Sometimes-Decryptable Homomorphic Encryption from Sub-exponential DDH
摘要
Homomorphic encryption (HE) is a popular cryptographic primitive with wide ranging applications. While many HE schemes have been proposed over the years, schemes that support general or even more than degree-two homomorphism are known only from lattice-based assumptions or program obfuscation. In particular, constructions based solely on group-based assumptions remain elusive. KWe propose the notion of sometimes-decryptable homomorphic encryption (s-HE)—a relaxation of HE that allows very high decryption error for homomorphically evaluated ciphertexts. We present a construction of s-HE for constant-depth (resp., logarithmic depth) threshold circuits based on the sub-exponential (resp., exponential) Decisional Diffie-Hellman (DDH) assumption. We demonstrate several applications of s-HE: