What Semi-Homomorphic Encryption Actually Lets You Compute
You can add and multiply encrypted data, but only to a fixed depth before noise makes it unreadable.

Semi-homomorphic encryption, usually shortened to SHE, allows a bounded mix of additions and multiplications on encrypted data, not an unlimited one. The boundary that defines that tier, and the reason it sits exactly where it does, is what this piece works through, from the mechanism that causes the limit to the systems that have been built around it.
The three tiers of homomorphic encryption
Homomorphic encryption schemes divide into three categorically distinct tiers. Partially homomorphic encryption (PHE) supports unlimited operations, but only of exactly one type: addition or multiplication, never both. A scheme built on addition can tally an arbitrary number of encrypted values together without ever running out of room, but it cannot multiply two ciphertexts by each other, not once, regardless of how the system is configured. Fully homomorphic encryption (FHE) is at the other end: it supports unlimited operations of any type, addition and multiplication mixed freely, achieved through an expensive refresh step called bootstrapping that will come up again shortly. Semi-homomorphic encryption occupies the middle, and the shape of that middle is what makes it distinct rather than transitional: it permits both addition and multiplication, mixed together, but only up to a bounded depth. That single word, limited, names the condition that governs what SHE can do with it.
Noise accumulation as the hard ceiling on SHE computation
The limit comes from noise, a quantity baked into every ciphertext in a lattice-based homomorphic scheme that grows every time an operation touches it. Addition adds noise slowly and close to linearly: combining two encrypted values produces a ciphertext whose noise is roughly the sum of the two inputs' noise, a manageable and predictable cost. Multiplication behaves very differently. Multiplying two ciphertexts together causes the noise to grow much faster than addition does. A scheme that tolerates thousands of additions before failing might tolerate only a handful of sequential multiplications before the same ciphertext becomes unreadable. That asymmetry sets the operative constraint engineers actually work against: a scheme's multiplicative depth, sometimes called its circuit depth, which is the number of sequential multiplications it can sustain before noise overwhelms the ciphertext and decryption stops returning the correct answer. Supporting a circuit of multiplicative depth L requires L+1 modulus layers built into the ciphertext structure, and each homomorphic multiplication performed during the computation consumes exactly one of those layers as it executes. When the layers run out, the computation stops, whether or not the underlying task is finished. FHE schemes escape this ceiling through bootstrapping, a procedure that refreshes a ciphertext and resets its noise budget partway through a computation so that further multiplications become possible again. Bootstrapping is computationally expensive, and a January 2025 paper in Electronics identifies it as the primary performance bottleneck in homomorphically encrypted deep neural-network inference. SHE has no such escape hatch. Its depth is fixed at the outset, and once it is spent, it is spent.
Noise Budget and Design Decisions
Because noise grows in a predictable, deterministic way with circuit depth, the order of operations for building anything on SHE runs in reverse of how most engineering normally proceeds. A developer cannot design the computation first and bolt encryption on afterward. The required multiplicative depth has to be worked out before any parameters are chosen, because the parameters themselves are what determine how much depth is available. For schemes without bootstrapping, the entire computation has to be planned to fit inside a noise budget fixed at setup time, and that analysis of circuit depth belongs at the start of the design process, not somewhere after the code already runs. There is a lever to pull: a larger coefficient modulus buys a higher noise budget and permits deeper multiplicative circuits. But it comes at a real cost, since arithmetic over a larger modulus runs slower and the ciphertexts themselves grow larger in memory. Nothing about that trade is free, and the consequence reaches well past the moment of multiplication itself. A developer who chooses a deeper circuit is choosing, in the same decision, larger ciphertext objects and slower operations across the entire pipeline, not only at the specific step where the extra multiplications happen. That is a different kind of worry than conventional encryption asks a developer to carry. With conventional encryption, the encryption layer sits mostly apart from the computation that happens afterward: encrypt the data, do the work, decrypt the result, and the choice of cipher rarely reshapes how the computation itself gets structured. SHE removes that separation. The scheme and the computation are designed together, as one decision. Knowing precisely which operations a given task actually needs, the subject of the next section, is not an academic exercise but the first thing that has to be settled before anything gets built.
What operations SHE supports and cannot handle natively
SHE's computable set is a strict superset of what PHE can do, but it falls well short of arbitrary computation, and the gap between the two is defined precisely by multiplicative depth and by the fact that transcendental functions cannot be evaluated natively. Additive PHE, Paillier being the standard example, supports addition, subtraction, and multiplication of a ciphertext by a known scalar, but not the multiplication of one ciphertext by another ciphertext. That single missing operation is the whole difference between the two tiers. SHE extends the additive case into a bounded mix of both operation types, which opens the door to polynomial evaluation, including multiplication up to some fixed depth and the raising of ciphertexts to powers, though all of it comes at a higher computational cost than pure PHE carries. Polynomial evaluation is the detail that makes SHE useful for more than aggregation: any function that can be approximated well by a polynomial of a manageable degree becomes computable, and that fact is the bridge connecting SHE to a meaningful slice of machine learning inference, where many activation functions admit reasonable polynomial approximations. What SHE and PHE both cannot do is evaluate transcendental functions directly: sign functions, logical functions, indicator functions, trigonometric functions. Under word-wise FHE schemes such as CKKS, BGV, and BFV, those functions still require polynomial approximation rather than direct evaluation; bit-wise FHE schemes like TFHE and FHEW can evaluate them directly through a technique called programmable bootstrapping, with no approximation step needed. That boundary, the inability to touch transcendental functions natively, is the most consequential limit for anyone building machine learning inference on top of these schemes, since activation functions like sigmoid or softmax live in exactly that territory. A Samsung Electronics patent addresses one slice of this gap directly: it performs approximate arithmetic on transcendental functions by executing homomorphic multiplication in a binary tree structure, which reduces the multiplicative depth needed to reach a given approximation quality. That is a specific technique for lowering the depth cost of approximation, and it should be read at that scale.
Real systems built within these bounds
The systems that have actually been built and studied on PHE and SHE share one structural feature: in each case, the designers matched the scheme to the operation type the problem genuinely required. Electronic voting is the cleanest illustration. The Paillier cryptosystem, additive PHE and nothing more, became the dominant choice for e-voting because tallying votes is pure addition from start to finish; the categorical restriction to one operation type is not a compromise in this setting, it is an exact fit. Vehicle-to-grid and smart-grid data aggregation show the same pattern at the level of a basic data-aggregation step: that task predominantly needs additive operations, which makes PHE sufficient there, though some adjacent V2G tasks, anomaly detection and dynamic pricing among them, need richer computation that pushes past what PHE alone can offer. Biometric border control supplies a third case. A 2025 study in Social Science Computer Review, by Hristov-Kalamov and colleagues, built a privacy-preserving ID creation framework on additive PHE, using Paillier together with Elliptic Curve ElGamal, aimed at biometric applications including border control, enabling rapid verification while still meeting ISO biometric security standards. Once again, the workload was purely additive, and the scheme chosen matched it. Multiparty computation over arithmetic circuits shows the fit working in a slightly different shape. Bendlin, Damgård, and coauthors, in a paper published through Springer, showed that semi-homomorphic encryption enables efficient multiparty computation for arithmetic circuits, with an online phase that needs no cryptographic operations at all: parties exchange additive shares and verify information-theoretic MACs, because the SHE layer absorbed the heavier structural work during preprocessing. The last case breaks the pattern of PHE sufficiency on purpose. Buchanan and coauthors used BFV, a somewhat homomorphic, leveled FHE scheme implemented through the OpenFHE library, to match encrypted IP addresses against an encrypted blacklist, and found that BFV compares favorably against Paillier, Damgård-Jurik, Okamoto-Uchiyama, Naccache-Stern, and Benaloh in most cases tested. Bitwise subnet matching cannot be reduced to pure addition, so a richer scheme was the right call, and the case stands as the clearest example in this set of where PHE's categorical limit genuinely bites.
PHE as the right tool for a large class of problems
Set against that record, PHE and SHE look less like stepping stones toward FHE and more like permanent, correct choices for a identifiable class of problems. Wherever a computation reduces to addition, or to a bounded polynomial, choosing PHE or SHE is not a compromise made for lack of something better. FHE's extra power, in that setting, is capacity nobody needed, bought at a cost nobody had to pay. The strongest case against this view comes from the FHE side of the argument: PHE and SHE's limited expressiveness forces protocol-level workarounds, splitting a computation into pieces or routing intermediate values to a trusted party for decryption mid-pipeline, and those workarounds can reintroduce exactly the attack surfaces homomorphic encryption exists to remove. One analysis notes that PHE schemes are limited in expressiveness and require protocol-level workarounds to support more complex functions. The criticism holds, but only under a specific condition: it applies when the scheme has been mismatched to the problem in the first place. Where the computation genuinely reduces to addition, as in voting tallies, gradient aggregation, or the basic aggregation step in V2G networks, there is no mid-pipeline decryption to perform and no attack surface being reintroduced, because the whole computation never leaves the additive structure the scheme was built for. The decision between PHE, SHE, and FHE is therefore an architectural one, driven by analyzing what operations the target computation actually needs, rather than a decision made for the sake of future-proofing or because the more powerful scheme carries more prestige.
Two 2025 developments that complicate the clean PHE/SHE/FHE taxonomy
Two recent lines of work suggest the three-tier picture, useful as it is for reasoning about a problem, is already being blurred at the edges by research moving faster than the taxonomy can track. The first is Hybrid Homomorphic Encryption. A 2024 ACM paper confirmed that combining Paillier, additive, with ElGamal, multiplicative, into a single hybrid scheme achieves both addition and multiplication at once, effectively reconstructing SHE's bounded mix out of two separate PHE components, while still exhibiting a workable level of security and reliability. That result collapses the boundary between PHE and SHE that the earlier sections of this piece treated as fixed, showing it can be approximated by composition rather than requiring a distinct scheme built from scratch. The second development concerns noise management itself. A January 2026 paper in Electronics applied reinforcement learning to adaptively manage the SHE noise budget during encrypted neural-network inference, addressing the fact that the substantial multiplicative depth of modern deep neural networks consumes that budget quickly and would otherwise force frequent bootstrapping. The RL-based scheduling defers or reduces that bottleneck without requiring a move to full FHE. Taken together, these two results point in a shared direction: the choice of tier is starting to look like something tunable at runtime, rather than a fixed commitment made once at design time and never revisited. A third line of work extends the same lesson to constrained environments. Megías, writing in the Journal of Information Security and Applications, demonstrates privacy-preserving aggregation of watermarked sensor data using partially homomorphic encryption, Paillier for aggregation and ElGamal for individual encryption, carried out over complex number arithmetic. That result shows additive PHE remaining the correct tier for resource-constrained edge devices even as more capable schemes become available elsewhere, which is a reminder that the newest tool is not automatically the right one. The question that follows from all three results is practical: given a specific computation in front of a specific engineer, how should the tier actually get chosen?
Choosing the right tier for a privacy-preserving computation
The right tier follows from the operation type and depth of the target computation, and starting anywhere else tends to produce a system that is either overbuilt or outright broken. The first step has to be decomposition: breaking the target computation down into its primitive operations and counting the multiplicative depth required, an analysis that has to happen before any cryptographic library or scheme gets selected, not after. If that analysis shows the computation is purely additive, covering tallying, aggregation, or gradient accumulation, PHE is both sufficient and the optimal choice, since PHE schemes carry out homomorphic operations much faster than FHE schemes do on workloads of exactly this shape. If the computation instead needs a bounded mix of addition and multiplication, such as polynomial evaluation or inference at a modest depth, SHE becomes the appropriate tier, provided the circuit depth is planned against the scheme's noise budget from the very first design decision rather than discovered partway through implementation. Where the computation requires transcendental functions, or depth that cannot be bounded in advance, two paths remain open: approximate those functions with a polynomial and stay inside SHE, or accept the bootstrapping overhead that comes with moving to full FHE. The Samsung Electronics binary-tree approach to structuring homomorphic multiplication is one concrete way of lowering the depth cost of that approximation, among the strategies available to a designer facing that fourth case. What ties all four steps together is the same principle that opened this piece: the operation type a computation needs, counted and planned before any code gets written, is what decides which tier of homomorphic encryption actually fits.
Sources
- Privacy-Aware White and Black List Searching for Fraud Analysis
- Homomorphic encryption system for supporting approximate arithmetic operation and method of operating the same
- Semi-homomorphic Encryption and Multiparty Computation
- A Reinforcement Learning-Based Optimization Strategy for Noise Budget Management in Homomorphically Encrypted Deep Network Inference
- Partially homomorphic framework for secure privacy-preserving ID creation - Nikola Hristov-Kalamov, Raúl Fernández-Ruiz, Cristina Conde, Agustín Álvarez-Marquina, Francisco Domínguez-Mateos, Pedro Gómez-Vilda, Daniel Palacios-Alonso, 2025
- A Comparative Study of Partially, Somewhat, and Fully Homomorphic Encryption in Modern Cryptographic Libraries
- Encrypted Vector Similarity Computations Using Partially ...
- Noise-Resilient Homomorphic Encryption: A Framework for Secure Data Processing in Health care Domain


