TY - GEN
T1 - Minimize the Randomness in Rasta-Like Designs: How Far Can We Go?
T2 - Application to Pasta
AU - Grassi, Lorenzo
AU - Liu, Fukang
AU - Rechberger, Christian
AU - Schmid, Fabian
AU - Walch, Roman
AU - Wang, Qingju
PY - 2025/3/13
Y1 - 2025/3/13
N2 - The Rasta design strategy allows building low-round ciphers due to its efficient prevention of statistical attacks and algebraic attacks by randomizing the cipher, which makes it especially suitable for hybrid homomorphic encryption (HHE), also known as transciphering. Such randomization is obtained by pseudorandomly sampling new invertible matrices for each round of each new cipher evaluation. However, naively sampling a random invertible matrix for each round significantly impacts the plain evaluation runtime, though it does not impact the homomorphic evaluation cost. To address this issue, Dasta was proposed at ToSC 2020 to reduce the cost of generating the random matrices. In this work, we address this problem from a different perspective: How far can the randomness in Rasta-like designs be reduced in order to minimize the plain evaluation runtime without sacrificing the security? To answer this question, we carefully studied the main threats to Rasta-like ciphers and the role of random matrices in ensuring security. We apply our results to the recently proposed cipher Pasta, proposing a modified version called PASTA
v2 instantiated with one initial random matrix and fixed linear layers – obtained by combining two MDS matrices with the Kronecker product – for the other rounds. Compared with Pasta, the state-of-the-art cipher for BGV- and BFV-style HHE, our evaluation shows that PASTA
v2 is up to 100 % faster in plain while having the same homomorphic runtime in the SEAL homomorphic encryption library and up to 30 % faster evaluation time in HElib, respectively.
AB - The Rasta design strategy allows building low-round ciphers due to its efficient prevention of statistical attacks and algebraic attacks by randomizing the cipher, which makes it especially suitable for hybrid homomorphic encryption (HHE), also known as transciphering. Such randomization is obtained by pseudorandomly sampling new invertible matrices for each round of each new cipher evaluation. However, naively sampling a random invertible matrix for each round significantly impacts the plain evaluation runtime, though it does not impact the homomorphic evaluation cost. To address this issue, Dasta was proposed at ToSC 2020 to reduce the cost of generating the random matrices. In this work, we address this problem from a different perspective: How far can the randomness in Rasta-like designs be reduced in order to minimize the plain evaluation runtime without sacrificing the security? To answer this question, we carefully studied the main threats to Rasta-like ciphers and the role of random matrices in ensuring security. We apply our results to the recently proposed cipher Pasta, proposing a modified version called PASTA
v2 instantiated with one initial random matrix and fixed linear layers – obtained by combining two MDS matrices with the Kronecker product – for the other rounds. Compared with Pasta, the state-of-the-art cipher for BGV- and BFV-style HHE, our evaluation shows that PASTA
v2 is up to 100 % faster in plain while having the same homomorphic runtime in the SEAL homomorphic encryption library and up to 30 % faster evaluation time in HElib, respectively.
KW - HHE
KW - Interweaving matrix
KW - PASTA 2
KW - Pasta
KW - Rasta
UR - https://www.scopus.com/pages/publications/105001269623
U2 - 10.1007/978-3-031-82841-6_9
DO - 10.1007/978-3-031-82841-6_9
M3 - Conference contribution
SN - 978-3-031-82840-9
T3 - Lecture Notes in Computer Science (LNCS)
SP - 207
EP - 238
BT - Selected Areas in Cryptography – SAC 2024 - 31st International Conference, 2024, Revised Selected Papers
A2 - Eichlseder, Maria
A2 - Gambs, Sébastien
PB - Springer
CY - Cham
ER -