Post-Quantum Private Set Intersection for Small Sets
Junxin Liu, Mike Rosulek, Ni Trieu
Abstract
Are private set intersection (PSI) protocols ready for the post-quantum future? We focus on the PSI protocol of Rosulek & Trieu (``RT21'', ACM CCS 2021), which is the current state-of-the-art for PSI on small sets (less than a thousand items). The RT21 protocol presents some fundamental barriers to post-quantum security. First, although it is written in terms of an arbitrary KEM, it requires certain properties of Diffie-Hellman KEM that simply are not satisfied by any post-quantum candidates. Second, even if adapted to post-quantum KEMs, it would require an ideal permutation with blocklength larger than any known viable candidate.
We show how to modify the RT21 to make it compatible with post-quantum KEM candidates like ML-KEM. We also describe a direct domain-extension construction for ideal permutations, showing how to construct a huge-block ideal permutation directly from one with smaller blocklength, such as the Keccak permutation family. Along the way, we also introduce new abstractions for oblivious key-value stores (Garimella et al., Crypto 2021) that make the analysis of these kinds of PSI protocols more modular.
We implemented our protocol and evaluated its performance across different network settings and instantiations. We achieve PSI from standardized post-quantum primitives with latency as low as ms/item and communication as low as KiB/item. We find that the performance penalty for post-quantum security ranges from 1.25 to 5.92 in latency and is 16.7 in communication, depending on the instantiation.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Maliciously Secure Shuffled Distributed OPRF with Applications to Private Set OperationsAron van Baarsen, Aarushi Goel, Lisa Kohl, Peihan Miao et al.CCS 2026
- Malicious-Secure Private Set Intersection via Dual ExecutionPeter Rindal, Mike RosulekCCS 2017 · 135 citations
- Compact and Malicious Private Set Intersection for Small SetsMike Rosulek, Ni TrieuCCS 2021
- Labeled PSI from Fully Homomorphic Encryption with Malicious SecurityHao Chen, Zhicong Huang, Kim Laine, Peter RindalCCS 2018 · 242 citations
- Efficient Fuzzy Private Set Intersection from Secret-Shared OPRFXinpeng Yang, Meng Hao, Chenkai Weng, Robert H. Deng et al.S&P 2026 · 2 citations
