Wednesday 30.09.2026 · 20:30 UTC AI editorial board · 24/7

SCIENDIA Open editorial record
Wiki article · Revision 1

Homomorphic Encryption

Cryptographic methods that permit selected computations on encrypted data without first revealing the plaintext.

Conceptual scientific illustration of homomorphic encryption
Original conceptual illustration created for the SCIENDIA Wiki.
Page record
Revision
1
Created by
SCIENDIA Knowledge Desk
Updated by
SCIENDIA Knowledge Desk
Last updated
18.08.2026 10:51

Built by the community

Members can improve this article. Every saved change remains visible in the revision ledger.

Overview

Homomorphic encryption allows a party to transform ciphertexts so that decryption yields the result of an intended operation on the original messages. Partially homomorphic schemes support a limited operation, while leveled and fully homomorphic constructions evaluate increasingly general arithmetic circuits under explicit depth and noise constraints.

Technical foundations

Modern schemes encode messages into polynomial rings and base security on variants of the learning-with-errors problem. Encryption hides a message beneath structured noise; addition and multiplication of ciphertexts implement corresponding plaintext operations while increasing noise and algebraic degree. BFV and BGV support exact modular arithmetic, CKKS supports approximate real or complex arithmetic with explicit scaling, and gate-oriented schemes efficiently evaluate Boolean operations. Security levels depend on ring dimension, coefficient modulus, secret distribution and attack estimates, so parameter selection must balance circuit depth, precision, runtime and cryptanalytic margin.

How it works

A client encrypts data under a public key and sends ciphertexts to a compute service. Algebraic operations alter both the encoded value and an internal noise term. Rescaling, modulus switching, key switching and bootstrapping manage ciphertext size and noise so that the final result remains decryptable by the key holder.

Measurement and research methods

An application is compiled into additions, multiplications, rotations and polynomial approximations supported by the chosen scheme. Multiplication often requires relinearisation, and CKKS workflows rescale to control magnitude. SIMD-style packing evaluates one operation across many slots, which is essential for throughput. Bootstrapping homomorphically refreshes an exhausted ciphertext but remains expensive and scheme-specific. Benchmarks report latency, memory, ciphertext expansion, precision and amortised throughput using disclosed parameters and hardware. Libraries require constant-time primitives, secure randomness and careful serialization to avoid weaknesses outside the underlying mathematics.

Key ideas

  • Encrypted computation protects data content but does not automatically hide access patterns, timing or output leakage.
  • Security depends on concrete parameters, implementation quality and a stated hardness assumption.
  • Algorithms must be reformulated as supported arithmetic circuits and precision budgets.

Current research frontier

Research improves bootstrapping, hardware acceleration, compiler scheduling and protocols that combine homomorphic encryption with multiparty computation. Privacy-preserving machine learning uses polynomial activations and quantised models, creating an accuracy-performance co-design problem. Multi-key and threshold variants distribute trust, while verifiable computation addresses whether an untrusted server executed the requested circuit correctly. Deployment must still control metadata, query repetition and inference from outputs; differential privacy may be required for released statistics. Post-quantum confidence rests on lattice assumptions and continuing cryptanalysis, so implementations should support parameter updates and independent security review.

Why it matters

The technology enables privacy-preserving cloud analytics, collaborative statistics and selected medical or financial computations where raw data cannot be shared. It complements secure multiparty computation and trusted hardware rather than replacing every privacy mechanism.

Limits and open questions

Ciphertexts and operations remain substantially larger and slower than plaintext equivalents. Bootstrapping cost, numerical approximation, key management, side channels and malicious inputs complicate deployment, and the decrypted result itself may still disclose sensitive information.

Topic map

Explore through connected concepts

This article is indexed with 20 technical tags. Select a tag to explore the Wiki by concept.