TY - GEN
T1 - Comparison of the Paillier and ElGamal Cryptosystems for Smart Grid Aggregation Protocols
AU - Knirsch, F.
AU - Unterweger, A.
AU - Unterrainer, M.
AU - Engel, D.
N1 - Conference code: 301229
Export Date: 14 December 2023
Funding details: Salzburger Landesregierung
Funding text 1: The financial support by the Federal State of Salzburg is gratefully acknowledged.
References: Adida, B., Helios: Web-based Open-Audit Voting (2008) USENIX Security Symposium, 17, pp. 335-348; Armknecht, F., Katzenbeisser, S., Peter, A., Group homomorphic encryption: Characterizations, impossibility results, and applications (2013) Designs, Codes, and Cryptography, 67, pp. 209-232; Barker, A., (2016) NIST Special Publication 800-57: Recommendation for Key Management - Part 1: General (Revised); Buescher, N., Boukoros, S., Bauregger, S., Katzenbeisser, S., Two Is Not Enough: Privacy Assessment of Aggregation Schemes in Smart Metering (2017) Proceedings on Privacy Enhancing Technologies, 2017 (4), pp. 118-134; Gesetz zur Digitalisierung der Energiewende (2016) Bundesgesetzblatt Teil I, 2016 (43), pp. 2034-2064; Burkhart, S., Unterweger, A., Eibl, G., Engel, D., Detecting Swimming Pools in 15-Minute Load Data (2018) 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications (TrustCom 2018), pp. 1651-1655. , New York, NY, USA. IEEE; Busom, N., Petrlic, R., Seb´e, F., Sorge, C., Valls, M., Efficient smart metering based on homomorphic encryption (2016) Computer Communications, 82, pp. 95-101; Catalano, D., Howgrave-graham, R. G. N., Nguyen, P. Q., Paillier’s Cryptosystem Revisited (2001) Proceedings of the 8th ACM conference on Computer and Communications Security, pp. 206-214. , ACM; Chaum, D., Carback, R., Clark, J., Essex, A., Popoveniuc, S., Rivest, R. L., Ryan, P. Y. A., Sherman, A. T., Scantegrity II: End-to-End Verifiability for Optical Scan Election Systems using Invisible Ink Confirmation Codes (2008) USENIX Security Symposium, 8, pp. 1-13; Cramer, R., Gennaro, R., Schoenmakers, B., A Secure and Optimally Efficient Multi-Authority Election Scheme (1997) Proceedings of the 16th Annual International Conference on Theory and Application of Cryptographic Techniques, EUROCRYPT’97, pp. 103-118. , Konstanz, Germany. Springer-Verlag; Cramer, R., Shoup, V., Design and Analysis of Practical Public-Key Encryption Schemes Secure against Adaptive Chosen Ciphertext Attack (2003) SIAM Journal on Computing, 33, pp. 167-226; Croman, K., Decker, C., Eyal, I., Gencer, A. E., Juels, A., Kosba, A., Miller, A., Wattenhofer, R., On Scaling Decentralized Blockchains (2016) International Conference on Financial Cryptography and Data Security, pp. 106-125. , Christ Church, Barbados. Springer; Culnane, C., Ryan, P. Y. A., Schneider, S., Teague, V., vVote: a Verifiable Voting System (2015) ACM Transactions on Information and System Security (TISSEC), 18 (1); Damg°ard, I., Jurik, M., Buus, J., A generalization of Paillier ’ s public-key system with applications to electronic voting (2010) International Journal of Information Security, pp. 371-385; Damg°ard, I., Jurik, M. J., A Generalisation, a Simplification and some Applications of Paillier’s Probabilistic Public-Key System (2001) PKC 2001: Public Key Cryptography, pp. 119-136; ElGamal, T., A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms (1985) IEEE Transactions on Information Theory, 31 (4), pp. 469-472; Erkin, Z., Private Data Aggregation with Groups for Smart Grids in a Dynamic Setting using CRT (2015) 2015 IEEE International Workshop on Information Forensics and Security (WIFS), , Rome, Italy. IEEE; Erkin, Z., Tsudik, G., Private Computation of Spatial and Temporal Power Consumption with Smart Meters (2012) Proceedings of the 10th international conference on Applied Cryptography and Network Security, ACNS’12, pp. 561-577. , Bao, F., Samarati, P., and Zhou, J., editors, pages Springer, Berlin Heidelberg; Fontaine, C., Galand, F., A Survey of Homomorphic Encryption for Nonspecialists (2007) EURASIP Journal on Information Security; Fouque, P. a., Poupard, G., Stern, J., Sharing de-cryption in the context of voting or lotteries (2001) Financial Cryptography, pp. 90-104; Galbraith, S. D., Elliptic curve Paillier schemes (2002) Journal of Cryptology, pp. 1-10; Hazay, C., Mikkelsen, G. L., Rabin, T., Toft, T., Efficient RSA key generation and threshold Paillier in the two-party setting (2012) Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 7178, pp. 313-331. , LNCS; Knirsch, F., Eibl, G., Engel, D., Errorresilient Masking Approaches for Privacy Preserving Data Aggregation (2018) IEEE Transactions on Smart Grid, 9 (4), pp. 3351-3361; Knirsch, F., Engel, D., Erkin, Z., A Faulttolerant and Efficient Scheme for Data Aggregation Over Groups in the Smart Grid (2017) 9th IEEE International Workshop on Information Forensics and Security (WIFS), pp. 1-6. , Rennes, France. IEEE; Kumar, V., Madrai, S., Secure Hierarchical Data Aggregation in Wireless Sensor Networks: Performance Evaluation and Analysis (2012) 13th International Conference on Mobile Data Management, pp. 196-201; Li, F., Luo, B., Liu, P., Secure Information Aggregation for Smart Grids Using Homomorphic Encryption (2010) Proceedings of First IEEE International Conference on Smart Grid Communications, pp. 327-332. , Gaithersburg, Maryland, USA. IEEE; Maqsood, F., Ahmed, M., Ali, M. M., Shah, M. A., Cryptography: A Comparative Analysis for Modern Techniques (2017) International Journal of Advanced Computer Science and Applications, 8 (6), pp. 442-448; McKenna, E., Richardson, I., Thomson, M., Smart meter data: Balancing consumer privacy concerns with legitimate applications (2012) Energy Policy, 41, pp. 807-814; (2010) Bundesgesetz, mit dem die Organisation auf dem Gebiet der Elektrizitatswirtschaft neu geregelt wird (Elektrizitatswirtschafts- und - organisationsgesetz 2010 – ElWOG 2010), , Nationalrat BGBl. I Nr. 110/2010 (NR: GP XXIV RV 994 AB 997 S. 86. BR: 8420 AB 8421 S. 791); Paillier, P., Public-Key Cryptosystems Based on Composite Degree Residuosity Classes (1999) Advances in Cryptology — EUROCRYPT ’99, volume 1592 of Lecture Notes in Computer Science, pp. 223-238. , Stern, J., editor, pages Springer, Berlin Heidelberg; Pollard, B. J. M., (1978) Monte Carlo Methods for Index Computation (mod p), 32 (143), pp. 918-924; Rane, S., Freudiger, J., Brito, A. E., Uzun, E., Privacy, Efficiency & Fault Tolerance in Aggregate Computations on Massive Star Networks (2015) 7th IEEE International Workshop on Information Forensics and Security (WIFS), pp. 1-6. , Rome, Italy. IEEE; Schnorr, C. P., Jakobsson, M., Security of Signed ElGamal Encryption (2000) Advances in Cryptology - ASIACRYPT 2000, pp. 73-89. , Okamoto, T., editor, pages Berlin Heidelberg. Springer Berlin Heidelberg; Shoup, V., Lower Bounds for Discrete Logarithms and Related Problems (1997) Advances in Cryptology - EUROCRYPT ’97, pp. 256-266. , Fumy, W., editor, pages Berlin Heidelberg. Springer Berlin Heidelberg; Unterweger, A., Taheri-Boshrooyeh, S., Eibl, G., Knirsch, F., Kupcu, A., Engel, D., Understanding Game-Based Privacy Proofs for Energy Consumption Aggregation Protocols (2019) IEEE Transactions on Smart Grid, 10 (5), pp. 5514-5523; Wicker, S. B., Thomas, R., A privacy-aware architecture for demand response systems (2011) Proceedings of the Annual Hawaii International Conference on System Sciences, , Koloa, HI, USA. IEEE
PY - 2020
Y1 - 2020
N2 - Many smart grid applications require the collection of fine-grained load data from customers. In order to protect customer privacy, secure aggregation protocols have been proposed that aggregate data spatially without allowing the aggregator to learn individual load data. Many of these protocols build on the Paillier cryptosystem and its additively homomorphic property. Existing works provide little or no justification for the choice of this cryptosystem and there is no direct performance comparison to other schemes that allow for an additively homomorphic property. In this paper, we compare the ElGamal cryptosystem with the established Paillier cryptosystem, both, conceptually and in terms of runtime, specifically for the use in privacy-preserving aggregation protocols. We find that, in the ElGamal cryptosystem, when made additively homomorphic, the runtime for encryption and decryption is distributed more asymmetrically between the smart meter and the aggregator than it is in the Paillier cryptosystem. This better reflects the setup typically found in smart grid environments, where encryption is performed on low-powered smart meters and decryption is usually performed on powerful machines. Thus, the ElGamal cryptosystem is a better, albeit overlooked, choice for secure aggregation protocols. © 2022 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved.
AB - Many smart grid applications require the collection of fine-grained load data from customers. In order to protect customer privacy, secure aggregation protocols have been proposed that aggregate data spatially without allowing the aggregator to learn individual load data. Many of these protocols build on the Paillier cryptosystem and its additively homomorphic property. Existing works provide little or no justification for the choice of this cryptosystem and there is no direct performance comparison to other schemes that allow for an additively homomorphic property. In this paper, we compare the ElGamal cryptosystem with the established Paillier cryptosystem, both, conceptually and in terms of runtime, specifically for the use in privacy-preserving aggregation protocols. We find that, in the ElGamal cryptosystem, when made additively homomorphic, the runtime for encryption and decryption is distributed more asymmetrically between the smart meter and the aggregator than it is in the Paillier cryptosystem. This better reflects the setup typically found in smart grid environments, where encryption is performed on low-powered smart meters and decryption is usually performed on powerful machines. Thus, the ElGamal cryptosystem is a better, albeit overlooked, choice for secure aggregation protocols. © 2022 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved.
KW - ElGamal Cryptosystem
KW - Paillier Cryptosystem
KW - Privacy
KW - Secure Aggregation
U2 - 10.5220/0008770902320239
DO - 10.5220/0008770902320239
M3 - Conference contribution
SN - 978-989-758-399-5
VL - 1
SP - 232
EP - 239
BT - Proceedings of the 6th International Conference on Information Systems Security and Privacy
T2 - 6th International Conference on Information Systems Security and Privacy, ICISSP 2020
Y2 - 25 February 2020 through 27 February 2020
ER -