Multi-client functional encryption extends (classical) functional encryption by allowing multiple independent clients to encrypt their data so that, upon decryption, an authorized party learns only specified functions of the aggregated data. A particularly interesting case is the computation of inner products, which underpins many procedures in statistics and machine learning. In this master’s thesis, we formally present multi-client functional encryption. Building on a known functional encryption scheme for inner products, we construct a multi-client scheme in which an authorized party with an appropriate decryption key learns only the inner product of the clients’ contributions. We formally define the security model and prove that the scheme is selectively secure in the random oracle model under the decisional Diffie-Hellman assumption. We implement the scheme and measure the execution times of its algorithms. We demonstrate the practicality of the scheme with an example of a survey in which respondents choose between two options. We also present a decentralized variant of the scheme that, by using pseudo-random functions, removes the central entity responsible for key generation and achieves selective-static security under the same assumptions.
|