Skip to main content
PVAC-HFHE supports encrypting arbitrary strings using enc_text and dec_text. This guide shows how to work with encrypted text.

Quick start

How it works

Text encryption packs strings into field elements using a chunked encoding:
1

Encode length

First ciphertext stores the string length as a uint64
2

Pack chunks

String is split into 15-byte chunks, each packed into a field element (127 bits)
3

Encrypt chunks

Each chunk is encrypted with increasing depth hints for better noise distribution
Each field element can hold 15 bytes (120 bits) within the 127-bit field, leaving 7 bits for safety margin.

Encryption function

From include/pvac/utils/text.hpp:39-61:

Packing algorithm

From include/pvac/utils/text.hpp:15-26:
The packing uses little-endian byte order. The first byte goes to the LSB of lo, bytes 8-14 go to hi.

Decryption function

From include/pvac/utils/text.hpp:63-87:

Unpacking algorithm

From include/pvac/utils/text.hpp:28-36:

Examples

ASCII text

From examples/basic_usage.cpp:230-232:

Special characters

From examples/basic_usage.cpp:234-236:

UTF-8 text

From examples/basic_usage.cpp:238-240:

Empty string

From examples/basic_usage.cpp:242-244:

Storage requirements

For a string of length N:
Text encryption is relatively expensive due to multiple ciphertexts. For short strings, consider encrypting a hash instead.

Performance characteristics

Encryption time

For a string of length N:
Examples:
  • 15 bytes: ~168ms (2 encryptions)
  • 100 bytes: ~672ms (8 encryptions)
  • 1000 bytes: ~5.7s (68 encryptions)

Decryption time

For a string of length N:
Examples:
  • 15 bytes: ~26ms
  • 100 bytes: ~104ms
  • 1000 bytes: ~884ms
Decryption is ~6.5x faster than encryption, similar to the ratio for numeric values.

Depth hint strategy

The encryption function uses increasing depth hints:
This ensures:
  • First chunk (depth 2): Optimized for short strings
  • Later chunks (depth 3+): More noise budget for longer strings
Starting at depth 2 provides a balance between encryption time and noise budget for typical text lengths.

Working with encrypted text

You can perform limited operations on encrypted text:

Concatenation

Direct text concatenation requires manual length adjustment. This is not a built-in feature.

Length queries

The first ciphertext always contains the length:

Limitations

No homomorphic operations

Unlike numeric encryption, you cannot:
  • Compare encrypted strings
  • Search encrypted text
  • Perform pattern matching on ciphertexts
Text encryption is designed for confidentiality, not computation. For searchable encryption, consider alternative schemes.

Binary data

The encoding supports arbitrary binary data, not just text:

Security considerations

Length leakage

The number of ciphertexts reveals the approximate string length:
This is a known side-channel in chunk-based encryption.

Randomization

Each encryption is fully randomized:

Best practices

For short strings (< 100 bytes)

For long strings (> 1 KB)

For strings longer than 1 KB, hybrid encryption (AES + PVAC) is significantly more efficient.

Next steps

Basic operations

Learn fundamental encryption operations

Performance tuning

Optimize text encryption performance