# Rotation by encrypted value

**URL:** <https://openfhe.discourse.group/t/rotation-by-encrypted-value/2102>\
**Category:** FHE Questions\
**Created:** [July 18, 2025, 10:25am UTC](https://openfhe.discourse.group/t/rotation-by-encrypted-value/2102 "2025-07-18T10:25:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![karlo\_73](https://avatars.discourse-cdn.com/v4/letter/k/43a26b/32.png) [@karlo\_73](https://openfhe.discourse.group/u/karlo_73)\
**Post date:** [July 18, 2025, 10:25am UTC](https://openfhe.discourse.group/t/rotation-by-encrypted-value/2102/1 "2025-07-18T10:25:00Z")

</div>

Hi all,

I was wondering if there is any way to perform rotations by an encrypted value (blind rotation?) in any of the schemes using batching (mainly CKKS)? Of course, normal rotations are a standard feature, but has anyone looked into this for rotating by a secret value?

Any insight would be appreciated.

Thanks!  
Karl

---

<div class="post-metadata">

**Author:** ![ypolyakov](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/ypolyakov/32/47_2.png) [@ypolyakov](https://openfhe.discourse.group/u/ypolyakov)\
**Post date:** [July 19, 2025, 5:48pm UTC](https://openfhe.discourse.group/t/rotation-by-encrypted-value/2102/2 "2025-07-19T17:48:45Z")

</div>

It might be worth looking at [SHIP: A Shallow and Highly Parallelizable CKKS Bootstrapping Algorithm](https://eprint.iacr.org/2025/784) and [PaCo: Bootstrapping for CKKS via Partial CoeffToSlot](https://eprint.iacr.org/2025/886). These papers try to work with a different definition of rotation, which is inspired by DM/CGGI blind rotation. The normal CKKS rotations are not directly compatible with the concept of rotating by a secret index.

---

<div class="post-metadata">

**Author:** ![Pro7ech](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/pro7ech/32/301_2.png) [@Pro7ech](https://openfhe.discourse.group/u/Pro7ech)\
**Post date:** [July 31, 2025, 11:16am UTC](https://openfhe.discourse.group/t/rotation-by-encrypted-value/2102/3 "2025-07-31T11:16:34Z")

</div>

I’ll add a concrete solution, not necessarily the best, but it is straight forward, which is to provide a base-d decomposition of the automorphism value in RGSW (one hot encoded) and evaluating log\_{d}(n/2)+1 (+1 for complex conjugation) sequential CMUX of the type CMUX(CT, rot(CT, d^i)…, RGSW(x\_i)…), each requiring d-1 automorphism (1 for complex conjugation) and RGSW products. Total key size would be d\*log\_{d}(n/2)+1 RGSW and automorphism keys.
