Lune

EUROCRYPT2025Top-tier venue

Drifting Towards Better Error Probabilities in Fully Homomorphic Encryption Schemes

Olivier Bernard, Marc Joye, Nigel P. Smart, Michael Walter

2025Year
6Citations
3Top-tier citations

Abstract

There are two security notions for FHE schemes the traditional notion of IND-CPA, and a more stringent notion of IND-CPAD^D. The notions are equivalent if the FHE schemes are perfectly correct, however for schemes with negligible failure probability the FHE parameters needed to obtain IND-CPAD^D security can be much larger than those needed to obtain IND-CPA security. This paper uses the notion of ciphertext drift in order to understand the practical difference between IND-CPA and IND-CPAD^D security in schemes such as FHEW, TFHE, and FINAL. This notion allows us to define a modulus switching operation (the main culprit for the difference in parameters) such that one does not require adapting IND-CPA cryptographic parameters to meet the IND-CPAD^D security level. Further, the extra cost incurred by the new techniques has no noticeable performance impact in practical applications. The paper also formally defines a stronger version for IND-CPAD^D security called sIND-CPAD^D, which is proved to be strictly separated from the IND-CPAD^D notion. Criterion for turning an IND-CPAD^D secure public-key encryption into an sIND-CPAD^D one is also provided.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext a285f2dd-ab67-4ccf-ad6b-9628e3aacf15

Cited by top-tier papers3

Ask how each one uses it

Builds on6

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines