Voltiamo pagina.
Il prossimo capitolo sta arrivando…
Psst… leggi a modo tuo.
Caratteri e temi sono in Aspetto. Anche i tuoi occhi possono scegliere.
Il prossimo capitolo sta arrivando…
Encryption that permits supported computations on ciphertexts, so an authorized party can decrypt the resulting answer without revealing the original inputs to the evaluator.
Verifica della lettura vocale del browser…
Questa lettura è attualmente disponibile in inglese. L’interfaccia usa la lingua selezionata.
Leggi l’originale inglese →Gentry's 2009 dissertation investigates whether arbitrary computations can be performed on encrypted data without giving the evaluator the decryption key. The construction moves from a scheme supporting limited computation to one that can refresh ciphertexts through bootstrapping. At a high level, the system evaluates a decryption-related circuit on encrypted key material to reduce accumulated noise and allow further computation.
Read this as an existence and construction result with stated assumptions. It does not claim that every program runs efficiently or that its original implementation is appropriate for modern deployment. Track which operations the scheme supports, what bounds their depth and what additional assumptions enter the bootstrapping step. The ability to compute without seeing inputs is a distinct guarantee from proving that the evaluator chose the correct computation.
The 2021 arXiv white paper by Gorantala and colleagues asks how developers can express encrypted computation without manually constructing every low-level operation. It describes a transpiler using Google's XLS infrastructure and the TFHE library to transform high-level programs into computations over encrypted data. Its modular design is intended to support alternative backends and facilitate comparisons.
The appropriate reading questions concern supported language features, data representations and the cost of the generated circuit. A program that is short in source code may contain expensive comparisons, loops or memory accesses after transformation. The paper is a research white paper; its existence is not evidence that an arbitrary application can be converted without redesign. Inspect the examples and constraints before extrapolating from a demonstration to a production workload.
Imagine a fictional scholarship service evaluating whether an encrypted age and income satisfy a published rule. The evaluator might learn neither input yet return an encrypted yes-or-no result to the applicant. This is a teaching example, not a claim about a deployed service. It exposes several design questions: who holds the key, who selects the rule, who receives the answer, and how the applicant knows the intended program was used.
Now permit a dishonest evaluator to issue thousands of slightly different threshold queries and receive their decrypted answers. Those outputs could reveal far more than the original single decision. Encryption of inputs does not settle the policy for releasing outputs. Likewise, an applicant could encrypt invented income unless another process attests to the input. Confidential computation, correct computation and truthful input are three separate requirements.
The Homomorphic Encryption Security Standard provides scheme descriptions, security discussion and parameter recommendations. Its consortium provenance matters: it is a community technical standard, not a blanket government approval of every product using the phrase FHE. Parameter choices connect security estimates to ciphertext sizes and computational cost, so benchmark comparisons need matching assumptions.
For a careful evaluation, record the scheme, parameter set, precision, circuit depth, key sizes, hardware and whether reported timing includes encryption, transfer and decryption. Compare the same workload rather than headline operations per second. In a blockchain application, also identify who can decrypt shared state and whether that role uses one key or a threshold system. Encryption does not automatically distribute authority, make data permanently available, or prevent a contract from leaking information through its public outputs.