{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T06:31:20Z","timestamp":1784874680775,"version":"3.55.0"},"reference-count":23,"publisher":"International Association for Cryptologic Research","issue":"1","license":[{"start":{"date-parts":[[2025,1,10]],"date-time":"2025-01-10T00:00:00Z","timestamp":1736467200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,3,11]]},"abstract":"<jats:p>In a recent Eurocrypt'24 paper, Manulis and Nguyen have proposed a new CCA security notion, vCCA, and associated construction blueprints to leverage both CPA-secure and correct FHE beyond the CCA1 security barrier. However, because their approach is only valid under the correctness assumption, it leaves a large part of the FHE spectrum uncovered, as many FHE schemes used in practice turn out to be approximate and, as such, do not satisfy the correctness assumption. In this paper, we improve their work by defining and investigating a variant of their security notion which is suitable for a more general case where approximate FHE are included. As the passive security of approximate FHE schemes is more appropriately captured by CPAD rather than CPA security, we start from the former notion to define our vCCAD new security notion. Although we show that vCCA and vCCAD are equivalent when the correctness assumption holds, we establish that vCCAD security is strictly stronger than vCCA security in the general case. In doing so, we interestingly establish several new separation results between variants of CPAD security of increasing strength. This allows us to clarify the relationship between vCCA security and CPAD security, and to reveal that the security notions landscape is much simpler for correct FHE than when approximate ones are included \u2014 in which case, for example, we establish that multiple challenges security notions are strictly stronger than single-challenge ones for both CPAD and vCCAD security. Lastly, we also give concrete construction blueprints, showing how to leverage some of the blueprints proposed by Manulis and Nguyen to achieve vCCAD security. As a result, vCCAD security is the strongest CCA security notion known so far to be achievable by both correct and approximate FHE schemes. <\/jats:p>","DOI":"10.62056\/aee0iv7sf","type":"journal-article","created":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T21:23:17Z","timestamp":1744147397000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":6,"title":["Relations Among New CCA Security Notions for Approximate FHE"],"prefix":"10.62056","volume":"2","author":[{"given":"Chris","family":"Brzuska","sequence":"first","affiliation":[{"name":"Aalto University","place":["Espoo, Finland"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"S\u00e9bastien","family":"Canard","sequence":"additional","affiliation":[{"name":"T\u00e9l\u00e9com Paris, Institut Polytechnique de Paris","place":["Palaiseau, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Caroline","family":"Fontaine","sequence":"additional","affiliation":[{"name":"Universit\u00e9 Paris-Saclay, CNRS, ENS Paris-Saclay, Laboratoire M\u00e9thodes Formelles","place":["Gif-sur-Yvette, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Duong","family":"Phan","sequence":"additional","affiliation":[{"name":"T\u00e9l\u00e9com Paris, Institut Polytechnique de Paris","place":["Palaiseau, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Pointcheval","sequence":"additional","affiliation":[{"name":"DIENS, Ecole normale sup\u00e9rieure, CNRS, Inria, PSL University","place":["Paris, France"]},{"name":"Cosmian","place":["Paris, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marc","family":"Renard","sequence":"additional","affiliation":[{"name":"Universit\u00e9 Paris-Saclay, CNRS, ENS Paris-Saclay, Laboratoire M\u00e9thodes Formelles","place":["Gif-sur-Yvette, France"]},{"name":"Universit\u00e9 Paris-Saclay, CEA, List","place":["Palaiseau, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Renaud","family":"Sirdey","sequence":"additional","affiliation":[{"name":"Universit\u00e9 Paris-Saclay, CEA, List","place":["Palaiseau, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,4,8]]},"reference":[{"key":"ref1:brakerski","doi-asserted-by":"publisher","first-page":"868","DOI":"10.1007\/978-3-642-32009-5_50","article-title":"Fully Homomorphic Encryption without Modulus Switching from\n  Classical GapSVP","author":"Z. Brakerski","year":"2012"},{"key":"ref2:bfv","volume-title":"Somewhat Practical Fully Homomorphic Encryption","author":"J. Fan","year":"2012"},{"key":"ref3:bgv","doi-asserted-by":"publisher","first-page":"309","DOI":"10.1145\/2090236.2090262","article-title":"(Leveled) Fully Homomorphic Encryption without\n  bootstrapping","author":"Z. Brakerski","year":"2012","journal-title":"ACM ITCS"},{"key":"ref4:ckks","doi-asserted-by":"publisher","first-page":"409","DOI":"10.1007\/978-3-319-70694-8_15","article-title":"Homomorphic Encryption for Arithmetic of Approximate\n  Numbers","author":"J. H. Cheon","year":"2017"},{"key":"ref5:TFHE16","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-662-53887-6_1","article-title":"Faster Fully Homomorphic Encryption: Bootstrapping in Less\n  Than 0.1 Seconds","author":"I. Chillotti","year":"2016"},{"key":"ref6:vCCA","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-031-58723-8_3","article-title":"Fully Homomorphic Encryption beyond IND-CCA1 Security:\n  Integrity through Verifiability","author":"M. Manulis","year":"2024"},{"key":"ref7:NY_public-key_1990","doi-asserted-by":"publisher","first-page":"427","DOI":"10.1145\/100216.100273","article-title":"Public-key cryptosystems provably secure against chosen\n  ciphertext attacks","author":"M. Naor","year":"1990"},{"key":"ref8:CPAD","doi-asserted-by":"publisher","first-page":"648","DOI":"10.1007\/978-3-030-77870-5_23","article-title":"On the Security of Homomorphic Encryption on Approximate\n  Numbers","author":"B. Li","year":"2021"},{"key":"ref9:CPADatt1","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-68382-4_1","article-title":"On the practical CPAD security of \u201cexact\u201d and threshold\n  FHE schemes","author":"M. Checri","year":"2024"},{"key":"ref10:CPADatt2","doi-asserted-by":"publisher","first-page":"2505","DOI":"10.1145\/3658644.3690341","article-title":"Attacks Against the IND-CPAD Security of Exact FHE\n  Schemes","author":"J. H. Cheon","year":"2024"},{"key":"ref11:CCA-sym","doi-asserted-by":"publisher","first-page":"394","DOI":"10.1109\/SFCS.1997.646128","article-title":"A concrete security treatment of symmetric encryption","author":"M. Bellare","year":"1997"},{"key":"ref12:CPAD-DP","doi-asserted-by":"publisher","first-page":"560","DOI":"10.1007\/978-3-031-15802-5_20","article-title":"Securing Approximate Homomorphic Encryption Using\n  Differential Privacy","author":"B. Li","year":"2022"},{"key":"ref13:CPADappaw","volume-title":"Application-Aware Approximate Homomorphic Encryption:\n  Configuring FHE for Practical Use","author":"A. Alexandru","year":"2024"},{"key":"ref14:CCA-NM","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1007\/BFb0055718","article-title":"Relations among notions of security for public-key\n  encryption schemes","author":"M. Bellare","year":"1998"},{"key":"ref15:sCPAD","volume-title":"Drifting Towards Better Error Probabilities in Fully\n  Homomorphic Encryption Schemes","author":"O. Bernard","year":"2024"},{"key":"ref16:NYerr","doi-asserted-by":"publisher","first-page":"342","DOI":"10.1007\/978-3-540-24676-3_21","article-title":"Immunizing Encryption Schemes from Decryption Errors","author":"C. Dwork","year":"2004"},{"key":"ref17:Rinnocchio","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/s00145-023-09481-3","article-title":"Rinocchio: SNARKs for Ring Arithmetic","author":"C. Ganesh","year":"2023","journal-title":"J. Cryptol."},{"key":"ref18:PST-FL","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/PST58708.2023.10320195","article-title":"Combining Homomorphic Encryption and differential\n  privacy in federated learning","author":"A. Grivet-S\u00e9bert","year":"2023"},{"key":"ref19:SPEED","doi-asserted-by":"publisher","first-page":"675","DOI":"10.1007\/s10994-021-05970-3","article-title":"SPEED: secure, PrivatE, and efficient deep learning","author":"A. Grivet-S\u00e9bert","year":"2021","journal-title":"Machine Learning"},{"key":"ref20:SHIELD","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1145\/3605759.3625258","article-title":"A Probabilistic Design for Practical Homomorphic Majority\n  Voting with Intrinsic Differential Privacy","author":"A. Grivet-S\u00e9bert","year":"2023"},{"key":"ref21:Guo-USENIX","first-page":"7447","article-title":"Key recovery attacks on approximate Homomorphic\n  Encryption with nonworst-case noise flooding countermeasures","author":"Q. Guo","year":"2024"},{"key":"ref22:OpenFHE","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1145\/3560827.3563379","article-title":"OpenFHE: Open-Source Fully Homomorphic Encryption\n  Library","author":"A. Al Badawi","year":"2022"},{"key":"ref23:viand-2023","volume-title":"Verifiable Fully Homomorphic Encryption","author":"A. Viand","year":"2023"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T21:24:29Z","timestamp":1744147469000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/1\/20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,8]]},"references-count":23,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,4,8]]}},"URL":"https:\/\/doi.org\/10.62056\/aee0iv7sf","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,8]]},"assertion":[{"value":"2025-01-10","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-03-11","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-1-27"}}