• property of a cryptographic proof
  • that allows certain types of operations to be performed on ciphertext
  • in such a way that the result of these operations when decrypted
  • matches the result of performing the same operations
  • on the original plaintext