Do I have this right: A homomorphic encryption is a function
e :: P -> C
between groups (P, -) and (C, +), where P is the set of plaintext and C is the set of gibberish and -, + are the respective group operations in either space, such that e is a homomorphism in the group theoretic sense?Because if so, the following basic properties must hold:
e(id_P) === id_C
e(inv(p)) === inv(e(p))
Suppose you are a malicious cloud services provider and you are manipulating encrypted data. Couldn't you use these group properties to make much more informed observations about the encrypted data without ever having to decrypt it?A very simple example: as a malicious cloud services provider, if you see a bunch of gibberish strings x, y1, y2 ... yn, and it turns out that x + y1 == y1, x + y2 == y2, ... x + yn == yn, wouldn't you at least have a sneaking suspicion, that x is the identity element? And in the situation where you could potentially make very damaging (to the other party) decisions based on this information, it would seem to defeat the purpose of homomorphic encryption.
Moreover, recall that the cloud services provider is technically also allowed to run any additional set of calculations using the group operation on the data you give it, not just those you provided. It seems that, in general, even with very unstructured data you could use the properties of homomorphisms to de-anonymize data very easily.
How is this issue addressed?