On Extension of Evaluation Algorithms in Keyed-Homomorphic Encryption

On Extension of Evaluation Algorithms in Keyed-Homomorphic Encryption
复制标题

DOI:
10.1007/978-3-031-15255-9_10
复制
发表时间:
2022
期刊:
IEICE Trans. Fundam. Electron. Commun. Comput. Sci.
影响因子:
--
通讯作者:
Hiroto Shinoki;K. Nuida
Hiroto Shinoki;K. Nuida
中科院分区:
其他
文献类型:
--
作者:
Hiroto Shinoki;K. Nuida

文献摘要

相似文献

同态加密(HE)是一种公钥加密,它能够在不解密密文的情况下对密文进行计算,但众所周知,他不能实现IND-CCA2安全。为了解决这个问题,引入了密钥同态加密(KH-PKE)的概念,KH-PKE具有单独的同态评估密钥,可以实现更强的安全性(Emura等人,PKC 2013)。首先,KH-PKE的语法假设对单个操作进行同态求值,并在此语法的基础上提出了KH-CCA安全的概念。因此,如果以将顺序运算集合为单一评估的方式来增强同态评估算法,则KH-CCA安全性是否被保持是不明显的。证明了在这种修改下,KH-CCA安全性一般不被保持,而当原始方案另外满足电路私密性时,KH-CCA安全性被保持。其次,Catalano和Fiore(ACM CCS 2015)提出了一种从线性HE方案到两级HE方案的转换方法,后者允许对密文进行加法和一次乘法。本文将这种转换推广到线性KH-PKE方案的情形,得到了两级KH-PKE方案。
Homomorphic encryption (HE) is public key encryption that enables computation over ciphertexts without decrypting them, while it is known that HE cannot achieve IND-CCA2 security. To overcome this issue, the notion of keyed-homomorphic encryption (KH-PKE) was introduced, which has a separate homomorphic evaluation key and can achieve stronger security (Emura et al., PKC 2013).The contributions of this paper are twofold. First, the syntax of KH-PKE assumes that homomorphic evaluation is performed for single operations, and its security notion called KH-CCA security was formulated based on this syntax. Consequently, if the homomorphic evaluation algorithm is enhanced in a way of gathering up sequential operations as a single evaluation, then it is not obvious whether or not KH-CCA security is preserved. In this paper, we show that KH-CCA security is in general not preserved under such modification, while KH-CCA security is preserved when the original scheme additionally satisfies circuit privacy.Secondly, Catalano and Fiore (ACM CCS 2015) proposed a conversion method from linearly HE schemes into two-level HE schemes, the latter admitting addition and a single multiplication for ciphertexts. In this paper, we extend the conversion to the case of linearly KH-PKE schemes to obtain two-level KH-PKE schemes.