Circular Security

Whether an encryption scheme stays secure when an encryption of its own secret key – or a cycle of keys encrypting each other – is published. The assumption every bootstrapping-based homomorphic scheme rests on, and the subject of a long line of counterexamples.

Status Statement Tags
Two-scheme key cycle
Open in both directions, and the source paper says why the existing separations miss it: the counterexamples fix both schemes, whereas here the second is chosen after the first. Two hypotheses left implicit in the printed statement have to be added before it is even non-vacuous. 7 open
Circular SecurityFully Homomorphic Encryptionassumption
Composability implies circular security
Open with no partial result in either direction. The converse – circular security plus limited homomorphism gives full composability – is the source paper’s Theorem 6; this direction, which would make the two properties essentially equivalent, is conjectured there and nothing has been published towards it. 7 open
Circular SecurityFully Homomorphic Encryptionequivalence
No matching items