<p>Most existing fully homomorphic encryption (FHE) security models cannot resist attacks from a malicious server that can arbitrarily replace the ciphertexts and evaluation functions used during homomorphic evaluation and obtain the decryption results of the evaluated ciphertexts. To address this security issue of FHE caused by the breakdown of computational integrity, we proposed two new primitives, called tagged-FHE and <InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(\hbox {tagged}^*\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>tagged</mtext> <mo>∗</mo> </msup> </math></EquationSource> </InlineEquation>-FHE with corresponding security notions IND-TAG-CCA and IND-<InlineEquation ID="IEq2"> <EquationSource Format="TEX">\(\hbox {TAG}^*\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>TAG</mtext> <mo>∗</mo> </msup> </math></EquationSource> </InlineEquation>-CCA. Unlike the verifiable FHE, which also focuses on preserving computational integrity, the new primitives and security concepts still require the compactness of ciphertexts. The size of the output of the evaluation algorithm must be independent of the complexity of the function during evaluation. Tagged-FHE enables users to detect whether a server has replaced the input ciphertexts of evaluation. While <InlineEquation ID="IEq3"> <EquationSource Format="TEX">\(\hbox {tagged}^*\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>tagged</mtext> <mo>∗</mo> </msup> </math></EquationSource> </InlineEquation>-FHE additionally enables users to detect whether a server has replaced the evaluation function. We present generic constructions for these two primitives with corresponding security notions. The IND-TAG-CCA tagged-FHE is achievable in the standard model using IND-CPA multi-key FHE and IND-CCA2 public-key encryption. The IND-<InlineEquation ID="IEq4"> <EquationSource Format="TEX">\(\hbox {TAG}^*\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>TAG</mtext> <mo>∗</mo> </msup> </math></EquationSource> </InlineEquation>-CCA <InlineEquation ID="IEq5"> <EquationSource Format="TEX">\(\hbox {tagged}^*\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>tagged</mtext> <mo>∗</mo> </msup> </math></EquationSource> </InlineEquation>-FHE additionally uses NIZK and SNARG and requires a heuristic assumption related to hash function collision resistance. These notions provide enhanced protection for FHE in the presence of malicious third-party servers.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Tagged-FHE: strong syntax, stronger security, and standard model

  • Ziqing Wang,
  • Mengdi Ouyang,
  • Zhaosen Shi,
  • Xinyan Wu,
  • Fuchun Guo,
  • Fagen Li

摘要

Most existing fully homomorphic encryption (FHE) security models cannot resist attacks from a malicious server that can arbitrarily replace the ciphertexts and evaluation functions used during homomorphic evaluation and obtain the decryption results of the evaluated ciphertexts. To address this security issue of FHE caused by the breakdown of computational integrity, we proposed two new primitives, called tagged-FHE and \(\hbox {tagged}^*\) tagged -FHE with corresponding security notions IND-TAG-CCA and IND- \(\hbox {TAG}^*\) TAG -CCA. Unlike the verifiable FHE, which also focuses on preserving computational integrity, the new primitives and security concepts still require the compactness of ciphertexts. The size of the output of the evaluation algorithm must be independent of the complexity of the function during evaluation. Tagged-FHE enables users to detect whether a server has replaced the input ciphertexts of evaluation. While \(\hbox {tagged}^*\) tagged -FHE additionally enables users to detect whether a server has replaced the evaluation function. We present generic constructions for these two primitives with corresponding security notions. The IND-TAG-CCA tagged-FHE is achievable in the standard model using IND-CPA multi-key FHE and IND-CCA2 public-key encryption. The IND- \(\hbox {TAG}^*\) TAG -CCA \(\hbox {tagged}^*\) tagged -FHE additionally uses NIZK and SNARG and requires a heuristic assumption related to hash function collision resistance. These notions provide enhanced protection for FHE in the presence of malicious third-party servers.