3 ms·
All modern FHE is lattice based, so pretty strong if you chose the right parameters. But of course if you dont chose secure parameters.. well, it wont be secure
by rhindi 6y ago
All modern FHE is lattice based, so pretty strong if you chose the right parameters. But of course if you dont chose secure parameters.. well, it wont be secure :)
There are tools to measure the security level of FHE schemes: https://bitbucket.org/malb/lwe-estimator/ https://bitbucket.org/malb/lwe-estimator/
- speedgoose 6y agoI guess only experts should chose the parameters.
- rhindi 6y agoYou have formulas to calculate the security level given a threat model, so the compiler could in theory do it automatically. Just specify that you wants 128 bits of security or whatever, and it will do the rest.
- ssmiler 6y agoCingulata automatically chooses secure parameters using https://github.com/CEA-LIST/CinguParam https://github.com/CEA-LIST/CinguParam module. It's a separate project because our intention is to provide an easier/faster way to chose HE parameters than lwe-estimator. You need to provide only the multiplicative depth (or the circuit describing the computation for example) and CinguParam will automatically generate the code snippet/parameter file for the HE scheme you want. Also as CinguParam contains a database of HE parameters the actual parameter generation is really faster than using lwe-estimator. There is a lot of work to be done on this project in order to automatize parameter database update, generate HE parameters more precisely using circuit representation instead of multiplicative depth, take into account HE libraries implementation details (RNS, NTT), etc.
- bawolff 6y agoFHE encryption is bleeding edge crypto. You probably shouldn't use it in real systems with hard security requirements at all without input from experts.