USENIX Security2025
Shechi: A Secure Distributed Computation Compiler Based on Multiparty Homomorphic Encryption
Haris Smajlovic, David Froelicher, Ariya Shajii, Bonnie Berger, Hyunghoon Cho, Ibrahim Numanagic
摘要
We present Shechi, an easy-to-use programming framework for secure high-performance computing on distributed datasets. Shechi automatically converts Pythonic code into a secure distributed equivalent using multiparty homomorphic encryption (MHE), combining homomorphic encryption (HE) and secure multiparty computation (SMC) techniques to enable efficient distributed computation. Shechi abstracts away considerations about the private and distributed aspects of the input data from end users through a familiar Pythonic syntax. Our framework introduces new data types for the efficient handling of distributed data as well as systematic compiler optimizations for cryptographic and distributed computations. We evaluate Shechi on a wide range of applications, including principal component analysis and complex genomic analysis tasks. Our results demonstrate Shechi's ability to uncover optimizations missed even by expert developers, achieving up to 15× runtime improvements over the prior state-of-the-art solutions and a 40-fold improvement in code expressiveness compared to code manually optimized by experts. Shechi represents the first MHE compiler, extending secure computation frameworks to the analysis of sensitive distributed datasets. * Co-first authors. leveraging fully homomorphic encryption (HE), secure multiparty computation (SMC), or their combination in the form of multiparty HE (MHE) to protect the privacy of each party's data [6, 18, 26-29, 42, 54, 74]. However, these methods come with several challenges that prevent their widespread adoption. In the case of HE, the computational overhead associated with its cryptographic primitives often leads to impractical runtimes on large datasets or necessitate the adoption of simplified, less accurate variants of the desired analysis. On the other hand, SMC involves interaction among multiple parties and typically suffers from a high communication overhead because all data must be shared and synchronized among the parties during the execution. Although a hybrid framework based on MHE can, in principle, lead to a significant reduction in computational costs on large-scale distributed datasets compared to existing methods based on HE and SMC, to the best of our knowledge, there does not exist a compiler for MHE that can streamline the development of such protocols. As a result, secure distributed software development currently demands profound expertise in the often disparate domains of cryptography, distributed algorithms, and domain-specific analytics. It typically entails (i) manually designing a distributed yet equivalent version of the original algorithm, (ii) developing a secure version of this algorithm by manually integrating cryptographic primitives while considering their capabilities and limitations, (iii) implementing the algorithm using low-level cryptographic libraries, and (iv) manually optimizing its performance. Each of these steps can affect a solution's runtime by several orders of magnitude, making the difference between practical and infeasible solutions [29] . Moreover, these steps typically must be considered jointly, requiring intricate manual optimizations and resulting in complex implementations whose security is difficult to verify, either manually or automatically, and challenging to maintain in the future. Here, we introduce Shechi, the first programming framework that automates the transformation of standard high-level Pythonic code into an efficient and secure MHE equivalent for execution on distributed datasets.
