3 ms·
Also, by itself, homomorphic encryption doesn't protect against chosen-ciphertext attacks, which makes it very unattractive for 99.9% of real world crypto use-c
by CiPHPerCoder 8y ago
Also, by itself, homomorphic encryption doesn't protect against chosen-ciphertext attacks, which makes it very unattractive for 99.9% of real world crypto use-cases.
https://tonyarcieri.com/all-the-crypto-code-youve-ever-written-is-probably-broken https://tonyarcieri.com/all-the-crypto-code-youve-ever-writt...
In my experience, a lot of teams also reach for FHE to solve problems that are easily and securely solved without it (i.e. searchable encryption):
https://github.com/paragonie/ciphersweet https://github.com/paragonie/ciphersweet
That being said, there is the 0.01% problem space where FHE makes perfect sense (mostly in the realm of encrypted databases and machine learning). For those systems, if the database can ever be considered adversarial (your threat model may rule this out, most applications' do not), a simple construction involving HMAC, a secure digital signature algorithm, and an append-only ledger can protect the application that reads from the database against chosen-ciphertext attacks.
https://paragonie.com/blog/2017/12/assuring-ciphertext-integrity-for-homomorphic-cryptosystems https://paragonie.com/blog/2017/12/assuring-ciphertext-integ...
- Ar-Curunir 8y agoWhy does lack of CCA security make FHE unattractive? The entire point of FHE is to allow malleability of ciphertexts.
- CiPHPerCoder 8y agoCCAs have historically been useful for defeating the confidentiality guarantees of cryptography protocols. BB'98, Vaudenay '02, the iMessage attack, etc. Selling "encryption, but not IND-CCA3" to a lot of (clueful, at least) companies is almost impossible. If you read the linked article, it discusses a way to hack it in.