Drifting Towards Better Error Probabilities in Fully Homomorphic Encryption Schemes
Olivier Bernard, Marc Joye, Nigel P. Smart, Michael Walter
Abstract
There are two security notions for FHE schemes the traditional notion of IND-CPA, and a more stringent notion of IND-CPA. The notions are equivalent if the FHE schemes are perfectly correct, however for schemes with negligible failure probability the FHE parameters needed to obtain IND-CPA security can be much larger than those needed to obtain IND-CPA security. This paper uses the notion of ciphertext drift in order to understand the practical difference between IND-CPA and IND-CPA security in schemes such as FHEW, TFHE, and FINAL. This notion allows us to define a modulus switching operation (the main culprit for the difference in parameters) such that one does not require adapting IND-CPA cryptographic parameters to meet the IND-CPA security level. Further, the extra cost incurred by the new techniques has no noticeable performance impact in practical applications. The paper also formally defines a stronger version for IND-CPA security called sIND-CPA, which is proved to be strictly separated from the IND-CPA notion. Criterion for turning an IND-CPA secure public-key encryption into an sIND-CPA one is also provided.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a285f2dd-ab67-4ccf-ad6b-9628e3aacf15Cited by top-tier papers3
- UnifOMR: Oblivious Message Retrieval with Near-optimal Concrete EfficiencyBen Fisch, Zeyu Liu, Eran Tromer, Yunhao WangCCS 2026
- IND-CPA-D of Relaxed Functional Bootstrapping: A New Attack, A General Fix, and A Stronger ModelZeyu Liu, Yunhao Wang, Ben FischCCS 2025
- Libra: Pattern-Scheduling Co-Optimization for Cross-Scheme FHE Code Generation over GPGPUSong Bian, Yintai Sun, Zian Zhao, Haowen Pan et al.USENIX Security 2026
Builds on6
- On the Security of Homomorphic Encryption on Approximate NumbersBaiyu Li, Daniele MicciancioEUROCRYPT 2021 · 165 citations
- Efficient FHEW Bootstrapping with Small Evaluation Keys, and Applications to Threshold Homomorphic EncryptionYongwoo Lee, Daniele Micciancio, Andrey Kim, Rakyong Choi et al.EUROCRYPT 2023 · 86 citations
- Securing Approximate Homomorphic Encryption Using Differential PrivacyBaiyu Li, Daniele Micciancio, Mark Schultz, Jessica SorrellCRYPTO 2022 · 55 citations
- On the Practical CPAD Security of "exact" and Threshold FHE Schemes and LibrariesMarina Checri, Renaud Sirdey, Aymen Boudguiga, Jean-Paul BultelCRYPTO 2024 · 31 citations
- Fully Homomorphic Encryption Beyond IND-CCA1 Security: Integrity Through VerifiabilityMark Manulis, Jérôme NguyenEUROCRYPT 2024 · 27 citations
Related papers
- Attacks Against the IND-CPAD Security of Exact FHE SchemesJung Hee Cheon, Hyeongmin Choe, Alain Passelègue, Damien Stehlé et al.CCS 2024 · 23 citations
- Updatable Public Key Encryption from DCR: Efficient Constructions With Stronger SecurityCalvin Abou Haidar, Benoît Libert, Alain PasselègueCCS 2022 · 7 citations
- New IND-CPA-D Attacks on BFV and BGVHyeongmin Choe, Minsik Kang, Damien StehléCCS 2026
- Efficient Arithmetic-and-Comparison Homomorphic Encryption with Space SwitchingErwin Eko Wahyudi, Yan Solihin, Qian LouS&P 2026
- A Key-Recovery Timing Attack on Post-quantum Primitives Using the Fujisaki-Okamoto Transformation and Its Application on FrodoKEMQian Guo, Thomas Johansson, Alexander NilssonCRYPTO 2020 · 84 citations
