Paper 2014/535

On Key Recovery Attacks against Existing Somewhat Homomorphic Encryption Schemes

Massimo Chenal and Qiang Tang

Abstract

In his seminal paper at STOC 2009, Gentry left it as a future work to investigate (somewhat) homomorphic encryption schemes with IND-CCA1 security. At SAC 2011, Loftus et al. showed an IND-CCA1 attack against the somewhat homomorphic encryption scheme presented by Gentry and Halevi at Eurocrypt 2011. At ISPEC 2012, Zhang, Plantard and Susilo showed an IND-CCA1 attack against the somewhat homomorphic encryption scheme developed by van Dijk et al. at Eurocrypt 2010. In this paper, we continue this line of research and show that most existing somewhat homomorphic encryption schemes are not IND-CCA1 secure. In fact, we show that these schemes suffer from key recovery attacks (stronger than a typical IND-CCA1 attack), which allow an adversary to recover the private keys through a number of decryption oracle queries. The schemes, that we study in detail, include those by Brakerski and Vaikuntanathan at Crypto 2011 and FOCS 2011, and that by Gentry, Sahai and Waters at Crypto 2013. We also develop a key recovery attack that applies to the somewhat homomorphic encryption scheme by van Dijk et al., and our attack is more efficient and conceptually simpler than the one developed by Zhang et al.. Our key recovery attacks also apply to the scheme by Brakerski, Gentry and Vaikuntanathan at ITCS 2012, and we also describe a key recovery attack for the scheme developed by Brakerski at Crypto 2012.

Metadata
Available format(s)
PDF
Publication info
Published elsewhere. Major revision. LATINCRYPT 2014
Keywords
Somewhat Homomorphic EncryptionKey Recovery AttackIND-CCA1 Security.
Contact author(s)
massimo chenal @ uni lu
History
2014-09-29: last of 2 revisions
2014-07-09: received
See all versions
Short URL
https://ia.cr/2014/535
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2014/535,
      author = {Massimo Chenal and Qiang Tang},
      title = {On Key Recovery Attacks against Existing Somewhat Homomorphic Encryption Schemes},
      howpublished = {Cryptology {ePrint} Archive, Paper 2014/535},
      year = {2014},
      url = {https://eprint.iacr.org/2014/535}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.