Paper 2026/269
Exact Error Analysis for Blind Rotation in Fully Homomorphic Encryption
Abstract
Blind rotation is the computational core of GINX, AP, and AP+ bootstrappings, yet its error behavior has not been precisely characterized. Prior analyses rely on heuristic independence assumptions that fail to capture the distinct error accumulation patterns of different algorithmic variants. We prove that no additional assumptions are needed: the (M)LWE assumption guaranteeing ciphertext indistinguishability also implies the independence properties required for an exact second-moment characterization of blind rotation error. We derive the first closed-form formulas covering all four combinations of decomposition type (full vs. approximated) and algorithmic variant (vanilla vs. unrolled). Our analysis reveals three structural phenomena previously overlooked: (i) a message-dependent residual term that halves the effective decomposition variance, (ii) a doubling coefficient inherent to unrolled implementations, and (iii) bounded cross-term correlations whose contribution remains constant in the security parameter. Our formulas match experimental measurements within 1%, whereas prior estimators deviate by up to 50% for unrolled blind rotation. Our results show that the (M)LWE assumption—already required for security— is sufficient to determine the exact error behavior of GINX, AP, and AP+ bootstrapping.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- Fully homomorphic encryptionBlind rotationGadget decompositionLearning with errors (LWE) problemError analysis
- Contact author(s)
-
thegimsin @ hanyang ac kr
kr2951 @ hanyang ac kr
dohyuk1000 @ hanyang ac kr
djshin @ hanyang ac kr - History
- 2026-02-18: revised
- 2026-02-16: received
- See all versions
- Short URL
- https://ia.cr/2026/269
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/269,
author = {Sin Kim and Seunghwan Lee and Dohyuk Kim and Dong-Joon Shin},
title = {Exact Error Analysis for Blind Rotation in Fully Homomorphic Encryption},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/269},
year = {2026},
url = {https://eprint.iacr.org/2026/269}
}