The jeweler with gloves inside the box.
Today, for a server to do any math with your data, it has to open the data. It is like handing the gold to the jeweler: you trust he won't keep a little. Ordinary encryption protects data in transit and on disk, but not during the computation.
With homomorphic encryption (FHE), the box arrives locked, the server works through the gloves and hands the box back still locked, now with the result inside. Whoever has the key opens it. The server never saw the number it added.
The price is real: every locked operation is far slower and far bigger than the open one. So FHE works well for some tasks (adding, counting, voting, simple statistics) and badly for others. The maturity and frontier pages say where, with measured numbers.
Three dialects, three kinds of math.
There is no single FHE. There are three families, and each speaks one kind of math well. Picking the wrong one is the most expensive mistake a project can make.
Exact integers
Adds and multiplies whole numbers with no error at all. Each locked box carries 16,384 numbers at once, like a tray with 16,384 slots.
In practice: voting, counts, sales totals. It is what this page's ballot box uses.
42 + 58 = 100 · the server never sees 42, 58 or 100Decimal numbers
Computes with real numbers, accepting a tiny error in the last digit (about one part in a million).
In practice: sensor averages, statistics, simple machine-learning models.
mean of 25.1; 24.3; … = 25.09 · error of ~0.000001Logic gates
Works bit by bit, with AND, OR and NOT gates. It can compute anything, but each gate is expensive, and comparing two numbers becomes hundreds of gates.
In practice: comparisons and decisions ("is A greater than B?") when there is no other way.
is 7 greater than 3? → yes · 246 logic gatesWho locks, who adds, who opens.
Each vote becomes a row with a 1 in the candidate's position and zeros elsewhere: voting for Carla is [0, 0, 1, 0]. The terminal locks that row with the public padlock. The server adds the locked rows on top of one another without opening any. At the end, only the sum is opened.
There are three separate roles: the election authority holds the key and opens only the total; the terminal locks the vote; the counting server adds. None of them alone can link a vote to a person.
Vote, count, check.
The same box as at the top, with every part: each vote goes through a blindly stamped credential, a proof that it is valid and a chained record. The counter is shared with all visitors.
empties the box for every visitor
How to know nobody touched the box.
Receipt
Each locked vote produces a fingerprint. You keep yours and check, on the public board, that it is there.
One credential per voter
Each voter ID gets a single voting token, stamped without the registry seeing the token. Using it twice is blocked.
Proof of a valid vote
The terminal proves the row has exactly one 1, without revealing where. A vote for two candidates is blocked.
Chained record
Each board entry carries the fingerprint of the previous one. Changing one entry breaks every later one.
Anyone can redo the sum
The board is public: anyone can add the locked votes again and compare with the result.
Is your vote in the sum?
After you vote, your receipt shows up here automatically. Paste a receipt (or use yours) and check it on the public board. Then check the whole chain.
Four attacks. Four blocks.
Each button attempts a real fraud against the live box. Next to it: which layer caught it and why.
Forge the credential
Make up a voting token without the registry's stamp.
Vote twice
Reuse the token of someone who already voted.
Vote for two candidates
Send a row with two 1s, which would add two votes.
Tamper with the board
Change an already recorded vote, on a copy of the board.
What makes the box serious.
Locked math solves the secrecy of the sum. An election needs four more parts, each for a different problem.
Proving without showing
The terminal proves the vote has exactly one 1, without revealing the position. Pick the candidate and generate the proof: it is checked without anyone learning who you voted for.
Stamping without seeing
The registry must make sure each voter gets one token, but must not know which token belongs to whom. The answer is a blind stamp: the voter puts the token inside a carbon envelope; the registry stamps the envelope without opening it; the stamp carries through to the token.
- The voter derives the token from the voter ID and picks a secret number.
- Wraps the token with that number: the registry cannot see the token.
- The registry stamps the wrapper.
- The voter unwraps: the stamp is now valid for the original token.
- Anyone can check the stamp; nobody can link the token to the voter ID.
The key split in five
The key that opens the total does not exist whole anywhere. It was split among five institutions; any three together can open it, two cannot. Choose who cooperates and try to open the count.
Shuffling so nobody can link
Even locked, the order of the votes can give someone away ("vote 42 came in at 2:03 pm, when only Maria was in line"). Three servers shuffle the votes one after the other and swap each vote's "outer padlock" without changing its contents. After the third, nobody knows which vote came from whom.
Local illustration: the shuffling runs in your browser, not on this demo's server.
To go deeper.
Data after it goes through the padlock. Without the key you see only noise. →
Adding, multiplying or comparing data without unlocking it. That is what "homomorphic" means. →
Convincing someone that something is true without revealing the secret. Here: the vote is valid, without saying for whom. →
Where this can mislead.
A demonstration, not an official election
This page's box is public and shared, any visitor can restart it, and there is no real voter roll. It shows the parts working, not a certified system.
The price of each vote
A locked vote takes about 1.5 MB, against a few bytes for an open vote. For a city, that is storage and bandwidth that must enter the budget.
Secrecy is not integrity
Locked math hides the votes, but does not by itself guarantee nobody cheated. That is why the other four parts exist. See maturity, "one bit per question is enough".
The shuffling here is illustrative
The three shufflers run in your browser to show the idea. This demo's server does not shuffle votes.
- Our own benchmark and demos in Go, with the Lattigo v6 library (BGV/BFV, CKKS) and TFHE; 128-bit security parameters; 16,384 numbers per box.
- Blind signature: David Chaum, 1983. Proof of a valid vote: Sigma protocol with Pedersen commitments on the P-256 curve and Fiat-Shamir. 3-of-5 key: Shamir secret sharing.
- Size of a locked vote (≈1.5 MB) and time to lock (tens of ms): measured on this demo's server; they vary with the machine.