Advanced Cryptography: new approaches to data privacy

In recent years, researchers have invented new mathematical techniques in Advanced Cryptography that enable users to handle, search and compute with sensitive data, while at the same time providing cryptographically strong protection to those data.
The NCSC has published a white paper on the applications of Advanced Cryptography to help users to assess which techniques could be suitable for their data processing requirements, and to highlight where further development is required before these techniques are ready for mainstream use.
The paper introduces several new forms of Advanced Cryptography, but this blog highlights a couple that are increasingly being proposed for real-world applications.
Homomorphic Encryption
Fully Homomorphic Encryption (FHE) has long been the holy grail for some cryptography researchers. FHE would allow arbitrary computations on encrypted data, separating the ability to carry out the computations from the permission to decrypt the data. This is counterintuitive, and was a notorious open problem for three decades after the invention of public key cryptography. Then, about 15 years ago, FHE was shown to be theoretically possible, sparking a chain of subsequent ideas, improvements and optimisations.
Today, FHE is practical for improving data privacy in some scenarios, including searching a database without revealing to the owner of the database what the search query was. However, this doesn’t mean that FHE is usable at scale; it’s still extremely computationally intensive, so early applications are either very limited in database size or search complexity, or use functionally more restricted versions of homomorphic encryption.
Multiparty Computation
Multiparty Computation (MPC) allows a group of participants to come together to pool their data to make certain, specific calculations, without ever having to share the raw data. MPC is gaining popularity as a protocol for banks and FinTech and enables applications such as:
- sealed-bid auctions without an auctioneer
- matching share-trading orders without revealing the positions of clients
- improving the privacy of encrypted transaction data by ensuring that no single individual has the ability to decrypt them
When deploying an Advanced Cryptography solution like MPC, it’s important to understand the trust model, and to know that the real-world trust relationships fit the mathematical properties of the protocol. For example, can you trust all the participants to follow the protocol without deviating from it? What if they follow the protocol, but send data that is specially constructed to try to learn some information about the others? Every Advanced Cryptography solution makes some assumptions about the behaviours of the participants, and if these don’t hold, then security can be compromised in unexpected ways.
A smorgasbord of algorithms
Advanced Cryptography is not a single technology, but a mixed collection of mathematical methods of varying complexity, utility and maturity. The paper doesn’t attempt to give an exhaustive list, since the boundaries are fuzzy and the field is evolving. However, we are clear about what is not in scope for this white paper. It’s not about making encryption ‘more secure’ by using more advanced mathematics. Nor is it about new encryption algorithms that defend against the quantum computing threat (which is covered in our guidance on timelines for migration to post-quantum cryptography).
Our white paper considers the new forms of cryptography that are emerging in academia (and are being developed by industry) to tackle problems that can’t be solved simply by encrypting, decrypting, signing, and verifying information. There are cautionary notes along the journey, and we don’t yet have all the standards and assurance processes in place to give us the same level of confidence in the security of many of these new techniques compared to the more established methods of encryption. In an increasingly data-driven world, this new frontier for cryptography holds the promise of enabling the use of datasets in more innovative and collaborative ways, without compromising the privacy of individuals' sensitive data.

