[论文解读] Octonion Algebra and Noise-Free Fully Homomorphic Encryption (FHE) Schemes
该论文提出了基于有限环 ℤₙ 上的四元数代数和八元数代数的首个无噪声全同态加密(FHE)方案,在求解多变量二次方程组和单变量高次多项式方程组的困难性假设下,实现了弱密文仅攻击模型下的安全性。该方案无需采用自举机制,已被证明是安全的,从而实现了云环境中高效隐私保护计算与程序混淆。
Brakerski showed that linearly decryptable fully homomorphic encryption (FHE) schemes cannot be secure in the chosen plaintext attack (CPA) model. In this paper, we show that linearly decryptable FHE schemes cannot be secure even in the ciphertext only security model. Then we consider the maximum security that a linearly decryptable FHE scheme could achieve. This paper designs fully homomorphic symmetric key encryption (FHE) schemes without bootstrapping (that is, noise-free FHE schemes). The proposed FHE schemes are based on quaternion/octonion algebra and Jordan algebra over finite rings Z_n and are secure in the weak ciphertext-only security model assuming the hardness of solving multivariate quadratic equation systems and solving univariate high degree polynomial equation systems in Z_n. It is up to our knowledge that this is the first noise-free FHE scheme that has ever been designed with a security proof (even in the weak ciphertext-only security model). It is argued that the weak ciphertext-only security model is sufficient for various applications such as privacy preserving computation in cloud. As an example, the proposed FHE schemes are used to construct obfuscated programs. This example could be further used to show that the scheme presented in this paper could be combined with existing FHE schemes with bootstrapping to obtain more efficient FHE schemes with bootstrapping in the fully CPA model. At the end of the paper, we point out the insecurity of several recently proposed noise-free FHE schemes.
研究动机与目标
- 为解决即使在弱密文仅攻击模型下,线性可解密的 FHE 方案仍不安全的问题,挑战了关于其可行性的先前假设。
- 设计一种无需自举的全同态对称密钥加密方案,消除噪声累积,提升效率。
- 在 ℤₙ 上求解多变量二次方程组与单变量高次多项式方程组的困难性假设下,建立所提 FHE 方案的安全性证明。
- 通过构造混淆程序并展示与现有自举型 FHE 方案的潜在集成,证明其实际适用性。
- 识别并揭示若干近期提出的无噪声 FHE 方案中的漏洞,强调其缺乏安全性。
提出的方法
- 利用有限环 ℤₙ 上的非结合代数结构——四元数代数与八元数代数,构建加密与同态运算机制。
- 采用 ℤₙ 上的 Jordan 代数,确保在所需代数运算下具有封闭性与稳定性,以支持同态计算。
- 设计一种对称密钥加密方案,使同态运算可直接在编码后的元素上执行,且无噪声增长。
- 以在 ℤₙ 上求解多变量二次方程组与单变量高次多项式方程组的计算困难性作为安全基础。
- 通过确保即使在被动监听下,密文也无法泄露任何关于明文的信息,构建出密文仅攻击安全的 FHE 方案。
- 利用代数结构的性质,实现无需噪声管理或自举机制的同态加法与乘法运算。
实验结果
研究问题
- RQ1在选择明文攻击下不安全的前提下,线性可解密的 FHE 方案是否仍能在弱密文仅攻击模型下保持安全?
- RQ2在有限环 ℤₙ 上,哪些代数结构可支持无噪声全同态加密并具备可证明的安全性?
- RQ3是否可能在标准假设下,构造一种无需自举的全同态对称密钥加密方案,且仍保持安全性?
- RQ4如何利用 ℤₙ 上的八元数代数与 Jordan 代数设计高效且安全的 FHE 原 primitive?
- RQ5若干近期提出的无噪声 FHE 方案存在哪些安全缺陷?为何它们在标准安全模型下会失效?
主要发现
- 所提出的 FHE 方案是首个在弱密文仅攻击模型下具备形式化安全性证明的无噪声全同态加密方案。
- 安全性基于在 ℤₙ 上求解多变量二次方程组与单变量高次多项式方程组的困难性,提供了具体的计算困难性假设。
- 该方案被证明可抵御密文仅攻击,表明此类弱安全模型足以支持云环境中隐私保护计算。
- 该构造支持混淆程序的生成,展示了其在理论 FHE 之外的实际应用价值。
- 若干近期提出的无噪声 FHE 方案被证明不安全,揭示了其设计与假设中的缺陷。
- 该方案可与现有自举型 FHE 方案结合,从而在完全 CPA 安全模型下构建更高效的 FHE 系统。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。