Homomorphic Encryption for Arithmetic of Approximate Numbers CKKS scheme の提案論文 BFV scheme が原型 cannonical embedding norm toohard ∥a∥∞can:=∥σ(a)∥∞: σ(x) のℓ∞ norm 性質 ∀a,b∈S, ∥a⋅b∥∞can≤∥a∥∞can⋅∥b∥∞can ∀a∈S,∥a∥∞can≤∥a∥ ∀a∈S,∥a∥∞can≤∃CM (const) CM=∥CRTM−1∥∞ ∥U∥∞:=max0≤i≤N∑j=0N−1∣uij∣ (U は原始 M 乗根のvandermonde matrix) valid encryption (c∈Rqℓ2,ℓ,ν,B) を m∈S の妥当な暗号文と呼ぶ ∥m∥∞can≤ν ⟨c,sk⟩=m+e(modqℓ) ∃e∈S,∥e∥∞can≤B