Concretely-Efficient Multi-Key Homomorphic Secret Sharing and Applications
Kaiwen He, Sacha Servan-Schreiber, Geoffroy Couteau, Srinivas Devadas
Abstract
Homomorphic secret sharing (HSS) is a powerful cryptographic primitive that enables efficient, lowcommunication secure computation without the use of fully homomorphic encryption. Public-key HSS is a well-known variant that supports inputs from multiple parties, but all parties must agree on a joint public key before any party can encode their inputs, requiring extra rounds of communication in applications. Recently, Couteau et al. (EUROCRYPT 2025) constructed multi-key HSS (MKHSS)—a new primitive which allows parties to encode their inputs under independent keys—under the DCR assumption. MKHSS assumes only a reusable common reference string, without the need for prior interactions between parties or a public-key infrastructure. In this paper, we construct and implement the first concretely-efficient MKHSS scheme under the same assumptions used by Couteau et al. Using an algorithmic insight that reduces the largest modulus in Couteau et al. from to , our optimized implementation can homomorphically multiply inputs in 5.0 milliseconds—while an implementation of Couteau et al. requires 224.6 milliseconds—thereby achieving a speedup. A powerful application of MKHSS is to realize attributebased non-interactive key exchange (ANIKE), which generalizes password-authenticated key exchange (PAKE) to arbitrary attribute policies. ANIKE is currently only known from MKHSS. We use our implementation to evaluate the first concretelyefficient ANIKE schemes for a range of practically useful policies. Using our implementation, two parties can perform a geolocation-based key exchange in under one second and a fuzzy PAKE on an 8-word passphrase in a few seconds for realistic parameters, on a single core, achieving a roughly speedup over Couteau et al. for both applications.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4a905723-7774-4b86-9dc4-376ccf0bd3d8Related papers
- Multi-Key Homomorphic Secret SharingGeoffroy Couteau, Lalita Devadas, Aditya Hegde, Abhishek Jain et al.EUROCRYPT 2025 · 11 citations
- Arbitrary-Threshold Fully Homomorphic Encryption with Lower ComplexityYijia Chang, Songze LiUSENIX Security 2025
- Large Message Homomorphic Secret Sharing from DCR and ApplicationsLawrence Roy, Jaspal SinghCRYPTO 2021 · 50 citations
- Homomorphic Secret Sharing: Optimizations and ApplicationsElette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval Ishai et al.CCS 2017 · 97 citations
- Succinct Homomorphic Secret SharingDamiano Abram, Lawrence Roy, Peter SchollEUROCRYPT 2024 · 25 citations
