEW and TFHE are compared by refresh latency, evaluation-key footprint, ciphertext conversion, lookup expressivity, packing, and word-level compilation.","heading":"Current claim"}],"status":"active","subtitle":"","summary":"FHEW and TFHE are compared by refresh latency, evaluation-key footprint, ciphertext conversion, lookup expressivity, packing, and word-level compilation.","title":"Gate and programmable bootstrapping track","type":"research_track","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-TRACK-003"},{"evidence":"primary_source_checked","id":"HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM","keywords":["atomic-result","foundations","privacy-homomorphism","encrypted-computation"],"metadata":{"claim_slug":"introduced-privacy-homomorphism-program","contribution_kind":"definition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"capability":["encrypted-computation-program"],"role":["definition"],"track":["theory"]},"historical_context":{"narrative":"Before this work, encryption and useful database computation were normally treated as opposing requirements: data had to be decrypted before it could be transformed. Rivest, Adleman, and Dertouzos instead formulated privacy homomorphisms, asking for encrypted representations on which selected operations could be performed without first revealing the underlying records. Their examples neither achieved modern semantic security nor supported arbitrary circuits, so this node is a problem definition rather than a secure FHE construction. Its publication-time significance was to make computation on protected data an explicit cryptographic interface and to expose the gap between preserving one algebraic operation and supporting general computation.","prior_boundary":"Conventional encryption protected stored data but required decryption before a database could perform useful transformations on it.","significance_at_publication":"Establishes the research question later separated into partial, somewhat, leveled, and fully homomorphic encryption, without itself supplying a modern secure general construction.","technical_delta":"Formulates the interface of storing ciphertexts while allowing designated operations to be carried out directly on their encrypted representations."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM","keywords":["foundations","privacy-homomorphism","encrypted-computation"],"limitations":["the proposed examples do not satisfy modern security definitions","arbitrary mixed circuits are not supported"],"paper_id":"HE-PAPER-1978-RAD","qualifiers":["historical 1978 terminology","problem formulation rather than a modern construction"],"source_locator":{"dossier_section":"HE-PAPER-1978-RAD § Atomic claims","primary_source":"Section I (Introduction), pp. 169–170","primary_source_url":"https://people.csail.mit.edu/rivest/pubs/RAD78.pdf","status":"section_checked"},"statement":"Rivest, Adleman, and Dertouzos formulate encrypted data processing as privacy homomorphisms that permit selected operations without exposing plaintexts.","statement_status":"source_normalized_statement","status":"published","title":"Defined the privacy-homomorphism computation program","work_id":"HE-PAPER-1978-RAD"},"primaryUrl":"https://people.csail.mit.edu/rivest/pubs/RAD78.pdf","sections":[{"content":"Defined the privacy-homomorphism computation program The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"On Data Banks and Privacy Homomorphisms","summary":"Rivest, Adleman, and Dertouzos formulate encrypted data processing as privacy homomorphisms that permit selected operations without exposing plaintexts.","title":"Defined the privacy-homomorphism computation program","type":"result","venue":"Foundations of Secure Computation","year":1978,"sourcePath":"data/he-catalog.json#HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM"},{"evidence":"primary_source_checked","id":"HE-RESULT-1999-PAILLIER-PRACTICAL-ADDITIVELY-HOMOMORPHIC-PUBLIC-KEY-ENCRYPTION","keywords":["atomic-result","partial-he","additive-homomorphism","composite-residuosity"],"metadata":{"claim_slug":"practical-additively-homomorphic-public-key-encryption","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"plaintext_operation":["addition"],"role":["capability"],"track":["theory"]},"historical_context":{"narrative":"The privacy-homomorphism program predated a clean, efficient public-key construction whose supported operation and limitation could both be stated precisely. Paillier uses composite-degree residuosity so that multiplying ciphertexts adds their plaintexts, and the additive operation can be repeated without introducing the noise-depth boundary of later lattice HE. This is an additive, not general, homomorphism: it does not evaluate arbitrary circuits containing both addition and multiplication. At publication, the scheme supplied a practical and mathematically crisp partial-HE baseline, showing that useful encrypted aggregation was attainable while leaving the general-computation boundary visibly unresolved.","prior_boundary":"Earlier privacy-homomorphism proposals did not provide a clean modern public-key construction with a well-scoped, repeatedly usable algebraic operation.","significance_at_publication":"Provides a canonical partial-homomorphism reference point, sharply separating useful unbounded addition from the still-open goal of mixed addition-and-multiplication circuits.","technical_delta":"Uses composite-degree residuosity to support repeated plaintext additions through ciphertext multiplication while retaining probabilistic public-key encryption."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-1999-PAILLIER-PRACTICAL-ADDITIVELY-HOMOMORPHIC-PUBLIC-KEY-ENCRYPTION","keywords":["partial-he","additive-homomorphism","composite-residuosity"],"limitations":["does not support arbitrary mixed arithmetic circuits","not a somewhat or fully homomorphic scheme"],"paper_id":"HE-PAPER-1999-PAILLIER","qualifiers":["public-key encryption","additive homomorphism","composite-degree residuosity"],"source_locator":{"dossier_section":"HE-PAPER-1999-PAILLIER § Atomic claims","primary_source":"Abstract; Section 4, Scheme 1 and homomorphic-property discussion, pp. 230–231","primary_source_url":"https://link.springer.com/chapter/10.1007/3-540-48910-X_16","status":"section_checked"},"statement":"Paillier encryption lets ciphertext multiplication realize addition of plaintexts, giving an efficient public-key scheme with an unbounded additive homomorphism.","statement_status":"source_normalized_statement","status":"published","title":"Unbounded plaintext addition in a public-key encryption scheme","work_id":"HE-PAPER-1999-PAILLIER"},"primaryUrl":"https://link.springer.com/chapter/10.1007/3-540-48910-X_16","sections":[{"content":"Unbounded plaintext addition in a public-key encryption scheme The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Public-Key Cryptosystems Based on Composite Degree Residuosity Classes","summary":"Paillier encryption lets ciphertext multiplication realize addition of plaintexts, giving an efficient public-key scheme with an unbounded additive homomorphism.","title":"Unbounded plaintext addition in a public-key encryption scheme","type":"result","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/he-catalog.json#HE-RESULT-1999-PAILLIER-PRACTICAL-ADDITIVELY-HOMOMORPHIC-PUBLIC-KEY-ENCRYPTION"},{"evidence":"primary_source_checked","id":"HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION","keywords":["atomic-result","fhe","first-feasibility","ideal-lattices"],"metadata":{"claim_slug":"first-fully-homomorphic-encryption","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"capability":["arbitrary-circuits"],"role":["first-feasibility"],"track":["theory"]},"historical_context":{"narrative":"Before 2009, homomorphic encryption was limited to one algebraic operation or bounded computation, and the existence of encryption supporting arbitrary circuits remained open. Gentry supplied the first construction by building a somewhat homomorphic ideal-lattice scheme, simplifying its decryption circuit, and then refreshing ciphertexts homomorphically. The resulting feasibility theorem did not imply practicality: the construction used squashing, large parameters, and ideal-lattice assumptions whose scope later work revisited. Its publication-time significance was nonetheless decisive—it changed FHE from an aspirational interface into a concrete cryptographic object and separated the existence question from the subsequent programs of assumption simplification and efficiency improvement.","prior_boundary":"Prior homomorphic schemes supported only restricted operations or bounded circuit families; no construction supported arbitrary computation while keeping data encrypted.","significance_at_publication":"Resolves the central feasibility question for fully homomorphic encryption, while leaving efficiency, assumptions, and the squashing step as major targets for subsequent work.","technical_delta":"Combines a noise-limited ideal-lattice scheme, a simplified decryption circuit, and homomorphic evaluation of that circuit to obtain arbitrary-depth evaluation."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION","keywords":["fhe","first-feasibility","ideal-lattices"],"limitations":["far from practical","uses squashing and additional assumption material"],"paper_id":"HE-PAPER-2009-GENTRY","qualifiers":["ideal-lattice construction","arbitrary circuit evaluation","bootstrapped from bounded-depth evaluation"],"source_locator":{"dossier_section":"HE-PAPER-2009-GENTRY § Atomic claims","primary_source":"STOC paper Sections 1 and 4; thesis overview and bootstrappable construction","primary_source_url":"https://crypto.stanford.edu/craig/craig-thesis.pdf","status":"section_checked"},"statement":"Gentry constructs the first fully homomorphic encryption scheme, enabling evaluation of arbitrary circuits by combining an ideal-lattice somewhat homomorphic scheme with bootstrapping.","statement_status":"source_normalized_statement","status":"published","title":"First encryption construction for arbitrary circuit evaluation","work_id":"HE-PAPER-2009-GENTRY"},"primaryUrl":"https://crypto.stanford.edu/craig/craig-thesis.pdf","sections":[{"content":"First encryption construction for arbitrary circuit evaluation The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Fully Homomorphic Encryption Using Ideal Lattices","summary":"Gentry constructs the first fully homomorphic encryption scheme, enabling evaluation of arbitrary circuits by combining an ideal-lattice somewhat homomorphic scheme with bootstrapping.","title":"First encryption construction for arbitrary circuit evaluation","type":"result","venue":"STOC 2009","year":2009,"sourcePath":"data/he-catalog.json#HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION"},{"evidence":"primary_source_checked","id":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","keywords":["atomic-result","bootstrapping","refresh","decryption-circuit"],"metadata":{"claim_slug":"introduced-bootstrapping-blueprint","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["bootstrapping"],"role":["mechanism"],"track":["theory"]},"historical_context":{"narrative":"Noise growth previously looked like an terminal depth limit: once a ciphertext exceeded its correctness budget, further evaluation was impossible. Gentry isolated bootstrappability as a reusable condition and showed that homomorphically evaluating an augmented decryption circuit produces a ciphertext of the same plaintext with a renewed budget. The original instantiation required squashed decryption and was prohibitively expensive, so the contribution is the mechanism and feasibility reduction rather than a practical refresh algorithm. At publication it reorganized FHE research around two separable tasks—construct a sufficiently capable bounded-depth scheme and make its decryption circuit cheap enough to evaluate—an architecture explicitly retained by later refresh systems.","prior_boundary":"Noise growth made existing candidate schemes cease decrypting correctly after a bounded number of operations, with no general mechanism for resetting that budget.","significance_at_publication":"Creates the reusable refresh blueprint that later integer, LWE/RLWE, gate-bootstrapping, and approximate-arithmetic lines instantiate with different decryption circuits and kernels.","technical_delta":"Turns decryption itself into an evaluated circuit so that a ciphertext is replaced by a fresh encryption of the same plaintext with a renewed noise budget."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","keywords":["bootstrapping","refresh","decryption-circuit"],"limitations":["does not by itself make bootstrapping efficient","the original proof uses squashed decryption"],"paper_id":"HE-PAPER-2009-GENTRY","qualifiers":["requires a bootstrappable or augmented-decryption-capable scheme","refresh preserves the plaintext"],"source_locator":{"dossier_section":"HE-PAPER-2009-GENTRY § Atomic claims","primary_source":"STOC paper bootstrapping theorem and decryption-circuit discussion; thesis Chapters 4–6","primary_source_url":"https://crypto.stanford.edu/craig/craig-thesis.pdf","status":"theorem_checked"},"statement":"A scheme that can homomorphically evaluate a suitable augmented form of its own decryption circuit can refresh noisy ciphertexts and be promoted from bounded-depth homomorphism to FHE.","statement_status":"source_normalized_statement","status":"published","title":"Bootstrapping bounded-depth HE by evaluating its decryption circuit","work_id":"HE-PAPER-2009-GENTRY"},"primaryUrl":"https://crypto.stanford.edu/craig/craig-thesis.pdf","sections":[{"content":"Bootstrapping bounded-depth HE by evaluating its decryption circuit The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Fully Homomorphic Encryption Using Ideal Lattices","summary":"A scheme that can homomorphically evaluate a suitable augmented form of its own decryption circuit can refresh noisy ciphertexts and be promoted from bounded-depth homomorphism to FHE.","title":"Bootstrapping bounded-depth HE by evaluating its decryption circuit","type":"result","venue":"STOC 2009","year":2009,"sourcePath":"data/he-catalog.json#HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT"},{"evidence":"abstract_checked","id":"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD","keywords":["atomic-result","integer-fhe","approximate-gcd","bootstrapping"],"metadata":{"claim_slug":"conceptually-simple-integer-fhe-from-agcd","contribution_kind":"construction","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"normalized","facets":{"assumption":["approximate-gcd"],"role":["construction"],"track":["theory"]},"historical_context":{"narrative":"Gentry's first FHE result left open whether its refresh architecture depended essentially on ideal lattices. DGHV gives a conceptually simpler instantiation over the integers: ciphertexts are approximate multiples of a secret integer, addition and multiplication grow an explicit noise term, and bootstrapping upgrades the bounded scheme. This change clarifies the mechanism but does not solve its concrete cost; the public key and ciphertexts are enormous, and the full security argument uses additional assumptions and evaluation material. At publication, the construction separated the bootstrapping blueprint from its first algebraic setting and provided an unusually transparent laboratory for reasoning about noise, depth, and refresh.","prior_boundary":"The first FHE construction intertwined bootstrapping with ideal-lattice arithmetic and a complicated geometric presentation.","significance_at_publication":"Demonstrates that bootstrapping is not tied to ideal lattices and makes noise growth and decryption especially transparent, though at very large concrete sizes.","technical_delta":"Replaces ideal-lattice ciphertexts with noisy approximate multiples of a secret integer while retaining a somewhat-homomorphic-to-bootstrapped-FHE path."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD","keywords":["integer-fhe","approximate-gcd","bootstrapping"],"limitations":["very large public keys and ciphertexts","full construction has additional assumption and circular-security caveats"],"paper_id":"HE-PAPER-2010-DGHV","qualifiers":["integer arithmetic","approximate-GCD family","bootstrapped FHE"],"source_locator":{"dossier_section":"HE-PAPER-2010-DGHV § Atomic claims","primary_source":"Abstract and Sections 1–4; exact theorem locator pending","primary_source_url":"https://eprint.iacr.org/2009/616","status":"abstract_checked"},"statement":"DGHV instantiates Gentry's bootstrapping blueprint with elementary integer arithmetic and security related to the approximate greatest common divisor problem.","statement_status":"source_normalized_statement","status":"published","title":"Integer FHE from approximate common divisors","work_id":"HE-PAPER-2010-DGHV"},"primaryUrl":"https://eprint.iacr.org/2009/616","sections":[{"content":"Integer FHE from approximate common divisors The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Fully Homomorphic Encryption over the Integers","summary":"DGHV instantiates Gentry's bootstrapping blueprint with elementary integer arithmetic and security related to the approximate greatest common divisor problem.","title":"Integer FHE from approximate common divisors","type":"result","venue":"EUROCRYPT 2010","year":2010,"sourcePath":"data/he-catalog.json#HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD"},{"evidence":"abstract_checked","id":"HE-RESULT-2011-BV-DIMENSION-MODULUS-REDUCTION-WITHOUT-SQUASHING","keywords":["atomic-result","lwe","modulus-reduction","dimension-reduction"],"metadata":{"claim_slug":"dimension-modulus-reduction-without-squashing","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"normalized","facets":{"mechanism":["dimension-modulus-reduction"],"role":["mechanism"],"track":["theory"]},"historical_context":{"narrative":"Gentry's first refresh construction made decryption evaluable by squashing it, introducing extra machinery and assumptions beyond the underlying lattice problem. The BV line instead uses dimension and modulus reduction to reshape LWE ciphertexts and their decryption computation without that squashing step. This contribution does not remove all evaluation material or circular-security questions, and it should not be read as a practical bootstrap by itself. Its publication-time significance was to show that the decryption bottleneck could be handled within standard-LWE-style transformations, reinforcing a modular program in which dimension, modulus, ciphertext form, and noise are managed explicitly.","prior_boundary":"The original bootstrap route simplified decryption through squashing and extra sparse-subset-sum-style assumptions, leaving assumption and circuit complexity intertwined.","significance_at_publication":"Shows that decryption-circuit management can be achieved within the LWE line and helps shift later work toward modulus and key-switching techniques rather than squashing.","technical_delta":"Uses dimension and modulus reduction to obtain a decryption circuit compatible with the LWE-based evaluation path while avoiding the earlier squashing mechanism."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2011-BV-DIMENSION-MODULUS-REDUCTION-WITHOUT-SQUASHING","keywords":["lwe","modulus-reduction","dimension-reduction"],"limitations":["does not eliminate bootstrapping for unbounded depth","does not settle circular-security treatment of evaluation keys"],"paper_id":"HE-PAPER-2011-BV","qualifiers":["LWE dimension and modulus transformation","avoids squashing"],"source_locator":{"dossier_section":"HE-PAPER-2011-BV § Atomic claims","primary_source":"Abstract and sections on dimension/modulus reduction; exact theorem locator pending","primary_source_url":"https://eprint.iacr.org/2011/344","status":"abstract_checked"},"statement":"The BV framework reduces LWE dimension and modulus to prepare ciphertexts for further homomorphic evaluation without using Gentry's squashed-decryption paradigm.","statement_status":"source_normalized_statement","status":"published","title":"Dimension–modulus reduction without squashed decryption","work_id":"HE-PAPER-2011-BV"},"primaryUrl":"https://eprint.iacr.org/2011/344","sections":[{"content":"Dimension–modulus reduction without squashed decryption The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Efficient Fully Homomorphic Encryption from (Standard) LWE","summary":"The BV framework reduces LWE dimension and modulus to prepare ciphertexts for further homomorphic evaluation without using Gentry's squashed-decryption paradigm.","title":"Dimension–modulus reduction without squashed decryption","type":"result","venue":"FOCS 2011","year":2011,"sourcePath":"data/he-catalog.json#HE-RESULT-2011-BV-DIMENSION-MODULUS-REDUCTION-WITHOUT-SQUASHING"},{"evidence":"abstract_checked","id":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","keywords":["atomic-result","lwe","somewhat-he","relinearization"],"metadata":{"claim_slug":"lwe-she-with-relinearization","contribution_kind":"construction","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"normalized","facets":{"mechanism":["relinearization"],"role":["construction"],"track":["theory"]},"historical_context":{"narrative":"Earlier FHE constructions were tied to ideal-lattice or approximate-GCD presentations, while ciphertext multiplication enlarged the algebraic representation and complicated further evaluation. Brakerski and Vaikuntanathan build a somewhat homomorphic scheme from standard LWE and introduce relinearization: after tensoring ciphertext components for multiplication, public evaluation material maps the result back to the base ciphertext form. The technique controls dimension, not all noise or depth costs, and an unbounded upgrade still needs refresh. At publication, this established standard LWE as a foundation for the main exact-arithmetic line and made ciphertext-shape management a reusable mechanism rather than a construction-specific trick.","prior_boundary":"Earlier FHE candidates either relied on ideal or approximate-GCD settings, and multiplication caused ciphertext representations to expand in ways that obstructed repeated evaluation.","significance_at_publication":"Moves a central FHE line to standard lattice assumptions and supplies a ciphertext-dimension-control technique inherited by exact-arithmetic descendants.","technical_delta":"Bases the bounded-depth scheme on standard LWE and introduces evaluation-key-assisted relinearization after tensor-product multiplication."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","keywords":["lwe","somewhat-he","relinearization"],"limitations":["unbounded evaluation still needs bootstrapping","evaluation material requires a separate security treatment"],"paper_id":"HE-PAPER-2011-BV","qualifiers":["standard LWE","bounded-depth somewhat homomorphic encryption","evaluation-key-assisted relinearization"],"source_locator":{"dossier_section":"HE-PAPER-2011-BV § Atomic claims","primary_source":"Abstract and construction overview; exact lemma locator pending","primary_source_url":"https://eprint.iacr.org/2011/344","status":"abstract_checked"},"statement":"Brakerski and Vaikuntanathan construct LWE-based somewhat homomorphic encryption and use relinearization to return post-multiplication ciphertexts to a controlled dimension.","statement_status":"source_normalized_statement","status":"published","title":"LWE somewhat-homomorphic multiplication with relinearization","work_id":"HE-PAPER-2011-BV"},"primaryUrl":"https://eprint.iacr.org/2011/344","sections":[{"content":"LWE somewhat-homomorphic multiplication with relinearization The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Efficient Fully Homomorphic Encryption from (Standard) LWE","summary":"Brakerski and Vaikuntanathan construct LWE-based somewhat homomorphic encryption and use relinearization to return post-multiplication ciphertexts to a controlled dimension.","title":"LWE somewhat-homomorphic multiplication with relinearization","type":"result","venue":"FOCS 2011","year":2011,"sourcePath":"data/he-catalog.json#HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION"},{"evidence":"primary_source_checked","id":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","keywords":["atomic-result","bgv","leveled-fhe","depth-planning"],"metadata":{"claim_slug":"leveled-fhe-without-bootstrapping","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"capability":["leveled-fhe"],"role":["capability"],"track":["theory"]},"historical_context":{"narrative":"Before BGV, bootstrapping dominated the conceptual path to FHE even when the target circuit depth was known in advance. BGV makes leveled FHE a complete construction goal: setup chooses a modulus chain for a predetermined depth, and ciphertexts descend that chain while evaluating the circuit, so no online refresh is required. The guarantee is not depth independent—larger depth changes parameters and evaluation material—and unrestricted evaluation still needs bootstrapping. At publication, this distinction redirected practical work toward depth planning, modulus management, and packing, because many applications could now be treated as complete homomorphic computations without paying the then-enormous bootstrap cost.","prior_boundary":"Earlier presentations treated bootstrapping as the route to general useful depth, even when an application circuit's depth was fixed before setup.","significance_at_publication":"Separates bounded but application-sufficient evaluation from unbounded FHE and establishes the dominant operational model for exact packed HE implementations.","technical_delta":"Makes leveled FHE a complete target: parameters depend on the chosen circuit depth, and evaluation proceeds through a planned modulus chain without online refresh."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","keywords":["bgv","leveled-fhe","depth-planning"],"limitations":["not depth-independent FHE without bootstrapping","requires depth-specific parameter planning"],"paper_id":"HE-PAPER-2012-BGV","qualifiers":["predetermined circuit depth","parameter size depends on depth","LWE/RLWE instantiations"],"source_locator":{"dossier_section":"HE-PAPER-2012-BGV § Atomic claims","primary_source":"Abstract; Sections 1.2 and 3; Theorem 3","primary_source_url":"https://eprint.iacr.org/2011/277","status":"theorem_checked"},"statement":"BGV evaluates any predetermined polynomial-size circuit without bootstrapping by selecting a depth-dependent modulus chain, while retaining bootstrapping only for depth-independent FHE.","statement_status":"source_normalized_statement","status":"published","title":"Predetermined-depth FHE evaluation without bootstrapping","work_id":"HE-PAPER-2012-BGV"},"primaryUrl":"https://eprint.iacr.org/2011/277","sections":[{"content":"Predetermined-depth FHE evaluation without bootstrapping The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Fully Homomorphic Encryption without Bootstrapping","summary":"BGV evaluates any predetermined polynomial-size circuit without bootstrapping by selecting a depth-dependent modulus chain, while retaining bootstrapping only for depth-independent FHE.","title":"Predetermined-depth FHE evaluation without bootstrapping","type":"result","venue":"ITCS 2012","year":2012,"sourcePath":"data/he-catalog.json#HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING"},{"evidence":"primary_source_checked","id":"HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT","keywords":["atomic-result","bgv","modulus-switching","noise-management"],"metadata":{"claim_slug":"modulus-switching-noise-management","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["modulus-switching"],"role":["mechanism"],"track":["theory"]},"historical_context":{"narrative":"LWE-based homomorphic multiplication consumes a finite noise budget, and keeping one modulus throughout evaluation gives poor depth growth. Brakerski and Vaikuntanathan had already introduced modulus switching inside a dimension-reduction procedure; BGV names and reuses that transformation iteratively. After multiplication, a ciphertext moves to the next smaller modulus so its absolute noise is scaled back down while one planned level is consumed. The method does not make depth free, and parameters still depend on the chosen circuit depth. Its publication-time significance was to make a calibrated modulus ladder the organizing mechanism of a complete leveled-FHE construction, rather than to claim first invention of modulus switching itself.","prior_boundary":"LWE ciphertext noise grew with homomorphic operations, and keeping one large modulus throughout evaluation gave an unfavorable depth and parameter tradeoff.","significance_at_publication":"Turns a one-shot ciphertext transformation into the organizing noise-management mechanism of a complete leveled-FHE construction and a reference point for later rescaling semantics.","technical_delta":"Reuses the BV modulus-switching transformation level by level along a calibrated decreasing modulus ladder, restoring the absolute noise after multiplication while consuming one planned level."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT","keywords":["bgv","modulus-switching","noise-management"],"limitations":["does not remove depth-dependent parameters","not itself a bootstrap"],"paper_id":"HE-PAPER-2012-BGV","qualifiers":["depth-indexed modulus chain","credits the underlying switching technique to Brakerski–Vaikuntanathan"],"source_locator":{"dossier_section":"HE-PAPER-2012-BGV § Atomic claims","primary_source":"Section 1.2, Modulus Switching; Lemma 1; Section 3","primary_source_url":"https://eprint.iacr.org/2011/277","status":"theorem_checked"},"statement":"BGV applies the preceding BV modulus-switching technique iteratively, moving ciphertexts through a decreasing modulus chain so multiplication noise is rescaled at each level of a predetermined-depth computation.","statement_status":"source_normalized_statement","status":"published","title":"Iterated modulus switching for depth-indexed noise management","work_id":"HE-PAPER-2012-BGV"},"primaryUrl":"https://eprint.iacr.org/2011/277","sections":[{"content":"Modulus switching for depth-indexed noise management The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Fully Homomorphic Encryption without Bootstrapping","summary":"BGV applies the preceding BV modulus-switching technique iteratively, moving ciphertexts through a decreasing modulus chain so multiplication noise is rescaled at each level of a predetermined-depth computation.","title":"Iterated modulus switching for depth-indexed noise management","type":"result","venue":"ITCS 2012","year":2012,"sourcePath":"data/he-catalog.json#HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT"},{"evidence":"abstract_checked","id":"HE-RESULT-2012-BRAKERSKI-SCALE-INVARIANT-FHE-WITH-LINEAR-NOISE-GROWTH","keywords":["atomic-result","scale-invariant","tensoring","noise-growth"],"metadata":{"claim_slug":"scale-invariant-fhe-with-linear-noise-growth","contribution_kind":"optimization","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"normalized","facets":{"resource":["noise-growth"],"role":["optimization"],"track":["theory"]},"historical_context":{"narrative":"BGV controlled homomorphic depth by moving ciphertexts down a modulus chain, while direct multiplication in earlier LWE schemes could make the noise grow quadratically. Brakerski changes that invariant through tensoring, obtaining linear growth in the prior noise and a scale-invariant construction that uses one modulus. The result is principally a theoretical and asymptotic simplification; it does not imply that the single-modulus design dominates RNS modulus-chain implementations in concrete workloads. At publication, it demonstrated that noise management was not synonymous with modulus switching and opened a separate design direction centered on the algebra of multiplication itself.","prior_boundary":"The BGV route managed depth by descending a modulus chain, and more direct multiplication analyses incurred quadratic growth in the ciphertext noise.","significance_at_publication":"Establishes an alternative conceptual axis for depth management: improve the multiplication invariant instead of reducing modulus after each level.","technical_delta":"Changes the multiplication invariant through tensoring so the noise grows linearly and a single-modulus, scale-invariant construction becomes possible."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2012-BRAKERSKI-SCALE-INVARIANT-FHE-WITH-LINEAR-NOISE-GROWTH","keywords":["scale-invariant","tensoring","noise-growth"],"limitations":["conceptual result rather than a normalized implementation comparison","unbounded depth still requires refresh"],"paper_id":"HE-PAPER-2012-BRAKERSKI","qualifiers":["standard LWE / classical GapSVP reduction","single modulus","linear multiplication-noise growth"],"source_locator":{"dossier_section":"HE-PAPER-2012-BRAKERSKI § Atomic claims","primary_source":"Abstract and construction overview","primary_source_url":"https://eprint.iacr.org/2012/078","status":"abstract_checked"},"statement":"Brakerski uses tensoring to obtain multiplication noise that grows linearly in the old noise and constructs a scale-invariant LWE scheme with one modulus rather than a modulus-switching chain.","statement_status":"source_normalized_statement","status":"published","title":"Single-modulus leveled FHE with linear multiplication-noise growth","work_id":"HE-PAPER-2012-BRAKERSKI"},"primaryUrl":"https://eprint.iacr.org/2012/078","sections":[{"content":"Single-modulus leveled FHE with linear multiplication-noise growth The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Fully Homomorphic Encryption without Modulus Switching from Classical GapSVP","summary":"Brakerski uses tensoring to obtain multiplication noise that grows linearly in the old noise and constructs a scale-invariant LWE scheme with one modulus rather than a modulus-switching chain.","title":"Single-modulus leveled FHE with linear multiplication-noise growth","type":"result","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/he-catalog.json#HE-RESULT-2012-BRAKERSKI-SCALE-INVARIANT-FHE-WITH-LINEAR-NOISE-GROWTH"},{"evidence":"abstract_checked","id":"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION","keywords":["atomic-result","bfv","rlwe","exact-arithmetic"],"metadata":{"claim_slug":"rlwe-exact-arithmetic-scheme-with-relinearization","contribution_kind":"construction","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"normalized","facets":{"role":["construction"],"semantics":["exact-modular"],"track":["theory"]},"historical_context":{"narrative":"LWE relinearization had supplied a general technique, but implementers still needed a compact ring-based construction with explicit exact plaintext arithmetic. Fan and Vercauteren present an RLWE scheme whose ciphertext multiplication is followed by relinearization, preserving exact modular semantics up to the scheme's noise bound. The base construction remains depth bounded, and its practical profile depends on later RNS representations, packing, and parameter selection; it is not an unbounded FHE engine by itself. At publication, the work crystallized the family now called BFV and provided a durable exact-arithmetic design point alongside BGV for later software and standardization efforts.","prior_boundary":"LWE relinearization and leveled techniques existed, but a compact ring-based construction tailored to exact modular arithmetic and implementation was still being consolidated.","significance_at_publication":"Establishes the construction family now commonly called BFV, one of the principal exact-arithmetic alternatives to BGV in libraries and parameter standards.","technical_delta":"Specializes the lattice HE line to packed polynomial-ring ciphertexts with exact plaintext-ring semantics and relinearized multiplication."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION","keywords":["bfv","rlwe","exact-arithmetic"],"limitations":["depth bounded without bootstrapping","concrete efficiency depends on later representation choices"],"paper_id":"HE-PAPER-2012-FV","qualifiers":["RLWE","exact modular plaintext arithmetic","relinearized multiplication"],"source_locator":{"dossier_section":"HE-PAPER-2012-FV § Atomic claims","primary_source":"Abstract and scheme description; exact theorem locator pending","primary_source_url":"https://eprint.iacr.org/2012/144","status":"abstract_checked"},"statement":"Fan and Vercauteren give an RLWE-based somewhat homomorphic construction for exact modular arithmetic with practical ciphertext multiplication and relinearization.","statement_status":"source_normalized_statement","status":"published","title":"RLWE exact modular arithmetic with relinearized multiplication","work_id":"HE-PAPER-2012-FV"},"primaryUrl":"https://eprint.iacr.org/2012/144","sections":[{"content":"RLWE exact modular arithmetic with relinearized multiplication The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Somewhat Practical Fully Homomorphic Encryption","summary":"Fan and Vercauteren give an RLWE-based somewhat homomorphic construction for exact modular arithmetic with practical ciphertext multiplication and relinearization.","title":"RLWE exact modular arithmetic with relinearized multiplication","type":"result","venue":"IACR ePrint 2012/144","year":2012,"sourcePath":"data/he-catalog.json#HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION"},{"evidence":"primary_source_checked","id":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","keywords":["atomic-result","aes","packed-he","end-to-end-evaluation"],"metadata":{"claim_slug":"end-to-end-evaluation-of-aes-with-packed-lhe","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"role":["implementation-result"],"track":["practice"],"workload":["aes"]},"historical_context":{"narrative":"Leveled FHE and SIMD packing had made individual ingredients look promising, but the cost of composing them for a substantial circuit remained unclear. Gentry, Halevi, and Smart build an end-to-end AES evaluation pipeline using packed ciphertexts, CRT representation, key switching, and depth-aware modulus planning, with a route to continue through bootstrapping. The result is a historical feasibility demonstration, not a hardware-normalized score against modern libraries, and its performance is tied to the chosen circuit and parameters. At publication, it forced HE evaluation to account for full workloads and exposed where representation, data movement, evaluation keys, and refresh dominate beyond asymptotic gate counts.","prior_boundary":"Leveled FHE and SIMD techniques had improved individual mechanisms, but their combined cost on a recognizable large cryptographic circuit was not yet exposed end to end.","significance_at_publication":"Turns abstract construction costs into an application-level systems profile and identifies memory, rotations, key switching, and refresh as distinct bottlenecks.","technical_delta":"Instantiates a BGV-style pipeline for AES, coordinating packing, CRT arithmetic, key switching, modulus planning, and an optional bootstrapped continuation."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","keywords":["aes","packed-he","end-to-end-evaluation"],"limitations":["historical hardware and parameters are not normalized","circuit-specific planning is required"],"paper_id":"HE-PAPER-2012-GHS-AES","qualifiers":["packed BGV-style leveled HE","AES circuit","paper-reported implementation"],"source_locator":{"dossier_section":"HE-PAPER-2012-GHS-AES § Atomic claims","primary_source":"Sections 3–4; Section 4.4 and Table 1","primary_source_url":"https://eprint.iacr.org/2012/099","status":"section_checked"},"statement":"Gentry, Halevi, and Smart combine packed leveled HE, CRT representation, key switching, and circuit planning to carry out an end-to-end homomorphic AES evaluation.","statement_status":"source_normalized_statement","status":"published","title":"End-to-end packed leveled-HE evaluation of AES","work_id":"HE-PAPER-2012-GHS-AES"},"primaryUrl":"https://eprint.iacr.org/2012/099","sections":[{"content":"End-to-end packed leveled-HE evaluation of AES The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Homomorphic Evaluation of the AES Circuit","summary":"Gentry, Halevi, and Smart combine packed leveled HE, CRT representation, key switching, and circuit planning to carry out an end-to-end homomorphic AES evaluation.","title":"End-to-end packed leveled-HE evaluation of AES","type":"result","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/he-catalog.json#HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE"},{"evidence":"primary_source_checked","id":"HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION","keywords":["atomic-result","simd","packing","parallel-recryption"],"metadata":{"claim_slug":"ciphertext-slot-packing-and-parallel-recryption","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["simd-packing"],"role":["mechanism"],"track":["theory","practice"]},"historical_context":{"narrative":"Early FHE ciphertexts were algebraically large while carrying little application data, and the efficient parameter choices then available did not retain the SIMD structure previously suggested. Smart and Vercauteren choose plaintext-ring parameters whose CRT decomposition encodes many finite-field elements as slots, so one homomorphic circuit acts componentwise across them; they also exploit that structure to parallelize recryption. All slots still follow the same circuit shape, and rotations or data-dependent movement require additional machinery. At publication, this made amortized throughput per slot, rather than latency per ciphertext alone, a first-class HE metric and supplied the packing vocabulary inherited by exact and approximate arithmetic systems.","prior_boundary":"Early FHE ciphertexts carried small plaintexts relative to their algebraic size, and the efficient key-generation parameters then in use did not preserve the proposed SIMD structure.","significance_at_publication":"Changes the relevant efficiency unit from one ciphertext operation to amortized work per slot and makes layout and rotations central HE design concerns.","technical_delta":"Restores a CRT slot decomposition compatible with practical key generation and shows both componentwise evaluation and a recryption procedure operating across slots in parallel."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION","keywords":["simd","packing","parallel-recryption"],"limitations":["data-dependent access is not native","rotations and repacking require extra transformations and keys"],"paper_id":"HE-PAPER-2012-SV-SIMD","qualifiers":["CRT plaintext slots","same circuit applied componentwise","parallel recryption"],"source_locator":{"dossier_section":"HE-PAPER-2012-SV-SIMD § Atomic claims","primary_source":"Abstract; Introduction; Sections 3–5","primary_source_url":"https://eprint.iacr.org/2011/133","status":"section_checked"},"statement":"Smart and Vercauteren select plaintext-ring parameters that encode many field elements as slots, evaluate one circuit across them, and use the SIMD structure to parallelize recryption.","statement_status":"source_normalized_statement","status":"published","title":"SIMD ciphertext slots with parallelized recryption","work_id":"HE-PAPER-2012-SV-SIMD"},"primaryUrl":"https://eprint.iacr.org/2011/133","sections":[{"content":"SIMD ciphertext slots with parallelized recryption The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Fully Homomorphic SIMD Operations","summary":"Smart and Vercauteren select plaintext-ring parameters that encode many field elements as slots, evaluate one circuit across them, and use the SIMD structure to parallelize recryption.","title":"SIMD ciphertext slots with parallelized recryption","type":"result","venue":"Designs, Codes and Cryptography","year":2012,"sourcePath":"data/he-catalog.json#HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION"},{"evidence":"primary_source_checked","id":"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","keywords":["atomic-result","gsw","lwe","matrix-ciphertext"],"metadata":{"claim_slug":"approximate-eigenvector-gsw-ciphertexts","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["approximate-eigenvector"],"role":["construction"],"track":["theory"]},"historical_context":{"narrative":"Earlier LWE-based multiplication formed a larger tensor-product ciphertext and then relinearized it with evaluation material. GSW replaces that representation with matrices for which the secret vector behaves as an approximate eigenvector; gadget decomposition lets matrix-style operations preserve the decryption invariant more directly. Raw GSW ciphertexts are large, and the contribution does not by itself deliver a compact practical FHE implementation. At publication, it provided a conceptually different LWE architecture and a reusable ciphertext-operation interface. The evidence-backed FHEW and TFHE line later uses GSW- or RingGSW-type operations as a core of fast gate refresh.","prior_boundary":"Earlier LWE schemes multiplied tensor products and then used evaluation-key-assisted relinearization to return ciphertexts to a manageable form.","significance_at_publication":"Introduces the matrix and external-product viewpoint that later fast gate-bootstrapping systems use as an algebraic core.","technical_delta":"Encodes ciphertexts as approximate-eigenvector matrices and uses gadget decomposition so multiplication preserves the ciphertext invariant directly."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","keywords":["gsw","lwe","matrix-ciphertext"],"limitations":["raw ciphertexts are large","practical descendants use ring variants and ciphertext-type switching"],"paper_id":"HE-PAPER-2013-GSW","qualifiers":["LWE","matrix ciphertexts","approximate eigenvector invariant"],"source_locator":{"dossier_section":"HE-PAPER-2013-GSW § Atomic claims","primary_source":"Abstract; Section 1.2; Section 3","primary_source_url":"https://eprint.iacr.org/2013/340","status":"section_checked"},"statement":"GSW represents LWE ciphertexts as matrices for which the secret key is an approximate eigenvector, enabling a direct homomorphic multiplication rule.","statement_status":"source_normalized_statement","status":"published","title":"Approximate-eigenvector matrix ciphertexts for LWE FHE","work_id":"HE-PAPER-2013-GSW"},"primaryUrl":"https://eprint.iacr.org/2013/340","sections":[{"content":"Approximate-eigenvector matrix ciphertexts for LWE FHE The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Homomorphic Encryption from Learning with Errors: Conceptually-Simpler, Asymptotically-Faster, Attribute-Based","summary":"GSW represents LWE ciphertexts as matrices for which the secret key is an approximate eigenvector, enabling a direct homomorphic multiplication rule.","title":"Approximate-eigenvector matrix ciphertexts for LWE FHE","type":"result","venue":"CRYPTO 2013","year":2013,"sourcePath":"data/he-catalog.json#HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS"},{"evidence":"primary_source_checked","id":"HE-RESULT-2013-GSW-MULTIPLICATION-WITHOUT-RELINEARIZATION","keywords":["atomic-result","gsw","multiplication","no-relinearization"],"metadata":{"claim_slug":"multiplication-without-relinearization","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["gadget-matrix-multiplication"],"role":["mechanism"],"track":["theory"]},"historical_context":{"narrative":"BV-style LWE multiplication expands a ciphertext through tensoring and then relies on relinearization to return it to the base form. GSW changes the representation: approximate-eigenvector matrix ciphertexts and gadget decomposition let multiplication remain within the same algebraic type, so there is no separate post-product relinearization step. This does not mean multiplication is free or that evaluation keys disappear from every descendant; the matrices and decomposition are expensive, and later systems switch among ciphertext types. At publication, the result demonstrated that ciphertext-dimension management could be encoded in the invariant rather than repaired after multiplication, creating a mechanism distinct from the BGV/BFV line.","prior_boundary":"BV-style LWE multiplication enlarged ciphertext dimension and required a separate relinearization map and evaluation material after each product.","significance_at_publication":"Shows that ciphertext-shape control can be designed into the representation itself, though at the cost of large matrix ciphertexts and decomposition work.","technical_delta":"Changes the ciphertext invariant so multiplication is expressed through matrix and gadget operations that remain within the GSW representation."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2013-GSW-MULTIPLICATION-WITHOUT-RELINEARIZATION","keywords":["gsw","multiplication","no-relinearization"],"limitations":["large matrix ciphertexts","does not imply lower concrete cost for general arithmetic"],"paper_id":"HE-PAPER-2013-GSW","qualifiers":["GSW matrix ciphertext invariant","no separate post-product relinearization"],"source_locator":{"dossier_section":"HE-PAPER-2013-GSW § Atomic claims","primary_source":"Section 1.2 and Section 3, homomorphic multiplication","primary_source_url":"https://eprint.iacr.org/2013/340","status":"section_checked"},"statement":"The GSW approximate-eigenvector invariant lets homomorphic multiplication stay in the same matrix ciphertext form without the post-product relinearization step used by BV-style schemes.","statement_status":"source_normalized_statement","status":"published","title":"Ciphertext multiplication without post-product relinearization","work_id":"HE-PAPER-2013-GSW"},"primaryUrl":"https://eprint.iacr.org/2013/340","sections":[{"content":"Ciphertext multiplication without post-product relinearization The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Homomorphic Encryption from Learning with Errors: Conceptually-Simpler, Asymptotically-Faster, Attribute-Based","summary":"The GSW approximate-eigenvector invariant lets homomorphic multiplication stay in the same matrix ciphertext form without the post-product relinearization step used by BV-style schemes.","title":"Ciphertext multiplication without post-product relinearization","type":"result","venue":"CRYPTO 2013","year":2013,"sourcePath":"data/he-catalog.json#HE-RESULT-2013-GSW-MULTIPLICATION-WITHOUT-RELINEARIZATION"},{"evidence":"primary_source_checked","id":"HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE","keywords":["atomic-result","implementation","bgv","aes"],"metadata":{"claim_slug":"realized-packed-bgv-aes-prototype","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"artifact":["paper-described-prototype"],"role":["implementation-result"],"track":["practice"]},"historical_context":{"narrative":"The 2012 paper had established end-to-end AES feasibility, but its later implementation line still needed a stable systems identity distinct from the original technical result. The January 2015 update realizes a packed BGV-style pipeline in HElib, combining CRT representation, slots, key switching, and circuit-specific modulus planning. This implementation contribution remains separate from its two parameterized benchmark observations. HElib is public, but the dossier has not pinned the exact historical revision or reproduced the Ubuntu 14.04 build. The update mattered because it converted the earlier feasibility claim into an explicit library-backed pipeline without backdating its improved measurements to 2012.","prior_boundary":"Construction and packing results did not establish that their representations, keys, and circuit schedule could be assembled into one executing AES workload.","significance_at_publication":"Creates a theory-to-practice bridge for the AES result while leaving the exact historical HElib revision and a reproducible build unresolved in the dossier.","technical_delta":"Provides a paper-described prototype for the complete packed-BGV evaluation pipeline and binds the architecture to a concrete implementation identity."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE","keywords":["implementation","bgv","aes"],"limitations":["exact historical HElib revision and build not normalized","historical platform prevents direct modern ranking"],"paper_id":"HE-PAPER-2012-GHS-AES","qualifiers":["paper-described research prototype","packed BGV-style AES pipeline"],"source_locator":{"dossier_section":"HE-PAPER-2012-GHS-AES § Atomic claims","primary_source":"January 3, 2015 updated report; Sections 1 and 4; Section 4.4","primary_source_url":"https://eprint.iacr.org/2012/099","status":"section_checked"},"statement":"The paper realizes its packed leveled-HE AES pipeline in a research prototype combining CRT representation, SIMD slots, key switching, and circuit-specific modulus planning.","statement_status":"source_normalized_statement","status":"published","title":"Paper-described packed-BGV AES prototype","work_id":"HE-PAPER-2012-GHS-AES","year":2015},"primaryUrl":"https://eprint.iacr.org/2012/099","sections":[{"content":"Paper-described packed-BGV AES prototype The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Homomorphic Evaluation of the AES Circuit","summary":"The paper realizes its packed leveled-HE AES pipeline in a research prototype combining CRT representation, SIMD slots, key switching, and circuit-specific modulus planning.","title":"Paper-described packed-BGV AES prototype","type":"result","venue":"CRYPTO 2012","year":2015,"sourcePath":"data/he-catalog.json#HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE"},{"evidence":"primary_source_checked","id":"HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE","keywords":["atomic-result","implementation","fhew","gate-bootstrap"],"metadata":{"claim_slug":"realized-fhew-gate-bootstrap-prototype","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"artifact":["research-prototype"],"role":["implementation-result"],"track":["practice"]},"historical_context":{"narrative":"A gate-refresh mechanism does not establish its concrete cost until an executable realization fixes arithmetic kernels, parameters, and evaluation-key handling. The FHEW prototype implements the paper's LWE/GSW-style path and is the artifact underlying its reported roughly half-second binary operation. This record does not claim that the version is reproduced here or that its performance is comparable to modern hardware; code-version provenance remains only at the paper-artifact level. At publication, the prototype made the new gate-bootstrap execution model inspectable and supplied a stable bridge between the construction contribution and a contextual measurement rather than treating the paper, software, and latency number as one object.","prior_boundary":"Theoretical gate-refresh mechanisms needed an executable artifact before their cost, key footprint, and implementation bottlenecks could be inspected concretely.","significance_at_publication":"Makes later replacement or reproduction of the implementation traceable without conflating an artifact version with the FHEW construction or its theorem.","technical_delta":"Implements the FHEW bootstrap path as a distinct artifact identity linked to the construction and its contextual latency observation."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE","keywords":["implementation","fhew","gate-bootstrap"],"limitations":["exact repository version not normalized","not independently reproduced in this dossier"],"paper_id":"HE-PAPER-2015-FHEW","qualifiers":["research prototype","FHEW gate bootstrapping","paper-artifact lineage"],"source_locator":{"dossier_section":"HE-PAPER-2015-FHEW § Atomic claims","primary_source":"Implementation and performance sections; artifact lineage in the paper","primary_source_url":"https://eprint.iacr.org/2014/816","status":"primary_source_checked"},"statement":"The FHEW research prototype realizes the paper's LWE/GSW-style gate-refresh path used for its reported subsecond binary operation.","statement_status":"source_normalized_statement","status":"published","title":"FHEW reference prototype for bootstrapped binary gates","work_id":"HE-PAPER-2015-FHEW"},"primaryUrl":"https://eprint.iacr.org/2014/816","sections":[{"content":"FHEW reference prototype for bootstrapped binary gates The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"FHEW: Bootstrapping Homomorphic Encryption in Less Than a Second","summary":"The FHEW research prototype realizes the paper's LWE/GSW-style gate-refresh path used for its reported subsecond binary operation.","title":"FHEW reference prototype for bootstrapped binary gates","type":"result","venue":"EUROCRYPT 2015","year":2015,"sourcePath":"data/he-catalog.json#HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE"},{"evidence":"primary_source_checked","id":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","keywords":["atomic-result","fhew","gate-bootstrap","subsecond"],"metadata":{"claim_slug":"subsecond-single-gate-bootstrapping","contribution_kind":"measurement_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"resource":["gate-bootstrap-latency"],"role":["implementation-result"],"track":["practice","measurement"]},"historical_context":{"narrative":"Bootstrapping made arbitrary depth possible, but its cost still discouraged treating refresh as an ordinary operation. FHEW reorganizes the computation around a single binary gate whose evaluation and refresh are combined through LWE and GSW-type operations, reporting roughly half a second in the paper's personal-computer setting. The number is contextual rather than a modern cross-platform benchmark, and the bootstrapping key remains large; packed or word-level workloads need additional techniques. At publication, the result changed the plausible execution model for FHE by making repeated gate bootstrap a concrete systems target instead of only a theoretical completion step.","prior_boundary":"Bootstrapping had established arbitrary-depth feasibility but remained too slow to serve as a routine operation in gate-by-gate computation.","significance_at_publication":"Shifts the practical target from occasional refresh of large arithmetic circuits to frequent bootstrapped Boolean operations, while retaining large-key and word-level limitations.","technical_delta":"Specializes refresh around LWE and GSW-type operations so one binary gate is evaluated and bootstrapped together, with a reported subsecond latency."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","keywords":["fhew","gate-bootstrap","subsecond"],"limitations":["large bootstrapping key","not a normalized modern benchmark","word arithmetic requires additional structure"],"paper_id":"HE-PAPER-2015-FHEW","qualifiers":["single binary gate","paper-reported personal-computer setting","roughly 0.5-second refresh"],"source_locator":{"dossier_section":"HE-PAPER-2015-FHEW § Atomic claims","primary_source":"Abstract and implementation results","primary_source_url":"https://eprint.iacr.org/2014/816","status":"primary_source_checked"},"statement":"FHEW combines evaluation of a simple binary operation with ciphertext refresh in roughly half a second on the paper's personal-computer setting.","statement_status":"source_normalized_statement","status":"published","title":"Roughly half-second bootstrapped binary-gate evaluation","work_id":"HE-PAPER-2015-FHEW"},"primaryUrl":"https://eprint.iacr.org/2014/816","sections":[{"content":"Roughly half-second bootstrapped binary-gate evaluation The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"FHEW: Bootstrapping Homomorphic Encryption in Less Than a Second","summary":"FHEW combines evaluation of a simple binary operation with ciphertext refresh in roughly half a second on the paper's personal-computer setting.","title":"Roughly half-second bootstrapped binary-gate evaluation","type":"result","venue":"EUROCRYPT 2015","year":2015,"sourcePath":"data/he-catalog.json#HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING"},{"evidence":"primary_source_checked","id":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","keywords":["atomic-result","tfhe","external-product","ringgsw"],"metadata":{"claim_slug":"external-product-tfhe-bootstrapping","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["external-product"],"role":["mechanism"],"track":["theory","practice"]},"historical_context":{"narrative":"FHEW established that bootstrapped gates could run in under a second, but its refresh kernel and bootstrapping-key footprint remained substantial. TFHE reformulates that path through an external product between LWE and RingGSW-style ciphertexts, using explicit ciphertext-type switching to implement the accumulator and refresh operations. The mechanism is tailored to gate-style computation and does not automatically provide the packing behavior of RLWE arithmetic schemes. At publication, the external-product design made the concrete bootstrap kernel itself a reusable object of study and supplied the algebraic base for the later circuit- and programmable-bootstrapping branch.","prior_boundary":"FHEW showed subsecond gate refresh, but its concrete kernel and bootstrapping-key footprint left substantial latency and memory costs.","significance_at_publication":"Establishes the external-product kernel that defines the TFHE family and underlies its later functional and programmable bootstrapping extensions.","technical_delta":"Uses ciphertext-type switching and an LWE–RingGSW external product to implement the core accumulator and refresh operations more efficiently."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","keywords":["tfhe","external-product","ringgsw"],"limitations":["native SIMD and word arithmetic remain separate problems","kernel costs are parameter and platform dependent"],"paper_id":"HE-PAPER-2016-TFHE","qualifiers":["LWE and RingGSW ciphertext types","gate-bootstrap kernel","evaluation-key-assisted"],"source_locator":{"dossier_section":"HE-PAPER-2016-TFHE § Atomic claims","primary_source":"Abstract and introduction; external-product construction sections","primary_source_url":"https://eprint.iacr.org/2016/870","status":"primary_source_checked"},"statement":"TFHE reformulates the FHEW refresh path around an external product between LWE and RingGSW-style ciphertexts, changing both the bootstrap kernel and evaluation-key profile.","statement_status":"source_normalized_statement","status":"published","title":"LWE–RingGSW external-product bootstrapping kernel","work_id":"HE-PAPER-2016-TFHE"},"primaryUrl":"https://eprint.iacr.org/2016/870","sections":[{"content":"LWE–RingGSW external-product bootstrapping kernel The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Faster Fully Homomorphic Encryption: Bootstrapping in Less Than 0.1 Seconds","summary":"TFHE reformulates the FHEW refresh path around an external product between LWE and RingGSW-style ciphertexts, changing both the bootstrap kernel and evaluation-key profile.","title":"LWE–RingGSW external-product bootstrapping kernel","type":"result","venue":"ASIACRYPT 2016","year":2016,"sourcePath":"data/he-catalog.json#HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING"},{"evidence":"primary_source_checked","id":"HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE","keywords":["atomic-result","implementation","tfhe","external-product"],"metadata":{"claim_slug":"realized-tfhe-external-product-prototype","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"artifact":["research-prototype"],"role":["implementation-result"],"track":["practice"]},"historical_context":{"narrative":"The external-product redesign changes the bootstrap algorithm, but concrete latency also depends on ciphertext layout, decomposition, key handling, and machine kernels. The TFHE prototype fixes those choices and realizes the LWE–RingGSW path used by the paper's reported sub-tenth-second refresh result. The dossier does not treat that source-reported artifact as independently reproduced, and its exact repository version is not normalized here. At publication, the implementation demonstrated that the algorithmic change survived engineering and supplied a clean bridge from the mechanism to its measurement, while preserving the distinction between a construction family, a software artifact, and one performance context.","prior_boundary":"The external-product redesign was an algorithmic claim until an implementation fixed ciphertext layouts, decomposition, key handling, and platform-specific kernels.","significance_at_publication":"Separates the reusable external-product mechanism from one software realization and one contextual measurement, enabling later artifacts to optimize the same object without rewriting the construction history.","technical_delta":"Provides the concrete prototype identity that instantiates the TFHE construction and supports the paper's reported latency and evaluation-key observations."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE","keywords":["implementation","tfhe","external-product"],"limitations":["exact repository version not normalized","not independently reproduced here"],"paper_id":"HE-PAPER-2016-TFHE","qualifiers":["research prototype","LWE–RingGSW external product","paper-artifact lineage"],"source_locator":{"dossier_section":"HE-PAPER-2016-TFHE § Atomic claims","primary_source":"Implementation and performance sections; artifact lineage in the paper","primary_source_url":"https://eprint.iacr.org/2016/870","status":"primary_source_checked"},"statement":"The TFHE prototype realizes the LWE–RingGSW external-product kernel used in the paper's sub-tenth-second gate-refresh measurement.","statement_status":"source_normalized_statement","status":"published","title":"TFHE prototype for the external-product bootstrap kernel","work_id":"HE-PAPER-2016-TFHE"},"primaryUrl":"https://eprint.iacr.org/2016/870","sections":[{"content":"TFHE prototype for the external-product bootstrap kernel The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Faster Fully Homomorphic Encryption: Bootstrapping in Less Than 0.1 Seconds","summary":"The TFHE prototype realizes the LWE–RingGSW external-product kernel used in the paper's sub-tenth-second gate-refresh measurement.","title":"TFHE prototype for the external-product bootstrap kernel","type":"result","venue":"ASIACRYPT 2016","year":2016,"sourcePath":"data/he-catalog.json#HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE"},{"evidence":"primary_source_checked","id":"HE-RESULT-2016-TFHE-SUB-TENTH-SECOND-GATE-REFRESH","keywords":["atomic-result","tfhe","gate-refresh","sub-tenth-second"],"metadata":{"claim_slug":"sub-tenth-second-gate-refresh","contribution_kind":"measurement_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"resource":["gate-bootstrap-latency"],"role":["measurement-result"],"track":["measurement"]},"historical_context":{"narrative":"FHEW's roughly half-second refresh made bootstrapped gates plausible, yet repeated Boolean evaluation still paid substantial latency and bootstrapping-key cost. The TFHE prototype realizes the LWE–RingGSW external-product kernel and reports refresh below 0.1 seconds, together with a reduced evaluation-key profile relative to the cited FHEW configuration. This is a source-reported historical observation, not a reproduced or hardware-normalized score, and it applies to the paper's single-gate parameters rather than arbitrary word workloads. At publication, the measurement established a new concrete latency point and validated the external-product redesign as more than an asymptotic change.","prior_boundary":"FHEW's roughly half-second gate refresh was a breakthrough, but latency and a large bootstrapping key still constrained repeated Boolean evaluation.","significance_at_publication":"Moves gate bootstrapping from subsecond to sub-tenth-second reported latency, while making clear that hardware, security parameters, key memory, and failure settings belong to the measurement context.","technical_delta":"Implements the external-product kernel and reports a sub-tenth-second refresh point together with a smaller evaluation-key profile in the paper's parameters."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2016-TFHE-SUB-TENTH-SECOND-GATE-REFRESH","keywords":["tfhe","gate-refresh","sub-tenth-second"],"limitations":["not independently reproduced here","not comparable without matched security, memory, and hardware"],"paper_id":"HE-PAPER-2016-TFHE","qualifiers":["single-gate refresh","paper-reported CPU and parameters","latency below 0.1 seconds"],"source_locator":{"dossier_section":"HE-PAPER-2016-TFHE § Atomic claims","primary_source":"Abstract and performance section","primary_source_url":"https://eprint.iacr.org/2016/870","status":"primary_source_checked"},"statement":"The TFHE prototype reports bootstrapping below 0.1 seconds for its single-gate refresh setting while reducing the evaluation-key size relative to the cited FHEW point.","statement_status":"source_normalized_statement","status":"published","title":"Reported sub-0.1-second TFHE gate refresh","work_id":"HE-PAPER-2016-TFHE"},"primaryUrl":"https://eprint.iacr.org/2016/870","sections":[{"content":"Reported sub-0.1-second TFHE gate refresh The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Faster Fully Homomorphic Encryption: Bootstrapping in Less Than 0.1 Seconds","summary":"The TFHE prototype reports bootstrapping below 0.1 seconds for its single-gate refresh setting while reducing the evaluation-key size relative to the cited FHEW point.","title":"Reported sub-0.1-second TFHE gate refresh","type":"result","venue":"ASIACRYPT 2016","year":2016,"sourcePath":"data/he-catalog.json#HE-RESULT-2016-TFHE-SUB-TENTH-SECOND-GATE-REFRESH"},{"evidence":"primary_source_checked","id":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","keywords":["atomic-result","ckks","approximate-arithmetic","rescaling"],"metadata":{"claim_slug":"approximate-arithmetic-with-rescaling","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"role":["capability"],"semantics":["approximate-numerical"],"track":["theory"]},"historical_context":{"narrative":"Exact BGV/BFV arithmetic required numerical applications to build approximation outside the encryption semantics and then track modular values indirectly. CKKS instead encodes approximate real or complex numbers in packed RLWE ciphertexts and defines correctness through controlled numerical error. After multiplication, rescaling reduces both the ciphertext modulus and the represented plaintext scale, aligning level consumption with fixed-point computation. The scheme is leveled unless refreshed, and its outputs are approximate rather than exactly equal to an arithmetic circuit over a finite ring. At publication, this created a new HE capability class for numerical workloads and made precision, scale, and error analysis part of the construction contract.","prior_boundary":"BGV and BFV treated plaintext arithmetic as exact modular computation, forcing numerical applications to encode approximation externally and manage growth without native error semantics.","significance_at_publication":"Creates a distinct HE branch for numerical workloads and turns precision planning, rather than exact equality alone, into a first-class security-and-correctness obligation.","technical_delta":"Makes approximation part of the cryptographic correctness contract and introduces rescaling so magnitude, rounding error, and ciphertext modulus evolve together."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","keywords":["ckks","approximate-arithmetic","rescaling"],"limitations":["correctness is approximate","depth and precision require scale planning","unbounded evaluation needs bootstrapping"],"paper_id":"HE-PAPER-2017-CKKS","qualifiers":["packed real/complex approximation","RLWE","rescaling after multiplication"],"source_locator":{"dossier_section":"HE-PAPER-2017-CKKS § Atomic claims","primary_source":"Abstract and Sections 1–3","primary_source_url":"https://eprint.iacr.org/2016/421","status":"primary_source_checked"},"statement":"CKKS encodes approximate real or complex values in packed RLWE ciphertexts and rescales ciphertext modulus and plaintext scale together after multiplication.","statement_status":"source_normalized_statement","status":"published","title":"Packed approximate-number arithmetic with rescaling","work_id":"HE-PAPER-2017-CKKS"},"primaryUrl":"https://eprint.iacr.org/2016/421","sections":[{"content":"Packed approximate-number arithmetic with rescaling The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Homomorphic Encryption for Arithmetic of Approximate Numbers","summary":"CKKS encodes approximate real or complex values in packed RLWE ciphertexts and rescales ciphertext modulus and plaintext scale together after multiplication.","title":"Packed approximate-number arithmetic with rescaling","type":"result","venue":"ASIACRYPT 2017","year":2017,"sourcePath":"data/he-catalog.json#HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING"},{"evidence":"primary_source_checked","id":"HE-RESULT-2017-TFHE-CB-TFHE-CIRCUIT-BOOTSTRAPPING-AND-PACKED-OPERATIONS","keywords":["atomic-result","tfhe","circuit-bootstrapping","ciphertext-conversion"],"metadata":{"claim_slug":"tfhe-circuit-bootstrapping-and-packed-operations","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["circuit-bootstrapping"],"role":["capability"],"track":["theory","practice"]},"historical_context":{"narrative":"The first TFHE construction efficiently refreshed LWE ciphertexts for Boolean gates, but the refreshed output was not directly the low-noise RingGSW control object needed by richer leveled circuits. The follow-up chains ordinary bootstrapping with private functional key switching to convert an encrypted LWE bit into a RingGSW ciphertext and gives explicit error bounds for the conversion. This is a ciphertext-type mechanism, not the paper's separate packed-operation contribution and not native RLWE SIMD arithmetic. Its publication-time significance was to make refreshed bits reusable as controls inside leveled TFHE circuits, at the cost of extra switching keys, memory, and a reported 137-millisecond conversion in the paper's parameter setting.","prior_boundary":"TFHE efficiently refreshed LWE ciphertexts for Boolean gates, but a refreshed LWE bit was not directly a low-noise RingGSW control ciphertext for subsequent leveled circuits.","significance_at_publication":"Adds a reusable ciphertext-type conversion to the TFHE stack, making bootstrapped bits available as controls inside richer leveled constructions without treating packing as the same contribution.","technical_delta":"Chains ordinary bootstrapping with private functional key switching to output a RingGSW encryption of the input bit, with an explicit correctness and noise theorem."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2017-TFHE-CB-TFHE-CIRCUIT-BOOTSTRAPPING-AND-PACKED-OPERATIONS","keywords":["tfhe","circuit-bootstrapping","ciphertext-conversion"],"limitations":["conversion and key-memory costs remain","packing model differs from CKKS/BGV SIMD"],"paper_id":"HE-PAPER-2017-TFHE-CB","qualifiers":["TFHE","LWE-to-RingGSW circuit bootstrap","LWE-to-RingGSW ciphertext conversion"],"source_locator":{"dossier_section":"HE-PAPER-2017-TFHE-CB § Atomic claims","primary_source":"Section 4; Algorithm 6; Theorem 4.1","primary_source_url":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","status":"theorem_checked"},"statement":"The TFHE follow-up gives a circuit-bootstrap procedure that converts an encrypted bit in an LWE ciphertext into a low-noise RingGSW ciphertext reusable as input to leveled homomorphic circuits.","statement_status":"source_normalized_statement","status":"published","title":"Circuit bootstrapping from LWE to low-noise RingGSW ciphertexts","work_id":"HE-PAPER-2017-TFHE-CB"},"primaryUrl":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","sections":[{"content":"Circuit bootstrapping from LWE to low-noise RingGSW ciphertexts The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Faster Packed Homomorphic Operations and Efficient Circuit Bootstrapping for TFHE","summary":"The TFHE follow-up gives a circuit-bootstrap procedure that converts an encrypted bit in an LWE ciphertext into a low-noise RingGSW ciphertext reusable as input to leveled homomorphic circuits.","title":"Circuit bootstrapping from LWE to low-noise RingGSW ciphertexts","type":"result","venue":"ASIACRYPT 2017","year":2017,"sourcePath":"data/he-catalog.json#HE-RESULT-2017-TFHE-CB-TFHE-CIRCUIT-BOOTSTRAPPING-AND-PACKED-OPERATIONS"},{"evidence":"primary_source_checked","id":"HE-RESULT-2017-TFHE-CB-TFHE-PACKED-LEVELED-OPERATIONS","keywords":["atomic-result","tfhe","packing","lookup","automata"],"metadata":{"claim_slug":"tfhe-packed-leveled-operations","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["packed-trlwe","blind-rotation"],"role":["capability"],"track":["theory","practice"]},"historical_context":{"narrative":"TFHE's fast gate bootstrap made encrypted Boolean operations practical, but lookup tables and state-machine workloads still risked expanding into long gate circuits. The follow-up develops packed TRLWE techniques, blind-rotation patterns, and automata-specific decompositions for evaluating lookup, finite-state, and weighted automata computations in leveled mode. This contribution is distinct from the paper's circuit bootstrap: it changes the data layout and workload decomposition rather than the output ciphertext type of refresh. It also does not provide the CRT-slot SIMD semantics of BGV or CKKS. At publication it opened a packed TFHE branch in which throughput depends on the represented automaton or lookup structure, not only on single-gate latency.","prior_boundary":"Fast TFHE gate bootstrapping operated primarily on individual encrypted bits, leaving higher-throughput lookup and state-machine computations to ad hoc Boolean circuits.","significance_at_publication":"Establishes a separate packed-computation branch inside TFHE while preserving its different data-layout and cost model from CRT-slot SIMD in BGV or CKKS.","technical_delta":"Uses packed TRLWE representations, blind rotation, and automata-specific decompositions to evaluate lookup and state-transition workloads as leveled homomorphic circuits."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2017-TFHE-CB-TFHE-PACKED-LEVELED-OPERATIONS","keywords":["tfhe","packing","lookup","automata"],"limitations":["not CRT-slot SIMD arithmetic","performance depends on the packed function representation","separate from circuit-bootstrapping conversion"],"paper_id":"HE-PAPER-2017-TFHE-CB","qualifiers":["TFHE packed TRLWE representation","lookup and automata workloads","leveled-circuit mode"],"source_locator":{"dossier_section":"HE-PAPER-2017-TFHE-CB § Atomic claims","primary_source":"Section 3, Leveled Homomorphic Circuits","primary_source_url":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","status":"section_checked"},"statement":"The paper develops packed TFHE leveled-circuit techniques for table lookup, finite-state and weighted-automata evaluation, and related operations over packed ciphertext representations.","statement_status":"source_normalized_statement","status":"published","title":"Packed TFHE leveled circuits for lookup and automata evaluation","work_id":"HE-PAPER-2017-TFHE-CB"},"primaryUrl":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","sections":[{"content":"Packed TFHE leveled circuits The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Faster Packed Homomorphic Operations and Efficient Circuit Bootstrapping for TFHE","summary":"The paper develops packed TFHE leveled-circuit techniques for table lookup, finite-state and weighted-automata evaluation, and related operations over packed ciphertext representations.","title":"Packed TFHE leveled circuits for lookup and automata evaluation","type":"result","venue":"ASIACRYPT 2017","year":2017,"sourcePath":"data/he-catalog.json#HE-RESULT-2017-TFHE-CB-TFHE-PACKED-LEVELED-OPERATIONS"},{"evidence":"primary_source_checked","id":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","keywords":["atomic-result","ckks","bootstrapping","approximate-modular-reduction"],"metadata":{"claim_slug":"first-ckks-bootstrapping-via-approximate-modular-reduction","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["approximate-modular-reduction"],"role":["construction"],"track":["theory","practice"]},"historical_context":{"narrative":"CKKS made approximate numerical evaluation efficient only for a predetermined depth, after which its modulus and scale budget was exhausted. Cheon et al. construct a native packed bootstrap by transforming between coefficient and slot views and homomorphically approximating the modular-reduction step in decryption. The first procedure is expensive and returns limited precision, so it establishes feasibility rather than a final performance point. At publication, it showed that approximate-number ciphertexts could be refreshed without decomposing the computation into Boolean gates and identified transforms, polynomial approximation, depth, and returned precision as the coupled objects later CKKS bootstrapping work must optimize.","prior_boundary":"CKKS supported efficient leveled approximate arithmetic, but its scale and modulus budget was exhausted after a predetermined multiplicative depth.","significance_at_publication":"Proves that approximate-number HE can refresh without converting the workload to Boolean gates and establishes precision-returned-versus-cost as a new optimization frontier.","technical_delta":"Builds a packed approximate bootstrap around coefficient/slot transforms and an approximate modular-reduction circuit, returning a ciphertext with renewed levels."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","keywords":["ckks","bootstrapping","approximate-modular-reduction"],"limitations":["initial refresh is expensive","returned precision is limited and parameter dependent"],"paper_id":"HE-PAPER-2018-CKKS-BOOT","qualifiers":["packed CKKS","approximate modular reduction","native approximate representation"],"source_locator":{"dossier_section":"HE-PAPER-2018-CKKS-BOOT § Atomic claims","primary_source":"Abstract and introduction; bootstrapping construction and evaluation sections","primary_source_url":"https://eprint.iacr.org/2018/153","status":"primary_source_checked"},"statement":"Cheon et al. extend leveled CKKS to FHE by homomorphically approximating the modular-reduction step of decryption in the native packed approximate representation.","statement_status":"source_normalized_statement","status":"published","title":"CKKS refresh through approximate modular reduction","work_id":"HE-PAPER-2018-CKKS-BOOT"},"primaryUrl":"https://eprint.iacr.org/2018/153","sections":[{"content":"CKKS refresh through approximate modular reduction The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Bootstrapping for Approximate Homomorphic Encryption","summary":"Cheon et al. extend leveled CKKS to FHE by homomorphically approximating the modular-reduction step of decryption in the native packed approximate representation.","title":"CKKS refresh through approximate modular reduction","type":"result","venue":"EUROCRYPT 2018","year":2018,"sourcePath":"data/he-catalog.json#HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION"},{"evidence":"primary_source_checked","id":"HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE","keywords":["atomic-result","implementation","ckks","bootstrapping"],"metadata":{"claim_slug":"realized-packed-ckks-refresh-prototype","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"artifact":["paper-described-prototype"],"role":["implementation-result"],"track":["practice"]},"historical_context":{"narrative":"The CKKS bootstrap construction specifies a refresh algorithm, but its feasibility also depends on implementing coefficient/slot transforms, approximation polynomials, rotations, and depth-aware parameters in the native packed representation. The paper-described prototype realizes that path and underlies the first contextual packed-refresh evaluation. This record does not claim an archived build or reproduced result; exact artifact and platform details remain unnormalized. At publication, the realization contribution showed that approximate modular reduction was executable as a complete pipeline rather than only a circuit sketch, while keeping the prototype distinct from both the construction theorem and the benchmark profile of latency, slots, and returned precision.","prior_boundary":"The CKKS bootstrap construction established an algorithm, but feasibility also required an implementation of transforms, approximation circuits, and parameter management in the native packed representation.","significance_at_publication":"Shows the approximate bootstrap could be executed end to end while leaving exact artifact, build, and parameter-normalized reproduction details pending.","technical_delta":"Provides a research prototype identity for the first packed CKKS refresh path and connects it to the construction and contextual evaluation record."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE","keywords":["implementation","ckks","bootstrapping"],"limitations":["artifact/build details not normalized","benchmark is source reported rather than reproduced"],"paper_id":"HE-PAPER-2018-CKKS-BOOT","qualifiers":["paper-described research prototype","packed CKKS refresh"],"source_locator":{"dossier_section":"HE-PAPER-2018-CKKS-BOOT § Atomic claims","primary_source":"Evaluation section; exact artifact and build locator pending","primary_source_url":"https://eprint.iacr.org/2018/153","status":"primary_source_checked"},"statement":"The paper-described CKKS prototype realizes coefficient/slot transforms and approximate modular reduction for refreshing packed approximate ciphertexts.","statement_status":"source_normalized_statement","status":"published","title":"Prototype for packed CKKS refresh in the native approximate representation","work_id":"HE-PAPER-2018-CKKS-BOOT"},"primaryUrl":"https://eprint.iacr.org/2018/153","sections":[{"content":"Prototype for packed CKKS refresh in the native approximate representation The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Bootstrapping for Approximate Homomorphic Encryption","summary":"The paper-described CKKS prototype realizes coefficient/slot transforms and approximate modular reduction for refreshing packed approximate ciphertexts.","title":"Prototype for packed CKKS refresh in the native approximate representation","type":"result","venue":"EUROCRYPT 2018","year":2018,"sourcePath":"data/he-catalog.json#HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE"},{"evidence":"primary_source_checked","id":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","keywords":["atomic-result","ckks","rns","word-size-arithmetic"],"metadata":{"claim_slug":"full-rns-ckks-with-word-size-arithmetic","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"resource":["machine-word-arithmetic"],"role":["optimization"],"track":["practice"]},"historical_context":{"narrative":"The original CKKS construction supplied native approximate semantics, but multiprecision arithmetic still interrupted a uniform high-performance implementation. The full-RNS variant redesigns modulus conversion and polynomial operations so ciphertexts remain in residue-number-system components handled with word-size arithmetic and NTT-friendly kernels. This is an implementation-aware optimization of representation, not a new numerical correctness definition, and it does not by itself solve bootstrapping depth, returned precision, or evaluation-key memory. At publication, the work closed a major gap between the CKKS abstraction and practical machine arithmetic, establishing the RNS execution pattern that later libraries use for approximate HE.","prior_boundary":"The original CKKS construction was conceptually efficient but retained multiprecision steps that obstructed a uniform high-performance implementation path.","significance_at_publication":"Turns CKKS into the implementation pattern used by modern libraries, without changing its approximate semantics or independently solving refresh precision and key-memory costs.","technical_delta":"Redesigns representation and modulus conversion so the CKKS pipeline stays in RNS components addressable by machine-word arithmetic."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","keywords":["ckks","rns","word-size-arithmetic"],"limitations":["approximate semantics are unchanged","does not by itself solve bootstrapping or certified precision"],"paper_id":"HE-PAPER-2018-RNS-CKKS","qualifiers":["full residue-number-system representation","word-size arithmetic","NTT-friendly kernels"],"source_locator":{"dossier_section":"HE-PAPER-2018-RNS-CKKS § Atomic claims","primary_source":"Abstract and construction/implementation overview","primary_source_url":"https://eprint.iacr.org/2018/931","status":"primary_source_checked"},"statement":"The full-RNS CKKS variant performs core polynomial arithmetic and approximate modulus switching entirely with residue-number-system and NTT-friendly word-size operations.","statement_status":"source_normalized_statement","status":"published","title":"Full-RNS CKKS using word-size modulus operations","work_id":"HE-PAPER-2018-RNS-CKKS"},"primaryUrl":"https://eprint.iacr.org/2018/931","sections":[{"content":"Full-RNS CKKS using word-size modulus operations The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"A Full RNS Variant of Approximate Homomorphic Encryption","summary":"The full-RNS CKKS variant performs core polynomial arithmetic and approximate modulus switching entirely with residue-number-system and NTT-friendly word-size operations.","title":"Full-RNS CKKS using word-size modulus operations","type":"result","venue":"SAC 2018","year":2018,"sourcePath":"data/he-catalog.json#HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC"},{"evidence":"primary_source_checked","id":"HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS","keywords":["atomic-result","implementation","ckks","rns","ntt"],"metadata":{"claim_slug":"realized-full-rns-ckks-word-kernels","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"artifact":["implementation-pattern"],"role":["implementation-result"],"track":["practice"]},"historical_context":{"narrative":"CKKS supplied approximate semantics, but its original execution path still left multiprecision arithmetic between the construction and a uniform machine-level implementation. The full-RNS work realizes modulus conversion and polynomial operations through residue components and NTT-friendly word-size kernels. The record is an implementation pattern described and evaluated by the paper, not a claim that one preserved library release has been independently rebuilt here. At publication, this realization showed that the representation-level optimization could support a complete CKKS arithmetic stack and clarified the reusable systems object inherited by later libraries, while keeping the abstract scheme and its exact artifact versions separate.","prior_boundary":"CKKS had approximate semantics, but the original execution path still left multiprecision arithmetic between the construction and a uniform high-performance implementation.","significance_at_publication":"Establishes the systems form in which the optimization can be reused, while not identifying one independently reproduced library release in the current dossier.","technical_delta":"Instantiates the full-RNS representation as a concrete implementation pattern for modulus operations and polynomial arithmetic."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS","keywords":["implementation","ckks","rns","ntt"],"limitations":["no independently reproduced artifact version normalized","does not establish bootstrapping performance"],"paper_id":"HE-PAPER-2018-RNS-CKKS","qualifiers":["paper-described implementation pattern","RNS/NTT word-size kernels"],"source_locator":{"dossier_section":"HE-PAPER-2018-RNS-CKKS § Atomic claims","primary_source":"Implementation description and evaluation; exact artifact version pending","primary_source_url":"https://eprint.iacr.org/2018/931","status":"primary_source_checked"},"statement":"The full-RNS CKKS work realizes approximate HE operations through RNS and NTT-friendly machine-word kernels rather than multiprecision core arithmetic.","statement_status":"source_normalized_statement","status":"published","title":"Implementation pattern for full-RNS CKKS word-size kernels","work_id":"HE-PAPER-2018-RNS-CKKS"},"primaryUrl":"https://eprint.iacr.org/2018/931","sections":[{"content":"Implementation pattern for full-RNS CKKS word-size kernels The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"A Full RNS Variant of Approximate Homomorphic Encryption","summary":"The full-RNS CKKS work realizes approximate HE operations through RNS and NTT-friendly machine-word kernels rather than multiprecision core arithmetic.","title":"Implementation pattern for full-RNS CKKS word-size kernels","type":"result","venue":"SAC 2018","year":2018,"sourcePath":"data/he-catalog.json#HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS"},{"evidence":"primary_source_checked","id":"HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP","keywords":["atomic-result","ckks","high-precision","error-variance"],"metadata":{"claim_slug":"direct-modular-reduction-approximation-for-high-precision-ckks-bootstrap","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"resource":["returned-precision","multiplicative-depth"],"role":["optimization"],"track":["theory","practice"]},"historical_context":{"narrative":"The first CKKS bootstrap proved that native approximate ciphertexts could be refreshed, but its modular-reduction approximation consumed substantial depth and returned limited precision. Lee et al. design a direct polynomial approximation whose coefficients and range are chosen to reduce error variance while controlling multiplicative depth. The improvement is parameter dependent: precision, failure behavior, runtime, and memory must be read together rather than ranked by latency alone. At publication, the work sharpened the CKKS refresh objective from feasibility to a measurable precision-versus-cost frontier and made the approximation polynomial itself an explicit optimization object.","prior_boundary":"The first CKKS bootstrap established native refresh but lost substantial precision and incurred deep, expensive approximation circuits.","significance_at_publication":"Changes the optimization target from merely completing refresh to balancing reliable output precision, depth, and runtime under a matched parameter profile.","technical_delta":"Replaces the earlier indirect approximation strategy with a direct error-variance-aware polynomial design targeted at returned precision and depth."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP","keywords":["ckks","high-precision","error-variance"],"limitations":["performance is parameter and approximation-range dependent","latency alone does not establish superiority"],"paper_id":"HE-PAPER-2020-HP-CKKS","qualifiers":["CKKS bootstrapping","direct polynomial approximation","error-variance minimization"],"source_locator":{"dossier_section":"HE-PAPER-2020-HP-CKKS § Atomic claims","primary_source":"Abstract and introduction; modular-reduction approximation and evaluation sections","primary_source_url":"https://eprint.iacr.org/2020/1549","status":"primary_source_checked"},"statement":"Lee et al. design a direct polynomial approximation to modular reduction that minimizes error variance and multiplicative depth in high-precision CKKS bootstrapping.","statement_status":"source_normalized_statement","status":"published","title":"Direct modular-reduction approximation for higher-precision CKKS refresh","work_id":"HE-PAPER-2020-HP-CKKS"},"primaryUrl":"https://eprint.iacr.org/2020/1549","sections":[{"content":"Direct modular-reduction approximation for higher-precision CKKS refresh The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"High-Precision Bootstrapping for Approximate Homomorphic Encryption by Error Variance Minimization","summary":"Lee et al. design a direct polynomial approximation to modular reduction that minimizes error variance and multiplicative depth in high-precision CKKS bootstrapping.","title":"Direct modular-reduction approximation for higher-precision CKKS refresh","type":"result","venue":"EUROCRYPT 2022","year":2020,"sourcePath":"data/he-catalog.json#HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP"},{"evidence":"primary_source_checked","id":"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING","keywords":["atomic-result","tfhe","processor","word-arithmetic"],"metadata":{"claim_slug":"general-purpose-eight-bit-processor-from-programmable-bootstrapping","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"capability":["word-level-instructions"],"role":["capability"],"track":["application","practice"]},"historical_context":{"narrative":"TFHE's programmable bootstrap can evaluate lookup functions, but application builders still faced low-level ciphertext conversions rather than a conventional word interface. Trama et al. encode each byte as two basis-16 digits and organize programmable lookups and key switching into more than fifty encrypted instructions, then compose those instructions into program workloads. The abstraction does not remove bootstrap latency, memory movement, or encrypted control-flow costs. Its reported basis-16 parameters also have a paper-specific failure profile, so a stronger correctness target may change the preferred decomposition. At publication, the work made reusable word semantics, rather than only gate latency, a distinct TFHE design object.","prior_boundary":"TFHE offered gate, circuit, and programmable bootstrapping primitives, but application code still had to assemble low-level encrypted operations without a conventional word-level interface.","significance_at_publication":"Demonstrates a move from cryptographic kernels to reusable word semantics, while retaining bootstrapping, memory movement, and encrypted-control-flow costs.","technical_delta":"Defines more than fifty 8-bit instructions over two encrypted nibbles, with basis-16 lookup and key-switching micro-operations selected for non-bitwise word operations."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING","keywords":["tfhe","processor","word-arithmetic"],"limitations":["does not eliminate bootstrapping cost","not directly comparable with packed approximate arithmetic","stronger bootstrap-failure targets may change the best decomposition basis"],"paper_id":"HE-PAPER-2024-TFHE-PROCESSOR","qualifiers":["TFHE programmable bootstrapping","8-bit word instructions","two basis-16 encrypted digits","more than fifty instructions","paper-described processor abstraction"],"source_locator":{"dossier_section":"HE-PAPER-2024-TFHE-PROCESSOR § Atomic claims","primary_source":"Section 1.1; Section 5; Appendix A","primary_source_url":"https://eprint.iacr.org/2024/1201","status":"section_checked"},"statement":"Trama et al. represent an encrypted byte as two basis-16 digits and organize programmable lookup and key-switching patterns into more than fifty reusable 8-bit instructions.","statement_status":"source_normalized_statement","status":"published","title":"Encrypted 8-bit instruction abstraction from programmable bootstrapping","work_id":"HE-PAPER-2024-TFHE-PROCESSOR"},"primaryUrl":"https://eprint.iacr.org/2024/1201","sections":[{"content":"Encrypted 8-bit instruction abstraction from programmable bootstrapping The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Designing a General-Purpose 8-bit (T)FHE Processor Abstraction","summary":"Trama et al. represent an encrypted byte as two basis-16 digits and organize programmable lookup and key-switching patterns into more than fifty reusable 8-bit instructions.","title":"Encrypted 8-bit instruction abstraction from programmable bootstrapping","type":"result","venue":"TCHES 2025","year":2024,"sourcePath":"data/he-catalog.json#HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING"},{"evidence":"primary_source_checked","id":"HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE","keywords":["atomic-result","implementation","tfhe","processor"],"metadata":{"claim_slug":"realized-encrypted-eight-bit-processor-prototype","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"artifact":["processor-prototype"],"role":["implementation-result"],"track":["practice"]},"historical_context":{"narrative":"A word-level encrypted processor interface is only useful if its programmable-bootstrap instructions can be composed in an executing system. The paper implements the instruction set over TFHElib and reports both instruction-level and multi-instruction workloads on a named single-core laptop environment. This realization remains distinct from the capability card and from the benchmark record that stores those observations. An immutable source revision and independently reproduced build are not yet bound in the dossier, and the workload class differs from packed CKKS or one-gate TFHE measurements. At publication, the prototype made the proposed word interface executable without turning its timings into timeless properties of TFHE.","prior_boundary":"A word-level encrypted processor abstraction required a concrete implementation to show that lookup-based instructions compose beyond isolated programmable-bootstrap examples.","significance_at_publication":"Provides a theory-to-system endpoint for the programmable-bootstrap line while leaving an immutable artifact revision and independently reproduced build unresolved.","technical_delta":"Implements the instruction layer over TFHElib and binds it to single-core instruction and program measurements on the paper's stated laptop platform."},"historical_context_status":"curator_synthesis","id":"HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE","keywords":["implementation","tfhe","processor"],"limitations":["immutable artifact revision not normalized","not independently reproduced","not comparable to different HE workload classes"],"paper_id":"HE-PAPER-2024-TFHE-PROCESSOR","qualifiers":["paper-described processor prototype","programmable bootstrapping","8-bit instruction workloads"],"source_locator":{"dossier_section":"HE-PAPER-2024-TFHE-PROCESSOR § Atomic claims","primary_source":"Section 7; Sections 8–9; Appendix A","primary_source_url":"https://eprint.iacr.org/2024/1201","status":"section_checked"},"statement":"The paper-described processor prototype implements its programmable-bootstrap-based 8-bit instructions and evaluates instruction- and program-level workloads.","statement_status":"source_normalized_statement","status":"published","title":"Prototype realizing the encrypted 8-bit TFHE instruction set","work_id":"HE-PAPER-2024-TFHE-PROCESSOR"},"primaryUrl":"https://eprint.iacr.org/2024/1201","sections":[{"content":"Prototype realizing the encrypted 8-bit TFHE instruction set The frontmatter is the canonical claim-level record. The parent paper provides bibliographic provenance; qualifiers and limitations bound the normalized statement without strengthening it.","heading":"Overview"}],"status":"published","subtitle":"Designing a General-Purpose 8-bit (T)FHE Processor Abstraction","summary":"The paper-described processor prototype implements its programmable-bootstrap-based 8-bit instructions and evaluates instruction- and program-level workloads.","title":"Prototype realizing the encrypted 8-bit TFHE instruction set","type":"result","venue":"TCHES 2025","year":2024,"sourcePath":"data/he-catalog.json#HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE"},{"evidence":"synthesis","id":"HE-ROUTE-001","keywords":["bootstrapping","exact-fhe","memory"],"metadata":{"dossier_type":"route","evidence":"synthesis","id":"HE-ROUTE-001","keywords":["bootstrapping","exact-fhe","memory"],"status":"active_route","targets":["HE-OP-001"],"title":"Co-design refresh representation, decomposition, and memory locality"},"primaryUrl":null,"sections":[{"content":"Treat bootstrap latency and evaluation-key traffic as one design problem: choose ciphertext representation, gadget decomposition, transforms, and key layout together.","heading":"Core mechanism"},{"content":"Publish an exact refresh result with latency, throughput, peak memory, key bytes, parameters, and failure probability measured in the same experiment.","heading":"Next bounded milestone"}],"status":"active_route","subtitle":"","summary":"Treat bootstrap latency and evaluation-key traffic as one design problem: choose ciphertext representation, gadget decomposition, transforms, and key layout together.","title":"Co-design refresh representation, decomposition, and memory locality","type":"route","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ROUTE-001"},{"evidence":"synthesis","id":"HE-ROUTE-002","keywords":["ckks","approximation","error-analysis"],"metadata":{"dossier_type":"route","evidence":"synthesis","id":"HE-ROUTE-002","keywords":["ckks","approximation","error-analysis"],"status":"active_route","targets":["HE-OP-002"],"title":"Certified polynomial approximation for CKKS modular reduction"},"primaryUrl":null,"sections":[{"content":"Co-optimize the approximation interval, polynomial basis, homomorphic transforms, rescaling schedule, and probabilistic input range, then expose a composable output-error bound.","heading":"Core mechanism"},{"content":"Verify a published CKKS bootstrap error budget independently from its implementation code.","heading":"Next bounded milestone"}],"status":"active_route","subtitle":"","summary":"Co-optimize the approximation interval, polynomial basis, homomorphic transforms, rescaling schedule, and probabilistic input range, then expose a composable output-error bound.","title":"Certified polynomial approximation for CKKS modular reduction","type":"route","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ROUTE-002"},{"evidence":"synthesis","id":"HE-ROUTE-003","keywords":["circuit-privacy","verifiability","composition"],"metadata":{"dossier_type":"route","evidence":"synthesis","id":"HE-ROUTE-003","keywords":["circuit-privacy","verifiability","composition"],"status":"exploratory_route","targets":["HE-OP-003"],"title":"Bind evaluated ciphertexts to circuit and parameter manifests"},"primaryUrl":null,"sections":[{"content":"Combine lightweight evaluation authentication or proof systems with circuit-private sanitization at the points where key switching and bootstrapping expose structure.","heading":"Core mechanism"},{"content":"Prove and benchmark one end-to-end packed inference circuit with both result integrity and circuit privacy.","heading":"Next bounded milestone"}],"status":"exploratory_route","subtitle":"","summary":"Combine lightweight evaluation authentication or proof systems with circuit-private sanitization at the points where key switching and bootstrapping expose structure.","title":"Bind evaluated ciphertexts to circuit and parameter manifests","type":"route","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ROUTE-003"},{"evidence":"synthesis","id":"HE-ROUTE-004","keywords":["circular-security","kdm","bootstrapping"],"metadata":{"dossier_type":"route","evidence":"synthesis","id":"HE-ROUTE-004","keywords":["circular-security","kdm","bootstrapping"],"status":"foundational_route","targets":["HE-OP-004"],"title":"Break same-key evaluation cycles in the refresh interface"},"primaryUrl":null,"sections":[{"content":"Use key hierarchies, multi-key refresh, or a modular KDM-secure component so that the evaluation key does not simply encrypt a secret under the same public key.","heading":"Core mechanism"},{"content":"Isolate the weakest KDM statement actually consumed by a modern bootstrap and prove it from a named standard assumption or identify the exact remaining gap.","heading":"Next bounded milestone"}],"status":"foundational_route","subtitle":"","summary":"Use key hierarchies, multi-key refresh, or a modular KDM-secure component so that the evaluation key does not simply encrypt a secret under the same public key.","title":"Break same-key evaluation cycles in the refresh interface","type":"route","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ROUTE-004"},{"evidence":"synthesis","id":"HE-ROUTE-005","keywords":["programmable-bootstrapping","packing","compiler"],"metadata":{"dossier_type":"route","evidence":"synthesis","id":"HE-ROUTE-005","keywords":["programmable-bootstrapping","packing","compiler"],"status":"active_route","targets":["HE-OP-005"],"title":"Hybrid packed arithmetic and programmable lookup compilation"},"primaryUrl":null,"sections":[{"content":"Keep linear and polynomial regions in packed RLWE form, switch only nonlinear bottlenecks to a programmable-bootstrap representation, and amortize conversions.","heading":"Core mechanism"},{"content":"Demonstrate a branch-heavy word program where automatic hybrid compilation beats both pure CKKS/BFV polynomialization and pure TFHE Booleanization.","heading":"Next bounded milestone"}],"status":"active_route","subtitle":"","summary":"Keep linear and polynomial regions in packed RLWE form, switch only nonlinear bottlenecks to a programmable-bootstrap representation, and amortize conversions.","title":"Hybrid packed arithmetic and programmable lookup compilation","type":"route","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ROUTE-005"},{"evidence":"synthesis","id":"HE-ROUTE-006","keywords":["benchmarking","standards","reproducibility"],"metadata":{"dossier_type":"route","evidence":"synthesis","id":"HE-ROUTE-006","keywords":["benchmarking","standards","reproducibility"],"status":"infrastructure_route","targets":["HE-OP-006"],"title":"Versioned benchmark and parameter manifests"},"primaryUrl":null,"sections":[{"content":"Store the circuit, plaintext distribution, packing map, modulus chain, secret distribution, estimator version, hardware, key footprint, and error target as a machine-readable experiment object.","heading":"Core mechanism"},{"content":"Reproduce one exact, one approximate, and one programmable-bootstrap workload across two libraries each.","heading":"Next bounded milestone"}],"status":"infrastructure_route","subtitle":"","summary":"Store the circuit, plaintext distribution, packing map, modulus chain, secret distribution, estimator version, hardware, key footprint, and error target as a machine-readable experiment object.","title":"Versioned benchmark and parameter manifests","type":"route","venue":null,"year":null,"sourcePath":"data/he-catalog.json#HE-ROUTE-006"},{"evidence":"abstract_checked","id":"HE-WORKLOAD-AES-2012","keywords":["workload","aes","transciphering"],"metadata":{"dossier_type":"workload","evidence":"abstract_checked","evidence_status":"reported","id":"HE-WORKLOAD-AES-2012","input_shape":"packed AES blocks","keywords":["workload","aes","transciphering"],"maps_to":["HE-OP-001","HE-OP-006"],"output_measure":"end-to-end circuit completion and runtime","paper_id":"HE-PAPER-2012-GHS-AES","status":"reported","title":"Homomorphic AES circuit evaluation","workload_class":"transciphering circuit","year":2012},"primaryUrl":null,"sections":[{"content":"Recognizable large Boolean or arithmetic circuit used to expose the interaction between packing, rotations, key switching, depth planning, memory, and optional refresh.","heading":"Workload"}],"status":"reported","subtitle":"2012","summary":"Recognizable large Boolean or arithmetic circuit used to expose the interaction between packing, rotations, key switching, depth planning, memory, and optional refresh.","title":"Homomorphic AES circuit evaluation","type":"workload","venue":null,"year":2012,"sourcePath":"data/he-catalog.json#HE-WORKLOAD-AES-2012"},{"evidence":"primary_source_checked","id":"HE-WORKLOAD-GATE-BOOTSTRAP","keywords":["workload","gate","bootstrapping"],"metadata":{"dossier_type":"workload","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-WORKLOAD-GATE-BOOTSTRAP","input_shape":"one or more LWE ciphertext bits","keywords":["workload","gate","bootstrapping"],"maps_to":["HE-OP-001","HE-OP-005","HE-OP-006"],"output_measure":"refreshed gate latency","paper_id":"HE-PAPER-2015-FHEW","status":"reported","title":"Single binary gate with ciphertext refresh","workload_class":"gate bootstrapping","year":2015},"primaryUrl":null,"sections":[{"content":"One Boolean operation fused with refresh. It is comparable only among systems using compatible security, failure, message, hardware, and key-memory settings.","heading":"Workload"}],"status":"reported","subtitle":"2015","summary":"One Boolean operation fused with refresh. It is comparable only among systems using compatible security, failure, message, hardware, and key-memory settings.","title":"Single binary gate with ciphertext refresh","type":"workload","venue":null,"year":2015,"sourcePath":"data/he-catalog.json#HE-WORKLOAD-GATE-BOOTSTRAP"},{"evidence":"primary_source_checked","id":"HE-WORKLOAD-CKKS-REFRESH","keywords":["workload","ckks","precision","bootstrapping"],"metadata":{"dossier_type":"workload","evidence":"primary_source_checked","evidence_status":"reported","id":"HE-WORKLOAD-CKKS-REFRESH","input_shape":"packed complex slots at a declared scale","keywords":["workload","ckks","precision","bootstrapping"],"maps_to":["HE-OP-002","HE-OP-006"],"output_measure":"latency, returned precision, slots, and failure probability","paper_id":"HE-PAPER-2018-CKKS-BOOT","status":"reported","title":"Packed CKKS ciphertext refresh","workload_class":"approximate packed bootstrapping","year":2018},"primaryUrl":null,"sections":[{"content":"Refresh of packed approximate values. Returned precision and failure probability are part of the result and must not be dropped when comparing latency.","heading":"Workload"}],"status":"reported","subtitle":"2018","summary":"Refresh of packed approximate values. Returned precision and failure probability are part of the result and must not be dropped when comparing latency.","title":"Packed CKKS ciphertext refresh","type":"workload","venue":null,"year":2018,"sourcePath":"data/he-catalog.json#HE-WORKLOAD-CKKS-REFRESH"},{"evidence":"primary_source_checked","id":"HE-WORKLOAD-TFHE-8BIT","keywords":["workload","tfhe","processor","lookup"],"metadata":{"dossier_type":"workload","evidence":"primary_source_checked","evidence_status":"section_checked","id":"HE-WORKLOAD-TFHE-8BIT","input_shape":"encrypted 8-bit words and instruction sequences","keywords":["workload","tfhe","processor","lookup"],"maps_to":["HE-OP-005","HE-OP-006"],"output_measure":"per-instruction and program cost","paper_id":"HE-PAPER-2024-TFHE-PROCESSOR","status":"reported","title":"Encrypted 8-bit instruction set","workload_class":"encrypted word-level processor","year":2024},"primaryUrl":null,"sections":[{"content":"More than fifty reusable encrypted 8-bit instructions and the paper's program suite, including array, arithmetic, and sigmoid workloads. Results should be compared at the same instruction or program level, not by substituting a single Boolean-gate latency.","heading":"Workload"}],"status":"reported","subtitle":"2024","summary":"More than fifty reusable encrypted 8-bit instructions and the paper's program suite, including array, arithmetic, and sigmoid workloads. Results should be compared at the same instruction or program level, not by substituting a single Boolean-gate latency.","title":"Encrypted 8-bit instruction set","type":"workload","venue":null,"year":2024,"sourcePath":"data/he-catalog.json#HE-WORKLOAD-TFHE-8BIT"}],"propertyAssertions":[{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-030BB3DFD791EC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_tfhe16","value":"exact discrete messages with failure probability"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-04E578A648DF34","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks_boot18","value":"approximate; refresh returns bounded precision"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-07E2C3BC580030","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks17","value":"native SIMD complex slots"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-0CEA807BFD5A19","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_rns_ckks18","value":"approximate with an explicit precision budget"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-1470AB699BB738","review_status":"scheme_declared","scope":"construction","subject_id":"he_scaleinv12","value":"single-modulus"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-185C2F968FC859","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_scaleinv12","value":"exact modular plaintexts"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-18A4C21AFE0F5D","review_status":"scheme_declared","scope":"construction","subject_id":"he_gentry09","value":"first-fhe"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-1B5F9BAC12CA73","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks17","value":"ckks"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-1E791C43FC391F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks17","value":"packed approximate real or complex numbers"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-206967386A368C","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bgv12","value":"SIMD via CRT plaintext slots"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-2DC809F6CFAB4C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_tfhe16","value":"bits and small torus messages"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-2E55FB2AA33348","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_fhew15","value":"exact bits with quantified decryption failure"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-304A2264C33134","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bgv12","value":"modulus switching chain plus key switching"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-31835222056136","review_status":"scheme_declared","scope":"construction","subject_id":"he_bfv12","value":"packing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-36CBAC7DBC6FA0","review_status":"scheme_declared","scope":"construction","subject_id":"he_bfv12","value":"exact"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-37295388E56F08","review_status":"scheme_declared","scope":"construction","subject_id":"he_ckks_boot18","value":"approximate"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-388113306A3774","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bv11","value":"FHE"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-388D96E3FA4E83","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_dghv10","value":"unbounded Boolean circuits after bootstrap"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-389B1493D69605","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_gentry09","value":"exact"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-38CF7069676BDD","review_status":"scheme_declared","scope":"construction","subject_id":"he_fhew15","value":"gate-bootstrapping"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-3A6167F8495222","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_gentry09","value":"FHE"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-3DAB31DE712FAD","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_tfhe16","value":"FHE"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-3DFA37A96F6E1A","review_status":"scheme_declared","scope":"construction","subject_id":"he_bv11","value":"standard-lwe"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-3E55EE3D3BE5F4","review_status":"scheme_declared","scope":"construction","subject_id":"he_rns_ckks18","value":"approximate"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-405BEFEEF3E3FB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_rns_ckks18","value":"native SIMD complex slots"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-4117823400CD69","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_gentry09","value":"unbounded circuits after bootstrap"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-413FE3C6EE9AB2","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_fhew15","value":"unbounded Boolean circuits"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-4206F38FA80B08","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"he_paillier99","value":"integers modulo n"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-442E397629AC56","review_status":"scheme_declared","scope":"construction","subject_id":"he_fhew15","value":"boolean"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-47C87665A4E6B8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks_boot18","value":"native SIMD complex slots"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-4A0EB67014F64B","review_status":"scheme_declared","scope":"construction","subject_id":"he_ckks17","value":"packing"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-4A35C9BCF4CE6D","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"he_paillier99","value":"no lattice noise budget"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-4B0D14131AD1EA","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bgv12","value":"optional for unbounded FHE"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-4D5F3239A8229E","review_status":"scheme_declared","scope":"construction","subject_id":"he_dghv10","value":"integer-fhe"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-4D661E2229F566","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_fhew15","value":"fhew_tfhe"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-4E162354C740FD","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks_boot18","value":"homomorphic transforms and scaled-sine modular reduction"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-51EDBF7CFA9B24","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bgv12","value":"exact modular arithmetic"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-5248057226F315","review_status":"scheme_declared","scope":"construction","subject_id":"he_rns_ckks18","value":"ntt"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-5263742C8A3D1A","review_status":"scheme_declared","scope":"construction","subject_id":"he_dghv10","value":"bootstrapping"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-5379E3DE459ED6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks17","value":"rescaling and modulus chain"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-537AB77964BE3B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_fhew15","value":"bits"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-540E3F678D4535","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_tfhe16","value":"external-product gate bootstrap below 0.1 seconds in the paper"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-54431362B99CF8","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bv11","value":"exact modular arithmetic"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-5590AA79658D49","review_status":"scheme_declared","scope":"construction","subject_id":"he_gsw13","value":"approximate-eigenvector"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-566A449500AC05","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_tfhe16","value":"limited in base gate mode"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-57AF036CEB92EE","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_fhew15","value":"FHE"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-59D1A6BC6F1B16","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_scaleinv12","value":"scale_invariant_lwe"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-59FAB6C426A3CE","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks17","value":"approximate with an explicit precision budget"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-5C8BAE18E8B12F","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_dghv10","value":"bits"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-5D67A6813AAD3C","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_gsw13","value":"FHE"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-658D29E647946D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_rns_ckks18","value":"LHE"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-659EAD989AC5F7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_gentry09","value":"ideal_lattice"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-68050154847210","review_status":"scheme_declared","scope":"construction","subject_id":"he_tfhe16","value":"gate-bootstrapping"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-691D28A8A91FC3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_tfhe16","value":"bootstrapping resets noise after nonlinear gates"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-6A0C73DCCFDCE5","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_gsw13","value":"ring variants and descendants"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-6B663D17EEC142","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_gentry09","value":"bits and ring elements"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-6B689360F5E8D4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks17","value":"LHE"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-6C5EFCA0361F61","review_status":"scheme_declared","scope":"construction","subject_id":"he_ckks_boot18","value":"bootstrapping"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-6F87351820F2EF","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bgv12","value":"predetermined-depth arithmetic circuits"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-700DF03517C0FF","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bv11","value":"bits or small modular plaintexts"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-701C516D6E4106","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bv11","value":"required for unbounded depth"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-7195EFDD376FED","review_status":"scheme_declared","scope":"construction","subject_id":"he_bgv12","value":"exact"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-747015F3427D49","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bfv12","value":"optional and not part of the basic leveled record"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-74F737BE9442CA","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_dghv10","value":"integer_agcd"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-75C378C457D540","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks_boot18","value":"FHE"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-781DFADDA8A168","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bgv12","value":"bgv"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-799F4347495234","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bgv12","value":"exact modular integers and packed slots"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-7AE97A9EF11368","review_status":"scheme_declared","scope":"construction","subject_id":"he_ckks17","value":"rescaling"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-7C35FB1597A81E","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bfv12","value":"SIMD when the plaintext ring splits"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-7CCA4E690A7838","review_status":"scheme_declared","scope":"construction","subject_id":"he_paillier99","value":"additive-homomorphism"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-7D0E9D469A4215","review_status":"scheme_declared","scope":"construction","subject_id":"he_rns_ckks18","value":"numerical"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-7DF87947D310B1","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bfv12","value":"LHE"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-7ECC153E3EB68C","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_scaleinv12","value":"available for unbounded depth"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-81C2E76D7E5053","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks_boot18","value":"rescaling plus approximate modular-reduction refresh"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-829E6E31C76F89","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_scaleinv12","value":"exact modular arithmetic"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-84A5D47749A753","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_fhew15","value":"subsecond LWE/RLWE gate bootstrap in the paper"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-8599F335CD32CB","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_gsw13","value":"gadget decomposition and asymmetric noise growth"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-87556FF97A4B7E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_fhew15","value":"limited in the base design"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-87E5948E2202AC","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_dghv10","value":"Gentry-style squashed decryption"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-92D58C60126261","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_gsw13","value":"bits or small modular plaintexts"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-931AE80489E54A","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_gsw13","value":"exact modular plaintext"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_fhew15.md","id":"HE-PROP-95BA4C8D4A6CEA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_fhew15","value":"bootstrap after a gate"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-95C258C991F87E","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"he_paillier99","value":"PHE"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-9901F773A7648E","review_status":"scheme_declared","scope":"construction","subject_id":"he_bfv12","value":"relinearization"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-9931FA7602373B","review_status":"scheme_declared","scope":"construction","subject_id":"he_scaleinv12","value":"exact"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-993907D054B5B7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_gentry09","value":"homomorphic evaluation of augmented decryption"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-9B5C6EA84902BB","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_dghv10","value":"approximate multiples; noise grows under multiplication"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-9B9DFA9640D0E8","review_status":"scheme_declared","scope":"construction","subject_id":"he_bv11","value":"key-switching"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-9D56C3E87D8D0E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_tfhe16","value":"fhew_tfhe"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-9EBCCDAA220241","review_status":"scheme_declared","scope":"construction","subject_id":"he_gsw13","value":"external-product-ancestor"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-9EC4B24FCAA38E","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_scaleinv12","value":"not the primary contribution"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-A0131254206A34","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bfv12","value":"bfv"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-A0ED24DEBD1282","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_dghv10","value":"FHE"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-A26C13E011D5FB","review_status":"scheme_declared","scope":"construction","subject_id":"he_bgv12","value":"packing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-A606F77D99032A","review_status":"scheme_declared","scope":"construction","subject_id":"he_bgv12","value":"modulus-switching"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-A7E7F21947437D","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bfv12","value":"exact modular arithmetic"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-A88697877FF78E","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bv11","value":"relinearization and dimension-modulus reduction"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-AA516020A65B27","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"he_paillier99","value":"additive circuits only"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-AB7B72C9EE9CD8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_tfhe16","value":"unbounded Boolean circuits"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-AD5C8D7F373425","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_rns_ckks18","value":"predetermined-depth numerical circuits"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-ADDC7CB6EA2513","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_gsw13","value":"general circuits after refresh"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-AE9C854C790F9D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_rns_ckks18","value":"RNS rescaling and approximate modulus switching"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-AF5F7EED306603","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_dghv10","value":"exact bits"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-B5B14565807726","review_status":"scheme_declared","scope":"construction","subject_id":"he_rns_ckks18","value":"packing"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-B5DB7473489362","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"he_paillier99","value":"not applicable"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-B63B74AFADAB06","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bgv12","value":"LHE"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-B70F50ECEADB8D","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_scaleinv12","value":"tensoring with linear multiplicative noise growth"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-B8B5F0521F2BE1","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bv11","value":"bounded depth before refresh; unbounded after refresh"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-B95372B26882DD","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_gentry09","value":"later variants only"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-BC4539CD11F5FA","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_gsw13","value":"gsw"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-BC786F2D71E0BF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks17","value":"predetermined-depth numerical circuits"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_dghv10.md","id":"HE-PROP-BC8BDE21421D83","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_dghv10","value":"none in the base scheme"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-BCE585D75B0C21","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_rns_ckks18","value":"ckks"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-BD38A120708786","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_scaleinv12","value":"predetermined-depth arithmetic circuits"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-BE332E750E73D5","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bfv12","value":"relinearization and modulus management; RNS in modern variants"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-BE4AA4CC04D63B","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bv11","value":"not the core contribution"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-C8313BBAE4B17B","review_status":"scheme_declared","scope":"construction","subject_id":"he_bv11","value":"relinearization"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-C8BD66D1B370B3","review_status":"scheme_declared","scope":"construction","subject_id":"he_tfhe16","value":"boolean"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-C8ECA986C7CB54","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"he_paillier99","value":"additive_phe"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_gsw13.md","id":"HE-PROP-CB418E9BC4266A","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_gsw13","value":"supported through homomorphic decryption"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-CCC44BC9263A99","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bfv12","value":"exact integers modulo t"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-CF9923273BE1C9","review_status":"scheme_declared","scope":"construction","subject_id":"he_ckks_boot18","value":"numerical"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-D03A3BDA4B4217","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_rns_ckks18","value":"compatible with later RNS bootstrap implementations"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_tfhe16.md","id":"HE-PROP-D16613334C06A9","review_status":"scheme_declared","scope":"construction","subject_id":"he_tfhe16","value":"external-product"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-D3C3FDC1C43F61","review_status":"scheme_declared","scope":"construction","subject_id":"he_scaleinv12","value":"tensoring"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-D4D4AA736BF69B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_rns_ckks18","value":"packed approximate real or complex numbers"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-D7EBD60797718D","review_status":"scheme_declared","scope":"construction","subject_id":"he_ckks_boot18","value":"packing"},{"dimension":"bootstrapping","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-D936D308A0BF88","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks17","value":"not in the base construction"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-D98EBFFF834BE8","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bfv12","value":"predetermined-depth arithmetic circuits"},{"dimension":"noise_management","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-D9DC326CC5F2E3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_gentry09","value":"somewhat-HE noise budget plus squashing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_rns_ckks18.md","id":"HE-PROP-E0B0F83A8A4A04","review_status":"scheme_declared","scope":"construction","subject_id":"he_rns_ckks18","value":"rns"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-E0DBF3F0BF9C90","review_status":"scheme_declared","scope":"construction","subject_id":"he_ckks17","value":"numerical"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_bv11.md","id":"HE-PROP-E1C8A980C604A7","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_bv11","value":"lwe_relinearization"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/he/schemes/he_scaleinv12.md","id":"HE-PROP-E58ABFCB6131BA","review_status":"abstract_reviewed","scope":"construction","subject_id":"he_scaleinv12","value":"LHE"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_ckks17.md","id":"HE-PROP-F01B0E2A3E585C","review_status":"scheme_declared","scope":"construction","subject_id":"he_ckks17","value":"approximate"},{"dimension":"plaintext_space","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-F0628831D6638E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks_boot18","value":"packed approximate real or complex numbers"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bgv12.md","id":"HE-PROP-F12DE9BF19CAA7","review_status":"scheme_declared","scope":"construction","subject_id":"he_bgv12","value":"key-switching"},{"dimension":"packing","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-F743C7333BEC7A","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"he_paillier99","value":"none in the base construction"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-F74DAF5F8F18DF","review_status":"scheme_declared","scope":"construction","subject_id":"he_paillier99","value":"exact"},{"dimension":"circuit_class","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-F8CAAAEBA38D48","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks_boot18","value":"unbounded numerical circuits with periodic bootstrap"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/he/schemes/he_ckks_boot18.md","id":"HE-PROP-FA7ADB56B4016D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"he_ckks_boot18","value":"ckks"},{"dimension":"exactness","evidence_ref":"knowledge/primitives/he/schemes/he_paillier99.md","id":"HE-PROP-FDA351048FBCC7","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"he_paillier99","value":"exact modular arithmetic"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_bfv12.md","id":"HE-PROP-FE574B324F2A02","review_status":"scheme_declared","scope":"construction","subject_id":"he_bfv12","value":"rns-friendly"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/he/schemes/he_gentry09.md","id":"HE-PROP-FE7AD7FB1C53E5","review_status":"scheme_declared","scope":"construction","subject_id":"he_gentry09","value":"bootstrapping"}],"researchMap":{"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"nodes":{"HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM":{"anchor_roles":["model_definition"],"group":"foundation","label":"Privacy homomorphisms","lane_rationale":"Introduces the privacy-homomorphism interface and encrypted-computation research program; the early examples are not promoted to modern secure FHE.","lenses":["he_general_fhe"],"primary":true,"selection_rationale":"Defines encrypted computation as the field's motivating interface while remaining visibly distinct from a secure general construction.","thread":"he_roots_capability","visibility":"backbone"},"HE-RESULT-1999-PAILLIER-PRACTICAL-ADDITIVELY-HOMOMORPHIC-PUBLIC-KEY-ENCRYPTION":{"anchor_roles":[],"group":"construction","label":"Additive HE","lane_rationale":"Gives a concrete probabilistic public-key scheme with additive plaintext homomorphism from composite-degree residuosity.","lenses":["he_general_fhe"],"primary":true,"selection_rationale":"Provides the canonical unbounded-addition partial-HE point without duplicating the later arbitrary-circuit transition.","thread":"he_roots_capability","visibility":"reviewed_related"},"HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION":{"anchor_roles":["first_feasibility","capability_boundary"],"group":"construction","label":"First FHE","lane_rationale":"The node is the first concrete ideal-lattice FHE construction combining somewhat HE and bootstrapping, not the prior definition of encrypted computation.","lenses":["he_general_fhe"],"primary":true,"selection_rationale":"Marks the first feasibility result for arbitrary circuit evaluation and prevents the overview from treating bootstrapping as if it preceded an FHE construction.","thread":"he_roots_capability","visibility":"backbone"},"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Bootstrapping blueprint","lane_rationale":"Provides the reusable transformation that evaluates augmented decryption to refresh ciphertexts and promote a bootstrappable scheme to FHE.","lenses":["he_general_fhe","he_noise_depth"],"selection_rationale":"Separates the reusable refresh mechanism from the same paper's feasibility theorem and anchors every later bootstrapping branch.","thread":"he_refresh","threads":["he_roots_capability","he_refresh"],"visibility":"backbone"},"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD":{"anchor_roles":[],"group":"construction","label":"Integer FHE","lane_rationale":"Instantiates the bootstrapping blueprint with noisy integer multiples and approximate-GCD security; review depth is retained rather than upgraded.","lenses":["he_general_fhe"],"primary":true,"selection_rationale":"Shows that the Gentry refresh architecture is not tied to ideal lattices, but remains expanded work because it does not define the later implementation line.","thread":"he_lwe_rlwe_exact","visibility":"reviewed_related"},"HE-RESULT-2011-BV-DIMENSION-MODULUS-REDUCTION-WITHOUT-SQUASHING":{"anchor_roles":[],"group":"construction","label":"Dimension–modulus reduction","lane_rationale":"Supplies a distinct reusable dimension/modulus-reduction mechanism avoiding the earlier squashed-decryption route.","lenses":["he_noise_depth"],"selection_rationale":"Records the decryption-circuit simplification separately from the BV construction so squashing removal is not lost inside a paper node.","thread":"he_lwe_rlwe_exact","visibility":"reviewed_related"},"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION":{"anchor_roles":[],"group":"construction","label":"LWE SHE + relinearization","lane_rationale":"Constructs LWE-based somewhat HE and its evaluation-key-assisted relinearization mechanism.","lenses":["he_noise_depth"],"primary":true,"selection_rationale":"Introduces the standard-LWE and relinearization base inherited by exact-arithmetic descendants, retained on expansion to keep the default map sparse.","thread":"he_lwe_rlwe_exact","visibility":"reviewed_related"},"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Predetermined-depth FHE","lane_rationale":"Realizes predetermined-depth FHE through a planned modulus chain; eliminating online refresh depends on depth-specific setup rather than an unconditional runtime comparison.","lenses":["he_general_fhe","he_noise_depth"],"primary":true,"selection_rationale":"Makes predetermined-depth evaluation a complete capability and explains why most practical exact HE can avoid online refresh.","thread":"he_lwe_rlwe_exact","visibility":"backbone"},"HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Iterated modulus switching","lane_rationale":"Uses iterated modulus switching as a reusable noise-management mechanism; modulus/noise conditions are not a separate research lane.","lenses":["he_noise_depth"],"selection_rationale":"Preserves BGV's level-by-level reuse of the preceding BV switching technique without miscrediting BGV with the underlying one-shot transformation.","thread":"he_lwe_rlwe_exact","visibility":"backbone"},"HE-RESULT-2012-BRAKERSKI-SCALE-INVARIANT-FHE-WITH-LINEAR-NOISE-GROWTH":{"anchor_roles":[],"group":"construction","label":"Single-modulus linear-noise FHE","lane_rationale":"Changes the multiplication invariant to yield a single-modulus scale-invariant construction; the source does not establish normalized concrete superiority.","lenses":["he_noise_depth"],"primary":true,"selection_rationale":"Preserves the alternative single-modulus noise invariant without suggesting that it displaced the modulus-chain implementation line.","thread":"he_lwe_rlwe_exact","visibility":"reviewed_related"},"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION":{"anchor_roles":[],"group":"construction","label":"BFV exact arithmetic","lane_rationale":"Constructs a ring-based exact modular arithmetic scheme with relinearized multiplication.","lenses":["he_noise_depth"],"primary":true,"selection_rationale":"Keeps BFV's durable exact-arithmetic family available while BGV represents the default leveled transition.","thread":"he_lwe_rlwe_exact","visibility":"reviewed_related"},"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE":{"anchor_roles":[],"group":"construction","label":"Packed AES evaluation","lane_rationale":"The principal contribution is the composed AES evaluation pipeline coordinating packed BGV, CRT arithmetic, key switching and modulus planning, distinct from its prototype/run records.","lenses":["he_packing_layout_problem","he_concrete_cost"],"primary":true,"selection_rationale":"Captures the end-to-end workload result separately from its prototype and measurement objects.","thread":"he_packing_layout","visibility":"reviewed_related"},"HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"SIMD slot packing","lane_rationale":"Introduces the reusable CRT-slot representation and parallel recryption mechanism; throughput is a consequence rather than a standalone benchmark claim.","lenses":["he_packing_layout_problem"],"primary":true,"selection_rationale":"Introduces the reusable slot-packing mechanism that changes HE's efficiency unit from ciphertext latency to per-slot throughput.","thread":"he_packing_layout","visibility":"backbone"},"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Approximate-eigenvector ciphertexts","lane_rationale":"Gives the approximate-eigenvector matrix representation and gadget-based multiplication rule reused by later constructions.","lenses":["he_programmable_words","he_noise_depth"],"primary":true,"selection_rationale":"Starts the matrix-ciphertext line that later gate-bootstrapping systems explicitly instantiate.","thread":"he_gsw_programmable","visibility":"backbone"},"HE-RESULT-2013-GSW-MULTIPLICATION-WITHOUT-RELINEARIZATION":{"anchor_roles":[],"group":"construction","label":"Multiplication without relinearization","lane_rationale":"Records the relinearization-free multiplication mechanism and its same-form invariant; absence of relinearization is not by itself an efficiency dominance claim.","lenses":["he_noise_depth"],"selection_rationale":"Exposes the representation-level multiplication invariant without adding a second default node for the same paper.","thread":"he_gsw_programmable","visibility":"reviewed_related"},"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING":{"anchor_roles":["practice_transition"],"group":"efficiency","label":"≈0.5 s FHEW gate bootstrap","lane_rationale":"The chosen claim is the optimized gate-and-refresh path's subsecond latency in the paper's stated setting, not the separate prototype release.","lenses":["he_general_fhe","he_programmable_words","he_concrete_cost"],"primary":true,"selection_rationale":"Marks the practice transition from bootstrapping as an exceptional operation to a repeatedly measured gate primitive.","thread":"he_gsw_programmable","threads":["he_gsw_programmable","he_refresh"],"visibility":"backbone"},"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"TFHE external product","lane_rationale":"Defines the LWE–RingGSW external-product refresh mechanism; the separate gate-latency contribution carries its empirical efficiency point.","lenses":["he_programmable_words","he_concrete_cost"],"primary":true,"selection_rationale":"Introduces the external-product kernel that defines the TFHE technical genealogy.","thread":"he_gsw_programmable","threads":["he_gsw_programmable","he_refresh"],"visibility":"backbone"},"HE-RESULT-2016-TFHE-SUB-TENTH-SECOND-GATE-REFRESH":{"anchor_roles":[],"group":"efficiency","label":"Sub-0.1 s TFHE gate refresh","lane_rationale":"Records a contextual improvement in gate-refresh latency and evaluation-key size; source-reported parameters and hardware remain part of the claim.","lenses":["he_concrete_cost"],"selection_rationale":"Keeps the source-reported latency delta distinct from the external-product mechanism and prototype identity.","thread":"he_gsw_programmable","visibility":"reviewed_related"},"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Approximate arithmetic + rescaling","lane_rationale":"Realizes packed approximate arithmetic through numerical encoding and joint scale/modulus rescaling; approximation is an explicit correctness facet.","lenses":["he_precision_correctness"],"primary":true,"selection_rationale":"Changes HE's correctness contract from exact modular output to controlled approximate numerical output.","thread":"he_ckks_approximate","visibility":"backbone"},"HE-RESULT-2017-TFHE-CB-TFHE-CIRCUIT-BOOTSTRAPPING-AND-PACKED-OPERATIONS":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"LWE→RingGSW circuit bootstrap","lane_rationale":"Gives a reusable LWE-to-low-noise-RingGSW circuit-bootstrap conversion with its own correctness/noise theorem.","lenses":["he_programmable_words"],"primary":true,"selection_rationale":"Isolates the ciphertext-type conversion that produces low-noise RingGSW controls, rather than merging it with the paper's separate packed leveled-circuit contribution.","thread":"he_gsw_programmable","visibility":"backbone"},"HE-RESULT-2017-TFHE-CB-TFHE-PACKED-LEVELED-OPERATIONS":{"anchor_roles":[],"group":"construction","label":"Packed TFHE lookup/automata circuits","lane_rationale":"Constructs packed lookup and automata-evaluation mechanisms using TRLWE and blind rotation, distinct from ordinary CRT SIMD arithmetic.","lenses":["he_packing_layout_problem","he_programmable_words"],"selection_rationale":"Keeps the paper's packed leveled-circuit capability separate from circuit bootstrapping and from CRT-slot SIMD arithmetic.","thread":"he_packing_layout","threads":["he_packing_layout","he_gsw_programmable"],"visibility":"reviewed_related"},"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION":{"anchor_roles":["first_feasibility"],"group":"construction","label":"CKKS bootstrapping","lane_rationale":"Constructs the first packed approximate CKKS bootstrap through transforms and approximate modular reduction.","lenses":["he_precision_correctness","he_general_fhe"],"primary":true,"selection_rationale":"Establishes the first native refresh path for the approximate-arithmetic branch.","thread":"he_ckks_approximate","threads":["he_ckks_approximate","he_refresh"],"visibility":"backbone"},"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC":{"anchor_roles":["practice_transition"],"group":"efficiency","label":"Word-size RNS CKKS","lane_rationale":"Replaces multiprecision core operations with word-size RNS/NTT arithmetic and approximate RNS modulus conversion.","lenses":["he_precision_correctness","he_concrete_cost"],"primary":true,"selection_rationale":"Represents the construction-to-machine-arithmetic transition that defines modern CKKS implementations.","thread":"he_ckks_approximate","visibility":"backbone"},"HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP":{"anchor_roles":[],"group":"efficiency","label":"Higher-precision CKKS refresh","lane_rationale":"Optimizes the precision-versus-depth trade-off through direct error-variance-aware modular-reduction polynomials.","lenses":["he_precision_correctness","he_concrete_cost"],"primary":true,"selection_rationale":"Shows the post-feasibility CKKS frontier moving to returned precision and approximation depth rather than another family node.","thread":"he_ckks_approximate","threads":["he_ckks_approximate","he_refresh"],"visibility":"reviewed_related"},"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING":{"anchor_roles":["current_frontier"],"group":"construction","label":"Encrypted 8-bit processor","lane_rationale":"Constructs a reusable encrypted-byte instruction layer from nibble encodings, programmable lookups and key-switching micro-operations; the artifact is separately excluded.","lenses":["he_programmable_words","he_concrete_cost"],"primary":true,"selection_rationale":"Provides the current word-level capability endpoint of the curated programmable-bootstrap thread.","thread":"he_gsw_programmable","visibility":"backbone"}},"overview_reading_path":["HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM","HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION","HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION","HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING"],"problems":[{"id":"he_general_fhe","label":"General computation and refresh","question":"How did homomorphic encryption progress from partial operations to refreshable general computation?","reading_path":["HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM","HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION","HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING"]},{"id":"he_noise_depth","label":"Noise, depth, and key growth","question":"Which mechanisms control noise, multiplicative depth, ciphertext dimension, and evaluation-key growth?","reading_path":["HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT","HE-RESULT-2012-BRAKERSKI-SCALE-INVARIANT-FHE-WITH-LINEAR-NOISE-GROWTH","HE-RESULT-2013-GSW-MULTIPLICATION-WITHOUT-RELINEARIZATION"]},{"id":"he_packing_layout_problem","label":"Packing and data movement","question":"How can one ciphertext carry and rearrange enough useful work to amortize homomorphic costs?","reading_path":["HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION","HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","HE-RESULT-2017-TFHE-CB-TFHE-CIRCUIT-BOOTSTRAPPING-AND-PACKED-OPERATIONS"]},{"id":"he_precision_correctness","label":"Numerical precision and correctness","question":"How do approximate HE systems manage scale, precision loss, and refresh error?","reading_path":["HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP"]},{"id":"he_programmable_words","label":"Programmable functions and words","question":"How did fast gate refresh become programmable lookup and word-level encrypted computation?","reading_path":["HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING"]},{"id":"he_concrete_cost","label":"Concrete runtime and portability","question":"Which algorithmic and systems choices reduce runtime, memory, and machine-word overhead in actual implementations?","reading_path":["HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING"]}],"relations":[{"change_dimensions":["model","functionality"],"evidence_locator":"Introduction and definition of FHE; exact cross-reference pending PDF audit","evidence_url":"https://crypto.stanford.edu/craig/craig-thesis.pdf","id":"lineage-45088743ce3d50e8","map_relation":"reference","predecessor":"HE-RESULT-1978-RAD-INTRODUCED-PRIVACY-HOMOMORPHISM-PROGRAM","relation_basis":"model_relation","relation_type":"GENERALIZES","review_status":"primary_source_checked","statement":"Gentry resolves the general computation goal posed by the privacy-homomorphism program by giving the first construction for arbitrary circuits.","successor":"HE-RESULT-2009-GENTRY-FIRST-FULLY-HOMOMORPHIC-ENCRYPTION"},{"change_dimensions":["mechanism","assumption"],"evidence_locator":"Abstract and introduction; exact section locator pending local PDF audit","evidence_url":"https://eprint.iacr.org/2009/616.pdf","id":"lineage-d46e15d8947cfb68","map_relation":"reference","predecessor":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","relation_basis":"technical_dependency","relation_type":"CHANGES_ASSUMPTION","review_status":"abstract_checked","statement":"DGHV retains Gentry's somewhat-HE-to-bootstrapping blueprint while replacing ideal-lattice arithmetic with approximate multiples of a hidden integer.","successor":"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD"},{"change_dimensions":["model","efficiency"],"evidence_locator":"BGV Sections 1.2 and 3; Theorem 3","evidence_url":"https://eprint.iacr.org/2011/277.pdf","id":"lineage-d83622c776d9a51a","map_relation":"lineage","predecessor":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"theorem_checked","statement":"BGV eliminates online bootstrapping for circuits of a predetermined depth by using depth-dependent parameters and a modulus chain; depth-independent FHE still uses bootstrapping. This is a scoped evaluation-cost trade-off.","successor":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING"},{"change_dimensions":["assumption","mechanism"],"evidence_locator":"Abstract, comparison with previous schemes; exact section locator pending local PDF audit","evidence_url":"https://eprint.iacr.org/2011/344.pdf","id":"lineage-aa8aa114b9d06967","map_relation":"reference","predecessor":"HE-RESULT-2010-DGHV-CONCEPTUALLY-SIMPLE-INTEGER-FHE-FROM-AGCD","relation_basis":"result_progression","relation_type":"CHANGES_ASSUMPTION","review_status":"abstract_checked","statement":"BV moves somewhat homomorphic encryption from integer and ideal assumptions to standard LWE and replaces squashing with relinearization and dimension-modulus reduction.","successor":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION"},{"change_dimensions":["mechanism","model","efficiency"],"evidence_locator":"BGV Sections 1.2 and 3; Theorem 3","evidence_url":"https://eprint.iacr.org/2011/277.pdf","id":"lineage-435e3cc40ebac0d4","map_relation":"lineage","predecessor":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"theorem_checked","statement":"BGV builds on BV noise-management techniques and introduces a modulus-chain approach yielding leveled FHE without bootstrapping.","successor":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING"},{"change_dimensions":["mechanism"],"evidence_locator":"Abstract; exact section locator pending local PDF audit","evidence_url":"https://eprint.iacr.org/2012/078.pdf","id":"lineage-1ecc458b3dce719d","map_relation":"reference","predecessor":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","relation_basis":"technical_dependency","relation_type":"CHANGES_NOISE_MECHANISM","review_status":"abstract_checked","statement":"Brakerski replaces quadratic multiplication-noise growth and modulus switching with tensoring that gives a scale-invariant single-modulus scheme.","successor":"HE-RESULT-2012-BRAKERSKI-SCALE-INVARIANT-FHE-WITH-LINEAR-NOISE-GROWTH"},{"change_dimensions":["mechanism","assumption"],"evidence_locator":"Introduction and construction overview; exact section locator pending local PDF audit","evidence_url":"https://eprint.iacr.org/2012/144.pdf","id":"lineage-2d1809561131801c","map_relation":"reference","predecessor":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"abstract_checked","statement":"FV specializes the relinearized LWE/RLWE arithmetic line into a practical ring-based exact modular construction.","successor":"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"GHS Sections 1 and 3–4","evidence_url":"https://eprint.iacr.org/2012/099.pdf","id":"lineage-1488ee3f37f143a7","map_relation":"lineage","predecessor":"HE-RESULT-2012-SV-SIMD-CIPHERTEXT-SLOT-PACKING-AND-PARALLEL-RECRYPTION","relation_basis":"technical_dependency","relation_type":"BUILDS_ON_RESULT","review_status":"section_checked","statement":"The AES evaluation uses SIMD packing to amortize many AES blocks inside one homomorphic computation.","successor":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"GHS Sections 1–3 and its BGV instantiation discussion","evidence_url":"https://eprint.iacr.org/2012/099.pdf","id":"lineage-68530e33cf2940b9","map_relation":"lineage","predecessor":"HE-RESULT-2012-BGV-LEVELED-FHE-WITHOUT-BOOTSTRAPPING","relation_basis":"technical_dependency","relation_type":"BUILDS_ON_RESULT","review_status":"section_checked","statement":"The AES implementation instantiates BGV-style modulus switching, key switching, CRT representation, and leveled evaluation.","successor":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE"},{"change_dimensions":["mechanism"],"evidence_locator":"GSW Section 1.2 and Section 3","evidence_url":"https://eprint.iacr.org/2013/340.pdf","id":"lineage-436c960d6e61a6d4","map_relation":"lineage","predecessor":"HE-RESULT-2011-BV-LWE-SHE-WITH-RELINEARIZATION","relation_basis":"technical_dependency","relation_type":"CHANGES_CIPHERTEXT_REPRESENTATION","review_status":"section_checked","statement":"GSW retains LWE security but replaces relinearized vector ciphertext multiplication with an approximate-eigenvector matrix representation.","successor":"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Abstract and introduction","evidence_url":"https://eprint.iacr.org/2014/816.pdf","id":"lineage-52034588ff778e8b","map_relation":"lineage","predecessor":"HE-RESULT-2009-GENTRY-INTRODUCED-BOOTSTRAPPING-BLUEPRINT","relation_basis":"technical_dependency","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"FHEW specializes the original refresh blueprint into subsecond bootstrapped Boolean operations.","successor":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING"},{"change_dimensions":["mechanism"],"evidence_locator":"Construction overview; exact section locator pending local PDF audit","evidence_url":"https://eprint.iacr.org/2014/816.pdf","id":"lineage-4c2f1af5dd6afc39","map_relation":"reference","predecessor":"HE-RESULT-2013-GSW-APPROXIMATE-EIGENVECTOR-GSW-CIPHERTEXTS","relation_basis":"technical_dependency","relation_type":"BUILDS_ON_RESULT","review_status":"abstract_checked","statement":"FHEW uses GSW-type ciphertext operations as part of its fast gate-bootstrapping construction.","successor":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Abstract and introduction","evidence_url":"https://eprint.iacr.org/2016/870.pdf","id":"lineage-92172d84d9c57c92","map_relation":"lineage","predecessor":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","relation_basis":"technical_dependency","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"TFHE rewrites FHEW through an LWE–RingGSW external product, reducing reported refresh time and bootstrapping-key size.","successor":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"Section 4; Algorithm 6; Theorem 4.1","evidence_url":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","id":"lineage-b66e2f2b9f764d2e","map_relation":"lineage","predecessor":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"theorem_checked","statement":"The follow-up extends the TFHE ciphertext stack with a circuit bootstrap that turns an LWE-encrypted bit into a low-noise RingGSW ciphertext for later leveled circuits.","successor":"HE-RESULT-2017-TFHE-CB-TFHE-CIRCUIT-BOOTSTRAPPING-AND-PACKED-OPERATIONS"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"Section 3, Leveled Homomorphic Circuits","evidence_url":"https://www.iacr.org/archive/asiacrypt2017/106240285/106240285.pdf","id":"lineage-c2c7d4d8508949e8","map_relation":"lineage","predecessor":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"section_checked","statement":"The follow-up adds packed TRLWE lookup and automata evaluation paths alongside the original TFHE gate-bootstrap line.","successor":"HE-RESULT-2017-TFHE-CB-TFHE-PACKED-LEVELED-OPERATIONS"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"Sections 3–5 and paper bibliography entries for TFHE","evidence_url":"https://eprint.iacr.org/2024/1201.pdf","id":"lineage-4f839e4d2e13fc19","map_relation":"lineage","predecessor":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"section_checked","statement":"The processor work builds its word interface over the TFHE bootstrap family and systematizes functional lookup patterns into more than fifty encrypted 8-bit instructions.","successor":"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING"},{"change_dimensions":["mechanism","model"],"evidence_locator":"Abstract and introduction","evidence_url":"https://eprint.iacr.org/2016/421.pdf","id":"lineage-6d7823b71dc26662","map_relation":"lineage","predecessor":"HE-RESULT-2012-BGV-MODULUS-SWITCHING-NOISE-MANAGEMENT","relation_basis":"technical_dependency","relation_type":"CHANGES_CORRECTNESS_SEMANTICS","review_status":"primary_source_checked","statement":"CKKS reinterprets modulus reduction as rescaling approximate plaintext and error together, changing the correctness semantics from exact modular arithmetic to controlled approximation.","successor":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING"},{"change_dimensions":["mechanism","model"],"evidence_locator":"Introduction and construction overview; exact section locator pending local PDF audit","evidence_url":"https://eprint.iacr.org/2016/421.pdf","id":"lineage-126afce9c02beb34","map_relation":"reference","predecessor":"HE-RESULT-2012-FV-RLWE-EXACT-ARITHMETIC-SCHEME-WITH-RELINEARIZATION","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"abstract_checked","statement":"CKKS retains packed RLWE ciphertext arithmetic and relinearization while replacing exact modular plaintext semantics with approximate numerical encoding and rescaling.","successor":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"Abstract and introduction","evidence_url":"https://eprint.iacr.org/2018/153.pdf","id":"lineage-58cf322d37f39d4a","map_relation":"lineage","predecessor":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"primary_source_checked","statement":"The bootstrapping paper turns leveled CKKS into FHE by approximately evaluating modular reduction in the decryption circuit.","successor":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Abstract","evidence_url":"https://eprint.iacr.org/2018/931.pdf","id":"lineage-42b2f81689e428d9","map_relation":"reference","predecessor":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","relation_basis":"technical_dependency","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"Full-RNS CKKS replaces multiprecision core arithmetic with word-size RNS/NTT operations and approximate RNS modulus switching.","successor":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Abstract and introduction","evidence_url":"https://eprint.iacr.org/2020/1549.pdf","id":"lineage-36d6f7095b21b29e","map_relation":"lineage","predecessor":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","relation_basis":"technical_dependency","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"The high-precision work replaces indirect modular-reduction approximations with a direct error-variance-minimizing polynomial design.","successor":"HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP"},{"change_dimensions":["mechanism","implementation"],"evidence_locator":"Introduction and implementation setting; exact section locator pending local PDF audit","evidence_url":"https://eprint.iacr.org/2020/1549.pdf","id":"lineage-cdf6ed0ee400a851","map_relation":"reference","predecessor":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","relation_basis":"technical_dependency","relation_type":"COMBINES","review_status":"abstract_checked","statement":"High-precision CKKS bootstrapping relies on the modern RNS implementation line while optimizing the approximation and depth of modular reduction.","successor":"HE-RESULT-2020-HP-CKKS-DIRECT-MODULAR-REDUCTION-APPROXIMATION-FOR-HIGH-PRECISION-CKKS-BOOTSTRAP"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Implementation evaluation; exact benchmark row pending","evidence_url":"https://eprint.iacr.org/2012/099.pdf","id":"lineage-b7dd9183975a7754","map_relation":"reference","predecessor":"HE-OPT-BGV-AES-PIPELINE-2012","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"abstract_checked","statement":"The end-to-end AES measurement evaluates the paper's CRT, packing, key-switching, and modulus-planning pipeline.","successor":"HE-BENCH-GHS-AES-2012"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Abstract and implementation results","evidence_url":"https://eprint.iacr.org/2014/816.pdf","id":"lineage-c2b1ff3ae4ac5c41","map_relation":"reference","predecessor":"HE-IMPL-FHEW-2015","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"primary_source_checked","statement":"The FHEW benchmark records the prototype's reported roughly half-second refreshed binary operation.","successor":"HE-BENCH-FHEW-2015"},{"change_dimensions":["mechanism","efficiency","implementation"],"evidence_locator":"Abstract and introduction","evidence_url":"https://eprint.iacr.org/2016/870.pdf","id":"lineage-c9d2de1c7a817434","map_relation":"reference","predecessor":"HE-IMPL-FHEW-2015","relation_basis":"technical_dependency","relation_type":"OPTIMIZES","review_status":"primary_source_checked","statement":"TFHE changes the concrete FHEW bootstrap path through an LWE–RingGSW external product.","successor":"HE-OPT-TFHE-EXTERNAL-PRODUCT-2016"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Abstract and performance section","evidence_url":"https://eprint.iacr.org/2016/870.pdf","id":"lineage-26213f11d9771e59","map_relation":"reference","predecessor":"HE-IMPL-TFHE-2016","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"primary_source_checked","statement":"The TFHE measurement is attached to the reported prototype, parameter record, and single-gate refresh workload.","successor":"HE-BENCH-TFHE-2016"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Abstract","evidence_url":"https://eprint.iacr.org/2018/931.pdf","id":"lineage-a13b643d46ee4598","map_relation":"reference","predecessor":"HE-RESULT-2017-CKKS-APPROXIMATE-ARITHMETIC-WITH-RESCALING","relation_basis":"technical_dependency","relation_type":"OPTIMIZES","review_status":"primary_source_checked","statement":"Full-RNS arithmetic turns the CKKS construction into word-size RNS and NTT kernels.","successor":"HE-OPT-CKKS-FULL-RNS-2018"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Evaluation section; exact row pending","evidence_url":"https://eprint.iacr.org/2018/153.pdf","id":"lineage-fb76d7d157452502","map_relation":"reference","predecessor":"HE-IMPL-CKKS-BOOT-2018","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"primary_source_checked","statement":"The benchmark anchors the first packed CKKS refresh claim to its prototype and parameter regime.","successor":"HE-BENCH-CKKS-BOOT-2018"},{"change_dimensions":["mechanism","efficiency","implementation"],"evidence_locator":"Introduction and implementation setting","evidence_url":"https://eprint.iacr.org/2020/1549.pdf","id":"lineage-268153e986af6c4d","map_relation":"reference","predecessor":"HE-OPT-CKKS-FULL-RNS-2018","relation_basis":"technical_dependency","relation_type":"OPTIMIZES","review_status":"primary_source_checked","statement":"The high-precision line retains modern RNS implementation machinery while improving approximate modular reduction.","successor":"HE-OPT-CKKS-HIGH-PRECISION-2020"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Implementation and evaluation sections; exact row pending","evidence_url":"https://eprint.iacr.org/2020/1549.pdf","id":"lineage-19355577f74fb496","map_relation":"reference","predecessor":"HE-OPT-CKKS-HIGH-PRECISION-2020","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"primary_source_checked","statement":"The high-precision benchmark measures the optimized approximation under its own precision and parameter profile.","successor":"HE-BENCH-HP-CKKS-2020"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"System evaluation; exact row pending","evidence_url":"https://eprint.iacr.org/2024/1201.pdf","id":"lineage-a6f2b035a2a8b685","map_relation":"reference","predecessor":"HE-IMPL-TFHE-PROCESSOR-2024","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"abstract_checked","statement":"The processor evaluation measures instruction- and program-level behavior rather than treating gate latency as the whole system result.","successor":"HE-BENCH-TFHE-PROCESSOR-2024"},{"change_dimensions":["implementation"],"evidence_locator":"Sections 1 and 4; HElib implementation description","evidence_url":"https://eprint.iacr.org/2012/099.pdf","id":"lineage-948365e7a35f6ab7","map_relation":"reference","predecessor":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","relation_basis":"technical_dependency","relation_type":"REALIZED_AS_PROTOTYPE","review_status":"section_checked","statement":"The end-to-end AES contribution is realized by the paper-described packed-BGV prototype combining CRT, slots, key switching, and modulus planning.","successor":"HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE"},{"change_dimensions":["implementation"],"evidence_locator":"Sections 1 and 4; HElib implementation description","evidence_url":"https://eprint.iacr.org/2012/099.pdf","id":"lineage-0ef603691f8f8260","map_relation":"reference","predecessor":"HE-RESULT-2012-GHS-AES-REALIZED-PACKED-BGV-AES-PROTOTYPE","relation_basis":"technical_dependency","relation_type":"DOCUMENTED_BY_IMPLEMENTATION","review_status":"section_checked","statement":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","successor":"HE-IMPL-GHS-AES-2012"},{"change_dimensions":["implementation"],"evidence_locator":"Implementation and performance sections","evidence_url":"https://eprint.iacr.org/2014/816.pdf","id":"lineage-5c20c47184ee71cf","map_relation":"reference","predecessor":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","relation_basis":"technical_dependency","relation_type":"REALIZED_AS_PROTOTYPE","review_status":"primary_source_checked","statement":"The FHEW gate-bootstrap result is realized by the research prototype underlying the paper's reported binary-gate measurement.","successor":"HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE"},{"change_dimensions":["implementation"],"evidence_locator":"Implementation and performance sections","evidence_url":"https://eprint.iacr.org/2014/816.pdf","id":"lineage-79ca3f8020a2c58f","map_relation":"reference","predecessor":"HE-RESULT-2015-FHEW-REALIZED-FHEW-GATE-BOOTSTRAP-PROTOTYPE","relation_basis":"technical_dependency","relation_type":"DOCUMENTED_BY_IMPLEMENTATION","review_status":"primary_source_checked","statement":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","successor":"HE-IMPL-FHEW-2015"},{"change_dimensions":["implementation"],"evidence_locator":"Implementation and performance sections","evidence_url":"https://eprint.iacr.org/2016/870.pdf","id":"lineage-9d2dfd59b3edd4fb","map_relation":"reference","predecessor":"HE-RESULT-2016-TFHE-EXTERNAL-PRODUCT-TFHE-BOOTSTRAPPING","relation_basis":"technical_dependency","relation_type":"REALIZED_AS_PROTOTYPE","review_status":"primary_source_checked","statement":"The TFHE realization implements the LWE–RingGSW external-product bootstrap kernel measured by the paper.","successor":"HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE"},{"change_dimensions":["implementation"],"evidence_locator":"Implementation and performance sections","evidence_url":"https://eprint.iacr.org/2016/870.pdf","id":"lineage-b765d11ade2dfe44","map_relation":"reference","predecessor":"HE-RESULT-2016-TFHE-REALIZED-TFHE-EXTERNAL-PRODUCT-PROTOTYPE","relation_basis":"technical_dependency","relation_type":"DOCUMENTED_BY_IMPLEMENTATION","review_status":"primary_source_checked","statement":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","successor":"HE-IMPL-TFHE-2016"},{"change_dimensions":["implementation"],"evidence_locator":"Bootstrapping evaluation section; exact artifact locator pending","evidence_url":"https://eprint.iacr.org/2018/153.pdf","id":"lineage-82914ac56a567e65","map_relation":"reference","predecessor":"HE-RESULT-2018-CKKS-BOOT-FIRST-CKKS-BOOTSTRAPPING-VIA-APPROXIMATE-MODULAR-REDUCTION","relation_basis":"technical_dependency","relation_type":"REALIZED_AS_PROTOTYPE","review_status":"primary_source_checked","statement":"The first CKKS bootstrap is realized by the paper-described packed refresh prototype evaluating approximate modular reduction.","successor":"HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE"},{"change_dimensions":["implementation"],"evidence_locator":"Bootstrapping evaluation section; exact artifact locator pending","evidence_url":"https://eprint.iacr.org/2018/153.pdf","id":"lineage-35d082a157e9e057","map_relation":"reference","predecessor":"HE-RESULT-2018-CKKS-BOOT-REALIZED-PACKED-CKKS-REFRESH-PROTOTYPE","relation_basis":"technical_dependency","relation_type":"DOCUMENTED_BY_IMPLEMENTATION","review_status":"primary_source_checked","statement":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","successor":"HE-IMPL-CKKS-BOOT-2018"},{"change_dimensions":["implementation"],"evidence_locator":"Implementation description and evaluation","evidence_url":"https://eprint.iacr.org/2018/931.pdf","id":"lineage-ac5a00b4f4d4123c","map_relation":"reference","predecessor":"HE-RESULT-2018-RNS-CKKS-FULL-RNS-CKKS-WITH-WORD-SIZE-ARITHMETIC","relation_basis":"technical_dependency","relation_type":"REALIZED_AS_PROTOTYPE","review_status":"primary_source_checked","statement":"The full-RNS contribution is realized as word-size RNS and NTT-friendly CKKS kernels in the paper's implementation pattern.","successor":"HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS"},{"change_dimensions":["implementation"],"evidence_locator":"Implementation description and evaluation","evidence_url":"https://eprint.iacr.org/2018/931.pdf","id":"lineage-d3781bbb53f918ef","map_relation":"reference","predecessor":"HE-RESULT-2018-RNS-CKKS-REALIZED-FULL-RNS-CKKS-WORD-KERNELS","relation_basis":"technical_dependency","relation_type":"DOCUMENTED_BY_IMPLEMENTATION","review_status":"primary_source_checked","statement":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","successor":"HE-IMPL-RNS-CKKS-2018"},{"change_dimensions":["implementation"],"evidence_locator":"Sections 5, 7, and 8; Appendix A","evidence_url":"https://eprint.iacr.org/2024/1201.pdf","id":"lineage-ffba40ef5cbaef15","map_relation":"reference","predecessor":"HE-RESULT-2024-TFHE-PROCESSOR-GENERAL-PURPOSE-EIGHT-BIT-PROCESSOR-FROM-PROGRAMMABLE-BOOTSTRAPPING","relation_basis":"technical_dependency","relation_type":"REALIZED_AS_PROTOTYPE","review_status":"section_checked","statement":"The encrypted 8-bit instruction abstraction is realized by the paper-described processor prototype used for system-level evaluation.","successor":"HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE"},{"change_dimensions":["implementation"],"evidence_locator":"Sections 5, 7, and 8; Appendix A","evidence_url":"https://eprint.iacr.org/2024/1201.pdf","id":"lineage-60d04a893d089b9a","map_relation":"reference","predecessor":"HE-RESULT-2024-TFHE-PROCESSOR-REALIZED-ENCRYPTED-EIGHT-BIT-PROCESSOR-PROTOTYPE","relation_basis":"technical_dependency","relation_type":"DOCUMENTED_BY_IMPLEMENTATION","review_status":"section_checked","statement":"This atomic realization contribution is represented by the separately versionable implementation object in the catalog.","successor":"HE-IMPL-TFHE-PROCESSOR-2024"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Section 4.4, non-bootstrapping implementation; Table 1","evidence_url":"https://eprint.iacr.org/2012/099.pdf","id":"lineage-d889fbfa134baf94","map_relation":"reference","predecessor":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","relation_basis":"analysis","relation_type":"CONTEXTUALIZED_BY_MEASUREMENT","review_status":"section_checked","statement":"The historical end-to-end AES claim is bounded by the separate parameter, workload, hardware, and source-reported measurement record.","successor":"HE-BENCH-GHS-AES-2012"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Section 4.4, implementation using bootstrapping; Table 1","evidence_url":"https://eprint.iacr.org/2012/099.pdf","id":"lineage-d6b0ddb09b7bd7b3","map_relation":"reference","predecessor":"HE-RESULT-2012-GHS-AES-END-TO-END-EVALUATION-OF-AES-WITH-PACKED-LHE","relation_basis":"analysis","relation_type":"CONTEXTUALIZED_BY_MEASUREMENT","review_status":"section_checked","statement":"The separate bootstrapped AES observation binds the same pipeline to its 23-level parameter regime, two recryptions, historical laptop, and reported memory.","successor":"HE-BENCH-GHS-AES-BOOT-2012"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Abstract and implementation results","evidence_url":"https://eprint.iacr.org/2014/816.pdf","id":"lineage-5a230d563e2330ce","map_relation":"reference","predecessor":"HE-RESULT-2015-FHEW-SUBSECOND-SINGLE-GATE-BOOTSTRAPPING","relation_basis":"analysis","relation_type":"CONTEXTUALIZED_BY_MEASUREMENT","review_status":"primary_source_checked","statement":"The roughly half-second FHEW gate-bootstrap claim is recorded as a contextual observation tied to the paper's prototype, parameters, and workload.","successor":"HE-BENCH-FHEW-2015"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Abstract and performance section","evidence_url":"https://eprint.iacr.org/2016/870.pdf","id":"lineage-b6e4947305f1179e","map_relation":"reference","predecessor":"HE-RESULT-2016-TFHE-SUB-TENTH-SECOND-GATE-REFRESH","relation_basis":"analysis","relation_type":"CONTEXTUALIZED_BY_MEASUREMENT","review_status":"primary_source_checked","statement":"The sub-0.1-second TFHE gate-refresh claim is bounded by the separate source-reported benchmark object and its parameter and workload context.","successor":"HE-BENCH-TFHE-2016"}],"rubric_version":1,"schema_version":1,"selection_policy":"semantic_contract_anchors","threads":[{"color":"#667784","description":"From partial homomorphism to the first general fully homomorphic construction.","id":"he_roots_capability","label":"PHE to general FHE"},{"color":"#2f718e","description":"Leveled and exact-arithmetic HE through relinearization and modulus management.","id":"he_lwe_rlwe_exact","label":"LWE/RLWE exact HE"},{"color":"#73549a","description":"SIMD slots, rotations, and layouts that amortize encrypted computation.","id":"he_packing_layout","label":"Packing and data layout"},{"color":"#b65358","description":"Gadget ciphertexts, external products, and fast gate or function refresh.","id":"he_gsw_programmable","label":"GSW and programmable bootstrapping"},{"color":"#4f7b60","description":"Approximate-number semantics, rescaling, RNS arithmetic, and CKKS refresh.","id":"he_ckks_approximate","label":"Approximate arithmetic and refresh"},{"color":"#9a6c2d","description":"Bootstrapping mechanisms reused across exact, gate, and approximate HE lines.","id":"he_refresh","label":"Refresh across HE families"}]},"stats":{"constructions":13,"countsByType":{"assumption":9,"barrier":4,"benchmark_run":7,"construction":13,"implementation":6,"milestone":18,"open_problem":6,"optimization":5,"paper":19,"parameter_set":7,"research_track":3,"result":31,"route":6,"workload":4},"entities":138,"lineageRelationships":13,"propertyAssertions":144,"relationships":354,"unresolvedReferences":0},"unresolved":[],"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}