arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.28700cs.CR

弥合PHE与FHE之间的差距:半同态BGN密码系统的性能与权衡分析

Bridging the Gap Between PHE and FHE: A Performance and Trade-off Analysis of The Somewhat Homomorphic BGN Cryptosystem

Sefik Serengil, Alper Ozpinar

首次发表
浏览论文内容

中文总结 AI 辅助

本文将半同态BGN密码系统集成到lightphe框架,对比PHE与FHE开展基准测试,揭示其计算与通信的权衡特性,确立其为带宽受限去中心化架构的实用隐私保护加密引擎。

中文摘要 AI 辅助

同态加密(HE)支持隐私保护数据分析,但从业者常需在轻量级部分同态加密(PHE)与计算开销较大的全同态加密(FHE)间做权衡。Boneh-Goh-Nissim(BGN)密码系统作为半同态加密(SWHE)方案可弥合这一差距,支持无限次加法和一次密文乘法。尽管其代数结构简洁,BGN的实际应用因缺乏易用软件实现而受阻。本文通过将BGN集成到lightphe Python框架,对其与PHE和FHE范式开展对比分析,仅需几行代码即可部署。我们在80位、112位和128位安全等级下,针对Paillier、Damgard-Jurik、Okamoto-Uchiyama等PHE方案,以及基于TenSEAL的FHE CKKS方案,对加密128维向量运算进行基准测试。结果显示存在计算-通信权衡:BGN因双线性配对,计算速度慢于PHE和SIMD优化的FHE,但公钥尺寸仅3-6 KB,比FHE小五个数量级。关键在于,BGN在一次乘法后可支持无限同态聚合,能实现线性回归推理、余弦相似度、平方欧氏距离等复杂任务。此外,2位优化精度即可匹配明文排名基线,克服目标群离散对数解密瓶颈。通过在lightphe中开源该流程,本研究确立BGN为带宽受限、去中心化架构的实用引擎。

英文摘要

Homomorphic encryption (HE) enables privacy-preserving data analytics, but practitioners often face a trade-off between lightweight Partially Homomorphic Encryption (PHE) and computationally dominant Fully Homomorphic Encryption (FHE). The Boneh-Goh-Nissim (BGN) cryptosystem bridges this gap as a Somewhat Homomorphic Encryption (SWHE) scheme supporting unlimited additions and one ciphertext multiplication. Despite its algebraic elegance, practical BGN adoption has been hindered by a lack of accessible software implementations. This paper presents a comparative analysis of BGN against PHE and FHE paradigms through its integration into the lightphe Python framework, allowing deployment in just a few lines of code. We benchmark encrypted 128-dimensional vector operations under 80-bit, 112-bit and 128-bit security levels against Paillier, Damgard-Jurik, Okamoto-Uchiyama, and the FHE CKKS scheme via TenSEAL. Results reveal a computation-communication trade-off: BGN is computationally slower due to bilinear pairings compared to PHE and SIMD-optimized FHE, but retains a microscopic public key size of 3-6 KB, up to five orders of magnitude smaller than FHE. Crucially, BGN enables boundless homomorphic aggregation after a single multiplication, supporting complex tasks such as linear regression inference, Cosine Similarity, and Squared Euclidean Distance. Furthermore, an optimized precision of 2 digits suffices to match plaintext ranking baselines, overcoming the target-group discrete logarithm decryption bottleneck. By open-sourcing this pipeline in lightphe, this work establishes BGN as a practical engine for bandwidth-constrained, decentralized architectures.

↑