Keyed-Fully Homomorphic Encryption without Indistinguishability Obfuscation

Keyed-Fully Homomorphic Encryption without Indistinguishability Obfuscation
复制标题

DOI:
10.1007/978-3-031-09234-3_1
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Shingo Sato;K. Emura;Atsushi Takayasu
Shingo Sato;K. Emura;Atsushi Takayasu
中科院分区:
其他
文献类型:
--
作者:
Shingo Sato;K. Emura;Atsushi Takayasu

文献摘要

相似文献

(完全)同态加密((F)HE)允许用户公开评估加密数据上的电路。尽管公共同态求值性质有各种应用,但由于其性质,(F)HE不能实现针对选择密文攻击(CCA 2)的安全性。为了同时实现CCA 2安全性和同态求值性质,Emura等人(PKC 2013)引入了密钥同态公钥加密(KH-PKE),并将其安全性形式化为security。KH-PKE有一个同态评估密钥,使用户能够执行同态操作。直观地说,KH-PKE实现了CCA 2安全性,除非对手有同态评估密钥。尽管Lai等人(PKC 2016)提出了第一个密钥化全同态加密(keyed-fully homomorphic encryption,简称keyed-FHE)方案,但其安全性依赖于不可混淆性(),并且该方案满足弱安全性。在这里,我们提出了一个通用的构造安全的密钥FHE方案从FHE方案安全的非自适应选择密文攻击(CCA 1)和强双系统仿真健全的非交互零知识(强DSS-NIZK)的论点系统,通过使用Naor-Yung范式。我们表明,有一个强大的DSS-NIZK和IND-CCA 1安全FHE计划,适合我们的通用建设。这表明存在来自比iO更简单的原语的密钥化FHE方案。
(Fully) homomorphic encryption ((F)HE) allows users to publicly evaluate circuits on encrypted data. Although public homomorphic evaluation property has various applications, (F)HE cannot achieve security against chosen ciphertext attacks (CCA2) due to its nature. To achieve both the CCA2 security and homomorphic evaluation property, Emura et al. (PKC 2013) introduced keyed-homomorphic public key encryption (KH-PKE) and formalized its security denoted bysecurity. KH-PKE has a homomorphic evaluation key that enables users to perform homomorphic operations. Intuitively, KH-PKE achieves the CCA2 security unless adversaries have a homomorphic evaluation key. Although Lai et al. (PKC 2016) proposed the first keyed-fully homomorphic encryption (keyed-FHE) scheme, its security relies on the indistinguishability obfuscation (), and this scheme satisfies a weak variant ofsecurity. Here, we propose a generic construction of asecure keyed-FHE scheme from an FHE scheme secure against non-adaptive chosen ciphertext attack (CCA1) and a strong dual-system simulation-sound non-interactive zero-knowledge (strong DSS-NIZK) argument system by using the Naor-Yung paradigm. We show that there are a strong DSS-NIZK and an IND-CCA1 secure FHE scheme that are suitable for our generic construction. This shows that there exists a keyed-FHE scheme from simpler primitives than iO.