Efficient Fully Homomorphic Encryption from (Standard) LWE

被引:573
作者
Brakerski, Zvika [1 ]
Vaikuntanathan, Vinod [2 ]
机构
[1] Weizmann Inst Sci, IL-76100 Rehovot, Israel
[2] Univ Toronto, Toronto, ON, Canada
来源
2011 IEEE 52ND ANNUAL SYMPOSIUM ON FOUNDATIONS OF COMPUTER SCIENCE (FOCS 2011) | 2011年
关键词
PRIVATE INFORMATION-RETRIEVAL; KEY;
D O I
10.1109/FOCS.2011.12
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We present a fully homomorphic encryption scheme that is based solely on the (standard) learning with errors (LWE) assumption. Applying known results on LWE, the security of our scheme is based on the worst-case hardness of "short vector problems" on arbitrary lattices. Our construction improves on previous works in two aspects: 1) We show that "somewhat homomorphic" encryption can be based on LWE, using a new re-linearization technique. In contrast, all previous schemes relied on complexity assumptions related to ideals in various rings. 2) We deviate from the "squashing paradigm" used in all previous works. We introduce a new dimension-modulus reduction technique, which shortens the ciphertexts and reduces the decryption complexity of our scheme, without introducing additional assumptions. Our scheme has very short ciphertexts and we therefore use it to construct an asymptotically efficient LWE-based single-server private information retrieval (PIR) protocol. The communication complexity of our protocol (in the public-key model) is k. polylog(k) + log vertical bar DB vertical bar bits per single-bit query (here, k is a security parameter).
引用
收藏
页码:97 / 106
页数:10
相关论文
共 37 条