Fully Homomorphic Encryption Beyond IND-CCA1 Security: Integrity Through Verifiability
Mark Manulis, Jérôme Nguyen
Abstract
We focus on the problem of constructing fully homomorphic encryption (FHE) schemes that achieve some meaningful notion of adaptive chosen-ciphertext security beyond CCA1. Towards this, we propose a new notion, called security against verified chosen-ciphertext attack (vCCA). The idea behind it is to ascertain integrity of the ciphertext by imposing a strong control on the evaluation algorithm. Essentially, we require that a ciphertext obtained by the use of homomorphic evaluation must be "linked" to the original input ciphertexts. We formalize the vCCA notion in two equivalent formulations; the first is in the indistinguishability paradigm, the second follows the non-malleability simulation-based approach, and is a generalization of the targeted malleability introduced by Boneh et al. in 2012.
We strengthen the credibility of our definitions by exploring relations to existing security notions for homomorphic encryption schemes, namely CCA1, RCCA, FuncCPA, CCVA, and HCCA. We prove that vCCA security is the strongest notion known so far, that can be achieved by an FHE scheme; in particular, vCCA is strictly stronger than CCA1.
Finally, we provide a general transformation, that takes any CPA-secure FHE scheme and makes it vCCA-secure. Our transformation first turns an FHE scheme into a CCA2-secure scheme where a part of the ciphertext retains the homomorphic properties and then extends it with a succinct non-interactive argument of knowledge (SNARK) to verifiably control the evaluation algorithm. In fact, we obtain four general variation of this transformation. We handle both the asymmetric and the symmetric key FHE schemes, and for each we give two variations differing in whether the ciphertext integrity can be verified publicly or requires the secret key. We use well-known techniques to achieve CCA security in the first step of our transformation. In the asymmetric case, we use the double encryption paradigm, and in the symmetric case, we use Encrypt-then-MAC techniques. Furthermore, our transformation also gives the first CCA-secure FHE scheme based on bootstrapping techniques.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get fdfb6ca2-8c18-4428-8c14-eb5dcb4f1fbcCited by top-tier papers3
- On the Practical CPAD Security of "exact" and Threshold FHE Schemes and LibrariesMarina Checri, Renaud Sirdey, Aymen Boudguiga, Jean-Paul BultelCRYPTO 2024 · 31 citations
- Drifting Towards Better Error Probabilities in Fully Homomorphic Encryption SchemesOlivier Bernard, Marc Joye, Nigel P. Smart, Michael WalterEUROCRYPT 2025 · 6 citations
- Towards Verifiable FHE in Practice: Proving Correct Execution of TFHE's Bootstrapping using plonky2Louis Tremblay Thibault, Michael WalterCCS 2025 · 1 citation
Related papers
- Fully Homomorphic Encryption with Chosen-Ciphertext Security from LWERupeng Yang, Zuoxia Yu, Willy SusiloCRYPTO 2025 · 5 citations
- Attacks Against the IND-CPAD Security of Exact FHE SchemesJung Hee Cheon, Hyeongmin Choe, Alain Passelègue, Damien Stehlé et al.CCS 2024 · 23 citations
- HasteBoots: Proving TFHE Programmable Bootstrapping in SecondsFengrun Liu, Haofei Liang, Xiang Xie, Yu Yu et al.USENIX Security 2026
- IND-CPA-D of Relaxed Functional Bootstrapping: A New Attack, A General Fix, and A Stronger ModelZeyu Liu, Yunhao Wang, Ben FischCCS 2025
- Securing Approximate Homomorphic Encryption Using Differential PrivacyBaiyu Li, Daniele Micciancio, Mark Schultz, Jessica SorrellCRYPTO 2022 · 55 citations
