Stickybit.← FHEPortuguêsApplications · homomorphic encryption · 2026
Homomorphic encryption · 20 applications

Compute on the data without ever opening it.

With homomorphic encryption (FHE), a server computes on encrypted data and returns the result still encrypted: only the key holder can read it. We picked 20 real uses and said, for each, whether it works today or sits at the frontier, using the costs measured on our bench.

Specimen · pick an application

Computes without opening
Why
Measured cost
Scheme
14work today
6at the frontier
6work only with a condition

Each application's band is our reading, based on the costs we measured (Apple M2, single thread, Lattigo v6.2.0, mean of 3 runs) and on the five-condition rule. Only voting was built end to end. Third-party numbers are marked.

In everyday terms

The jeweller with gloves.

Picture a locked glass box with built-in gloves. The owner puts the gold inside and keeps the key. The jeweller makes the piece through the gloves: working on the gold without ever being able to take it out. At the end, only the owner opens the box and sees the finished piece.

Homomorphic encryption does this with data. The hospital, the bank or the voter encrypts the data with their own key and sends it to the server. The server adds, multiplies, applies a model, all on the encrypted data, and returns the result still encrypted. Whoever computed never saw the data or the result.

The new post-quantum locks and homomorphic encryption rest on the same kind of math problem, the lattice. That is why homomorphic encryption also resists a quantum computer. The rest of the stack is in what breaks, what stays, what to swap.

the locked box the jeweller works through the gloves raw gold(the data) jewel (result) the key holder opens it and sees the finished piece
The idea of homomorphic encryption: working on the contents without taking them out of the box.
Why it costs

Each operation leaves a little noise.

Encrypted data carries deliberate "noise", which is what makes it secure. Each operation adds to that noise, and multiplication adds much more than addition. After about 8 multiplications in a row, the noise goes over the limit and the result comes out wrong.

Worse: it comes out wrong silently. On our bench, with a budget for four levels, BFV was right up to the seventh multiplication and at the eighth returned 28323 where the answer was 282, with no error or warning. That is why the circuit must be known before generating the keys.

To go past the budget there is the "cleanup" (bootstrap), which clears the noise: 1 min 18 s per operation at real security parameters, with 10.26 GB of keys. It works, but it becomes a batch job, not an app response.

budget limit (depends on parameters) 123456789 past it: silent error multiplications in a row accumulated noise "cleanup" (bootstrap): 1 min 18 s
Illustrative: noise grows with each multiplication in a row; the limit and the cleanup cost are measured.
The rule of thumb

It works when five things hold together.

Our maturity measurement produced a simple rule. Homomorphic encryption is a calm engineering decision when the five conditions below all hold at once. Remove one, and the cost changes by orders of magnitude.

The three bands, with the measured number for each, are in FHE maturity in 2026.

Three ways to compute

Arithmetic, integers or logic.

There is no single FHE. There are three main families, and each application calls for one. CKKS works with approximate decimal numbers: averages, models, distances. BGV (and BFV) works with exact integers: counts and votes. TFHE works bit by bit: it is the one that can compare and decide "if this, then that".

The cost gap between families is structural. On our bench, one logical comparison takes 1.74 s with TFHE, and switching families mid-computation costs 13.9 s per position. Hence the rule of returning the score and deciding on the key holder's side: there, the same decision costs microseconds.

CKKSdecimal numbers, approximateaverages, models, distancesBGV / BFVwhole numbers, exactcounts, votes, sumsTFHElogic, bit by bitcompare, decide, "if then"
The three families and what each does well.
The cost nobody budgets for

Secrecy is not integrity.

Homomorphic encryption hides the data, but it does not stop the server from tampering with the result. And there is a simple attack: the server adds a value to the encrypted data and watches whether the app accepts or rejects the result. That reaction is one bit, and repeated a few dozen times it gives the data away.

We measured it: about 47 queries and 79 ms to recover a 16-bit value, succeeding on 24 of 24 secrets. Control positions ("canaries") catch 100% of blind tampering but only 0.37% of an attacker who chooses where to tamper. If the server may be malicious, you need a proof of the computation or attested hardware, with published costs from ~2% to over 1000%.

Three words on this page
Homomorphic encryption (FHE)

Computing on encrypted data without opening it. Whoever computes sees neither the data nor the result.

Cleanup (bootstrap)

The operation that clears the noise accumulated by computations. It allows long computations but costs over a minute per operation.

Decision on the client

The server returns the encrypted score and the key holder decides. It is what makes most of these uses work today.

Limits

Where this could be wrong.

The band is our reading

We classified each use from the measured costs and the five-condition rule. Only voting was built end to end; the other 19 are projections.

One machine, one library

Apple M2, single thread, Lattigo v6.2.0. Between sessions the same test varies up to ~1.8×; ratios between operations are stable.

Third-party numbers

The "confidential blockchain in production" and the cost of integrity proofs come from third-party publications, not from our bench.

A malicious server changes everything

All bands assume a curious but honest server. If it can tamper, add the cost of a proof, which can range from negligible to prohibitive.

See also

← FHE: computing without opening the data · stickybit.com.br

Sources