🤖 AI Summary
This work addresses the challenge of deploying homomorphic encryption on resource-constrained microcontrollers, where local decryption remains infeasible. We propose the first MCU-level BFV homomorphic encryption library supporting embedded vector instruction sets and on-device encryption and decryption. By leveraging ARM Helium extensions, the implementation optimizes vectorized number-theoretic transforms (NTT) and integer arithmetic, incorporates a timing-leakage-resistant decryption procedure, and ensures compatibility with the Microsoft SEAL server, thereby bridging functional gaps in existing CKKS-based approaches. Evaluated on an STM32N6 platform, encoding and decoding for 4096-dimensional polynomials require approximately 5 ms with RAM consumption below 500 KB, while the vector engine achieves a 2.7× speedup over scalar execution. This library provides an efficient and practical solution for privacy-preserving computation in Internet of Things environments.
📝 Abstract
The growth of the Internet of Things (IoT) has raised concerns over the privacy of data collected by resource-constrained sensing devices. Homomorphic encryption (HE) addresses this by letting a device encrypt its data once and an untrusted cloud server compute on the ciphertext without seeing the values. In practice, HE's memory and computational cost have kept it out of reach of microcontroller-class devices. Prior work, SEAL-Embedded, made this feasible using CKKS, but left three gaps: its arithmetic is entirely scalar, even on hardware with a vector instruction set; it never decrypts on the device, so the client cannot consume a result; and it does not explore BFV, whose encoding uses only integer arithmetic and decrypts exactly. We present Zeppelin, the first HE library to use an embedded vector instruction set, the first to support both encryption and decryption on an embedded device, and the first BFV implementation on MCU-class hardware. Zeppelin vectorizes the number-theoretic transform, HE's main bottleneck, for ARM's Helium extension, and includes a decryption procedure that avoids large-integer arithmetic and timing leakage of the secret key. A server-side adapter converts Zeppelin's ciphertexts into a format compatible with Microsoft SEAL, so the device handles encryption and decryption while the server performs all homomorphic computation. On an STM32N6 MCU with an ARM Cortex-M55, Zeppelin encodes and encrypts 4096 packed values in 4.76 ms (seeded symmetric, 128-bit security per the HE standard) and decrypts and decodes the result in 5.38 ms, using under 500 KB of RAM, with the vectorized NTT engine ${\sim}2.7\times$ faster than an equivalent scalar implementation on the same core.