Zeppelin: Client-Side BFV Encryption and Decryption for Helium-Powered Microcontrollers
Zeppelin brings BFV encryption and decryption to Arm Helium microcontrollers, encrypting 4096 values in 4.76 ms.
Zeppelin is the first BFV homomorphic-encryption library for microcontroller-class hardware and the first to use Arm Helium vector instructions for both encryption and decryption. On an STM32N6 with a Cortex-M55, it encodes and encrypts 4096 packed values in 4.76 ms and decrypts and decodes them in 5.38 ms at 128-bit security, using under 500 KB of RAM. A server-side adapter converts its ciphertexts for Microsoft SEAL, leaving homomorphic computation to the server. The vectorized number-theoretic transform is about 2.7 times faster than an equivalent scalar implementation, closing gaps left by SEAL-Embedded.
- First BFV library on MCU-class hardware with on-device encryption and decryption.
- Helium-vectorized NTT is about 2.7x faster than scalar code on the same core.
- STM32N6 encrypts 4096 values in 4.76 ms using under 500 KB RAM.
- A server adapter makes ciphertexts compatible with Microsoft SEAL.
Full article262 words · extracted from arxiv.org · click to collapse
The growth of the Internet of Things (IoT) has raised concerns over the privacy of data collected by resource-constrained sensing devices. Homomorphic encryption (HE) addresses this by letting a device encrypt its data once and an untrusted cloud server compute on the ciphertext without seeing the values. In practice, HE's memory and computational cost have kept it out of reach of microcontroller-class devices. Prior work, SEAL-Embedded, made this feasible using CKKS, but left three gaps: its arithmetic is entirely scalar, even on hardware with a vector instruction set; it never decrypts on the device, so the client cannot consume a result; and it does not explore BFV, whose encoding uses only integer arithmetic and decrypts exactly. We present Zeppelin, the first HE library to use an embedded vector instruction set, the first to support both encryption and decryption on an embedded device, and the first BFV implementation on MCU-class hardware. Zeppelin vectorizes the number-theoretic transform, HE's main bottleneck, for ARM's Helium extension, and includes a decryption procedure that avoids large-integer arithmetic and timing leakage of the secret key. A server-side adapter converts Zeppelin's ciphertexts into a format compatible with Microsoft SEAL, so the device handles encryption and decryption while the server performs all homomorphic computation. On an STM32N6 MCU with an ARM Cortex-M55, Zeppelin encodes and encrypts 4096 packed values in 4.76 ms (seeded symmetric, 128-bit security per the HE standard) and decrypts and decodes the result in 5.38 ms, using under 500 KB of RAM, with the vectorized NTT engine ${\sim}2.7\times$ faster than an equivalent scalar implementation on the same core.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2610.08301