What Is Homomorphic Encryption?
Homomorphic encryption lets you compute on encrypted data without ever decrypting it, so a third party can process data it can never actually read.
Homomorphic encryption is a form of encryption that allows computation to be performed directly on ciphertext, producing an encrypted result that — once decrypted — matches what you’d get from running the same computation on the plaintext. The party doing the computing never sees the underlying data at any point. It’s the cryptographic answer to a specific problem: how do you let someone process your data without trusting them with it?
The problem it solves
Normally, using a third party to process your data means decrypting it for them first. A cloud provider running analytics on your data, an ad platform matching audiences, or a hospital sharing records with a research partner — all of these traditionally require handing over readable data, or trusting the recipient’s own encryption at rest and access controls to keep it safe once it arrives.
Homomorphic encryption removes that step. Data stays encrypted through the entire pipeline: it’s encrypted at the source, computed on while encrypted, and the result comes back encrypted — decryptable only by whoever holds the original key. The computing party operates entirely on ciphertext it cannot read.
How it works, conceptually
The “homomorphic” property is a mathematical one: certain encryption schemes are built so that an operation on two ciphertexts (like addition or multiplication) produces a ciphertext that, when decrypted, equals the same operation applied to the original plaintexts.
Encrypt(a) + Encrypt(b) = Encrypt(a + b)
That property doesn’t come from a general-purpose cipher like AES — it requires encryption schemes purpose-built around specific algebraic structures (lattice-based cryptography is the basis for most modern schemes), which is also why many of the same underlying constructions show up in post-quantum cryptography: both fields lean on lattice problems that are hard for classical and quantum computers alike.
There are three broad tiers, differing in how many operations they support:
- Partially homomorphic encryption (PHE) supports one operation — either addition or multiplication — an unlimited number of times. Useful for narrow cases like tallying encrypted votes.
- Somewhat homomorphic encryption (SHE) supports a limited number of both addition and multiplication operations before the accumulated noise in the ciphertext makes decryption fail.
- Fully homomorphic encryption (FHE) supports unlimited addition and multiplication, which together are enough to build arbitrary computation. FHE schemes achieve this with a “bootstrapping” step that refreshes accumulated noise, at a significant computational cost.
Why it’s still not everywhere
Fully homomorphic encryption has existed as a theoretical construction since 2009 and has matured steadily since, but its computational overhead remains the main barrier to broad adoption. Operations on homomorphically encrypted data can be orders of magnitude slower than the same operations on plaintext, which rules it out for latency-sensitive, general-purpose workloads today. It’s practical for narrower, high-value cases — specific aggregate computations, privacy-preserving machine learning inference on sensitive records, secure multi-party analytics — rather than as a drop-in replacement for ordinary processing.
Homomorphic encryption vs confidential computing
These two approaches are often mentioned together because they solve overlapping problems, but the trust model is fundamentally different, as covered in more depth in what is confidential computing:
| Homomorphic encryption | Confidential computing | |
|---|---|---|
| Data during computation | Stays encrypted | Decrypted, but inside a hardware-isolated enclave |
| Trust required | Math only — no trust in the compute provider | Trust in the CPU vendor’s hardware isolation guarantees |
| Performance | Significant overhead, improving but still costly | Near-native speed |
| Maturity | Narrower production use cases today | More widely deployed in cloud offerings |
Confidential computing trusts a hardware boundary; homomorphic encryption removes the need to trust anything but the math. Some systems combine both, using confidential computing for general workloads and homomorphic encryption for the narrower cases where even hardware-level trust is unacceptable.
That distinction matters most when the threat model includes the hardware vendor itself, or a compromise of the enclave. Confidential computing’s guarantees rest on the CPU manufacturer having implemented isolation correctly and not having a backdoor — a reasonable assumption for most threat models, but not a universal one. Homomorphic encryption sidesteps that question entirely: even a fully compromised, malicious server computing on your ciphertext learns nothing, because the data it’s operating on never exists in decrypted form anywhere it can reach.
Where it’s used today
Real deployments tend to cluster around a few use cases: privacy-preserving analytics on healthcare or financial records where regulation prohibits sharing raw data, encrypted machine learning inference where a model provider processes a client’s sensitive input without seeing it, and secure genomic data analysis, where the sensitivity of the underlying data is extreme and the volume of computation is comparatively small. As hardware acceleration and algorithmic improvements continue to narrow the performance gap, the set of practical use cases keeps expanding — but it’s not yet a substitute for standard encryption in general-purpose systems.
The takeaway
Homomorphic encryption lets a third party compute on your data without ever being able to read it, by using encryption schemes whose mathematical structure preserves operations like addition and multiplication through encryption. Fully homomorphic schemes support arbitrary computation but carry a real performance cost, which keeps adoption concentrated in high-sensitivity, lower-throughput use cases rather than as a general-purpose replacement for standard encryption plus access control.
Tagged
Keep reading
Chisato · · 5 min read What Is Envelope Encryption? Data Keys and KEKs Explained
Envelope encryption encrypts data with a data key, then encrypts that key with a master key held in a KMS. How it works, why clouds use it, and key rotation.
Chisato · · 4 min read Post-Quantum Cryptography: Why Migration Starts Now
Quantum computers threaten RSA and ECC. The NIST post-quantum standards are finalized — here's what they replace, what's already deployed, and how to prepare.
Chisato · · 5 min read What Is Data Loss Prevention (DLP)?
Data loss prevention (DLP) is a set of tools and policies that detect and block sensitive data from leaving an organization's control improperly.