发表机构
School of Science and Engineering, Lahore University of Management Sciences(拉合尔管理科学大学科学与工程学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
Zeppelin是首个在微控制器上利用向量指令集实现BFV加密与解密的库,通过向量化NTT和防泄漏解密,在STM32N6上实现快速加密解密,并兼容SEAL服务器端计算。
AI 中文摘要
物联网(IoT)的发展引发了对资源受限传感设备所收集数据隐私的担忧。同态加密(HE)通过让设备一次性加密其数据,并允许不受信任的云服务器在不查看数值的情况下对密文进行计算,从而解决了这一问题。然而在实践中,HE的内存和计算开销使其难以应用于微控制器类设备。先前的工作SEAL-Embedded利用CKKS方案使这一目标变得可行,但遗留了三个缺口:其算术运算完全采用标量方式,即使在具有向量指令集的硬件上也是如此;它从不在设备端进行解密,因此客户端无法消费结果;并且它未探索BFV方案,而BFV的编码仅使用整数算术且解密精确。我们提出了Zeppelin,这是第一个使用嵌入式向量指令集的HE库,第一个在嵌入式设备上同时支持加密和解密的库,以及第一个在MCU级硬件上实现的BFV方案。Zeppelin针对ARM的Helium扩展对数论变换(HE的主要瓶颈)进行了向量化,并包含了一个避免大整数算术和秘密密钥时序泄漏的解密过程。一个服务器端适配器将Zeppelin的密文转换为与Microsoft SEAL兼容的格式,因此设备负责加密和解密,而服务器执行所有同态计算。在带有ARM Cortex-M55的STM32N6 MCU上,Zeppelin在4.76毫秒内编码并加密4096个打包值(种子对称,128位安全性符合HE标准),并在5.38毫秒内解密和解码结果,使用不到500 KB的RAM,向量化NTT引擎比同一核心上的等效标量实现快约2.7倍。
英文摘要
The growth of the Internet of Things (IoT) has raised concerns over the privacy of data collected by resource-constrained sensing devices. Homomorphic encryption (HE) addresses this by letting a device encrypt its data once and an untrusted cloud server compute on the ciphertext without seeing the values. In practice, HE's memory and computational cost have kept it out of reach of microcontroller-class devices. Prior work, SEAL-Embedded, made this feasible using CKKS, but left three gaps: its arithmetic is entirely scalar, even on hardware with a vector instruction set; it never decrypts on the device, so the client cannot consume a result; and it does not explore BFV, whose encoding uses only integer arithmetic and decrypts exactly. We present Zeppelin, the first HE library to use an embedded vector instruction set, the first to support both encryption and decryption on an embedded device, and the first BFV implementation on MCU-class hardware. Zeppelin vectorizes the number-theoretic transform, HE's main bottleneck, for ARM's Helium extension, and includes a decryption procedure that avoids large-integer arithmetic and timing leakage of the secret key. A server-side adapter converts Zeppelin's ciphertexts into a format compatible with Microsoft SEAL, so the device handles encryption and decryption while the server performs all homomorphic computation. On an STM32N6 MCU with an ARM Cortex-M55, Zeppelin encodes and encrypts 4096 packed values in 4.76 ms (seeded symmetric, 128-bit security per the HE standard) and decrypts and decodes the result in 5.38 ms, using under 500 KB of RAM, with the vectorized NTT engine ${\sim}2.7\times$ faster than an equivalent scalar implementation on the same core.