Configuration and modulus chain
CkksConfig fixes the mathematical CKKS parameter set used by an execution context: the polynomial ring, default scale, ordered ciphertext-modulus groups, special modulus, Galois generator, error distribution, and security-budget selection. It contains exact prime values rather than device or machine-word policy.
Ownership
| Object | Responsibility |
|---|---|
Preset | Select a reviewed, named parameter baseline and resolve it to exact primes |
CkksConfig | Store the placement-independent CKKS and security parameters |
fhelium.eager.Engine | Select an RNS execution format and lazily create device-local arithmetic, random, and key resources |
A benchmark profile and a Bootstrap circuit are separate objects. Neither redefines CKKS parameters.
Ring and slots
For logN = k,
Q depth groups and P special primes
FHElium writes the ciphertext modulus as an ordered sequence of Q depth groups:
Each config.q_depth_groups stores these groups and their order. config.max_depth is
At public depth
The special modulus is
where the config.p_moduli. Hybrid key switching temporarily extends a Q value to the QP basis and then removes P by ModDown. P is not part of the public depth sequence.
For a dense RNS tensor, the limb axis is ordered as
[active Q rows, all P rows]when modulus_basis="QP", and contains only the first region when modulus_basis="Q". prime_ids records which configured prime each compact local row represents.
Integers, RNS, and the Chinese remainder theorem
A Residue Number System (RNS) represents an integer modulo a product of pairwise-coprime moduli. At a fixed depth, write the active Q primes as
Each remainder fits its individual modulus even when
Consequently, the residues determine exactly one integer class modulo
Reconstruction and signed representatives
Let
Each term reproduces its selected residue and vanishes modulo the other primes. For the odd moduli used here, the centered representative is
The standard and centered forms describe the same residue vector. A signed integer lying in the centered interval is recovered with its sign; a value outside that interval wraps to another representative of its class.
As an integer CRT example, take moduli
The integer
Polynomial coefficients and independent arithmetic
CKKS applies this representation to every coefficient of a polynomial in
The RNS Tensor therefore has a prime-row axis and a polynomial-coordinate axis. A row contains one residue of every coefficient, rather than a block of binary digits from each integer. CRT preserves addition and multiplication: polynomial arithmetic modulo
FHElium's encoder first produces signed int64 coefficients and reduces them into these rows. Subsequent homomorphic arithmetic can represent coefficient classes modulo a many-prime
A mixed-radix form expresses the same standard representative as
where an empty product equals one. The digits
Removing and extending a basis
Dropping Q rows projects the residue class onto the product of the remaining primes. Modulus switching performs this projection while preserving the recorded scale. Rescaling additionally computes a rounded quotient by the dropped group's product, so it requires arithmetic correction in the retained rows and divides the actual scale by that product.
Extending a basis requires a representative convention. One residue vector identifies a class containing both
Depth and depth remaining
Depth identifies the first active Q group. At depth zero, all Q groups are active. For
The public interval is 0 <= depth <= max_depth. FHElium reports
depth_remaining = max_depth - depthas the number of further rescale transitions in this chain. At max_depth, the active Q basis contains only
A Bootstrap composition declares its own entry requirements. The supplied full-slot composition uses bootstrap.input_depth, one step before the terminal basis; an ordinary rescale then reaches the basis it uses for centered ModRaise. This does not remove a depth from the general CKKS chain.
mod_switch_to_depth(value, target_depth) removes complete leading groups without quotient scaling. It preserves actual scale. rescale_to_next_depth removes one complete group and divides the actual scale by that group's product. No intermediate CKKS depth is created when a group contains several primes.
Scale is independent of prime width
config.default_scale supplies a creation and planning default. Every plaintext and ciphertext carries its own positive finite actual scale
A default scale near
RNS execution format
Encoding first produces signed int64 integer coefficients. The integer_coefficients_to_rns transition reduces those coefficients modulo each active prime and materializes the Engine's RNS dtype. Ciphertexts and live keys then retain that dtype.
The Engine selects the narrowest supported execution format for the exact QP prime set. rns_dtype= is an expert override and is validated against every configured modulus. Montgomery radix, lazy-reduction bounds, and native table layout belong to the device-local RnsContext, not CkksConfig. This keeps one Ciphertext, Engine, operation set, and Backend model across supported execution formats.
Exact configuration and serialization
A resolved configuration contains:
logN
default_scale
q_depth_groups
p_moduli
galois_generator
sigma
security_bits
enforce_security_budget2
3
4
5
6
7
8
CkksConfig.dumps() serializes these values and the FHElium package version. CkksConfig.parse() reconstructs that exact parameter set. Runtime placement, process groups, caches, NTT implementation choice, and RNS dtype do not enter configuration identity.
Cost and security consequences
Let
bytes of Tensor payload, where
The built-in security assessment applies to the exact complete QP product. A parameter plan must also validate numerical precision, message range, error growth, and native arithmetic bounds for its workload.