<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">75573</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2026.075573</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>TQKD: A More Efficient QKD Network Based on Homomorphic Encryption Technology</article-title>
<alt-title alt-title-type="left-running-head">TQKD: A More Efficient QKD Network based on Homomorphic Encryption Technology</alt-title>
<alt-title alt-title-type="right-running-head">TQKD: A More Efficient QKD Network based on Homomorphic Encryption Technology</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Lin</surname><given-names>Tianhua</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Xie</surname><given-names>Sijiang</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><email>xiesj@besti.edu.cn</email></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Yan</surname><given-names>Yalong</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Xie</surname><given-names>Jianguo</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Liu</surname><given-names>Ang</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Cyberspace Security, Beijing Electronic Science and Technology Institute</institution>, <addr-line>Beijing</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>Institute of Information Security, Beijing Electronic Science and Technology Institute</institution>, <addr-line>Beijing</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Sijiang Xie. Email: <email>xiesj@besti.edu.cn</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2026</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>8</day><month>5</month><year>2026</year>
</pub-date>
<volume>88</volume>
<issue>1</issue>
<elocation-id>30</elocation-id>
<history>
<date date-type="received">
<day>04</day>
<month>11</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>16</day>
<month>01</month>
<year>2026</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026 The Authors. Published by Tech Science Press.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder>The Authors</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_75573.pdf"></self-uri>
<abstract>
<p>Quantum key distribution (QKD) provides unconditional security but relies on repeaters to extend coverage, thereby introducing repeater trust risks&#x2014;compromised repeaters may leak keys. Brakerski/Fan-Vercauteren scheme (BFV)-based QKD addresses this issue through key encryption and quantum attack resistance. However, Fast Fully Homomorphic Encryption over the Torus (TFHE) outperforms BFV in encryption/decryption speed for single-qubit homomorphic XOR operations, which is critical for the real-time requirements of QKD. We propose TFHE-based QKD (TQKD), a quantum key distribution protocol based on public-key TFHE. During key forwarding, it leverages the &#x201C;usable-but-unobservable&#x201D; property of homomorphic encryption to prevent key exposure. A reduction proof verifies the scheme&#x2019;s Indistinguishability under Chosen-Plaintext Attack (IND-CPA) security. To validate TQKD&#x2019;s computational speed advantage, we developed code using the Open-Source Fully Homomorphic Encryption Library (OpenFHE) platform and designed single-pass and multi-hop relay experiments. We compared the computational efficiency of TQKD against QKD schemes based on similar homomorphic encryption algorithms, Brakerski-Gentry-Vaikuntanathan scheme (BGV) and BFV. Results demonstrate that our scheme achieves faster key encryption/decryption speeds in both scenarios, significantly reducing processing time compared to similar algorithms. Furthermore, while enhancing the scalability of quantum key distribution networks, the added computational overhead is negligible, indicating higher practical value.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Quantum key distribution</kwd>
<kwd>untrusted relay</kwd>
<kwd>homomorphic encryption</kwd>
<kwd>learning with errors</kwd>
<kwd>TFHE</kwd>
<kwd>OpenFHE</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>National Key Science and Technology Project</funding-source>
<award-id>2021ZD0301301</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Fundamental Research Funds for the Central Universities</funding-source>
<award-id>3282025009</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>In 1984, Bennett and Brassard proposed the first quantum key distribution protocol, namely the BB84 protocol [<xref ref-type="bibr" rid="ref-1">1</xref>], opening a new chapter in secure communication based on quantum properties. QKD is a secure communication technology based on the principles of quantum mechanics. Its core function is to establish a connection between two geographically separated users and distribute symmetric encryption keys. Unlike traditional public-key cryptosystems based on computational complexity, the security of QKD is not built on complex mathematical problems but on fundamental physical principles of quantum mechanics, such as Heisenberg&#x2019;s uncertainty principle and the quantum no-cloning theorem. It provides a guarantee of the theoretical security of information rather than computational assumptions, ensuring the unconditional security of the key generation and distribution process. At first, this technology did not attract people&#x2019;s attention. It was not until the emergence of quantum computing that traditional encryption algorithms faced unprecedented challenges. Peter Shor&#x2019;s Shor algorithm, which can be implemented on a quantum computer, can solve in polynomial time the decomposition and elliptic curve logarithm problems for large numbers [<xref ref-type="bibr" rid="ref-2">2</xref>,<xref ref-type="bibr" rid="ref-3">3</xref>]. It almost destroyed the current mainstream public-key cryptography systems represented by RSA, ECC, DH, and DSA [<xref ref-type="bibr" rid="ref-4">4</xref>]. At the same time, the Grover algorithm [<xref ref-type="bibr" rid="ref-5">5</xref>] proposed by Lov Grover can significantly accelerate brute-force cracking of symmetric encryption. That means it has had a significant impact on brute-force cracking. However, QKD possesses the theoretically unconditional security property, rendering it immune to attacks from these quantum algorithms. It has prompted researchers in the field of information security to actively explore schemes based on QKD and Post-Quantum Cryptography(PQC). Consequently, QKD is regarded as the most important, mainstream, and promising technology in current quantum secure communication research and applications.</p>
<p>Although QKD is theoretically highly secure, it faces significant challenges in practical applications and large-scale deployment that cannot be ignored. The core of QKD lies in using quantum states at the single-photon level, such as photon polarization or phase, to encode information. These quantum states are highly fragile and readily interact with surrounding matter, leading to decoherence or absorption that destroys the quantum information they carry. Therefore, QKD requires a medium that maximizes the protection of quantum signals and enables their stable transmission, and fiber-optic channels precisely meet this core requirement. Although free space, such as the atmosphere or satellites, also represents an important research direction for quantum channels, the existing highly developed fiber-optic communication infrastructure network significantly reduces deployment costs and engineering complexity when implementing QKD. Consequently, fiber-optic channels possess an irreplaceable advantage. However, single-photon propagation in optical fibers is inevitably affected by signal attenuation and background noise. Takeoka et al. [<xref ref-type="bibr" rid="ref-6">6</xref>] were the first to rigorously demonstrate that the key generation rate in optical QKD is bounded by a ceiling determined solely by channel loss&#x2014;meaning there exists a maximum effective communication distance between two optical nodes without relaying. This limit was later extended to 300 km by Korzh et al. [<xref ref-type="bibr" rid="ref-7">7</xref>]. To address this critical issue, researchers have proposed various schemes over the years, as outlined in <xref ref-type="sec" rid="s2">Section 2</xref>, to extend the effective transmission distance of QKD and build large-scale networks.</p>
<p>After years of practical exploration, researchers worldwide have conducted numerous experiments deploying QKD networks [<xref ref-type="bibr" rid="ref-8">8</xref>&#x2013;<xref ref-type="bibr" rid="ref-12">12</xref>]. Currently, most QKD experimental projects rely on trusted relays, in which quantum keys from adjacent segments are XORed within the relay. While this design ensures real-time and accurate key delivery, it introduces a significant security vulnerability: if any relay node is compromised, leading to the leakage of one quantum key, the attacker can reconstruct the quantum key for the other segment based on the XOR result, thereby compromising all quantum keys along the entire path. Therefore, the key to resolving this issue lies in ensuring key security even when relays are untrusted.</p>
<p>Our TQKD scheme focuses on relay-based QKD, employing the TFHE homomorphic encryption algorithm to ensure privacy and security during relay-based quantum key forwarding. It eliminates reliance on trusted relays, enabling efficient and secure QKD key transmission in untrusted relay scenarios. By performing bitwise homomorphic XOR operations on quantum keys in relays, TFHE demonstrates significant advantages over BGV and BFV algorithms in terms of ciphertext noise reset and logical gate operations. Through its Fast Bootstrapping mechanism, TFHE can instantly reset the ciphertext noise after homomorphic XOR operations, moving it from the threshold edge to a secure level. This eliminates the need for BGV and BFV algorithms to pre-evaluate the circuit&#x2019;s noise threshold before performing Bootstrapping. Furthermore, TFHE incorporates efficient logic gate circuits. The XOR operation is implemented via <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mi>B</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, whereas BGV and BFV lack native XOR logic gates. Consequently, XOR in these algorithms must be decomposed into AND/OR/NOT combinations, requiring multiple rounds of operations per XOR calculation and incurring substantial redundant overhead.</p>
<p>The structure of this paper is as follows: In <xref ref-type="sec" rid="s2">Section 2</xref>, we outline the development trajectory of QKD networks, categorize them based on different QKD implementation schemes, and discuss previous seminal work. In <xref ref-type="sec" rid="s3">Section 3</xref>, we explain how the advanced mechanisms of TFHE influence our proposed scheme. In <xref ref-type="sec" rid="s4">Section 4</xref>, we introduce the public-key version of the TFHE algorithm and the TQKD network model, presenting a complete workflow for TQKD. In <xref ref-type="sec" rid="s5">Section 5</xref>, we design two experimental scenarios to evaluate the innovative value of TFHE in terms of efficiency and propose potential directions for improvement. Finally, in <xref ref-type="sec" rid="s6">Section 6</xref>, we summarize the advantages of the TFHE scheme and identify areas requiring future effort.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>In this section, we will categorize and present the progress of relevant work based on different implementation approaches, including relay-based QKD.</p>
<sec id="s2_1">
<label>2.1</label>
<title>XOR Based QKD (XOR-QKD)</title>
<p>XOR-QKD is a QKD scheme based on trusted relays that requires full trust in them. Its core concept involves using the lightweight XOR operation to preprocess the key at the trusted relay node, then relaying it hop-by-hop to adjacent nodes. It enables efficient reconstruction of the shared key at the target QKD node, achieving end-to-end key distribution. As shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>, each pair of adjacent nodes shares the same quantum key based on the BB84 protocol, denoted as <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>. Alice needs to share the key <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> with Bob. Trusted relay A first computes <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2295;</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> and then transmits it to trusted relay B. Trusted relay B computes <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2295;</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2295;</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> to obtain <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>, then calculates <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2295;</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> and sends it to Bob. Upon receiving it, Bob computes <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2295;</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2295;</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> to obtain <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>. At this point, Alice and Bob securely share the same quantum key <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>. When transmitting data over classical communication networks, both parties can directly use the quantum key <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> to encrypt information. Notably, this key employs the OTP algorithm, as validated by Shannon, ensure its theoretical security.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>XOR-QKD.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-1.tif"/>
</fig>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Measurement Device Independent-QKD (MDI-QKD)</title>
<p>MDI-QKD is a QKD protocol based on untrusted relays, proposed by Hoi Kwong et al. The protocol innovatively installs quantum measurement devices within untrusted relays, ensuring that even if an eavesdropper takes control, the overall security of the system remains unaffected. As illustrated in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, its core concept involves delegating quantum measurement to an untrusted third party (typically Charlie). Alice and Bob independently and randomly select BB84-encoded basis vectors (linear polarization basis or diagonal basis) and bit values. They prepare corresponding quantum states using phase-randomized weak light pulses and transmit them to Charlie via a channel. Subsequently, Charlie performs Bell state measurements and publicly discloses the results. Finally, Alice and Bob generate the key based on these measurements.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>MDI-QKD.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-2.tif"/>
</fig>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Multipath-QKD</title>
<p>Multipath-QKD is a QKD scheme based on partially trusted relays, as illustrated in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>. The communication parties are Alice and Bob. Alice divides the key <italic>K</italic> to be distributed to Bob into several key fragments <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>4</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and distributes them simultaneously via multiple independent paths, rather than relying on a single path. The relay nodes on these paths are categorized as trusted nodes and untrusted nodes. Trusted nodes possess extremely high security, effectively resisting eavesdropper attacks; untrusted nodes have lower security and may be successfully intercepted. Furthermore, relay nodes along different paths do not overlap&#x2014;i.e., no relay node appears on more than one path&#x2014;further reducing the risk of a single point being compromised. Ultimately, upon receiving these key fragments, Bob reconstructs them into a global key through key assembly. Unless an attacker can simultaneously eavesdrop on all paths, they cannot obtain the complete key.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Multipath-QKD.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-3.tif"/>
</fig>
</sec>
<sec id="s2_4">
<label>2.4</label>
<title>Quantum Repeaters-QKD</title>
<p>Briegel et al. first proposed the concept of quantum repeaters [<xref ref-type="bibr" rid="ref-13">13</xref>] and analyzed their role in long-distance quantum communication. Quantum repeaters are key devices for extending the range of quantum communication. In long-distance quantum communication, quantum repeaters divide the path into multiple short-distance segments. Each relay establishes quantum entangled pairs with its neighboring node. Subsequently, the relay performs Bell state measurements to link the entangled states of adjacent segments. Each node stores the received quantum states in quantum memory, awaiting the completion of entanglement swapping across all segments. Ultimately, the two segments generate a shared key via the entangled state. Due to the nonlocality of entangled states, any eavesdropping attempt is detected, eliminating the need for trust in relay nodes. However, under current technological constraints, quantum repeater technology remains immature. Without employing trusted relay techniques, long-distance QKD cannot be achieved [<xref ref-type="bibr" rid="ref-14">14</xref>]. Future QKD advancements hinge on quantum repeater technology, which is the key solution to overcoming QKD&#x2019;s distance limitations [<xref ref-type="bibr" rid="ref-15">15</xref>,<xref ref-type="bibr" rid="ref-16">16</xref>].</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Preliminaries</title>
<p>This section introduces the mathematical foundations and key technical features of TFHE used in the public-key TFHE homomorphic encryption QKD scheme, laying the groundwork for the next section <xref ref-type="sec" rid="s4">Section 4</xref>.</p>
<sec id="s3_1">
<label>3.1</label>
<title>Homomorphic Encryption</title>
<p>Homomorphic encryption is a cryptographic technique that enables specific computations to be performed directly on encrypted data while preserving the functional and structural properties of the data. The decrypted result matches the outcome of operating directly on the plaintext. Taking additive homomorphic encryption as an example, as shown in <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>, for sample messages <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>x</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>y</mml:mi></mml:math></inline-formula>, encrypting them using the homomorphic encryption function <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mi>r</mml:mi><mml:mi>y</mml:mi><mml:mi>p</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> yields <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Adding these results produces <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo>+</mml:mo><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, with the entire encryption process requiring no explicit knowledge of <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi>x</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>y</mml:mi></mml:math></inline-formula>.
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo>+</mml:mo><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>This differs significantly from traditional encryption schemes. Homomorphic encryption does not require decrypting encrypted data beforehand; instead, it enables mathematical operations and data processing while the plaintext remains unknown. It effectively safeguards user privacy, eliminating concerns about data leaks even when stored in the cloud or on servers. It aligns perfectly with our enhanced solution. Applying homomorphic encryption to QKD effectively prevents key leakage caused by relay attacks.</p>
<p>Looking back at the history of homomorphic encryption, this technology was first named &#x201C;privacy homomorphism&#x201D; by Rivest et al. in 1978 [<xref ref-type="bibr" rid="ref-17">17</xref>]. Subsequently, researchers worldwide built upon this foundation to design numerous homomorphic encryption schemes, including: RSA cryptosystem (1978) supporting multiplicative homomorphic operations [<xref ref-type="bibr" rid="ref-18">18</xref>], the encryption algorithm proposed by Goldwasser and Micali (1982) [<xref ref-type="bibr" rid="ref-19">19</xref>], the ElGamal algorithm for randomized encryption (1985) [<xref ref-type="bibr" rid="ref-20">20</xref>], Benaloh&#x2019;s (1994) [<xref ref-type="bibr" rid="ref-21">21</xref>], the widely used additive homomorphic Paillier algorithm (1999) [<xref ref-type="bibr" rid="ref-22">22</xref>], and the encryption algorithm proposed by Boneh et al. (2005) [<xref ref-type="bibr" rid="ref-23">23</xref>], which supports both additive and multiplicative operations. Goh and Nissim&#x2019;s cryptographic scheme (2005) [<xref ref-type="bibr" rid="ref-23">23</xref>], which supports both additive and multiplicative operations, allowing infinite additive homomorphisms but only a single multiplicative homomorphism. However, it was not until 2009 that Gentry constructed the first fully homomorphic encryption scheme supporting arbitrary circuit evaluation in his doctoral dissertation [<xref ref-type="bibr" rid="ref-24">24</xref>]. The scheme is based on ideal lattices and innovatively introduces Bootstrapping technology to reduce ciphertext noise. Building upon this foundation, various novel homomorphic encryption schemes have been proposed. Among the most representative are BGV (2012) [<xref ref-type="bibr" rid="ref-25">25</xref>], BFV (2012) [<xref ref-type="bibr" rid="ref-26">26</xref>,<xref ref-type="bibr" rid="ref-27">27</xref>], GSW (2013) [<xref ref-type="bibr" rid="ref-28">28</xref>], TFHE (2016) [<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>], CKKS (2017) [<xref ref-type="bibr" rid="ref-31">31</xref>]. Among these, the TFHE algorithm excels at Boolean operations (XOR), aligning with key operations in QKD relays. It enables faster computation of key bits while maintaining resistance to quantum attacks. We attempted to apply it to QKD scenarios and achieved significant results through simulation experiments.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Learning with Errors (LWE) &#x0026; Torus Learning with Errors (TLWE)</title>
<p>LWE was proposed by American computer scientist Oded Regev in 2005 [<xref ref-type="bibr" rid="ref-32">32</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>], and remains one of his most significant contributions to date. The LWE problem is a computationally complex problem whose security relies on worst-case lattice problems (such as the Shortest Vector Problem, SVP). It serves as a core tool in post-quantum cryptography. Its fundamental concept is to recover the original secret vector from a set of linear equations deliberately corrupted by errors. It is precisely the presence of these errors that renders the LWE problem computationally challenging.</p>
<p>The formal definition is given below: Dimension <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>n</mml:mi></mml:math></inline-formula>, modulus <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mi>q</mml:mi></mml:math></inline-formula>, noise distribution <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mi>&#x03C7;</mml:mi></mml:math></inline-formula> (typically a Gaussian distribution over <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi></mml:msub></mml:math></inline-formula>). Noise term <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mi>e</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>&#x03C7;</mml:mi></mml:math></inline-formula>. Several samples <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mi>n</mml:mi></mml:msubsup><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi></mml:msub></mml:math></inline-formula>, each containing a secret vector <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mi>s</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mi>n</mml:mi></mml:msubsup></mml:math></inline-formula>.
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mi>b</mml:mi><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mo>+</mml:mo><mml:mi>e</mml:mi><mml:mtext>&#x00A0;&#x00A0;</mml:mtext><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mtext>&#x00A0;&#x00A0;</mml:mtext><mml:mi>q</mml:mi></mml:math></disp-formula></p>
<p>Given a genuine sample <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> that satisfies equation <xref ref-type="disp-formula" rid="eqn-2">Eq. (2)</xref>. Intuitively, when <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is known, it is difficult to determine whether <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mi>b</mml:mi></mml:math></inline-formula> is the inner product of <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mi>a</mml:mi></mml:math></inline-formula> and a secret vector <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mi>s</mml:mi></mml:math></inline-formula> with added noise, or a completely random value. This computational difficulty underlies cryptographic applications of LWE. By exploiting this difficulty, public-key cryptography can be constructed.</p>
<p>Although LWE is secure and versatile, homomorphic operations cause rapid noise expansion and require frequent <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mtext>&#x00A0;&#x00A0;</mml:mtext><mml:mi>q</mml:mi></mml:math></inline-formula> operations, potentially introducing additional noise. It presents a significant flaw in fully homomorphic encryption. The TFHE algorithm ingeniously resolves this issue by incorporating the Torus. The TLWE problem replaces the integer modulus space <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi></mml:msub></mml:math></inline-formula> of LWE with the Torus, as detailed in <xref ref-type="sec" rid="s3_3_1">Section 3.3.1</xref>. Similar to LWE, the TLWE problem involves samples <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow><mml:mi>n</mml:mi></mml:msup><mml:mo>&#x00D7;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow></mml:math></inline-formula> satisfying equation <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>.
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mi>b</mml:mi><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mo>+</mml:mo><mml:mi>e</mml:mi><mml:mtext>&#x00A0;&#x00A0;</mml:mtext><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mtext>&#x00A0;&#x00A0;</mml:mtext><mml:mn>1</mml:mn></mml:math></disp-formula></p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>TFHE</title>
<p>TFHE is a Fast Bootstrapping fully homomorphic encryption framework based on the torus, reducing bootstrapping time from seconds to under 0.1 seconds and enabling millisecond-level homomorphic computations. This framework was first proposed by Chillotti et al. in 2016 [<xref ref-type="bibr" rid="ref-29">29</xref>]. In 2020, Chillotti et al. systematically expanded and optimized the 2016 work [<xref ref-type="bibr" rid="ref-30">30</xref>], formalizing the TFHE framework under its official name and open-sourcing it. This scheme represents the third generation of fully homomorphic encryption technology, achieving significant breakthroughs in computational efficiency and practicality compared to previous generations. Next, we will introduce some key features of TFHE.</p>
<sec id="s3_3_1">
<label>3.3.1</label>
<title>Torus</title>
<p>The &#x201C;T&#x201D; in TFHE stands for &#x201C;Torus&#x201D;, denoted as <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow></mml:math></inline-formula>. Its rigorous mathematical definition is the quotient space of the set of real numbers <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:math></inline-formula> by the set of integers <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:math></inline-formula>, as shown in <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>.
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:math></disp-formula></p>
<p>In layman&#x2019;s terms, it can be visualized by folding the real number line into a torus with a period of 1. Any real number <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:math></inline-formula> corresponds to the element <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mi>x</mml:mi><mml:mspace width="0.444em" /><mml:mo stretchy="false">(</mml:mo><mml:mi>mod</mml:mi><mml:mspace width="0.333em" /><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> on the Torus, where every element can be uniquely represented as <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> or <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac></mml:mrow><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. To support efficient ring operations (based on Ring Learning with Errors(RLWE)), TFHE further defines the torus over a polynomial ring, denoted as <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, as shown in <xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref>. Here, <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>X</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the anti-cyclic polynomial, ensuring compatibility with RLWE.
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>X</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mspace width="1em" /><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mtext>&#x00A0;&#x00A0;</mml:mtext><mml:mn>1</mml:mn></mml:math></disp-formula></p>
<p>The Torus design offers several advantages.</p>
<p><italic>Natural noise compression</italic></p>
<p>In traditional LWE encryption, ciphertext noise expands as the modulus <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mi>q</mml:mi></mml:math></inline-formula> increases. To ensure correct decryption, the condition <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mrow><mml:mfrac><mml:mi>q</mml:mi><mml:mn>2</mml:mn></mml:mfrac></mml:mrow></mml:math></inline-formula> must be satisfied, where <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:math></inline-formula> denotes the absolute value of the noise [<xref ref-type="bibr" rid="ref-34">34</xref>]. However, noise after homomorphic operations still needs to be reduced modulo <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mi>q</mml:mi></mml:math></inline-formula>, which may introduce uncontrolled noise. Torus&#x2019;s &#x201C;mod 1&#x201D; property inherently compresses noise. In TFHE, noise <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mi>e</mml:mi></mml:math></inline-formula> is defined as a small element on the torus, <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>e</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x003C;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>4</mml:mn></mml:mfrac></mml:math></inline-formula>. After homomorphic computation, the noise remains confined within <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> or <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:mo>,</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, eliminating the need for additional modulo reduction operations.</p>
<p><italic>Scale invariance</italic></p>
<p>Torus&#x2019;s &#x201C;mod 1&#x201D; property grants it scale invariance. Regardless of the original data&#x2019;s length or value range, it can be mapped to a unified space on the Torus for processing without requiring adaptation to data formats or modulus <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mi>q</mml:mi></mml:math></inline-formula>. It eliminates the complex trade-offs involved in selecting modulus <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mi>q</mml:mi></mml:math></inline-formula> in traditional schemes (<inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>q</mml:mi></mml:math></inline-formula> must simultaneously satisfy security, noise upper bound, and computational efficiency requirements). In other words, for QKD, keys generated across different links may vary in length and format due to device and protocol differences. However, after Torus processing, TFHE homomorphic operations (key XOR operations at relays) can be executed directly within this unified space. It eliminates the need to design encryption parameters individually for each QKD link, thereby reducing adaptation costs for cross-scenario applications.</p>
<p><italic>High-efficiency ring</italic></p>
<p>The polynomial extension of the torus, denoted as <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, forms the foundation for realizing Torus Ring Learning with Errors(TRLWE). Within <inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, ring operations can be accelerated using Fast Fourier Transform (FFT) operations, reducing computational complexity from <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:msup><mml:mi>log</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> [<xref ref-type="bibr" rid="ref-35">35</xref>]. Furthermore, the external product operation <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mo>&#x22A1;</mml:mo></mml:math></inline-formula> in TRGSW requires multiplying polynomials by vectors over <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. The periodicity of the torus ensures that the result remains within the controlled space, thereby preventing coefficient overflow.</p>
</sec>
<sec id="s3_3_2">
<label>3.3.2</label>
<title>Fast Bootstrapping</title>
<p>The core challenge of fully homomorphic encryption is noise accumulation. After each round of homomorphic computation, noise within the ciphertext is amplified. Following a finite number of homomorphic operations, the noise exceeds the decryption threshold, rendering plaintext recovery impossible. To overcome the limitation, Gentry introduced a novel technique called Bootstrapping [<xref ref-type="bibr" rid="ref-24">24</xref>,<xref ref-type="bibr" rid="ref-36">36</xref>], which addresses the issue by refreshing noise. Early algorithms like BGV and BFV achieved full homogeneity using this technique, but it imposed significant computational overhead, reducing efficiency and hindering the practical implementation of FHE. The Fast Bootstrapping technique proposed in TFHE drastically reduces the noise refresh time, enabling real-time applications such as QKD key relaying.</p>
<p>The breakthrough of Fast Bootstrapping technology lies in its mathematical structure, based on the torus, which replaces the traditional discrete integer ring with a continuous torus to simplify noise quantization and computational rules. Simultaneously, through Noiseless Blind Rotation and a Look-Up Table (LUT), the core bootstrapping step is simplified from polynomial multiplication to vector operations. Its essence lies in performing the decryption-re-encryption process under encryption, achieving noise reset via homomorphic computation of symbolic functions. Let the ciphertext be defined as <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, the phase as <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mi>&#x03C6;</mml:mi></mml:math></inline-formula>, and the private key as <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:mi>s</mml:mi></mml:math></inline-formula>. The bootstrapping key for the private key component encrypted by <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mi>T</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>u</mml:mi><mml:mi>s</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>G</mml:mi><mml:mi>S</mml:mi><mml:mi>W</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mi>G</mml:mi><mml:mi>S</mml:mi><mml:mi>W</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mi>b</mml:mi><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>T</mml:mi><mml:mi>G</mml:mi><mml:mi>S</mml:mi><mml:mi>W</mml:mi><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mi>G</mml:mi><mml:mi>S</mml:mi><mml:mi>W</mml:mi><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mi>G</mml:mi><mml:mi>S</mml:mi><mml:mi>W</mml:mi><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. The homomorphic computation symbol function <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mi>g</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C6;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. enumerates all possible values of <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mi>&#x03C6;</mml:mi></mml:math></inline-formula> in the plaintext domain, computes the corresponding <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mi>g</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C6;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> results, and stores them as the LUT. During homomorphic computation, no real-time derivation is required; results are obtained directly by matching <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:mi>&#x03C6;</mml:mi></mml:math></inline-formula> via the LUT, significantly enhancing computational efficiency and enabling real-time processing of QKD keys. The core steps are as follows:
<list list-type="simple">
<list-item><label>1.</label><p><bold>Homomorphic decryption:</bold> Perform homomorphic computation on the ciphertext <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> using <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mi>b</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula> without decryption to obtain the encrypted phase <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C6;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p></list-item>
<list-item><label>2.</label><p><bold>Symbolic functions mapping:</bold> Calculate <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mi>g</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C6;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> via LUT. While preserving the plaintext information <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mi>m</mml:mi></mml:math></inline-formula> in the output, it also compresses the noise back to the initial security level (<inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo>&#x003C;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>4</mml:mn></mml:mrow></mml:math></inline-formula>) to ensure that subsequent homomorphic operations still satisfy the decryption threshold requirements.</p></list-item>
<list-item><label>3.</label><p><bold>Output new ciphertext:</bold> Convert the output of <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mi>g</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C6;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> into a standard TLWE ciphertext to complete noise reset.</p></list-item>
</list></p>
<p>In our TQKD solution, Fast Bootstrapping serves as the core technology for implementing cryptographic key processing on untrusted relay nodes. It reduces processing time to under 0.1 s, meeting the real-time requirements of QKD systems. Since QKD keys undergo multi-hop relaying, each hop introduces additional noise. Fast Bootstrapping resets this noise from the threshold edge back to its initial level. Consequently, ciphertexts remain decryptable even after multiple homomorphic processing steps at relays, eliminating limitations imposed by the number of homomorphic operations. The security of Fast Bootstrapping relies on the LWE problem over a Torus, providing quantum-resistant properties that complement QKD&#x2019;s unconditional security. The entire process operates in an encrypted state, preventing relay nodes from accessing key information and ensuring key security.</p>
</sec>
<sec id="s3_3_3">
<label>3.3.3</label>
<title>Efficient Boolean Operation</title>
<p>For performing Boolean operations on encrypted bit strings, TFHE employs an efficient processing mode. Its core mechanism involves applying external multiplication and bootstrapping to achieve efficient XOR operations. The specific principle is as follows:</p>
<p>In TFHE, reference [<xref ref-type="bibr" rid="ref-29">29</xref>] proposes combining TLWE and TGSW, followed by noise reduction via Fast Bootstrapping. Specifically, TLWE samples are used to encrypt data, while TGSW samples encrypt control bits. These two can be multiplied to form new TLWE samples. Applying this method to logic gate circuits yields a series of basic logic gates, including <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>p</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>c</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>N</mml:mi><mml:mi>O</mml:mi><mml:mi>T</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>c</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>N</mml:mi><mml:mi>O</mml:mi><mml:mi>T</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>c</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>p</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>c</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>A</mml:mi><mml:mi>N</mml:mi><mml:mi>D</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>A</mml:mi><mml:mi>N</mml:mi><mml:mi>D</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>p</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>c</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>N</mml:mi><mml:mi>A</mml:mi><mml:mi>N</mml:mi><mml:mi>D</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>N</mml:mi><mml:mi>A</mml:mi><mml:mi>N</mml:mi><mml:mi>D</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>p</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>c</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>O</mml:mi><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>O</mml:mi><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>X</mml:mi><mml:mi>O</mml:mi><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> are single-bit TLWE ciphers under TFHE. For our homomorphic encryption QKD scheme, <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>X</mml:mi><mml:mi>O</mml:mi><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> requires detailed elaboration. We will briefly verify it next. As shown in <xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref>, it can also be implemented via <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:mi>B</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>X</mml:mi><mml:mi>O</mml:mi><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>B</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>As shown by the specific algorithm in <xref ref-type="sec" rid="s4_1">Section 4.1</xref>, the homomorphic addition of two ciphers results in <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:mn>2</mml:mn><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. After decryption, the phase result is <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:mi>&#x03C6;</mml:mi></mml:math></inline-formula>, as detailed in <xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref>.
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mi>&#x03C6;</mml:mi><mml:mo>=</mml:mo><mml:mn>2</mml:mn><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mspace width="1em" /><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mtext>&#x00A0;&#x00A0;</mml:mtext><mml:mi>q</mml:mi></mml:math></disp-formula></p>
<p>Fast Bootstrapping refreshes the noise after HomXOR, resetting it to its initial level. The results are shown in <xref ref-type="table" rid="table-1">Table 1</xref>, where <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> represents the four plaintext combinations of bits, <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mi>X</mml:mi><mml:mi>O</mml:mi><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the XOR result of the plaintext combination, and <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mi>&#x03C6;</mml:mi></mml:math></inline-formula> is the core information obtained after eliminating the private key component during decryption. <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mi>B</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the offset from zero after Fast Bootstrapping the phase <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mi>&#x03C6;</mml:mi><mml:mo>=</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. If the phase is close to zero, it maps to zero; if the phase is far from zero, it maps to one, yielding the result of <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>X</mml:mi><mml:mi>O</mml:mi><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>HomXOR.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th><inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>)</th>
<th><inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mi>X</mml:mi><mml:mi>O</mml:mi><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></th>
<th><inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mi>&#x03C6;</mml:mi></mml:math></inline-formula></th>
<th><inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mi>B</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></th>
<th><inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mi>H</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>X</mml:mi><mml:mi>O</mml:mi><mml:mi>R</mml:mi></mml:math></inline-formula></th>
</tr>
</thead>
<tbody>
<tr>
<td>(0, 0)</td>
<td>0</td>
<td><inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:mi>e</mml:mi></mml:math></inline-formula></td>
<td>Close 0</td>
<td>0</td>
</tr>
<tr>
<td>(0, 1)</td>
<td>1</td>
<td><inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mn>2</mml:mn><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:math></inline-formula></td>
<td>Apart 0</td>
<td>1</td>
</tr>
<tr>
<td>(1, 0)</td>
<td>1</td>
<td><inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mn>2</mml:mn><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:math></inline-formula></td>
<td>Apart 0</td>
<td>1</td>
</tr>
<tr>
<td>(1, 1)</td>
<td>0</td>
<td><inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:mi>e</mml:mi></mml:math></inline-formula></td>
<td>Close 0</td>
<td>0</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Through linear operations of addition, subtraction, and scaling, the difference <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> between ciphertexts is transformed into a distinguishable phase state. Subsequently, a single Fast Bootstrapping step eliminates noise and maps the result to 0/1, ultimately achieving the HomXOR operation. The entire process avoids nonlinear operations or complex gate circuits (e.g., AND, MUX), with noise linearly superimposed. Subsequent processing requires only a single lightweight Fast Bootstrapping step. It represents a lightweight approach that bypasses complex gate combinations by directly leveraging the phase characteristics of TLWE.</p>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>TQKD</title>
<p>We designed the TQKD scheme, whose core leverages the asymmetric encryption properties of public-key TFHE and its efficient Boolean homomorphic computation capabilities to enhance QKD efficiency. Simultaneously, based on the Zero-Trust architecture proposed by Brazaola-Vicario et al. [<xref ref-type="bibr" rid="ref-37">37</xref>], we addressed the trust bottleneck in traditional QKD networks caused by relay nodes, thereby reducing trust dependencies and mitigating single-point risks. The approach also aligns with NIST requirements, Specifically, the proposed Zero-Trust Architecture (ZTA) [<xref ref-type="bibr" rid="ref-38">38</xref>], which aims to minimize trust boundaries within systems and avoid reliance on broad trust domains.</p>
<sec id="s4_1">
<label>4.1</label>
<title>Public-Key TFHE</title>
<p>The TFHE algorithm stands as a quintessential example of efficient fully homomorphic encryption technology. However, it is noteworthy that its encryption and decryption processes rely on the same set of keys, fundamentally constituting a symmetric-key-based encryption system. This characteristic limits TFHE&#x2019;s applicability in scenarios requiring shared keys and identity authentication, such as multi-party secure communication and cloud storage. To address this issue, Marc Joye proposed a public-key version of TFHE [<xref ref-type="bibr" rid="ref-39">39</xref>], which overcomes this limitation and is particularly suited for untrusted relay scenarios in QKD networks. Public-key TFHE transforms TLWE&#x2019;s symmetric-key architecture into an asymmetric form via a key-separation mechanism, while preserving TFHE&#x2019;s torus structure and noise-control advantages to maximize efficient fully homomorphic computation. To facilitate the description of the TQKD scheme, we define the algorithm below.</p>

<p><bold>Definition 1:</bold> <italic>TQKD comprises five algorithms: Setup, SecretKeyGen, Encreption, Decryption, and HomXOR</italic>.</p>

<p><list list-type="bullet">
<list-item>
<p><bold>Setup:</bold> Generate the public parameter set (pp) for the QKD scenario (Algorithm 1).</p></list-item>
<list-item>
<p><bold>SecretKeyGen:</bold> Generate a public-private key pair for encryption and decryption (Algorithm 2).</p></list-item>
<list-item>
<p><bold>Encreption:</bold> Input message <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:mi>m</mml:mi></mml:math></inline-formula>, output ciphertext <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mi>c</mml:mi></mml:math></inline-formula> (Algorithm 3).</p></list-item>
<list-item>
<p><bold>Decryption(Dec):</bold> Input ciphertext <inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:mi>c</mml:mi></mml:math></inline-formula>, output message <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:mi>m</mml:mi></mml:math></inline-formula> (Algorithm 4).</p></list-item>
<list-item>
<p><bold>HomXOR:</bold> Input two ciphertexts <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, obtain the ciphertext after homomorphic computation (Algorithm 5).</p></list-item>
</list></p>
<fig id="fig-10">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-10.tif"/>
</fig>
<fig id="fig-11">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-11.tif"/>
</fig>
<fig id="fig-12">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-12.tif"/>
</fig>
<fig id="fig-13">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-13.tif"/>
</fig>
<fig id="fig-14">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-14.tif"/>
</fig>
<p>These algorithms are based on the work of Chillotti, Joye, and others [<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>,<xref ref-type="bibr" rid="ref-39">39</xref>], and we do not elaborate on the specific proofs and details here. Throughout the TQKD scheme, both the public-private key pairs and ciphertexts are derived from the integer modulus field <inline-formula id="ieqn-142"><mml:math id="mml-ieqn-142"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>q</mml:mi><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. It does not conflict with Torus but rather represents a complementary relationship between theoretical models and engineering applications. Torus and TLWE provide the theoretical foundation for cryptographic security and noise control, while <inline-formula id="ieqn-143"><mml:math id="mml-ieqn-143"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>q</mml:mi><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> serves as the carrier for discretizing the Torus, enabling data storage and computation. For any Torus element <inline-formula id="ieqn-144"><mml:math id="mml-ieqn-144"><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">T</mml:mi></mml:mrow></mml:math></inline-formula>, it can be discretized in the integer modulus as <inline-formula id="ieqn-145"><mml:math id="mml-ieqn-145"><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mi>x</mml:mi><mml:mi>q</mml:mi><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>q</mml:mi></mml:math></inline-formula>. This mapping quantizes the continuous Torus space into an integer space, enabling computers to process Torus elements through integer operations while avoiding precision issues associated with computing continuous real numbers.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>TQKD Network Model</title>
<p>We divide the QKD network into three layers: Quantum Layer at the bottom, Key Network Layer in the middle, and Key Service Layer at the top [<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>], as shown in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>. The network is described in detail as follows:</p>

<p><list list-type="simple">
<list-item><label>1.</label><p><bold>Quantum Layer:</bold> It serves as the physical foundation and primary source of TQKD networks, composed of optical nodes interconnected via optical links (fiber-optic cables). Based on quantum mechanical principles (the no-cloning theorem and the uncertainty principle), as well as QKD protocols such as BB84, E91, and B92 [<xref ref-type="bibr" rid="ref-1">1</xref>,<xref ref-type="bibr" rid="ref-42">42</xref>,<xref ref-type="bibr" rid="ref-43">43</xref>], it primarily involves the preparation, detection, and post-processing of quantum states to achieve secure key agreement between adjacent nodes. Its core function is to generate unconditionally secure quantum keys between two directly connected nodes.</p></list-item>
<list-item><label>2.</label><p><bold>Key Management Layer:</bold> As the core control layer of the TQKD network, it validates and manages previously generated keys, serving as a bridge between layers. It interfaces downward with the point-to-point keys from the Quantum Layer, extending the reach of key distribution through hop-by-hop relaying. Upward, it provides schedulable key resources to the Key Service Layer while maintaining the network-wide key state. Its core function is to resolve the challenge of converting short-range keys generated at the quantum layer into wide-area, routable key resources.</p></list-item>
<list-item><label>3.</label><p><bold>Key Service Layer:</bold> As the user interface layer of the TQKD network, it is responsible for converting the raw quantum keys provided by the Key Network Layer into usable keys suitable for various application scenarios. Its core function is to ensure application systems can conveniently and securely utilize QKD keys.</p></list-item>
</list></p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>TQKD network model based on relay.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-4.tif"/>
</fig>
<p>During the key generation phase, the Optical Node in the Quantum layer generates quantum keys using a quantum random number generator (QRNG) [<xref ref-type="bibr" rid="ref-44">44</xref>], which exploits the inherent randomness of quantum mechanics (e.g., superposition states, measurement collapse). This randomness stems from the depletion of quantum coherence, enabling the generation of truly random numbers&#x2014;a capability unavailable in classical physical schemes. Leveraging the uncertainty principle and the no-cloning theorem, eavesdropping during key exchange is prevented, ensuring attackers cannot intercept or alter information. When the key is transmitted to the Key Network Layer, each Relay (labeled A through F) connects via QKD links. Each QKD link shares a QKD key, termed the QKD Link Key, represented by the same color in the diagram. At this layer, keys are transmitted via Relays using homomorphic encryption. Intermediate Relays remain unaware of the key information, enhancing key privacy. Within the Key Service Layer, each user possesses a corresponding public-private key pair (the diagram illustrates two users, Alice and Bob). These pairs are used to encrypt the QKD link keys from the Key Network Layer, ensuring the smooth operation of homomorphic encryption. After obtaining the recipient&#x2019;s QKD Key, the sender encrypts the message using OTP (a theoretically unbreakable encryption method proposed by information theory founder Shannon [<xref ref-type="bibr" rid="ref-45">45</xref>]), thereby enabling secure communication.</p>
<p>Next, we will demonstrate a complete encrypted communication process using this scheme to understand how public-key TFHE works in conjunction with QKD and the role of homomorphic encryption in this process. As shown in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>, Alice wishes to communicate with Bob via QKD and plans to send the generated quantum key <inline-formula id="ieqn-146"><mml:math id="mml-ieqn-146"><mml:mi>q</mml:mi><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mspace width="negativethinmathspace" /><mml:mi>y</mml:mi></mml:math></inline-formula> to Bob. The specific steps are as follows:</p>

<p><list list-type="simple">
<list-item><label>1.</label><p>During the initialization phase, each user generates a TFHE public-private key pair <inline-formula id="ieqn-147"><mml:math id="mml-ieqn-147"><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and a bootstrapping key <inline-formula id="ieqn-148"><mml:math id="mml-ieqn-148"><mml:mi>b</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula> (Algorithm 1). Simultaneously, adjacent relay nodes share a quantum key <inline-formula id="ieqn-149"><mml:math id="mml-ieqn-149"><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo></mml:math></inline-formula> via QKD, preparing for peer-to-peer QKD.</p></list-item>
<list-item><label>2.</label><p>Alice sends a QKD request to Bob via the communication link, intending to distribute a quantum key to Bob through the QKD link. Each relay node obtains Bob&#x2019;s public key <inline-formula id="ieqn-150"><mml:math id="mml-ieqn-150"><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula> and encrypts the quantum key using algorithm Algorithm 3, yielding <inline-formula id="ieqn-151"><mml:math id="mml-ieqn-151"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p></list-item>
<list-item><label>3.</label><p>Relay A performs homomorphic encryption on <inline-formula id="ieqn-152"><mml:math id="mml-ieqn-152"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-153"><mml:math id="mml-ieqn-153"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> using Algorithm 5 (<xref ref-type="disp-formula" rid="eqn-8">Eq. (8))</xref>, yielding <inline-formula id="ieqn-154"><mml:math id="mml-ieqn-154"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, then transmits the result to Relay B.
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p></list-item>
<list-item><label>4.</label><p>Relay B receives <inline-formula id="ieqn-155"><mml:math id="mml-ieqn-155"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and similarly performs homomorphic computation on <inline-formula id="ieqn-156"><mml:math id="mml-ieqn-156"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-157"><mml:math id="mml-ieqn-157"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> via Algorithm 5.
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula>
yielding <inline-formula id="ieqn-158"><mml:math id="mml-ieqn-158"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (<xref ref-type="disp-formula" rid="eqn-9">Eqs. (9)</xref> and <xref ref-type="disp-formula" rid="eqn-10">(10)</xref>), then sends the result to Relay C.
<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p></list-item>
<list-item><label>5.</label><p>Subsequent relays receive the homomorphic encryption result and perform the same steps until the final relay F receives the ciphertext <inline-formula id="ieqn-159"><mml:math id="mml-ieqn-159"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Then, using homomorphic operations, the quantum key <inline-formula id="ieqn-160"><mml:math id="mml-ieqn-160"><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi></mml:math></inline-formula> encrypted with the public key is recovered (<xref ref-type="disp-formula" rid="eqn-11">Eq. (11)</xref>).
<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p></list-item>
<list-item><label>6.</label><p>Bob uses the private key <inline-formula id="ieqn-161"><mml:math id="mml-ieqn-161"><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula> of the TFHE algorithm to decrypt <inline-formula id="ieqn-162"><mml:math id="mml-ieqn-162"><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> via Algorithm 4 (<xref ref-type="disp-formula" rid="eqn-12">Eq. (12)</xref>), thereby obtaining the quantum key Alice intends to distribute.
<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p></list-item>
</list></p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>TQKD communication.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-5.tif"/>
</fig>
<p>In this example, we have not described the Fast Bootstrapping process nor depicted it in the diagram. The process occurs during the HomXOR procedure. It is worth noting that Alice and Bob merely represent the communicating parties. For explanatory purposes, only these two users are highlighted in the network. However, each user corresponds to a relay and a QRNG. These nodes can not only generate quantum keys but also act as relays to forward quantum keys from other users, regardless of their position within the network topology.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>TQKD Security Proof</title>
<p>The network model of TQKD is based on a quantum-classical hybrid channel architecture, whose security proof encompasses both the information-theoretic security at the quantum layer and the computational security at the key management layer. Since the security at the quantum layer is grounded in fundamental principles of quantum mechanics, independent of any computational assumptions, and is widely regarded as unconditional, this paper does not delve into its security proof in detail. Instead, it focuses on demonstrating the computational security involving the homomorphic encryption algorithm. Below, we will prove that the TQKD scheme is IND-CPA secure based on Definition 2.</p>

<p><bold>Definition 2:</bold> <italic>We define an honest but curious adversary <inline-formula id="ieqn-163"><mml:math id="mml-ieqn-163"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>, a challenger <inline-formula id="ieqn-164"><mml:math id="mml-ieqn-164"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula>, and the rules governing their behavior</italic>.</p>

<p><inline-formula id="ieqn-165"><mml:math id="mml-ieqn-165"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>:
<list list-type="bullet">
<list-item>
<p>Possessing probabilistic polynomial-time(PPT) computational capabilities, it cannot resolve fundamental problems in quantum mechanics or those that are hard on lattices.</p></list-item>
<list-item>
<p>Control relay nodes to strictly adhere to the public-key TFHE algorithm process, collecting publicly available information <inline-formula id="ieqn-166"><mml:math id="mml-ieqn-166"><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mi>k</mml:mi><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> without tampering with data or terminal transmission.</p></list-item>
<list-item>
<p>Recover quantum keys from intercepted information or distinguish plaintexts corresponding to homomorphic encrypted ciphers.</p></list-item>
</list></p>
<p><inline-formula id="ieqn-167"><mml:math id="mml-ieqn-167"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula>:
<list list-type="bullet">
<list-item>
<p>Generate <inline-formula id="ieqn-168"><mml:math id="mml-ieqn-168"><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>S</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>u</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and provide it to <inline-formula id="ieqn-169"><mml:math id="mml-ieqn-169"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Generate <inline-formula id="ieqn-170"><mml:math id="mml-ieqn-170"><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>S</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>K</mml:mi><mml:mi>e</mml:mi><mml:mi>y</mml:mi><mml:mi>G</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. When <inline-formula id="ieqn-171"><mml:math id="mml-ieqn-171"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> issues a request, <inline-formula id="ieqn-172"><mml:math id="mml-ieqn-172"><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula> are distributed. <inline-formula id="ieqn-173"><mml:math id="mml-ieqn-173"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> may request a polynomial number of such keys.</p></list-item>
</list></p>

<p><bold>Definition 3:</bold> <italic>For any PPT adversary <inline-formula id="ieqn-174"><mml:math id="mml-ieqn-174"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> and two challenge plaintexts <inline-formula id="ieqn-175"><mml:math id="mml-ieqn-175"><mml:msub><mml:mi>m</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mi>M</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-176"><mml:math id="mml-ieqn-176"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> outputs a guess <inline-formula id="ieqn-177"><mml:math id="mml-ieqn-177"><mml:msup><mml:mi>b</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. The advantage of game <inline-formula id="ieqn-178"><mml:math id="mml-ieqn-178"><mml:msub><mml:mi>G</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is defined as: <inline-formula id="ieqn-179"><mml:math id="mml-ieqn-179"><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula>, where the function <inline-formula id="ieqn-180"><mml:math id="mml-ieqn-180"><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>g</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is negligible: for any polynomial <inline-formula id="ieqn-181"><mml:math id="mml-ieqn-181"><mml:mi>P</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, when <inline-formula id="ieqn-182"><mml:math id="mml-ieqn-182"><mml:mi>&#x03BB;</mml:mi></mml:math></inline-formula> is sufficiently large, <inline-formula id="ieqn-183"><mml:math id="mml-ieqn-183"><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>g</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x003C;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>P</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></italic>.</p>

<p>We have demonstrated that TQKD is IND-CPA secure through the following series of Games. <inline-formula id="ieqn-184"><mml:math id="mml-ieqn-184"><mml:msub><mml:mi>Game</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> is the baseline game, fully reproducing the original scheme&#x2019;s encryption logic. Both the public key and ciphertext components are TLWE samples. The advantages of <inline-formula id="ieqn-185"><mml:math id="mml-ieqn-185"><mml:msub><mml:mi>Game</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> are shown in <xref ref-type="disp-formula" rid="eqn-13">Eq. (13)</xref>.
<disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><inline-formula id="ieqn-186"><mml:math id="mml-ieqn-186"><mml:msub><mml:mi>Game</mml:mi><mml:mrow><mml:mo>&#x00A0;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> substitutes the public key with a randomly selected <inline-formula id="ieqn-187"><mml:math id="mml-ieqn-187"><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> from the TLWE sample, rather than using the actual public key from the original scheme. The advantage of  <inline-formula id="ieqn-188"><mml:math id="mml-ieqn-188"><mml:msub><mml:mi>Game</mml:mi><mml:mrow><mml:mo>&#x00A0;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> is shown in <xref ref-type="disp-formula" rid="eqn-14">Eq. (14)</xref>.
<disp-formula id="eqn-14"><label>(14)</label><mml:math id="mml-eqn-14" display="block"><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>Since the public keys of <inline-formula id="ieqn-189"><mml:math id="mml-ieqn-189"><mml:msub><mml:mi>Game</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-190"><mml:math id="mml-ieqn-190"><mml:msub><mml:mi>Game</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> are distribution-equivalent, any PPT attacker cannot distinguish between their public keys. <inline-formula id="ieqn-191"><mml:math id="mml-ieqn-191"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2A7D;</mml:mo><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>g</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-192"><mml:math id="mml-ieqn-192"><mml:msub><mml:mi>G</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">&#x2194;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> are indistinguishable.</p>
<p> <inline-formula id="ieqn-193"><mml:math id="mml-ieqn-193"><mml:msub><mml:mi>Game</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> samples a public key <inline-formula id="ieqn-194"><mml:math id="mml-ieqn-194"><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> from a uniform random distribution, with  <inline-formula id="ieqn-195"><mml:math id="mml-ieqn-195"><mml:msub><mml:mi>Game</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>&#x2019;s advantage as shown in <xref ref-type="disp-formula" rid="eqn-15">Eq. (15)</xref>.
<disp-formula id="eqn-15"><label>(15)</label><mml:math id="mml-eqn-15" display="block"><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>E</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>Given the TLWE assumption that <inline-formula id="ieqn-196"><mml:math id="mml-ieqn-196"><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:msup><mml:mi mathvariant="normal">&#x2032;</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup></mml:math></inline-formula> sampled from a uniform random distribution is indistinguishable from <inline-formula id="ieqn-197"><mml:math id="mml-ieqn-197"><mml:mi>p</mml:mi><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> sampled from the TLWE distribution, then <inline-formula id="ieqn-198"><mml:math id="mml-ieqn-198"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2A7D;</mml:mo><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>g</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and <inline-formula id="ieqn-199"><mml:math id="mml-ieqn-199"><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">&#x2194;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> are indistinguishable.</p>
<p>Finally, using the triangle inequality, the advantage differences across games are combined, as shown in <xref ref-type="disp-formula" rid="eqn-16">Eq. (16)</xref>:
<disp-formula id="eqn-16"><label>(16)</label><mml:math id="mml-eqn-16" display="block"><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2A7D;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2A7D;</mml:mo><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>g</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>g</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>g</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>Through this series of games, the security of the TQKD scheme is reduced to the computational hardness of the TLWE problem, thereby proving the IND-CPA security of TQKD.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Experiment</title>
<p>To validate the feasibility and superiority of the QKD scheme based on the public-key TFHE algorithm, we designed a series of experimental scenarios in Python. These experiments evaluate the TQKD scheme&#x2019;s performance metrics for homomorphic operation latency, ensuring it meets the real-time requirements of QKD networks. Simultaneously, by comparing it with QKD schemes based on homomorphic encryption algorithms such as BGV and BFV, we highlight the TQKD scheme&#x2019;s unique performance advantages and provide data to support its engineering implementation.</p>
<sec id="s5_1">
<label>5.1</label>
<title>Experiment Design</title>
<p>Currently, the open-source community has developed multiple mature toolkits with distinct functionalities. Among them, the most prominent and active open-source homomorphic encryption libraries include: Simple Encrypted Arithmetic Library(SEAL) [<xref ref-type="bibr" rid="ref-46">46</xref>] developed by Microsoft, OpenFHE [<xref ref-type="bibr" rid="ref-47">47</xref>] released by the open-source community, Homomorphic Encryption library(HElib) [<xref ref-type="bibr" rid="ref-48">48</xref>] developed and maintained by IBM, and concreteML [<xref ref-type="bibr" rid="ref-49">49</xref>] developed by Zama. However, our approach involves bit-level homomorphic encryption operations and requires support for BGV, BFV, and TFHE algorithms. OpenFHE supports most mainstream algorithms, including BGV, BFV, CKKS, FHEW, and TFHE, making it suitable for our experimental requirements.</p>
<p>OpenFHE is an open-source, fully homomorphic encryption library written in C&#x002B;&#x002B;. Maintained by a community comprising experts from multiple universities and industry, it can be regarded as the official continuation and significant evolution of the early renowned HE library PALISADE [<xref ref-type="bibr" rid="ref-50">50</xref>]. A standout feature of OpenFHE is its comprehensive support for homomorphic encryption schemes, encompassing nearly all mainstream fully homomorphic encryption protocols. Furthermore, it provides comprehensive Application Programming Interface(API) documentation [<xref ref-type="bibr" rid="ref-51">51</xref>] and extensive code examples, significantly lowering the learning curve. OpenFHE delivers a modern, fully-featured, modular, high-performance, and user-friendly homomorphic encryption development platform suitable for both academic research and industrial applications.</p>
<p>To highlight the speed advantage of the TFHE algorithm in QKD, we designed two experimental scenarios for verification:
<list list-type="simple">
<list-item><label>1.</label><p><bold>Single-Pass Homomorphic Encryption:</bold> This experimental scenario simulates a HomXOR operation performed on encrypted keys within a single relay node, without forwarding to subsequent nodes or the recipient. Specifically, it involves a single HomXOR operation between two encrypted keys. Its core objective is to validate fundamental performance differences among BGV and BFV technical solutions on the shortest path by comparing their key performance metrics. The process aims to eliminate path-length-related performance interference (such as the number of relay nodes and physical distance), ensuring that performance differences stem solely from the inherent design of the technical solutions rather than topological complexity. It establishes a baseline for subsequent multi-relay, multi-hop performance analysis.</p></list-item>
<list-item><label>2.</label><p><bold>Multi-Hop Relay Homomorphic Encryption:</bold> Simulating quantum key distribution in practical scenarios, where the sender forwards the key to the receiver through multiple relay nodes. This tests the scheme&#x2019;s noise control characteristics during long-distance transmission and verifies the performance differences between TFHE and BGV/BFV algorithms after multi-hop relay forwarding and repeated homomorphic encryption. In multi-hop scenarios, ciphertexts undergo multiple HomXOR operations, causing noise accumulation. To ensure accurate decryption of the ciphertext, noise reduction is required. TFHE employs Fast Bootstrapping technology to reduce noise-reduction time, thereby accelerating key distribution. It provides theoretical data support for the practical application of the technical solution.</p></list-item>
</list></p>
<p>The specific experimental hardware environment is shown in <xref ref-type="table" rid="table-2">Table 2</xref>:</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Hardware environment configuration.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Hardware Category</th>
<th>Parameter</th>
</tr>
</thead>
<tbody>
<tr>
<td>Central Processing Unit (CPU)</td>
<td>Intel (R) Core (TM) i7-1065G7 CPU @ 1.30 GHz</td>
</tr>
<tr>
<td>Operating System (OS)</td>
<td>Ubuntu 24.04.2 LTS</td>
</tr>
<tr>
<td>Cache Size</td>
<td>8 GB DDR4 Dual Channel</td>
</tr>
<tr>
<td>Memory</td>
<td>30 GB SSD</td>
</tr>
<tr>
<td>Python</td>
<td>Python 3.8.20</td>
</tr>
<tr>
<td>OpenFHE</td>
<td>1.4.0.1.20.4</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-2fn1" fn-type="other">
<p>Note: All hardware is in its default factory state, with no overclocking or modification of hardware parameters.</p>
</fn>
</table-wrap-foot>
</table-wrap>
<p>In the experiments, we disregarded the time spent on model initialization and key initialization, recording only the duration from the start to the completion of the bit-homomorphic computation in the code. To ensure the accuracy and scientific rigor of the experimental data, we repeated the experiments multiple times and filtered the data from each run. Based on the variance and mean, we discarded data points that deviated excessively from the mean, thereby approximating a normal distribution. For the TFHE algorithm, a dedicated API for XOR logic gates is available. However, for the BFV and BGV algorithms, no specialized XOR logic gates exist. Consequently, the XOR functionality must be implemented through additive and multiplicative operations (<xref ref-type="disp-formula" rid="eqn-17">Eq. (17)</xref>).
<disp-formula id="eqn-17"><label>(17)</label><mml:math id="mml-eqn-17" display="block"><mml:mi>a</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>b</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mo>+</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mi>a</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>b</mml:mi></mml:math></disp-formula></p>
<p>Furthermore, in practical engineering applications, quantum bits in QKD are continuously generated and encrypted. This means that the sender or relay typically does not wait for a certain number of quantum bits to accumulate before performing operations; instead, operations are conducted bit by bit. Therefore, we also simulated this scenario without using the batch-processing capabilities of the BFV and BGV algorithms in OpenFHE (specifically, acceleration via Python&#x2019;s list data structure). Both algorithms process only one quantum bit at a time, rather than a string of quantum bits, and TFHE operates similarly. Consequently, the experimental data in <xref ref-type="sec" rid="s5_2">Section 5.2</xref> are based on single-quantum-bit operations, not the computation time for entire strings of quantum bits.</p>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Result and Analysis</title>
<p>We conducted simulation experiments with OpenFHE to demonstrate the feasibility of the proposed TQKD scheme. TQKD not only achieves faster HomXOR computation speeds than BGV and BFV algorithms but also supports accommodating more relays in QKD network while maintaining the original encryption efficiency compared to the other two algorithms. Notably, we also observed an interesting phenomenon: under specific parameter settings, the XOR operation efficiency of TFHE algorithms is lower than that of BGV and BFV algorithms. However, the special case above is uncommon in practical applications and therefore does not affect our conclusions.</p>
<p>First, we analyze the first experimental scenario: performing a single homomorphic encryption operation on two distinct ciphers. The algorithms used in the experiment are TFHE, BFV, and BGV. Due to the construction principles of the BFV and BGV algorithms, it is necessary to set the maximum number of consecutive multiplications allowed in homomorphic operations, known as the multiplicative depth. In other words, it represents the maximum number of consecutive homomorphic operations (including multiplication, where addition does not consume a count) that can be performed on the same ciphertext while still guaranteeing successful decryption. As shown in <xref ref-type="disp-formula" rid="eqn-17">Eq. (17)</xref>, BFV and BGV require two multiplications to perform a single XOR operation. Therefore, we set the multiplicative depth of BFV and BGV to 2. Interestingly, at this point, the computational efficiency of BFV and BGV surpasses that of TFHE, requiring less time&#x2014;contrary to previous theoretical analysis. Subsequently, we progressively increased the multiplicative depth of BFV and BGV. The experimental results, shown in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>, reveal that the computation time is positively correlated with the multiplicative depth. When the multiplicative depth reaches 7, the TFHE algorithm achieves higher computational efficiency than BFV and BGV, consuming less time&#x2014;a result consistent with the theoretical analysis. Subsequently, we conducted comparative experiments on CPU and RAM usage across the three algorithms at different multiplicative depths, with results shown in <xref ref-type="fig" rid="fig-7">Figs. 7</xref> and <xref ref-type="fig" rid="fig-8">8</xref>.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Comparison of computational time for TFHE, BFV, and BGV at different multiplication depths.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-6.tif"/>
</fig><fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Comparison of CPU usage for TFHE, BFV, and BGV algorithms at different multiplicative depths.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-7.tif"/>
</fig><fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Comparison of RAM usage for TFHE, BFV, and BGV algorithms at different multiplicative depths.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-8.tif"/>
</fig>
<p>Regarding CPU usage, TFHE remained consistently around 5.8%. When the multiplicative depth was set to 2, BGV and BFV exhibited slightly lower CPU usage than TFHE, indicating higher computational efficiency. However, as the multiplicative depth increased, their CPU usage exceeded TFHE&#x2019;s, while TFHE maintained superior performance. Regarding RAM usage, although the optimized XOR operation in TFHE increases memory consumption, it only requires slightly more RAM compared to BGV and BFV algorithms. This trade-off yields a significant reduction in computation time, making homomorphic XOR more efficient. This approach, sacrificing a small amount of space for substantial time savings, is worthwhile.</p>
<p>Through analysis, we identified discrepancies between the experimental results and the theoretical analysis. These discrepancies stem not from flaws in the theoretical framework itself, but from the strong correlation between the computational overhead of the BFV and BGV algorithms and their multiplicative depth. The multiplicative depth of both algorithms directly determines the complexity of the cryptographic context, thereby impacting computational speed. Within the parameter generation logic, a greater multiplicative depth necessitates a larger Ring Dimension (RingDim), increasing the number of polynomials involved in the computation and consequently elevating computational overhead. Simultaneously, the multiplicative depth impacts the allocation of the initial noise budget. With a smaller multiplicative depth, there is no need to reserve noise space for subsequent rounds of multiplication or perform additional noise control. Conversely, a larger multiplicative depth necessitates reserving a substantial noise budget for future rounds, thereby increasing the overhead of noise control and slowing down computation speed. However, the BFV and BGV algorithms exhibit faster performance because their parameters are over-optimized, operating within an optimal performance range. At this point, both the RingDim of the algorithm model and noise control operate at minimal overhead. It effectively streamlines BFV and BGV algorithms to support only the current task, thereby maximizing computational speed.</p>
<p>In practical applications, sender encryption and receiver decryption each require one HomXOR operation, consuming a total of four multiplicative depths. Each relay node performs two HomXOR operations; if there are <inline-formula id="ieqn-200"><mml:math id="mml-ieqn-200"><mml:mi>n</mml:mi></mml:math></inline-formula> relay nodes, the multiplicative depth for the BFV and BGV algorithms is <inline-formula id="ieqn-201"><mml:math id="mml-ieqn-201"><mml:mn>4</mml:mn><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mi>n</mml:mi></mml:math></inline-formula>. A QKD network includes multiple relay nodes, and once the number of nodes exceeds 1, the computational efficiency of BFV and BGV falls behind that of TFHE. Therefore, the advantages of these two algorithms under lightweight implementations are not significant in practical applications. It does not affect the conclusion that our proposed TQKD scheme achieves higher computational efficiency. In <xref ref-type="table" rid="table-3">Table 3</xref>, we summarize the overall performance of TFHE algorithms vs. BFV/BGV for the variable multiplicative depth. When the multiplicative depth is small, BFV/BGV algorithms perform better because shallower depths require fewer initialization parameters. However, in actual HomXOR, the multiplicative depth increases with the number of relays, rendering shallow depths impractical. When the multiplicative depth is large, TFHE demonstrates superior overall performance, enabling the reliable operation of QKD networks with a certain number of relays.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Overall algorithm performance comparison.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th rowspan="2">Overall Algorithm Performance</th>
<th align="center" rowspan="2">Index</th>
<th colspan="2">Algorithms</th>
</tr>
<tr>

<th>TFHE</th>
<th>BGV/BFV</th>
</tr>
</thead>
<tbody>
<tr>
<td rowspan="10">Multiplicative depth</td>
<td>2</td>
<td></td>
<td><inline-formula id="ieqn-202"><mml:math id="mml-ieqn-202"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>

<td>3</td>
<td></td>
<td><inline-formula id="ieqn-203"><mml:math id="mml-ieqn-203"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>

<td>4</td>
<td></td>
<td><inline-formula id="ieqn-204"><mml:math id="mml-ieqn-204"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>

<td>5</td>
<td></td>
<td><inline-formula id="ieqn-205"><mml:math id="mml-ieqn-205"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>

<td>6</td>
<td></td>
<td><inline-formula id="ieqn-206"><mml:math id="mml-ieqn-206"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>

<td>7</td>
<td><inline-formula id="ieqn-207"><mml:math id="mml-ieqn-207"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td></td>
</tr>
<tr>

<td>8</td>
<td><inline-formula id="ieqn-208"><mml:math id="mml-ieqn-208"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td></td>
</tr>
<tr>

<td>9</td>
<td><inline-formula id="ieqn-209"><mml:math id="mml-ieqn-209"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td></td>
</tr>
<tr>

<td>10</td>
<td><inline-formula id="ieqn-210"><mml:math id="mml-ieqn-210"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td></td>
</tr>
<tr>

<td><inline-formula id="ieqn-211"><mml:math id="mml-ieqn-211"><mml:mo>&#x2026;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-212"><mml:math id="mml-ieqn-212"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In the second experiment, due to limitations in the experimental environment, we simulated only the scenario in which ciphertexts undergo homomorphic operations and are forwarded across two relays. The experimental results are shown in <xref ref-type="fig" rid="fig-9">Fig. 9</xref>, where the BFV and BGV algorithms have a multiplicative depth of 12 (each relay performs two homomorphic XOR operations on each ciphertext, thus requiring 4 multiplicative depth operations). It can be observed that TFHE demonstrates a significant speed advantage in practical applications. Furthermore, due to its unique algorithmic design, Fast Bootstrapping technique, and optimized XOR logic gates, TFHE eliminate the limitation on multiplication depth, accommodating a certain number of HomXOR operations. It allows TFHE to accommodate more relay nodes joining the key distribution process. In contrast, QKD based on BFV and BGV algorithms requires pre-calculating the necessary multiplicative depth based on the number of relay nodes in the QKD network. It not only reduces computational efficiency but also limits the addition of relay nodes, thereby diminishing the node scalability of the QKD network.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Comparison of computational time for TFHE, BFV, and BGV Algorithms in multi-relay scenarios.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_75573-fig-9.tif"/>
</fig>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Conclusion</title>
<p>QKD achieves unconditional security based on quantum mechanical principles. However, traditional QKD networks rely on trusted relays, which introduce trust issues and single-point vulnerabilities. Furthermore, although previously proposed QKD networks based on the BFV algorithm transmit keys in encrypted form during distribution, effectively ensuring key confidentiality even if relays are compromised, thereby addressing the relay-trust issue, the BFV algorithm itself has limitations. Its computational efficiency degrades as the number of nodes in the QKD network increases, and it cannot scale nodes wirelessly, necessitating optimization in speed and scalability. This study proposes a QKD scheme based on the public-key TFHE algorithm, termed TQKD. By leveraging TFHE&#x2019;s unique Fast Bootstrapping mechanism and an optimized XOR logic gate design, this scheme achieves secure transmission and efficient processing of QKD keys in untrusted relay scenarios.</p>
<p>Furthermore, we conducted two comparative experiments using OpenFHE for validation. This approach provides technical support for the large-scale deployment and application of QKD networks. Although the scheme demonstrated feasibility in experiments, limitations remain. Currently, no TRLWE ciphertext version exists for public-key TFHE algorithms, preventing bit-string encoding into a single TRLWE ciphertext. Furthermore, single-operation processing is restricted to one bit, precluding batch HomXOR operations on ciphertexts&#x2014;a key focus for future research.</p>
</sec>
</body>
<back>
<ack>
<p>Not applicable.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This research was funded by the National Key Science and Technology Project: &#x201C;Quantum Science and Technology-National Science and TechnologyMajor Project (QNMP)&#x201D; (Grant No. 2021ZD0301301) and &#x201C;the Fundamental Research Funds for the Central Universities&#x201D; (Grant No. 3282025009);.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>Conceptualization, Tianhua Lin and Jianguo Xie; methodology, Tianhua Lin and Sijiang Xie; software, Yalong Yan; validation, Tianhua Lin, Sijiang Xie, and Ang Liu; formal analysis, Jianguo Xie; investigation, Tianhua Lin; resources, Sijiang Xie; data curation, Tianhua Lin; writing&#x2014;original draft preparation, Tianhua Lin; writing&#x2014;review and editing, Yalong Yan; visualization, Tianhua Lin; supervision, Sijiang Xie; project administration, Tianhua Lin; funding acquisition, Sijiang Xie and Yalong Yan. All authors reviewed and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>Data supporting the findings of <xref ref-type="sec" rid="s5">Section 5</xref> are available from the corresponding author, Sijiang Xie, upon reasonable request.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>This study did not involve any human or animal subjects, and therefore, ethical approval was not required.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bennett</surname> <given-names>CH</given-names></string-name>, <string-name><surname>Brassard</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Quantum cryptography: public key distribution and coin tossing</article-title>. <source>Theor Comput Sci</source>. <year>2014</year>;<volume>560</volume>:<fpage>7</fpage>&#x2013;<lpage>11</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.tcs.2014.05.025</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ugwuishiwu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Orji</surname> <given-names>U</given-names></string-name>, <string-name><surname>Ugwu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Asogwa</surname> <given-names>C</given-names></string-name></person-group>. <article-title>An overview of quantum cryptography and Shor&#x2019;s algorithm</article-title>. <source>Int J Adv Trends Comput Sci Eng</source>. <year>2021</year>;<volume>9</volume>(<issue>5</issue>):<fpage>7487</fpage>&#x2013; <lpage>7495</lpage>. doi:<pub-id pub-id-type="doi">10.30534/ijatcse/2020/82952020</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shor</surname> <given-names>PW</given-names></string-name></person-group>. <article-title>Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer</article-title>. <source>SIAM Rev</source>. <year>1999 Jun</year>;<volume>41</volume>(<issue>2</issue>):<fpage>303</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1137/s0036144598347011</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zolanvari</surname> <given-names>M</given-names></string-name>, <string-name><surname>Jain</surname> <given-names>R</given-names></string-name></person-group>. <article-title>A survey of important issues in quantum computing and communications</article-title>. <source>IEEE Commun Surv Tuts</source>. <year>2023</year>;<volume>25</volume>(<issue>2</issue>):<fpage>1059</fpage>&#x2013;<lpage>94</lpage>. doi:<pub-id pub-id-type="doi">10.1109/comst.2023.3254481</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Szab&#x0142;owski</surname> <given-names>PJ</given-names></string-name></person-group>. <article-title>Understanding mathematics of Grover&#x2019;s algorithm</article-title>. <source>Quantum Inf Process</source>. <year>2021</year>;<volume>20</volume>(<issue>5</issue>):<fpage>191</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s11128-021-03125-w</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Takeoka</surname> <given-names>M</given-names></string-name>, <string-name><surname>Guha</surname> <given-names>S</given-names></string-name>, <string-name><surname>Wilde</surname> <given-names>MM</given-names></string-name></person-group>. <article-title>Fundamental rate-loss tradeoff for optical quantum key distribution</article-title>. <source>Nat Commun</source>. <year>2014 Oct</year>;<volume>5</volume>(<issue>1</issue>):<fpage>5235</fpage>. doi:<pub-id pub-id-type="doi">10.1038/ncomms6235</pub-id>; <pub-id pub-id-type="pmid">25341406</pub-id></mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Korzh</surname> <given-names>B</given-names></string-name>, <string-name><surname>Lim</surname> <given-names>CCW</given-names></string-name>, <string-name><surname>Houlmann</surname> <given-names>R</given-names></string-name>, <string-name><surname>Gisin</surname> <given-names>N</given-names></string-name>, <string-name><surname>Li</surname> <given-names>MJ</given-names></string-name>, <string-name><surname>Nolan</surname> <given-names>D</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Provably secure and practical quantum key distribution over 307 km of optical fibre</article-title>. <source>Nat Photonics</source>. <year>2015 Feb</year>;<volume>9</volume>(<issue>3</issue>):<fpage>163</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1038/nphoton.2014.327</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>F</given-names></string-name>, <string-name><surname>Li</surname> <given-names>L</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>NL</given-names></string-name>, <string-name><surname>Pan</surname> <given-names>JW</given-names></string-name></person-group>. <article-title>Quantum information research in China</article-title>. <source>Quantum Sci Technol</source>. <year>2019 Nov</year>;<volume>4</volume>(<issue>4</issue>):<fpage>040503</fpage>. doi:<pub-id pub-id-type="doi">10.1088/2058-9565/ab4bea</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>YA</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>TY</given-names></string-name>, <string-name><surname>Cai</surname> <given-names>WQ</given-names></string-name>, <string-name><surname>Liao</surname> <given-names>SK</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>An integrated space-to-ground quantum communication network over 4600 kilometres</article-title>. <source>Nature</source>. <year>2021</year>;<volume>589</volume>(<issue>7841</issue>):<fpage>214</fpage>&#x2013;<lpage>9</lpage>. doi:<pub-id pub-id-type="doi">10.1038/s41586-020-03093-8</pub-id>; <pub-id pub-id-type="pmid">33408416</pub-id></mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Yin</surname> <given-names>Z-Q</given-names></string-name>, <string-name><surname>He</surname> <given-names>D-Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>R-Q</given-names></string-name>, <string-name><surname>Ye</surname> <given-names>P</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Twin-field quantum key distribution over 830-km fibre</article-title>. <source>Nat Photon</source>. <year>2022</year>;<volume>16</volume>(<issue>2</issue>):<fpage>154</fpage>&#x2013;<lpage>61</lpage>. doi:<pub-id pub-id-type="doi">10.1038/s41566-021-00928-2</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>HQ</given-names></string-name>, <string-name><surname>Li</surname> <given-names>GC</given-names></string-name>, <string-name><surname>Hong</surname> <given-names>XS</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>SQ</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Informationally complete distributed metrology without a shared reference frame</article-title>. <source>Nat Commun</source>. <year>2026</year>;<volume>17</volume>(<issue>1</issue>):<fpage>1025</fpage>. doi:<pub-id pub-id-type="doi">10.1038/s41467-025-67771-9</pub-id>; <pub-id pub-id-type="pmid">41444481</pub-id></mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Cai</surname> <given-names>WQ</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>JG</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>CZ</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>M</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>L</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Microsatellite-based real-time quantum key distribution</article-title>. <source>Nature</source>. <year>2025 Mar</year>;<volume>640</volume>(<issue>8057</issue>):<fpage>47</fpage>&#x2013;<lpage>54</lpage>. doi:<pub-id pub-id-type="doi">10.1038/s41586-025-08739-z</pub-id>; <pub-id pub-id-type="pmid">40108471</pub-id></mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Briegel</surname> <given-names>HJ</given-names></string-name>, <string-name><surname>D&#x00FC;r</surname> <given-names>W</given-names></string-name>, <string-name><surname>Cirac</surname> <given-names>JI</given-names></string-name>, <string-name><surname>Zoller</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Quantum repeaters: the role of imperfect local operations in quantum communication</article-title>. <source>Phys Rev Lett</source>. <year>1998 Dec</year>;<volume>81</volume>:<fpage>5932</fpage>&#x2013;<lpage>5</lpage>. doi:<pub-id pub-id-type="doi">10.1103/physrevlett.81.5932</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Huttner</surname> <given-names>B</given-names></string-name>, <string-name><surname>All&#x00E9;aume</surname> <given-names>R</given-names></string-name>, <string-name><surname>Diamanti</surname> <given-names>E</given-names></string-name>, <string-name><surname>Fr&#x00F6;wis</surname> <given-names>F</given-names></string-name>, <string-name><surname>Grangier</surname> <given-names>P</given-names></string-name>, <string-name><surname>H&#x00FC;bel</surname> <given-names>H</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Long-range QKD without trusted nodes is not possible with current technology</article-title>. <source>npj Quantum Inf</source>. <year>2022</year>;<volume>8</volume>(<issue>1</issue>):<fpage>108</fpage>. doi:<pub-id pub-id-type="doi">10.1038/s41534-022-00613-4</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sangouard</surname> <given-names>N</given-names></string-name>, <string-name><surname>Simon</surname> <given-names>C</given-names></string-name>, <string-name><surname>de Riedmatten</surname> <given-names>H</given-names></string-name>, <string-name><surname>Gisin</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Quantum repeaters based on atomic ensembles and linear optics</article-title>. <source>Rev Mod Phys</source>. <year>2011 Mar</year>;<volume>83</volume>(<issue>1</issue>):<fpage>33</fpage>&#x2013;<lpage>80</lpage>. doi:<pub-id pub-id-type="doi">10.1103/revmodphys.83.33</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Singh</surname> <given-names>A</given-names></string-name>, <string-name><surname>Dev</surname> <given-names>K</given-names></string-name>, <string-name><surname>Siljak</surname> <given-names>H</given-names></string-name>, <string-name><surname>Joshi</surname> <given-names>HD</given-names></string-name>, <string-name><surname>Magarini</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Quantum internet&#x2014;applications, functionalities, enabling technologies, challenges, and research directions</article-title>. <source>IEEE Commun Surv Tutor</source>. <year>2021</year>;<volume>23</volume>(<issue>4</issue>):<fpage>2218</fpage>&#x2013;<lpage>47</lpage>. doi:<pub-id pub-id-type="doi">10.1109/comst.2021.3109944</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rivest</surname> <given-names>RL</given-names></string-name>, <string-name><surname>Adleman</surname> <given-names>L</given-names></string-name>, <string-name><surname>Dertouzos</surname> <given-names>ML</given-names></string-name></person-group>. <article-title>On data banks and privacy homomorphisms</article-title>. <source>Found Secur Comput</source>. <year>1978</year>;<volume>4</volume>(<issue>11</issue>):<fpage>169</fpage>&#x2013;<lpage>80</lpage>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rivest</surname> <given-names>RL</given-names></string-name>, <string-name><surname>Shamir</surname> <given-names>A</given-names></string-name>, <string-name><surname>Adleman</surname> <given-names>L</given-names></string-name></person-group>. <article-title>A method for obtaining digital signatures and public-key cryptosystems</article-title>. <source>Commun ACM</source>. <year>1978 Feb</year>;<volume>21</volume>(<issue>2</issue>):<fpage>120</fpage>&#x2013;<lpage>6</lpage>. doi:<pub-id pub-id-type="doi">10.1145/359340.359342</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Goldwasser</surname> <given-names>S</given-names></string-name>, <string-name><surname>Micali</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Probabilistic encryption &#x0026; how to play mental poker keeping secret all partial information</article-title>. In: <conf-name>Proceedings of the fourteenth annual ACM symposium on Theory of computing; 1982 May 5&#x2013;7; San Francisco, CA, USA</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>1982</year>. p. <fpage>365</fpage>&#x2013;<lpage>77</lpage>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Elgamal</surname> <given-names>T</given-names></string-name></person-group>. <article-title>A public key cryptosystem and a signature scheme based on discrete logarithms</article-title>. <source>IEEE Trans Inf Theory</source>. <year>1985</year>;<volume>31</volume>(<issue>4</issue>):<fpage>469</fpage>&#x2013;<lpage>72</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Benaloh</surname> <given-names>J</given-names></string-name></person-group>. <chapter-title>Dense probabilistic encryption</chapter-title>. In: <source>Proceedings of the Workshop on Selected Areas of Cryptography</source>; <year>2026 Aug 24&#x02013;28</year>; <comment>Ottawa, ON, Canada</comment>. p. <fpage>120</fpage>&#x2013;<lpage>128</lpage>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Paillier</surname> <given-names>P</given-names></string-name></person-group>. <chapter-title>Public-key cryptosystems based on composite degree residuosity classes</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Stern</surname> <given-names>J</given-names></string-name></person-group>, editor. <source>Advances in cryptology&#x2014;EUROCRYPT &#x2019;99</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>1999</year>. p. <fpage>223</fpage>&#x2013;<lpage>38</lpage>. doi: <pub-id pub-id-type="doi">10.1007/3-540-48910-x_16</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Boneh</surname> <given-names>D</given-names></string-name>, <string-name><surname>Goh</surname> <given-names>EJ</given-names></string-name>, <string-name><surname>Nissim</surname> <given-names>K</given-names></string-name></person-group>. <chapter-title>Evaluating 2-DNF formulas on ciphertexts</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Kilian</surname> <given-names>J</given-names></string-name></person-group>, editor. <source>Theory of cryptography</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2005</year>. p. <fpage>325</fpage>&#x2013;<lpage>41</lpage>. doi: <pub-id pub-id-type="doi">10.1007/978-3-540-30576-7_18</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Gentry</surname> <given-names>C</given-names></string-name></person-group>. <source>A fully homomorphic encryption scheme</source>. <publisher-loc>Stanford, CA, USA</publisher-loc>: <publisher-name>Stanford University</publisher-name>; <year>2009</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Brakerski</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Gentry</surname> <given-names>C</given-names></string-name>, <string-name><surname>Vaikuntanathan</surname> <given-names>V</given-names></string-name></person-group>. <article-title>(Leveled) fully homomorphic encryption without bootstrapping</article-title>. In: <conf-name>Proceedings of the 3rd Innovations in Theoretical Computer Science Conference; 212 Jan 8&#x2013;10; Cambridge, MA, USA</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2012</year>. p. <fpage>309</fpage>&#x2013;<lpage>25</lpage>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Brakerski</surname> <given-names>Z</given-names></string-name></person-group>. <chapter-title>Fully homomorphic encryption without modulus switching from classical gapSVP</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Safavi-Naini</surname> <given-names>R</given-names></string-name>, <string-name><surname>Canetti</surname> <given-names>R</given-names></string-name></person-group>, editor. <source>Advances in Cryptology&#x2014;CRYPTO 2012</source>. <publisher-loc>Berlin/Heidelberg</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2012</year>. p. <fpage>868</fpage>&#x2013;<lpage>86</lpage>. doi: <pub-id pub-id-type="doi">10.1007/978-3-642-32009-5_50</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Fan</surname> <given-names>J</given-names></string-name>, <string-name><surname>Vercauteren</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Somewhat practical fully homomorphic encryption</article-title>. <source>Cryptology ePrint Archive</source>. <year>2012</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Gentry</surname> <given-names>C</given-names></string-name>, <string-name><surname>Sahai</surname> <given-names>A</given-names></string-name>, <string-name><surname>Waters</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Homomorphic encryption from learning with errors: conceptually-simpler, asymptotically-faster, attribute-based</article-title>. <source>Cryptology ePrint Archive</source>. <year>2013</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Chillotti</surname> <given-names>I</given-names></string-name>, <string-name><surname>Gama</surname> <given-names>N</given-names></string-name>, <string-name><surname>Georgieva</surname> <given-names>M</given-names></string-name>, <string-name><surname>Izabach&#x00E8;ne</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Faster fully homomorphic encryption: bootstrapping in less than 0.1 seconds</article-title>. <source>Cryptology ePrint Archive</source>. <year>2016</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Chillotti</surname> <given-names>I</given-names></string-name>, <string-name><surname>Gama</surname> <given-names>N</given-names></string-name>, <string-name><surname>Georgieva</surname> <given-names>M</given-names></string-name>, <string-name><surname>Izabach&#x00E8;ne</surname> <given-names>M</given-names></string-name></person-group>. <article-title>TFHE: fast fully homomorphic encryption over the torus</article-title>. <comment>Cryptology ePrint Archive</comment>. <year>2018</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Cheon</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>A</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Song</surname> <given-names>Y</given-names></string-name></person-group>. <source>Homomorphic encryption for arithmetic of approximate numbers</source>. <publisher-loc>Cham, Switzerland</publisher-loc>: <publisher-name>Springer International Publishing</publisher-name>; <year>2016</year>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Regev</surname> <given-names>O</given-names></string-name></person-group>. <article-title>Lattice-based cryptography</article-title>. In: <conf-name>Proceedings of the 26th Annual International Conference on Advances in Cryptology; 2006 Aug 20&#x2013;24; Santa Barbara, CA, USA</conf-name>. <publisher-loc>Berlin, Heidelberg/Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2006</year>. p. <fpage>131</fpage>&#x2013;<lpage>41</lpage>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Regev</surname> <given-names>O</given-names></string-name></person-group>. <article-title>On lattices, learning with errors, random linear codes, and cryptography</article-title>. <source>J ACM</source>. <year>2009 Sep</year>;<volume>56</volume>(<issue>6</issue>):<fpage>34</fpage>. doi:<pub-id pub-id-type="doi">10.1145/1568318.1568324</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Brakerski</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Vaikuntanathan</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Efficient fully homomorphic encryption from (standard) LWE</article-title>. <source>SIAM J Comput</source>. <year>2014</year>;<volume>43</volume>(<issue>2</issue>):<fpage>831</fpage>&#x2013;<lpage>71</lpage>. doi:<pub-id pub-id-type="doi">10.1137/120868669</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cooley</surname> <given-names>JW</given-names></string-name>, <string-name><surname>Tukey</surname> <given-names>JW</given-names></string-name></person-group>. <article-title>An algorithm for the machine calculation of complex Fourier series</article-title>. <source>Math Comput</source>. <year>1965</year>;<volume>19</volume>:<fpage>297</fpage>&#x2013;<lpage>301</lpage>. doi:<pub-id pub-id-type="doi">10.1090/s0025-5718-1965-0178586-1</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gentry</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Computing arbitrary functions of encrypted data</article-title>. <source>Commun ACM</source>. <year>2010 Mar</year>;<volume>53</volume>(<issue>3</issue>):<fpage>97</fpage>&#x2013;<lpage>105</lpage>. doi:<pub-id pub-id-type="doi">10.1145/1666420.1666444</pub-id>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Brazaola-Vicario</surname> <given-names>A</given-names></string-name>, <string-name><surname>Lage</surname> <given-names>O</given-names></string-name>, <string-name><surname>Bernab&#x00E9;-Rodr&#x00ED;guez</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jacob</surname> <given-names>E</given-names></string-name>, <string-name><surname>Astorga</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Privacy enhanced QKD networks: zero trust relay architecture based on homomorphic encryption</article-title>. <source>Comput Netw</source>. <year>2026</year>;<volume>280</volume>:<fpage>112172</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.comnet.2026.112172</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rose</surname> <given-names>SW</given-names></string-name>, <string-name><surname>Borchert</surname> <given-names>O</given-names></string-name>, <string-name><surname>Mitchell</surname> <given-names>S</given-names></string-name>, <string-name><surname>Connelly</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Zero trust architecture</article-title>. <source>Gaithersburg, Maryland: National Institute of Standards and Technology (NIST)</source>; <year>2020</year>. doi:<pub-id pub-id-type="doi">10.6028/NIST.SP.800-207</pub-id>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Joye</surname> <given-names>M</given-names></string-name></person-group>. <source>TFHE public-key encryption revisited</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer-Verlag</publisher-name>; <year>2024</year>. p. <fpage>277</fpage>&#x2013;<lpage>91</lpage>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tysowski</surname> <given-names>PK</given-names></string-name>, <string-name><surname>Ling</surname> <given-names>X</given-names></string-name>, <string-name><surname>L&#x00FC;tkenhaus</surname> <given-names>N</given-names></string-name>, <string-name><surname>Mosca</surname> <given-names>M</given-names></string-name></person-group>. <article-title>The engineering of a scalable multi-site communications system utilizing quantum key distribution (QKD)</article-title>. <source>Quantum Sci Technol</source>. <year>2018 Jan</year>;<volume>3</volume>(<issue>2</issue>):<fpage>024001</fpage>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mehic</surname> <given-names>M</given-names></string-name>, <string-name><surname>Niemiec</surname> <given-names>M</given-names></string-name>, <string-name><surname>Rass</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>J</given-names></string-name>, <string-name><surname>Peev</surname> <given-names>M</given-names></string-name>, <string-name><surname>Aguado</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Quantum key distribution: a networking perspective</article-title>. <source>ACM Comput Surv</source>. <year>2020</year>;<volume>53</volume>:<fpage>41</fpage>. doi:<pub-id pub-id-type="doi">10.1145/3402192</pub-id>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bennett</surname> <given-names>CH</given-names></string-name></person-group>. <article-title>Quantum cryptography using any two nonorthogonal states</article-title>. <source>Phys Rev Lett</source>. <year>1992 May</year>;<volume>68</volume>(<issue>21</issue>):<fpage>3121</fpage>&#x2013;<lpage>4</lpage>. doi:<pub-id pub-id-type="doi">10.1103/physrevlett.68.3121</pub-id>; <pub-id pub-id-type="pmid">10045619</pub-id></mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ekert</surname> <given-names>AK</given-names></string-name></person-group>. <article-title>Quantum cryptography based on Bell&#x2019;s theorem</article-title>. <source>Phys Rev Lett</source>. <year>1991 Aug</year>;<volume>67</volume>(<issue>6</issue>):<fpage>661</fpage>&#x2013;<lpage>3</lpage>. doi:<pub-id pub-id-type="doi">10.1103/physrevlett.67.661</pub-id>; <pub-id pub-id-type="pmid">10044956</pub-id></mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ma</surname> <given-names>X</given-names></string-name>, <string-name><surname>Yuan</surname> <given-names>X</given-names></string-name>, <string-name><surname>Cao</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Qi</surname> <given-names>B</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>Quantum random number generation</article-title>. <source>npj Quantum Inf</source>. <year>2016</year>;<volume>2</volume>(<issue>1</issue>):<fpage>1</fpage>&#x2013;<lpage>9</lpage>. doi:<pub-id pub-id-type="doi">10.1038/npjqi.2016.21</pub-id>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shannon</surname> <given-names>CE</given-names></string-name></person-group>. <article-title>Communication theory of secrecy systems</article-title>. <source>Bell Syst Tech J</source>. <year>1949</year>;<volume>28</volume>(<issue>4</issue>):<fpage>656</fpage>&#x2013;<lpage>715</lpage>. doi:<pub-id pub-id-type="doi">10.1002/j.1538-7305.1949.tb00928.x</pub-id>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>H</given-names></string-name>, <string-name><surname>Laine</surname> <given-names>K</given-names></string-name>, <string-name><surname>Player</surname> <given-names>R</given-names></string-name></person-group>. <chapter-title>Simple encrypted arithmetic library &#x2013; SEAL v2.1</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Brenner</surname> <given-names>M</given-names></string-name>, <string-name><surname>Rohloff</surname> <given-names>K</given-names></string-name>, <string-name><surname>Bonneau</surname> <given-names>J</given-names></string-name>, <string-name><surname>Miller</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ryan</surname> <given-names>PYA</given-names></string-name>, <string-name><surname>Teague</surname> <given-names>V</given-names></string-name> <etal>et al.</etal></person-group>, editors. <source>Financial cryptography and data security</source>. <publisher-loc>Cham, Switzerland</publisher-loc>: <publisher-name>Springer International Publishing</publisher-name>; <year>2017</year>. p. <fpage>3</fpage>&#x2013;<lpage>18</lpage>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Al Badawi</surname> <given-names>A</given-names></string-name>, <string-name><surname>Bates</surname> <given-names>J</given-names></string-name>, <string-name><surname>Bergamaschi</surname> <given-names>F</given-names></string-name>, <string-name><surname>Cousins</surname> <given-names>DB</given-names></string-name>, <string-name><surname>Erabelli</surname> <given-names>S</given-names></string-name>, <string-name><surname>Genise</surname> <given-names>N</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>OpenFHE: open-source fully homomorphic encryption library</article-title>. In: <conf-name>Proceedings of the 10th Workshop on Encrypted Computing &#x0026; Applied Homomorphic Cryptography. WAHC&#x2019;22; 2022 Nov 7; Los Angeles, CA, USA</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2022</year>. p. <fpage>53</fpage>&#x2013;<lpage>63</lpage>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Halevi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Shoup</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Design and implementation of a homomorphic-encryption library</article-title>. <source>IBM Research</source>. <year>2013</year>;<volume>6</volume>(<issue>12&#x2013;15</issue>):<fpage>8</fpage>&#x2013;<lpage>36</lpage>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Zama</collab></person-group>. <article-title>Concrete ML: privacy-preserving machine learning library</article-title>. <comment>Version 1.5.0 [Internet]. 2024 [cited 2026 Jan 14]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://github.com/zama-ai/concrete-ml">https://github.com/zama-ai/concrete-ml</ext-link>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Polyakov</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Rohloff</surname> <given-names>K</given-names></string-name>, <string-name><surname>Ryan</surname> <given-names>GW</given-names></string-name></person-group>. <article-title>PALISADE lattice cryptography library [Internet]</article-title>. <year>2018</year> <comment>[cited 2026 Jan 14]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://github.com/fuz-woo/PALISADE">https://github.com/fuz-woo/PALISADE</ext-link>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Polyakov</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Quah</surname> <given-names>I</given-names></string-name>, <string-name><surname>Oliveira</surname> <given-names>R</given-names></string-name>, <string-name><surname>Triplett</surname> <given-names>M</given-names></string-name></person-group>. <article-title>The OpenFHE Development Team. OpenFHE-python documentation</article-title>. <comment>Version 0.8.0 [Internet]. 2024 [cited 2024 Aug 6]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://openfhe-python.readthedocs.io/">https://openfhe-python.readthedocs.io/</ext-link>.</mixed-citation></ref>
</ref-list>
</back></article>