Skip to main content

Advanced Cryptography

Deciding when to use Advanced Cryptography to protect your data

MF3d via GettyImages

What is Advanced Cryptography ?

The NCSC uses the term Advanced Cryptography to refer to a range of techniques that use cryptographic methods to provide data-processing functionality beyond that which can be achieved by applications of traditional cryptographic functions. These include techniques where multiple parties cooperate to process the data, but have only partial trust in each other so wish to keep some of their information secret. They vary in their degrees of computational complexity as practical solutions, and the extent to which their security properties are fully understood.

The NCSC defines Advanced Cryptography as Cryptographic techniques for processing encrypted data, providing enhanced functionality over and above that provided by traditional cryptography.

The following are examples of Advanced Cryptography techniques illustrating the kind of enhanced functionality that can be achieved. These examples are expanded upon in the Appendix.

  • Homomorphic encryption:

    performing calculations directly on encrypted data

  • Private information retrieval:

    conducting a query into a database, without revealing the query to the owner of the database

  • Multiparty computation:

    carrying out a calculation cooperatively, but without sharing secret inputs

  • Zero-knowledge proofs:

    proving the possession of some secret knowledge without revealing it

  • Private set intersection:

    learning which data items you have in common with someone else, without revealing your whole list

  • Attribute-based encryption:

    limiting decryption of messages to anyone possessing a specific set of attributes

Relation to Privacy Enhancing Technologies

The term Privacy Enhancing Technologies (PETs) is commonly used to refer to a variety of technologies that enable the privacy-respecting processing of data. There is some overlap between Advanced Cryptography and PETs, but the two terms are not synonymous.

Advanced Cryptography provides the enabling functionality for some PETs. However, some other PETs are applications of traditional cryptography - for example, anonymous web-browsing technologies are usually based on traditional cryptography and are not reliant on Advanced Cryptography. Other PETs are not cryptographic in nature at all, for example statistical techniques for anonymising or adding noise to datasets to enhance privacy.

This white paper focuses on the applications of Advanced Cryptography, not the other forms of PETs. 


Cryptography can be used to secure data during processing, where some of the data is sensitive and should not be shared openly. However, traditional cryptography can be a barrier if not every party engaged in processing the data has equal permission to view and/or modify all the data.

Advanced Cryptography might provide an appropriate solution to a secure data processing problem if most of the following are true:

  • multiple parties need to cooperate to achieve the desired result
  • there is no trusted third party that can perform the operation on behalf of the parties
  • a significant increase in performance overhead (such as computation cost, communications bandwidth or processing time) is acceptable
  • a small number of participating parties may be unreliable or act dishonestly.

Answering the following questions should help you to identify whether Advanced Cryptography is likely to be a good answer to your problem. If you are unsure how to proceed, you could explore these questions with your supplier base, with a consultant who has appropriate cryptographic expertise, or (for UK government and public sector use-cases) with the NCSC. 

Define the problem statement

  • What are you trying to achieve? What kinds of data are you processing, what actions need to occur, where does the data need to be, and how will data be stored and communicated?

  • What data is sensitive and requires strong cryptographic protection; what data is less sensitive?

  • What operation or computation do you need to perform? 

  • Who are the parties participating in the data processing application, and what are their roles (for example, client, server, trusted third party, untrusted proxy)?

  • Can individuals consent to having their private data processed in this way? If not, can you establish a legal basis for the processing of private data?

  • What practical constraints exist (for example, on bandwidth or response time, or on the processing power of the parties' devices)?

Understand the threat model

  • Who would benefit from compromising the sensitive data?

  • What kind of access to data do the threat actors have? For example, do they have access to the raw data at source, can they read or manipulate log files, can they forge requests or responses?

  • Can you trust each party to only send legitimate, well-formed messages (and not to try to subvert the application to access sensitive data)?

  • Can you trust each party to not attempt to discover additional sensitive data beyond what they are authorised to access, through examination of well-formed messages?

  • Is there a danger of the parties colluding with each other (or with an external threat actor) to obtain access to sensitive data?

  • Are the communication channels between the parties secured so that a threat actor cannot eavesdrop on (or interfere with) data in transit?

Explore possible solutions

  • What is the status quo; how is this problem tackled at the moment? Does this suffice?

  • Can trust be improved between the parties, for example by obtaining user consent to data processing, using a trusted intermediary or making data-sharing agreements?

  • Is it possible to design a solution to the problem built entirely with traditional cryptographic technologies (such as secure communications through TLS or SSH channels, encrypted databases, public key infrastructures)? If not, what aspects of the problem are not solved?

  • Which Advanced Cryptography technique (or combination of techniques) solves an aspect of the problem not met by traditional cryptography?

  • What additional restrictions would an Advanced Cryptography solution impose? (for example, limited formats and quantities of data, data throughput rate, processing latency)

  • Can you assess the cost of the whole solution (which may include system engineering, resource usage, new hardware, licence fees, maintenance and support contracts)?

Examine the risks

  • Does a product implementing the solution already exist, or would you need to build your own?

  • Are you confident that the proposed solution would satisfy the operational requirements? Are you able to run a pilot exercise to test its viability?

  • What assurance do you need in the quality of the solution? If you need to protect against elevated threats, then the NCSC’s design guidelines for high assurance products apply.

  • How will you gain confidence in the cryptographic security of the proposed solution? Note that, so far, there are few standards or certified implementations of Advanced Cryptography.

  • Have you performed a risk assessment of a failure (malicious or accidental) of the solution to cryptographically secure the data it is supposed to be protecting?


Many problems in data protection have solutions that can be formulated in terms of traditional cryptographic operations. If they suffice for the problem, these traditional cryptography solutions may be preferable to Advanced Cryptography solutions, for the following reasons:

  • Traditional cryptography exists in the form of algorithmic standards. Standardisation exposes algorithms to extensive scrutiny from academia, industry and government, so the security properties are generally well-understood.
  • Traditional cryptography is much less computationally complex than some Advanced Cryptography techniques, so will generally be highly performant and will sometimes benefit from hardware acceleration on commodity IT platforms.
  • Standards-based cryptography will offer a route to certification (for example through a cryptographic validation programme) and may be interoperable with other vendors' products, helping to avoid vendor lock-in.

Consider also whether there is an additional assumption that could be made (for example, using a centralised trusted authority, a mutually-trusted intermediary, or a different hardware processing platform such as a Trusted Execution Environment) that would enable an overall simpler solution.

Choosing an Advanced Cryptography solution

There is a small but growing number of Advanced Cryptography products available on a commercial or open-source basis. These are typically more niche than mainstream traditional cryptography products, but their vendors have identified use cases that are relevant to certain sectors – such as healthcare – where the privacy of the individual’s medical data is paramount.

From the definition of your problem statement and your threat model, you should be able to identify which of the Advanced Cryptography techniques is applicable to your use case. You will then need to research which products can implement this technique. Your research should identify the product’s

  • applicability to your problem
  • performance characteristics
  • security level
  • certifications achieved (if any)

It is a good idea to seek a demonstration of the solution in a small-scale pilot, but be aware that the performance on operational-sized problems will be slower so you should seek reassurance on the scalability of the solution. You should also ensure that the product offers the functionality that your user-base will require (for example, being able to make sufficiently general queries) and seek advice on any cyber security implications of using the product, such as what its use would mean for your cyber intrusion detection systems.

Note

In almost all cases, it is bad practice for users to design and/or implement their own cryptography; this applies to Advanced Cryptography even more than traditional cryptography because of the complexity of the algorithms. It also applies to writing your own application based on a cryptographic library that implements the Advanced Cryptography primitive operations, because subtle flaws in how they are used can lead to serious security weaknesses.