Lune

EUROCRYPT2026Top-tier venue

Is PSI Really Faster Than PSU? Achieving Efficient PSU with Invertible Bloom Filters

Lucas Piske, Ni Trieu

2026Year
2Citations

Abstract

Private Set Union (PSU) enables two parties to compute the union of their private sets without revealing anything beyond the union itself. Existing PSU protocols remain much slower than private set intersection (PSI), often by a factor of around 30×30\times.

In this work, we present the first PSU protocol based on Invertible Bloom Lookup Tables (IBLTs), introducing a fundamentally new framework that departs from traditional, inefficient approaches. Our protocol exploits structural invariants between each party’s IBLTs and their union to compute the union efficiently without explicitly constructing a combined IBLT. Central to our approach is the notion of union peelability, which allows union elements to be recovered directly from the original IBLTs. We securely implement this functionality using only Oblivious Transfer (OT) and Oblivious Pseudorandom Function (OPRF) for equality checks, ensuring no information beyond the union is leaked.

As a result, for set sizes ranging from 2142^{14} to 2202^{20}, our protocol achieves a runtime of 0.080.08 to 2.952.95 seconds in the LAN setting, which is comparable to state-of-the-art PSI. We also show substantial speedups over prior PSU work—up to 10×10\times faster in LAN settings and consistently faster in WAN scenarios—while maintaining linear computation and communication complexity with small constants.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 4b6f6108-1246-4efc-8703-d722c752375d

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines