Paper 2026/957
Threshold FHE with Short Decryption Shares without a Semi-trusted Server
Abstract
Threshold fully homomorphic encryption (ThFHE) enables decryption by collecting decryption shares from any T-out-of-N parties. A major drawback of previous ThFHE schemes is that they require a super-polynomial modulus (or are subject to other limitations), resulting in long ciphertexts, keys, and decryption shares. Passel`egue and Stehl´e (Asiacrypt 2024) proposed a ThFHE scheme in which a semi-trusted server rounds the input ciphertexts to produce polynomially short ciphertexts and sends them to the parties, thereby making the rest of the decryption process efficient. Although the input ciphertexts are still super-polynomially large, the communication cost of sending them from the parties to the server can be reduced to polynomial size via the transciphering technique; as a result, an entirely low-communication ThFHE is achieved. However, if even a single party colludes with the server (contrary to the assumption), the secret key can be efficiently recovered. Such a risky scenario would be unsuitable for practical deployment. In this paper, we tackle this issue. We propose two serverless ThFHE schemes with polynomially short decryption shares. The core idea is to let the parties directly round the decryption shares, rather than rely on the semi-trusted server to round the ciphertexts. We can also achieve low-communication ThFHE by reducing the communication required to send input ciphertexts to the parties to polynomial size via transciphering. Our first scheme, based on binary coefficient linear secret sharing ({0,1}-LSS), strictly improves upon Boneh et al. (CRYPTO 2018), achieving short decryption shares without any trade-offs. Our second scheme, based on Shamir secret sharing, adapts the technique of Okada and Takagi (Asiacrypt 2025) to eliminate the $O(N^{4.3})$ overhead in share size of our first scheme, further reducing communication costs.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Major revision. ACISP 2026
- DOI
- 10.1007/978-981-92-3015-0_8
- Keywords
- LatticeFHEThreshold Cryptography
- Contact author(s)
- ir-okada @ kddi com
- History
- 2026-07-29: revised
- 2026-05-14: received
- See all versions
- Short URL
- https://ia.cr/2026/957
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/957,
author = {Hiroki Okada and Tsuyoshi Takagi},
title = {Threshold {FHE} with Short Decryption Shares without a Semi-trusted Server},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/957},
year = {2026},
doi = {10.1007/978-981-92-3015-0_8},
url = {https://eprint.iacr.org/2026/957}
}