Cryptology ePrint Archive: Report 2019/129

Homomorphic Secret Sharing from Lattices Without FHE

Elette Boyle and Lisa Kohl and Peter Scholl

Abstract: Homomorphic secret sharing (HSS) is an analog of somewhat- or fully homomorphic encryption (S/FHE) to the setting of secret sharing, with applications including succinct secure computation, private manipulation of remote databases, and more. While HSS can be viewed as a relaxation of S/FHE, the only constructions from lattice-based assumptions to date build atop specific forms of threshold or multi-key S/FHE. In this work, we present new techniques directly yielding efficient 2-party HSS for polynomial-size branching programs from a range of lattice-based encryption schemes, without S/FHE. More concretely, we avoid the costly key-switching and modulus-reduction steps used in S/FHE ciphertext multiplication, replacing them with a new distributed decryption procedure for performing "restricted" multiplications of an input with a partial computation value. Doing so requires new methods for handling the blowup of "noise'' in ciphertexts in a distributed setting, and leverages several properties of lattice-based encryption schemes together with new tricks in share conversion. The resulting schemes support a superpolynomial-size plaintext space and negligible correctness error, with share sizes comparable to SHE ciphertexts, but cost of homomorphic multiplication roughly one order of magnitude faster. Over certain rings, our HSS can further support some level of packed SIMD homomorphic operations. We demonstrate the practical efficiency of our schemes within two application settings, where we compare favorably with current best approaches: 2-server private database pattern-match queries, and secure 2-party computation of low-degree polynomials.

Category / Keywords: cryptographic protocols / homomorphic secret sharing, lattices

Original Publication (with major differences): IACR-EUROCRYPT-2019

Date: received 8 Feb 2019

Contact author: eboyle at alum mit edu, lisa kohl@kit edu, peter scholl@cs au dk

Available format(s): PDF | BibTeX Citation

Version: 20190213:172836 (All versions of this report)

Short URL: ia.cr/2019/129


[ Cryptology ePrint archive ]