Cryptanalysis and Modification of a Variant of Matrix Operation for Randomization or Encryption (v-MORE)
摘要
A variant of Matrix Operation for Randomization or Encryption (v-MORE) is a lightweight, real number-based, fully homomorphic encryption scheme used for outsourced secure medical data processing. This paper shows the vulnerability of v-MORE to a ciphertext-only attack when it is used in privacy-preserving applications where the data is not random. From the ciphertexts of v-MORE, the attacker can solve for its secrets based on linear algebra and predict the plaintext from a new ciphertext with 100% confidence. Hence, v-MORE can not ensure the privacy of medical data, which is not random, while processing it remotely and transmitting it over networks. Experimental analysis shows that the attack complexity is very low. v-MORE encryption is modified to mitigate the proposed ciphertext-only attack and developed additively homomorphic encryption that operates on real numbers (AHE-R). Also, experimental analysis and security analysis confirm that the modifications do not noticeably affect the computational and communication overhead while providing data security.