Lune

CRYPTO2024Top-tier venue

Fully Malicious Authenticated PIR

Marian Dietz, Stefano Tessaro

2024Year
8Citations
4Top-tier citations

Abstract

Authenticated PIR enables a server to initially commit to a database of NN items, for which a client can later privately obtain individual items with complexity sublinear in NN, with the added guarantee that the retrieved item is consistent with the committed database. A crucial requirement is privacy with abort, i.e., the server should not learn anything about a query even if it learns whether the client aborts.

This problem was recently considered by Colombo et al. (USENIX '23), who proposed solutions secure under the assumption that the database is committed to honestly. Here, we close this gap for their DDH-based scheme, and present a solution that tolerates fully malicious servers that provide potentially malformed commitments. Our scheme has communication and client computational complexity Oλ(N)\mathcal{O}_{\lambda}(\sqrt{N}), does not require any additional assumptions, and does not introduce heavy machinery (e.g., generic succinct proofs). We do so by introducing validation queries, which, from the server's perspective, are computationally indistinguishable from regular PIR queries. Provided that the server succeeds in correctly answering κ\kappa such validation queries, the client is convinced with probability 1−12κ1-\frac{1}{2^\kappa} that the server is unable to break privacy with abort.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Cited by top-tier papers4

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines