Pool: A Practical OT-based OPRF from Learning with Rounding
Alex Davidson, Amit Deo, Louis Tremblay Thibault
Abstract
We propose Pool: a conceptually simple post-quantum (PQ) oblivious pseudorandom function (OPRF) protocol, that is round-optimal (with input-independent preprocessing), practically efficient, and has security based on the well-understood hardness of the learning with rounding (LWR) problem. Specifically, our design permits oblivious computation of the LWR-based pseudorandom function Fsk(x) = ⌉ H(x)⊤ ⋅ sk ⌋q,p, for random oracle H: 0,1 * → ℤ qn and uniformly chosen sk∈ 0,1 n. For 128-bits of semi-honest security, the Pool OPRF has an online communication cost of 11.9 kB, and a computational runtime of less than 3 ms on a single thread (via an open-source software implementation). This is more efficient (in either online communication cost or runtime) than constructions from well-known PQ PRFs, and is competitive even with constructions that only conjecture PQ security on lesser-known assumptions. As a result, our design gives high-performance, post-quantum variants of established OPRF applications in multi-party computation and private set operation protocols.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 478a3328-aa39-42db-a4b2-653a59ef605bBuilds on16
- Efficient Batched Oblivious PRF with Applications to Private Set IntersectionVladimir Kolesnikov, Ranjit Kumaresan, Mike Rosulek, Ni TrieuCCS 2016 · 429 citations
- PSI from PaXoS: Fast, Malicious Private Set IntersectionBenny Pinkas, Mike Rosulek, Ni Trieu, Avishay YanaiEUROCRYPT 2020 · 198 citations
- Protocols for Checking Compromised CredentialsLucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan et al.CCS 2019 · 80 citations
- LaBRADOR: Compact Proofs for R1CS from Module-SISWard Beullens, Gregor SeilerCRYPTO 2023 · 59 citations
- Endemic Oblivious TransferDaniel Masny, Peter RindalCCS 2019 · 50 citations
Related papers
- The 2Hash OPRF Framework and Efficient Post-quantum InstantiationsWard Beullens, Lucas Dodgson, Sebastian H. Faller, Julia HesseEUROCRYPT 2025 · 14 citations
- LeOPaRd: Towards Practical Post-quantum Oblivious PRFs via 2HashDH ParadigmMuhammed F. Esgin, Ron Steinfeld, Erkan Tairi, Jie XuCRYPTO 2026
- Leap: A Fast, Lattice-Based OPRF with Application to Private Set IntersectionLena Heimberger, Daniel Kales, Riccardo Lolato, Omid Mir et al.EUROCRYPT 2025 · 9 citations
- Gold OPRF: Post-Quantum Oblivious Power-Residue PRFYibin Yang, Fabrice Benhamouda, Shai Halevi, Hugo Krawczyk et al.S&P 2025
- High-throughput Verifiable Distributed OPRF from Gold PRFNan Cheng, Yohei Watanabe, Yugo Kasashima, Ioannis Katis et al.CCS 2026
