Fully Homomorphic Encryption (FHE) permits the evaluation of an arbitrary function on encrypted data. However, FHE ciphertexts, particularly those based on lattice assumptions such as LWE/RLWE are very large compared to the underlying plaintext. Large ciphertexts are hard to communicate over the network and this is an obstacle to the adoption of FHE, particularly for clients with limited bandwidth. In this work, we propose the first technique to compress ciphertexts sent from the server to the client using an additive encryption scheme with smaller ciphertexts. Using the additive scheme, the client sends auxiliary information to the server which is used to compress the ciphertext. Our evaluation shows up to 95% percent and 97% compression for LWE and RLWE ciphertexts, respectively.
翻译:完全同态加密 (FHE) 允许在加密数据上评估任意函数。然而,基于格假设(如 LWE/RLWE)的 FHE 密文与底层明文相比非常大。较大的密文难以通过网络进行通信,这是采用 FHE 的障碍,特别是对于带宽有限的客户端。在这项工作中,我们提出了首个使用具有较小密文的加性加密方案压缩从服务器发送到客户端的密文的技术。使用加性方案,客户端向服务器发送辅助信息,用于压缩密文。我们的评估显示,对于 LWE 和 RLWE 密文,分别达到 95% 和 97% 的压缩率。