Researchers can steal data during homomorphic encryption
news.ncsu.edu
news.ncsu.edu
“We weren’t able to crack homomorphic encryption using mathematical tools,” says Aydin Aysu, senior author of a paper on the work and an assistant professor of computer engineering at North Carolina State University. “Instead, we used side-channel attacks. Basically, by monitoring power consumption in a device that is encoding data for homomorphic encryption, we are able to read the data as it is being encrypted. This demonstrates that even next generation encryption technologies need protection against side-channel attacks.”
Homomorphic encryption is really about the utility when it leaves the device, not at the encryption stage.
There's no reason rowhammer should be able to break homomorphic encryption. Homomorphic encryption means at no point is the data on the machine unencrypted, so there is nothing to leak from RAM.
>Homomorphic encryption is really about the utility when it leaves the device, not at the encryption stage.
???
This make no sense. Homomorphic encryption is used for a device to do computations on encrypted data without the device knowing what the encrypted data is.
For example, computing the square of an integer that is homorphically encrypted would not tell the device doing the computation what the original number is or what the square is. Encrypted data comes in, stays encrypted at all times, an algorithm does some operations on the encrypted data, and encrypted data is then sent out.
This paper and attack are not about the encryption stage. The attack is on the operating on homomorphic data.
What NC State achieved is cool, but it seems a bit like saying "Homomorphic encryption is broken when you can blackmail the sysadmin."
I’m off to read this paper S I don’t understand how they are using a side channel to extract information that the operating device theoretically shouldn’t have. If there’s a measurable power usage difference over the operations that implies that the encrypted bits do leak information about what is encrypted.
This attack is on machine A, not machine B. The "leak" happens as the data is being encrypted. They're sidechanneling a machine that has the plaintext on it.
>Our proposed attack targets the Gaussian sampling in the SEAL’s encryption phase
It's literally about stealing the data from the encryptor, which is usually a trusted machine.
The idea of 'homomorphic encryption' was even introduced by another Rivest and Adleman paper, almost immediately after the famous 1977 RSA algorithm ("On Data Banks and Privacy Homomorphisms" by Rivest, Adleman, and Dertouzos 1978).
If they become relevant, then your attacker is really quite close to the device. In most scenarios, once the attacker is that close you are probably fucked anyway. There are exceptions of-course. Using in-memory encryption, ingress detection, etc you might be able to remain safe in these cases. Moreover an attacker might be able to do power-analysis without leaving a trace. Whereas pulling out the RAM-sticks after freezing them leaves more of a mark.
However, few of the scenarios involving good reason to use homomorphic encryption really stand up to an attacker having physical access to the encrypting device. Most of these scenarios are about secure shared computation. Where the threat model revolves around 'what if my computational partner is evil', not 'what if Ethan Hunt breaks in'. Generally, if someone has access to the machine, they will have access to the raw data anyway.
The fact that a library implementing a cutting edge method has not matured this much yet is not really a surprise.
Moreover, the fun parts of homomorphic encryption involve sending it to someone else who can process it. That someone else is probably not going to be able to measure your power draw. Though timing attacks can still be a worry.