If you need to trust the encryption and trust the hardware itself, it may not be suitable for your environment/ threat model.
If you need to trust the encryption and trust the hardware itself, it may not be suitable for your environment/ threat model.
The textbook example application of FHE is phone book search. The server "multiply" the whole phonebook database file with your encrypted query, and sends back the whole database file to you every time regardless of queries. When you decrypt the file with the key used to encrypt the query, the database is all corrupt and garbled except for the rows matching the query, thereby causing the search to have practically occurred. The only information that exists in the clear are query and the size of entire database.
Sounds fantastically energy-efficient, no? That's the problem with FHE, not risks of backdooring.
So here's my question: Could FHE hardware be used to extremely quickly and reliably secure something like a database connection?
I looked through Gemini, and it says the following:
"Zama are building libraries that use FHE accelerators to allow "Confidential Smart Contracts" or private AI queries. You could send a highly sensitive health query to an AI, and the AI hardware would process it and send the answer back without the AI company ever knowing what you asked."
Which is why I ask. Because if you have a backdoor into the hardware, as either a corporation or a government, then you can get access to those "very sensitive and fully secured communications".
They also discuss a crypto / smart contracts use case, and advertise " securing L1 or L2".
First you encrypt the data. Then you send it to hardware to compute, get result back and decrypt it.
Are we reading the same article? It's talking about homorphic encryption, ie. doing mathematical operations on already encrypted data, without being aware of its cleartext contents. It's not related to SGX or other trusted computing technologies.
"We believe that just like the internet went from zero encryption with HTTP to encrypting data in transit with HTTPS, the next natural step will be to use FHE to enable end-to-end encryption by default in every application, something we call HTTPZ"
That's my point, this sounds like a way to create a backdoor for at-rest data.
I encrypt some data and keep the key. I send the encrypted data to you (probably some cloud provider). I tell you to do some operations on the data. I don't tell you the key or what the data is or what the operations mean. You send the results back to me. I use the key to decrypt them.
You have helped me with my compute task, but the data you have is totally meaningless without the key, and only I have the key.
It's hard to believe that it's possible to make encryption where this can do useful work, but it is.
I get the feeling honestly it seems more expensive and more effort to backdoor it..