{"title":"A Secure Resilient Homomorphic Encryption Scheme for Control Systems","authors":"Moritz Fauser;Ping Zhang","doi":"10.1109/TAC.2024.3518356","DOIUrl":null,"url":null,"abstract":"Recently, the so-called resilient homomorphic encryption (RHE) scheme has been proposed by Fauser and Zhang (2021). Different from the existing homomorphic encryption schemes, the RHE scheme is able to neutralize the effect of an attack injected into the ciphertexts. Thus, a control system can still operate even if an attack takes place. In this article, the RHE scheme is further developed so that it can not only neutralize additive attacks but also satisfy the security requirement of indistinguishability under chosen plaintext attack (IND-CPA). This is achieved by choosing the modulus and the random values in the RHE scheme suitably so that the ciphertexts obtained by the secure resilient homomorphic encryption (SRHE) scheme follow the approximate greatest common divisor (AGCD) distribution. Since it can be shown that the AGCD distribution is computationally indistinguishable from the uniform distribution, the distribution of the ciphertexts obtained by the SRHE scheme is also computationally indistinguishable from the uniform distribution. Therefore, the SRHE scheme satisfies IND-CPA. An approach is given to select the parameters of the SRHE scheme systematically to guarantee the desired security level. Moreover, considering the quantization error caused by the transformation between real values and integer values, a condition for the stability of the closed-loop encrypted control system with a dynamic output feedback controller is provided. Finally, the SRHE scheme is illustrated through the well-established quadruple-tank system and analyzed with respect to the execution time of the encrypted controller, the requirement on network capacity and the usage of storage.","PeriodicalId":13201,"journal":{"name":"IEEE Transactions on Automatic Control","volume":"70 6","pages":"3711-3726"},"PeriodicalIF":7.0000,"publicationDate":"2024-12-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Automatic Control","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10803041/","RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"AUTOMATION & CONTROL SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
Recently, the so-called resilient homomorphic encryption (RHE) scheme has been proposed by Fauser and Zhang (2021). Different from the existing homomorphic encryption schemes, the RHE scheme is able to neutralize the effect of an attack injected into the ciphertexts. Thus, a control system can still operate even if an attack takes place. In this article, the RHE scheme is further developed so that it can not only neutralize additive attacks but also satisfy the security requirement of indistinguishability under chosen plaintext attack (IND-CPA). This is achieved by choosing the modulus and the random values in the RHE scheme suitably so that the ciphertexts obtained by the secure resilient homomorphic encryption (SRHE) scheme follow the approximate greatest common divisor (AGCD) distribution. Since it can be shown that the AGCD distribution is computationally indistinguishable from the uniform distribution, the distribution of the ciphertexts obtained by the SRHE scheme is also computationally indistinguishable from the uniform distribution. Therefore, the SRHE scheme satisfies IND-CPA. An approach is given to select the parameters of the SRHE scheme systematically to guarantee the desired security level. Moreover, considering the quantization error caused by the transformation between real values and integer values, a condition for the stability of the closed-loop encrypted control system with a dynamic output feedback controller is provided. Finally, the SRHE scheme is illustrated through the well-established quadruple-tank system and analyzed with respect to the execution time of the encrypted controller, the requirement on network capacity and the usage of storage.
期刊介绍:
In the IEEE Transactions on Automatic Control, the IEEE Control Systems Society publishes high-quality papers on the theory, design, and applications of control engineering. Two types of contributions are regularly considered:
1) Papers: Presentation of significant research, development, or application of control concepts.
2) Technical Notes and Correspondence: Brief technical notes, comments on published areas or established control topics, corrections to papers and notes published in the Transactions.
In addition, special papers (tutorials, surveys, and perspectives on the theory and applications of control systems topics) are solicited.