# Polynomial Multiplication in CKKS

**URL:** <https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845>\
**Category:** FHE Questions\
**Created:** [October 13, 2023, 3:31pm UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845 "2023-10-13T15:31:00Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![marc-alonso](https://avatars.discourse-cdn.com/v4/letter/m/6f9a4e/32.png) [@marc-alonso](https://openfhe.discourse.group/u/marc-alonso)\
**Post date:** [October 13, 2023, 3:31pm UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/1 "2023-10-13T15:31:00Z")

</div>

Hello,

is it possible to perform a polynomial multiplication between two ciphertexts?

for example:

c\_1 = [2, 3, 1]\\ c\_2 = [1, 2, 4]\\ (2x^2 + 3x + 1) \times (x^2 + 2x + 4) 

results in:

2x^4 + 7x^3 + 15x^2 + 14x + 4

I would like to extract the first three slots c\_{res} = [2, 7, 15] of the resulting multiplication, would it be possible? Thank you

---

<div class="post-metadata">

**Author:** ![iquah](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/iquah/32/8_2.png) [@iquah](https://openfhe.discourse.group/u/iquah)\
**Post date:** [October 13, 2023, 6:00pm UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/2 "2023-10-13T18:00:57Z")

</div>

> I would like to extract the first three slots

Depends on what you mean by extract, but you can multiply by a mask and that will zero out everything else that’s not of interest

---

<div class="post-metadata">

**Author:** ![marc-alonso](https://avatars.discourse-cdn.com/v4/letter/m/6f9a4e/32.png) [@marc-alonso](https://openfhe.discourse.group/u/marc-alonso)\
**Post date:** [October 13, 2023, 6:35pm UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/3 "2023-10-13T18:35:00Z")

</div>

By performing c\_1 \cdot c\_2 slot-wise, we would obtain [2, 6, 4], but I’d like to get the result of the actual c\_1, c\_2 polynomial multiplication

---

<div class="post-metadata">

**Author:** ![iquah](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/iquah/32/8_2.png) [@iquah](https://openfhe.discourse.group/u/iquah)\
**Post date:** [October 13, 2023, 8:42pm UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/4 "2023-10-13T20:42:30Z")

</div>

Ahh, sorry, I skimmed the numbers which led to my misunderstanding.

---

<div class="post-metadata">

**Author:** ![ypolyakov](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/ypolyakov/32/47_2.png) [@ypolyakov](https://openfhe.discourse.group/u/ypolyakov)\
**Post date:** [October 13, 2023, 11:43pm UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/5 "2023-10-13T23:43:47Z")

</div>

In CKKS, we only support the CRT/Evaluation encoding (you can go to coefficient encoding using the SlotsToCoef subroutine in CKKS bootstrapping). The coefficient encoding is natively supported in BGV/BFV (along with CRT encoding).

You are asking about doing a multiplication in the coefficient encoding and then doing extraction. Extraction can be done by homomorphically switching to the CRT encoding (expensive) and then doing a masked multiplication or using LWE extraction. Extracting coefficients (via LWE) in the coefficient encoding can be done using automorphisms (a subroutine for this is implemented as part of CKKS scheme switching) - this is cheaper.

At a high level, these are advanced operations that require FHE expertise.

---

<div class="post-metadata">

**Author:** ![marc-alonso](https://avatars.discourse-cdn.com/v4/letter/m/6f9a4e/32.png) [@marc-alonso](https://openfhe.discourse.group/u/marc-alonso)\
**Post date:** [October 14, 2023, 9:41am UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/6 "2023-10-14T09:41:56Z")

</div>

So you don’t think there’s an easy way to perform it? I saw [this paper](https://ieeexplore.ieee.org/document/10089847) in which they perform a CNN convolution using polynomial multiplication but they used lattigo

---

<div class="post-metadata">

**Author:** ![narger](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/narger/32/420_2.png) [@narger](https://openfhe.discourse.group/u/narger)\
**Post date:** [October 17, 2023, 9:45am UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/7 "2023-10-17T09:45:44Z")

</div>

I checked the paper and it seems that they do not encode values “as usual”, values are encoded as polynomial coefficients (therefore they also use N slots and not N/2), I think this method has a slower ReLU evaluation and bootstrapping though, since slot-wise operations are not easy with that encoding. It is the first thing I thought when reading, but I am curious and will try to go into details!

---

<div class="post-metadata">

**Author:** ![narger](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/narger/32/420_2.png) [@narger](https://openfhe.discourse.group/u/narger)\
**Post date:** [October 23, 2023, 8:29am UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/8 "2023-10-23T08:29:08Z")

</div>

@marc-alonso I think the drawback about their approach is about ReLU evaluation, since slot-wise multiplications are more difficult (check [this recent thread](https://openfhe.discourse.group/t/format-switching-in-ckks/851/3))

Edit: ReLU was ok (is indeed computed after the CtoS step, on the re-encoded ciphertext), I think the way they consider convolutions as polynomial negacyclic convolutions is cool, it indeed avoids to run multiple multiplications and rotations. I guess the main issue is about packing LWE ciphertexts (which needs many rotation keys), but as soon as you have enough RAM, it is ok.

---

<div class="post-metadata">

**Author:** ![marc-alonso](https://avatars.discourse-cdn.com/v4/letter/m/6f9a4e/32.png) [@marc-alonso](https://openfhe.discourse.group/u/marc-alonso)\
**Post date:** [November 6, 2023, 9:07am UTC](https://openfhe.discourse.group/t/polynomial-multiplication-in-ckks/845/9 "2023-11-06T09:07:25Z")

</div>

Thank you. I got it now
