property of a cryptographic proof that allows certain types of operations to be performed on ciphertext in such a way that the result of these operations when decrypted matches the result of performing the same operations on the original plaintext