Secure Intrusion Detection based on Homomorphic Encryption and Secret Sharing
Peiyin Yao · Atlantis highlights in economics, business and management/Atlantis Highlights in Economics, Business and Management · 2025
With the increasing complexity of network attack methods, there are serious data leakage risks and system stability problems in traditional Intrusion Detection System (IDS) in data collection, transmission, a1nalysis and storage.Therefore, this paper proposes a Private Secure Intrusion Detection System (PSIDS) that integrates Fully Homomorphic Encryption (FHE) and Shamir secret sharing mechanism.Build an end-to-end data protection and anti-attack system.PSIDS introduces an encryption and decryption layer on the basis of the traditional three-layer architecture, and uses the BFV algorithm to encrypt the original traffic, so that the detection node can directly perform detection and analysis on the encrypted data, achieving "data available but not visible"; At the same time, the Shamir (t, n) threshold secret sharing mechanism is introduced in the system, and the key data of the intrusion detection model are divided into n shares for distributed storage.Only when at least t nodes cooperate, the original information can be reconstructed, which effectively resists single-point attacks and improves the robustness of the system.The experiment compares PSIDS with Centralized IDS, Distributed IDS and Machine Learning based IDS.The results show that PSIDS has achieved breakthroughs in data privacy and system stability.The collaborative application of FHE and secret sharing technology in IDS is realized for the first time.