Edit: Try Greg Egan's book Permutation City.
Today it's not practical, but we see advances like this every year, maybe in a decade it will be practical.
If one can spoof the canary payload effectively, one would have broken the FHE scheme, probabilistically, right?
Unless I'm thinking about this wrong, the FH part of FHE makes this a pretty solvable problem. Is this not already fundamental to any FHE scheme?
https://eprint.iacr.org/2014/202.pdf
You also have to be careful to ensure that the canary cannot be identified in the plaintext; otherwise the evaluator can homomorphically identify the canary (i.e. it can compute the canary values honestly and cheat everywhere else).
Enclaves have the downside of being a bit of a pain to use. But hell, FHE isn’t any easier.
With SGX you have to trust Intel to build CPUs that isolate securely. Meltdown, Spectre (multiple variants), bugs in Intel TXT and ME, and that's only some of the headline issues from the last 4 years.
That said you can still shave it down and start FIBing if you have the $$$.
But the encryption process is public right ? So you can encrypt just like any client ?
You are exactly describing Mimblewimble.
https://github.com/ignopeverell/grin/blob/master/doc/intro.m...
The idea is that you can prove that the encrypted input and output amounts in a transaction balance to zero, without having to actually reveal what any of those amounts are.
The real-world use case is being able upload data to a cloud provider and do queries and computation on it without the provider ever knowing what's inside. e.g. "How much did I spend last month?"