错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

On the Practical \(\text {CPA}^{D}\) Security of “exact” and Threshold FHE Schemes and Libraries

  • Marina Checri,
  • Renaud Sirdey,
  • Aymen Boudguiga,
  • Jean-Paul Bultel

摘要

In their Eurocrypt’21 seminal paper, Li and Micciancio presented a passive attack against the CKKS approximate FHE scheme and introduced the notion of \(\text {CPA}^{D}\) security. The current status quo is that this line of attacks does not apply to “exact” FHE. In this paper, we challenge this status quo by exhibiting a \(\text {CPA}^{D}\) key recovery attack on the linearly homomorphic Regev cryptosystem, which easily generalizes to other xHE schemes such as BFV, BGV and TFHE, showing that these cryptosystems are not \(\text {CPA}^{D}\) secure in their basic form. We also show that existing threshold variants of BFV, BGV and CKKS are particularly exposed to \(\text {CPA}^{D}\) attackers and would be \(\text {CPA}^{D}\) -insecure without proper smudging noise addition after partial decryption. Finally, we successfully implement our attack against several mainstream FHE libraries and discuss a number of natural countermeasures as well as their consequences in terms of FHE practice, security and efficiency. The attack itself is quite practical as it typically takes less than an hour on an average laptop PC, requiring a few thousand ciphertexts as well as up to around a million evaluations/decryptions, to perform a full key recovery.