scieee AI-readable full text Open interactive document viewer

Integrating Levelled-Homomorphic Encryption in a Secure Process Control Application

Leonow, Sebastian; Mönnigmann, Martin; Dyrska, Raphael; Holaza, Juraj

Full text

sebastian.leono[email protected]e, raphael.dyrsk[email protected], [email protected], martin.moennigm[email protected] Integrating Levelled-Homomorphic Encryption in a Secure Process Control Application Sebastian Leonow, Raphael Dyrska, Juraj Holaza, and Martin Mönnigmann Motivation & Goal ▪Outsourcing computationally demanding controllers to acloud reduces on-site hardware demand ▪Homomorphic encryption allows to evaluate the control law on encrypted data without disclosing sensitive information ▪We demonstrate control of a 1.1 kW water heater based on homomorphic encryption, using lean embedded hardware and a cloud computer Challenges ▪Existing fullyor levelled-homomorphic encryption methods can handle even complex computations [1] but are computationally demanding ▪Levelled-homomorphic methods are mature enough for transition into practical applications but have a limit on the number of subsequent mathematical operations ▪On-site hardware shall be kept lean in computational power and energy demand Methods ▪We implement the levelled-homomorphic Brakerski Fan-Vercauteren (BFV) cryptosystem [2] and use Micropython as implementation language on an on-site ESP32 microcontroller ▪We implement a polynomial control law approximating explicit model predictive control [3] ▪We outline computational bottlenecks and optimize the specific computations to meet cycle time requirements Application setup ▪The temperature of the hot water outflow from a boiler is controlled ▪The ESP32 receives the measured temperature 𝑥 𝑡 , encrypts it and sends it to the cloud ▪The cloud computer evaluates the polynomial control-law and returns 𝑢(𝑡) to the ESP32 ▪The cloud computer never decrypts any data ▪The ESP32 decrypts 𝑢(𝑡) and applies it to the heater boilerheater feedwater (disturbance) hot water thermocouple triac ESP32 WROVER plant input 𝑢 𝑡 (PWM) 𝑢 𝑡 (voltage) measured temperature 𝑥 𝑡 WIFI cloud computer 𝑥 𝑡 𝑢 𝑡 𝑢 𝑡 𝑥 𝑡 𝑥 𝑡 𝑢 𝑡   encrypted open encrypt 𝑋(𝑘) compute 𝐶𝑢(𝑘) decrypt 𝐶𝑢(𝑘) encode 𝑥(𝑘) send 𝐶𝑥(𝑘) to cloud receive 𝐶𝑥(𝑘) from ESP send 𝐶𝑢(𝑘) to ESP receive 𝐶𝑢(𝑘) from cloud decode 𝑈(𝑘) 𝑥(𝑘) 𝑢(𝑘) ESP32 cloud 𝒒𝟏 𝒒𝟏 𝒒𝟐 Encryption of state 𝑋 with pre-transformed public key 𝑃 and online-transformed random 𝑈: 𝑋1 ′′ =𝑃′′ ∗ 𝑈 + 𝜖′′ 𝑞1, 𝑋1 ′=𝑃′∗ 𝑈 +𝛿𝑋 + 𝜖′𝑞1 Compute 𝑚1≔ 𝑘1𝑥 with modulus shift to 𝑞2= 𝑞1 𝑛 for re-linearization after multiplication: rnd 𝑡 ⋅ 𝑋2 ′, 𝐾1 ′′ ∗ 𝐾1 ′, 𝑋2 ′′ 𝑞1 →෩ 𝑀1 ′,෩ 𝑀1 ′′,෩ 𝑀1 ′′′ , 𝑀1 ′=෩ 𝑀1 ′+ rnd ෩ 𝑀1 ′′′ ∗ 𝑅′ 𝑞2𝑞1 ,𝑀1 ′′ =෩ 𝑀1 ′′ + rnd ෩ 𝑀1 ′′′ ∗ 𝑅′′ 𝑞2𝑞1 Decrypt control action 𝑈: 𝑈 = 𝑡 ⋅ rnd 𝑀1 ′+𝑀1 ′′∗𝑆 𝑞1 𝑞1𝑡 ▪The Brakerski Fan-Vercauteren cryptosystem works on dual 𝑁th-order polynomials representing plainand ciphertexts, with integer coefficients modulo 𝑡for plaintext and modulo 𝑞1for ciphertext ➢Primary computational bottleneck is the convolution (∗) of polynomials ▪Number Theoretic Transform (NTT) representation allows element-wise multiplication of the polynomial coefficients, boosting convolution performance ➢We extend NTT application also to the re-linearization after multiplication by switching to a larger modulus 𝑞2~𝑞1 𝑛. ▪Onlineand pre-transformations further reduce the online computational load ▪One cycle of closed-loop control with control law 𝑢 = 𝑥2+𝑘1𝑥 ⋅ 𝑥2+𝑘2𝑥 + 𝑘3 allows for the following online and pre-transformations (exemplary for the part 𝑘1𝑥): ESP32 ESP32 transmission & cloud cycle time Implementation Results ▪We measured an approx. 15 minute time series of the closed-loop, secure control with fixed setpoint at 𝟖𝟎°C and two disturbances by increased feedwater flow ▪BFV parameters: 𝑁 = 1024, 𝑡 = 256, 𝑞1~251, 𝑛 = 4, cycle-time 5s The encrypted control closely matches the unencrypted reference, demonstrating effective implementation. The profiling reveals that encryption and decryption are most elaborate since they run on the slow ESP. Controller evaluation (green) requires large number of timeconsuming convolutions and takes up to 30 seconds when not optimized. References [1] A. Bertolace et al. (2023). Homomorphically Encrypted Gradient Descent Algorithms for Quadratic Programming. 62nd IEEE Conference on Decision and Control,3844-3849. [2] J. Fan and F. Vercauteren (2012). Somewhat Practical Fully Homomorphic Encryption. Cryptology ePrint Archive. [3] M. Kvasnica et al. (2011). Stabilizing Polynomial Approximation of Explicit MPC. Automatica 47 (10), 2292-2297. 200 100 0 -600 -200 200 𝑢(𝑘) 𝑥(𝑘) 𝐶𝑥(𝑘) 𝐶𝑢(𝑘) Funded by the European Commission under the grant no.101079342 (Fostering Opportunities Towards Slovak Excellence in Advanced Control for Smart Industries). 25th International Conference on Process Control 2025