3 ms·
FHE doesn't provide authentication of correctness (i.e. that the correct operation was performed) but you can verify its signature. You can still verify that it
by jacoblambda 5y ago
FHE doesn't provide authentication of correctness (i.e. that the correct operation was performed) but you can verify its signature. You can still verify that it's your data but you just can't verify what they've done with it.
With the use cases of FHE though that just is not a major downside. Instead if you rely on some consensus protocol you can get a reasonable guarantee of correctness. If a random N out of M available operators are selected and all produce the same result or hash of a result, you can be reasonably sure that the expected operation was performed.
Additionally, as the "master" who can actually read the FHE data, for most non-trivial tasks I suspect there is often a proof or heuristic you can use to reasonably judge whether the result is correct or at the very least reasonable which should stave off a significant portion of the avenues for attack.