[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83734-en":3,"doc-seo-83734-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83734,549758252649,"Ivy","https://ap-avatar.wpscdn.com/avatar/8000253669c5317157?_k=1778319167496531819",8,"Research & Report","Rotation-Optimal Noncommutative Prefix Scans in Bit-Reversed Homomorphic Layouts","Packed homomorphic encryption enables parallel slotwise operations, yet nonlocal communication is realized via cyclic rotations whose cost depends on the physical slot layout. The work analyzes ordered prefix computations over n = 2^m elements of an associative, possibly noncommutative monoid stored in bit-reversed order. It replaces direct routing with a replicated-aggregate invariant, yielding inclusive or exclusive scans with m rotations, monoid depth m, two live state vectors, and at most 2·m−1 packed compositions. Proven bounds show exact rotation optimality, and a Lattigo implementation reports large rotation and latency reductions.","arXiv :2607 .0363 1v 1 [ cs .CR] 3 Jul 2026  \nRotation-Optimal Noncommutative Prefix Scansin Bit-Reversed Homomorphic Layouts  \nAnis Bkakria 1 , Madicke-Diadji MBODJ 1 ,2 , Mawloud Omar2 , and Reda Yaich 1  \n1 IRT SystemX, France  \n2 UBS, France  \nAbstract. Packed homomorphic encryption evaluates slotwise operations in parallel, but nonlocal communication is realized by cyclic rotations whose cost depends on the physical slot layout. We study ordered prefix computation on n = 2m elements of an associative, possibly noncommutative monoid stored in bit-reversed order. A direct transported-predecessor scan uses m·(m+1)/2 rotations because one logical shift decomposes into several cyclic displacement classes. We introduce a replicated-aggregate invariant in which every slot of an aligned logical block stores the same complete block aggregate. Semantic replication makes the copies interchangeable: at each level, one global cyclic rotation supplies every slot with a valid aggregate of its sibling block, even though it need not reach the exact logical partner. The resulting inclusive or exclusive scan uses m rotations, monoid depth m, two live state vectors, and at most 2 · m − 1 packed monoid compositions.  \nIn a model where all non-routing operations are slotwise and every cyclic rotation invocation is counted, both bounds are exact: D ⋆ (m) = R⋆ (m) = m. Equality is rigid—the m rotation offsets contain exactly one representative of every 2-adic valuation 0 , . . . , m − 1. With at most K directly keyed offsets, we prove a product lower bound on online rotation calls and an exact frontier K · (2m/K − 1) whenever K divides m. We instantiate the exclusive scan for radix carry and borrow in bit-reversed CKKS slots, avoiding both layout restoration and a final logical-predecessor shift. In our Lattigo implementation at m = 7, the replicated scan reduces the direct bit-reversed baseline from 28 to 7 rotations, lowers evaluation-key storage by 70.0%, lowers peak heap usage by 63.9%, and improves isolated scan latency by 19.9% . Ina depth-5 downstream pipeline, retaining six additional modulus levels avoids one bootstrap and yields a mean paired speedup of 4.31 × with a 95% confidence interval of [3 .69 , 4.92] .  \nKeywords: homomorphic encryption · parallel prefix · cyclic rotations · bit reversal · CKKS · carry propagation  \n1 Introduction  \nPacked computation and layout-sensitive communication. Modern lattice-based homomorphicencryption schemes expose a SIMD abstraction: a ciphertext encrypts a vector of slots, and additionsand multiplications act slotwise on the entire vector. In CKKS, this abstraction supports approximate arithmetic over packed complex values and has become a standard foundation for encrypted numerical computation [Che+17] . Slotwise parallelism, however, does not make communication free. Moving encrypted values between slots requires Galois automorphisms, commonly exposed as cyclic rotations followed by key switching. The number of logical dependencies in an algorithm and the number of encrypted rotations needed to realize them are therefore different resources.  \nThe distinction becomes particularly sharp when data is kept in a public structured layout. Fast transforms, packing conversions, and transposed representations may leave logical indices in bit-reversed or related orders. A classical prefix network is normally analyzed by its gate count, depth, and fanout [LF80; Har03] . Those measures do not determine the encrypted routing cost: one rotation realizes the same cyclic displacement at all slots, so many logical edges can share a rotation, while a single logical predecessor relation may split into several displacement classes after conjugation by the layout. The relevant question is consequently not only how many prefix gates are needed, but how many global cyclic translations are needed when the layout must be preserved.  \nMotivating application: exact carry in radix CKKS. Approximate arithmetic does not dir","cbCaioj3h1Q0kLr1","https://ap.wps.com/l/cbCaioj3h1Q0kLr1","pdf",753131,5,1,39,"English","en",105,"# Abstract\n# Introduction\n## Packed computation and layout-sensitive communication\n## Motivating application: exact carry in radix CKKS\n## Key idea: route semantic copies, not exact partners","[{\"question\":\"Why does cyclic rotation cost depend on the slot layout in packed homomorphic encryption?\",\"answer\":\"Because moving encrypted values between slots uses Galois automorphisms, commonly implemented as cyclic rotations with key switching. Different physical slot layouts cause the same logical dependency to map onto different rotation displacement classes.\"},{\"question\":\"What does the paper optimize for ordered prefix scans on bit-reversed data?\",\"answer\":\"It optimizes the number of global cyclic rotations required to perform inclusive or exclusive prefix scans when the monoid elements are stored in bit-reversed order, even for possibly noncommutative monoids.\"},{\"question\":\"How does the replicated-aggregate invariant reduce rotation routing complexity?\",\"answer\":\"Instead of routing each destination to an exact logical predecessor, the method replicates each aligned logical block’s complete aggregate across all slots in the block. Then a global rotation at each level provides valid aggregates from sibling blocks for all slots.\"}]",1784190081,98,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"rotation-optimal-noncommutative-prefix-scans-in-bit-reversed-homomorphic-layouts","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/rotation-optimal-noncommutative-prefix-scans-in-bit-reversed-homomorphic-layouts/83734/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why does cyclic rotation cost depend on the slot layout in packed homomorphic encryption?","Question",{"text":76,"@type":77},"Because moving encrypted values between slots uses Galois automorphisms, commonly implemented as cyclic rotations with key switching. Different physical slot layouts cause the same logical dependency to map onto different rotation displacement classes.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What does the paper optimize for ordered prefix scans on bit-reversed data?",{"text":81,"@type":77},"It optimizes the number of global cyclic rotations required to perform inclusive or exclusive prefix scans when the monoid elements are stored in bit-reversed order, even for possibly noncommutative monoids.",{"name":83,"@type":74,"acceptedAnswer":84},"How does the replicated-aggregate invariant reduce rotation routing complexity?",{"text":85,"@type":77},"Instead of routing each destination to an exact logical predecessor, the method replicates each aligned logical block’s complete aggregate across all slots in the block. Then a global rotation at each level provides valid aggregates from sibling blocks for all slots.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]