Homomorphic encryption (HE) enables the secure offloading of computations to the cloud by providing computation on encrypted data (ciphertexts). HE is based on noisy encryption schemes in which noise accumulates as more computations are applied to the data. The limited number of operations applicable to the data prevents practical applications from exploiting HE. Bootstrapping enables an unlimited number of operations or fully HE (FHE) by refreshing the ciphertext. Unfortunately, bootstrapping requires a significant amount of additional computation and memory bandwidth as well. Prior works have proposed hardware accelerators for computation primitives of FHE. However, to the best of our knowledge, this is the first to propose a hardware FHE accelerator that supports bootstrapping as a first-class citizen. In particular, we propose BTS - Bootstrappable, Technologydriven, Secure accelerator architecture for FHE. We identify the challenges of supporting bootstrapping in the accelerator and analyze the off-chip memory bandwidth and computation required. In particular, given the limitations of modern memory technology, we identify the HE parameter sets that are efficient for FHE acceleration. Based on the insights gained from our analysis, we propose BTS, which effectively exploits the parallelism innate in HE operations by arranging a massive number of processing elements in a grid. We present the design and microarchitecture of BTS, including a network-on-chip design that exploits a deterministic communication pattern. BTS shows 5,556x and 1,306x improved execution time on ResNet-20 and logistic regression over a CPU, with a chip area of 373.6mm^2 and up to 163.2W of power.
翻译:计算机加密(HE) 能够安全地卸载计算到云层的计算, 方法是提供加密数据( 密码文本) 的计算 。 HE 是基于噪音聚集的噪音加密计划, 在对数据应用更多计算后, 噪音会累积到这个系统。 适用于数据的操作数量有限, 使得无法实际应用 HE 。 启动使FHE 的操作数量无限, 或完全 HE (FHE) 能够刷新密码。 不幸的是, 靴子安装需要大量额外的计算和记忆带宽。 先前的工程已经提出了计算FHE 原始数据的硬件加速器 。 然而, 根据我们的知识, 这是第一个提出一个硬件 FHE 加速加速器的硬件加速器 。 特别是, 我们从现代的存储技术上, 我们从计算机加速加速器的系统设计模型, 技术驱动器, 安全加速器, 安全加速器的加速器 。