# Collective key switching

**URL:** <https://openfhe.discourse.group/t/collective-key-switching/112>\
**Category:** Library Questions\
**Created:** [August 26, 2022, 9:22am UTC](https://openfhe.discourse.group/t/collective-key-switching/112 "2022-08-26T09:22:24Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mpuskaric](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@mpuskaric](https://openfhe.discourse.group/u/mpuskaric)\
**Post date:** [August 26, 2022, 9:22am UTC](https://openfhe.discourse.group/t/collective-key-switching/112/1 "2022-08-26T09:22:24Z")

</div>

Hello,

I am currently experimenting with the re-encryption in a multi party setup using CKKS scheme, the idea is to re-encrypt the ciphertext which was encrypted using the shared public key. The setup is the following:

Parties 1 and 2 and their corresponding secret shares of key pairs `kp1` and `kp2` are used to create the shared public key (SharedPubKey). The ciphertext ct1 is encrypted using the shared public key. The receiver has the key pair kp3 and provides its public key for the re-encryption process.

I tried to perform a re-encryption in a following way:

```auto
// Ciphertext
ct1 = cc->Encrypt(SharedPubKey, plaintext);

// Party 1
evalKey1 = cc->ReKeyGen(kp1.secretKey, kp3.publicKey);
REct1 = cc->ReEncrypt(ct1, evalKey1);

// Party 2
evalKey2 = cc->ReKeyGen(kp2.secretKey, kp3.publicKey);
REct2 = cc->ReEncrypt(REct1, evalKey2);

//Receiver
cc->Decrypt(kp3.secretKey, REct2, &Result);

```

but this results with an error saying that decryption cannot be done due to the high approximation error[1], which probably means that the procedure is not correct.

The crypto context parameters are: multDepth = 1, scaleFactorBits = 50 and batchSize = 64. Following functionalities are enabled: PKE, KEYSWITCH, PRE, LEVELEDSHE, ADVANCEDSHE, MULTIPARTY. I went through a similar post on this topic (proxy re-encryption using ckks) and unit tests for multi party, ckks and multiHopPRE.

I would appreciate any feedback on this matter.

Thanks

[1] src/pke/lib/encoding/ckkspackedencoding.cpp:515 The decryption failed because the approximation error is too high. Check the parameters.

EDIT:

just found in `src/pke/include/cryptocontext.h:2368 MultipartyKeyGen(const PublicKey<Element> publicKey, bool makeSparse = false, bool fresh = false)`  
when creating keypair kp2 for the party 2, ‘fresh’ parameter should be set to true, in order for re-encryption to work in a multi party setup. Then, only party 2 would need to do the following:

```auto
// Party 2
evalKey2 = cc->ReKeyGen(kp2.secretKey, kp3.publicKey);
REct2 = cc->ReEncrypt(ct1, evalKey2);

// Receiver
cc->Decrypt(kp3.secretKey, REct2, &Result);

```

It is however then also possible to decrypt the ct1 using only kp2.secretKey.

---

<div class="post-metadata">

**Author:** ![iquah](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/iquah/32/8_2.png) [@iquah](https://openfhe.discourse.group/u/iquah)\
**Post date:** [August 26, 2022, 5:40pm UTC](https://openfhe.discourse.group/t/collective-key-switching/112/2 "2022-08-26T17:40:28Z")

</div>

@mpuskaric

Sounds like your issue/question was resolved based on your edit? I might be wrong. Can you confirm if that’s the case and if not I’ll float it to other members to see if they can help

---

<div class="post-metadata">

**Author:** ![mpuskaric](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@mpuskaric](https://openfhe.discourse.group/u/mpuskaric)\
**Post date:** [August 26, 2022, 11:09pm UTC](https://openfhe.discourse.group/t/collective-key-switching/112/3 "2022-08-26T23:09:30Z")

</div>

@iquah  
Thanks for the feedback, the issue regarding re-encryption has been resolved with the follow-up part.

However, I’m still wondering whether it is possible to perform a re-encryption process in the same way as a multi-party decryption, where each party computes a partial re-encryption, and fusion of the partial re-encryptions is done in the last step.

---

<div class="post-metadata">

**Author:** ![iquah](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/iquah/32/8_2.png) [@iquah](https://openfhe.discourse.group/u/iquah)\
**Post date:** [August 29, 2022, 7:30pm UTC](https://openfhe.discourse.group/t/collective-key-switching/112/4 "2022-08-29T19:30:52Z")

</div>

Would you mind making a new post for that question? That way it’ll ping the relevant people from the openfhe team 🙂

Thank you!

---

<div class="post-metadata">

**Author:** ![ypolyakov](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/ypolyakov/32/47_2.png) [@ypolyakov](https://openfhe.discourse.group/u/ypolyakov)\
**Post date:** [September 3, 2022, 9:28am UTC](https://openfhe.discourse.group/t/collective-key-switching/112/5 "2022-09-03T09:28:21Z")

</div>

@mpuskaric Could you clarify which of the following two scenarios you are asking about?

1. Do re-encryption only (without refreshing the noise - switch from the shared key to another key)
2. Do interactive bootstrapping (reset the noise and do key switching).

---

<div class="post-metadata">

**Author:** ![mpuskaric](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@mpuskaric](https://openfhe.discourse.group/u/mpuskaric)\
**Post date:** [September 4, 2022, 8:17am UTC](https://openfhe.discourse.group/t/collective-key-switching/112/6 "2022-09-04T08:17:34Z")

</div>

@ypolyakov I actually had the first scenario in mind when I wrote the post. Thanks

---

<div class="post-metadata">

**Author:** ![ypolyakov](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/ypolyakov/32/47_2.png) [@ypolyakov](https://openfhe.discourse.group/u/ypolyakov)\
**Post date:** [September 7, 2022, 3:21pm UTC](https://openfhe.discourse.group/t/collective-key-switching/112/7 "2022-09-07T15:21:57Z")

</div>

Hi @mpuskaric

Theoretically it is possible to do re-encryption using secret shares, but this is not currently supported by OpenFHE.

I am wondering why you prefer this approach over proxy re-encryption. In the PRE case, the distributed process is needed only during the generation of the re-encryption key (i.e., offline). Then the re-encryption of a ciphertext can be done using a single re-encryption operation (like key switching), i.e., the parties do not need to interact.

---

<div class="post-metadata">

**Author:** ![mpuskaric](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@mpuskaric](https://openfhe.discourse.group/u/mpuskaric)\
**Post date:** [September 13, 2022, 9:13pm UTC](https://openfhe.discourse.group/t/collective-key-switching/112/8 "2022-09-13T21:13:03Z")

</div>

thanks @ypolyakov for the clarification.

I was trying to implement a workflow for the distributed re-encryption key generation, but so far without success. In case of a multi party setup, where KeyPair1 and KeyPair2 are used for generating shared keys, how the workflow for generating the re-encryption key should look like?  
My understanding is that the first step is for both parties to run the **RunKeyGen** function using respective private keys and the receiver’s public key, but then there should be an additional step for creating a joint key, like with summation keys.  
So far, I’ve looked in the **UnitTestMultihopPRE.cpp** , **UnitTestPRE.cpp** and **UnitTestMultiparty.cpp** files for possible answers. I am using a CKKS scheme.

I would appreciate any hint or a suggestion.

---

<div class="post-metadata">

**Author:** ![ypolyakov](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/ypolyakov/32/47_2.png) [@ypolyakov](https://openfhe.discourse.group/u/ypolyakov)\
**Post date:** [September 16, 2022, 9:15pm UTC](https://openfhe.discourse.group/t/collective-key-switching/112/9 "2022-09-16T21:15:18Z")

</div>

I believe you are asking about `MultiAddEvalKeys`. This function adds two evaluation keys, where the first polynomials are the same, and the second ones get added. Please search for examples with `MultiAddEvalKeys`, e.g., in `threshold-fhe.cpp`

---

<div class="post-metadata">

**Author:** ![Nightingale](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/nightingale/32/93_2.png) [@Nightingale](https://openfhe.discourse.group/u/Nightingale)\
**Post date:** [February 15, 2023, 12:57pm UTC](https://openfhe.discourse.group/t/collective-key-switching/112/10 "2023-02-15T12:57:25Z")

</div>

Hi,

In threshold-fhe.cpp, party A generates key pair with KeyGen() then the other party uses MultipartyKeyGen(patyA.publickey) for generating joint public key .

Can i run KeyGen() algorithm for all party and then generate joint public key? I read the documantation but i could not find.  
I tried this idea but i couldnt perform any operation on the parties’ public key.

Thank you.

---

<div class="post-metadata">

**Author:** ![Caesar](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/caesar/32/63_2.png) [@Caesar](https://openfhe.discourse.group/u/Caesar)\
**Post date:** [February 15, 2023, 1:46pm UTC](https://openfhe.discourse.group/t/collective-key-switching/112/11 "2023-02-15T13:46:30Z")

</div>

The [example](https://github.com/FedericoMazzone/openfhe-ml/blob/main/src/threshold_bootstrap_BFV.cpp#L401) in this [post](https://openfhe.discourse.group/t/about-key-combination-in-threshold-fhe/283/2) should help you achieve what you want.
