A Fast and Simple Partially Oblivious PRF, with Applications
Nirvan Tyagi, Sofía Celi, Thomas Ristenpart, Nick Sullivan, Stefano Tessaro, Christopher A. Wood
Abstract
We build the first construction of a partially oblivious pseudorandom function (POPRF) that does not rely on bilinear pairings. Our construction can be viewed as combining elements of the 2HashDH OPRF of Jarecki, Kiayias, and Krawczyk with the Dodis-Yampolskiy PRF. We analyze our POPRF's security in the random oracle model via reduction to a new one-more gap strong Diffie-Hellman inversion assumption. The most significant technical challenge is establishing confidence in the new assumption, which requires new proof techniques that enable us to show that its hardness is implied by the q-DL assumption in the algebraic group model.
Our new construction is as fast as the current, standards-track OPRF 2HashDH protocol, yet provides a new degree of flexibility useful in a variety of applications. We show how POPRFs can be used to prevent token hoarding attacks against Privacy Pass, reduce key management complexity in the OPAQUE password authenticated key exchange protocol, and ensure stronger security for password breach alerting services.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4c903e28-f8d1-41b1-b19b-cc34f1e19fc1Cited by top-tier papers10
- Leap: A Fast, Lattice-Based OPRF with Application to Private Set IntersectionLena Heimberger, Daniel Kales, Riccardo Lolato, Omid Mir et al.EUROCRYPT 2025 · 9 citations
- Secure Account Recovery for a Privacy-Preserving Web ServiceRyan Little, Lucy Qin, Mayank VariaUSENIX Security 2024 · 7 citations
- Non-interactive Anonymous Tokens with Private Metadata BitFoteini Baldimtsi, Lucjan Hanzlik, Quan Nguyen, Aayush YadavCCS 2026 · 5 citations
- POPSTAR: Lightweight Threshold Reporting with Reduced LeakageHanjun Li, Sela Navot, Stefano TessaroUSENIX Security 2024 · 5 citations
- Security Analysis of Privately Verifiable Privacy PassKonrad Hanff, Anja Lehmann, Cavit ÖzbayCCS 2025
Builds on7
- Blind Schnorr Signatures and Signed ElGamal Encryption in the Algebraic Group ModelGeorg Fuchsbauer, Antoine Plouviez, Yannick SeurinEUROCRYPT 2020 · 109 citations
- Protocols for Checking Compromised CredentialsLucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan et al.CCS 2019 · 80 citations
- Two-Sided Malicious Security for Private Intersection-Sum with CardinalityPeihan Miao, Sarvar Patel, Mariana Raykova, Karn Seth et al.CRYPTO 2020 · 60 citations
- A Classification of Computational Assumptions in the Algebraic Group ModelBalthazar Bauer, Georg Fuchsbauer, Julian LossCRYPTO 2020 · 45 citations
- Anonymous Tokens with Private Metadata BitBen Kreuter, Tancrède Lepoint, Michele Orrù, Mariana RaykovaCRYPTO 2020 · 35 citations
Related papers
- A Fully-Adaptive Threshold Partially-Oblivious PRFRuben Baecker, Paul Gerhart, Daniel Rausch, Dominique SchröderCRYPTO 2025 · 1 citation
- Crypto Dark Matter on the Torus - Oblivious PRFs from Shallow PRFs and TFHEMartin R. Albrecht, Alex Davidson, Amit Deo, Daniel GardhamEUROCRYPT 2024 · 27 citations
- Combining Oblivious Pseudorandom FunctionsSebastian H. Faller, Marc Fischlin, Julius Hardt, Julia HesseEUROCRYPT 2026 · 1 citation
- The 2Hash OPRF Framework and Efficient Post-quantum InstantiationsWard Beullens, Lucas Dodgson, Sebastian H. Faller, Julia HesseEUROCRYPT 2025 · 14 citations
- High-throughput Verifiable Distributed OPRF from Gold PRFNan Cheng, Yohei Watanabe, Yugo Kasashima, Ioannis Katis et al.CCS 2026
