Paper 2023/382

On Homomorphic Secret Sharing from Polynomial-Modulus LWE

Thomas Attema, Centrum Wiskunde & Informatica, Leiden University, Netherlands Organisation for Applied Scientific Research
Pedro Capitão, Centrum Wiskunde & Informatica, Leiden University
Lisa Kohl, Centrum Wiskunde & Informatica
Abstract

Homomorphic secret sharing (HSS) is a form of secret sharing that supports the local evaluation of functions on the shares, with applications to multi-server private information retrieval, secure computation, and more. Insisting on additive reconstruction, all known instantiations of HSS from "Learning with Error (LWE)"-type assumptions either have to rely on LWE with superpolynomial modulus, come with non-negligible error probability, and/or have to perform expensive ciphertext multiplications, resulting in bad concrete efficiency. In this work, we present a new 2-party local share conversion procedure, which allows to locally convert noise encoded shares to non-noise plaintext shares such that the parties can detect whenever a (potential) error occurs and in that case resort to an alternative conversion procedure. Building on this technique, we present the first HSS for branching programs from (Ring-)LWE with polynomial input share size which can make use of the efficient multiplication procedure of Boyle et al.~(Eurocrypt 2019) and has no correctness error. Our construction comes at the cost of a -- on expectation -- slightly increased output share size (which is insignificant compared to the input share size) and a more involved reconstruction procedure. More concretely, we show that in the setting of 2-server private counting queries we can choose ciphertext sizes of only a quarter of the size of the scheme of Boyle et al. at essentially no extra cost.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in PKC 2023
Keywords
homomorphic secret sharinglattices
Contact author(s)
thomas attema @ tno nl
pedro @ cwi nl
lisa kohl @ cwi nl
History
2023-03-24: approved
2023-03-16: received
See all versions
Short URL
https://ia.cr/2023/382
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2023/382,
      author = {Thomas Attema and Pedro Capitão and Lisa Kohl},
      title = {On Homomorphic Secret Sharing from Polynomial-Modulus {LWE}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2023/382},
      year = {2023},
      url = {https://eprint.iacr.org/2023/382}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.