Skip to main content
QUICK REVIEW

[Paper Review] Multi-Message Private Information Retrieval: Capacity Results and Near-Optimal Schemes

Karim Banawan, Şennur Ulukuş|arXiv (Cornell University)|Feb 6, 2017
Cryptography and Data Security22 references16 citations
TL;DR

This paper establishes the information-theoretic sum capacity of multi-message private information retrieval (MPIR) from N non-communicating replicated databases, where a user retrieves P out of M messages privately. It derives exact capacity for P ≥ M/2 and tight bounds for P < M/2, showing joint retrieval of multiple messages is strictly more efficient than sequential single-message retrieval, with a maximum gap of 0.0082 between bounds for N=2, M=5, P=2.

ABSTRACT

We consider the problem of multi-message private information retrieval (MPIR) from $N$ non-communicating replicated databases. In MPIR, the user is interested in retrieving $P$ messages out of $M$ stored messages without leaking the identity of the retrieved messages. The information-theoretic sum capacity of MPIR $C_s^P$ is the maximum number of desired message symbols that can be retrieved privately per downloaded symbol. For the case $P \geq \frac{M}{2}$, we determine the exact sum capacity of MPIR as $C_s^P=\frac{1}{1+\frac{M-P}{PN}}$. The achievable scheme in this case is based on downloading MDS-coded mixtures of all messages. For $P \leq \frac{M}{2}$, we develop lower and upper bounds for all $M,P,N$. These bounds match if the total number of messages $M$ is an integer multiple of the number of desired messages $P$, i.e., $\frac{M}{P} \in \mathbb{N}$. In this case, $C_s^P=\frac{1-\frac{1}{N}}{1-(\frac{1}{N})^{M/P}}$. The achievable scheme in this case generalizes the single-message capacity achieving scheme to have unbalanced number of stages per round of download. For all the remaining cases, the difference between the lower and upper bound is at most $0.0082$, which occurs for $M=5$, $P=2$, $N=2$. Our results indicate that joint retrieval of desired messages is more efficient than successive use of single-message retrieval schemes.

Motivation & Objective

  • To determine the information-theoretic sum capacity of multi-message private information retrieval (MPIR) from N non-communicating, replicated databases.
  • To analyze the efficiency gain of jointly retrieving P messages versus sequentially retrieving them one-by-one using single-message PIR schemes.
  • To derive tight lower and upper bounds on the sum capacity for all M, P, N, especially when M/P is not an integer.
  • To propose a novel achievable scheme based on MDS-coded mixtures and unbalanced download stages that generalizes single-message PIR to multi-message retrieval.
  • To demonstrate that joint retrieval achieves higher retrieval rates and is information-theoretically optimal under privacy constraints.

Proposed method

  • Derives the sum capacity for P ≥ M/2 as C_s^P = 1 / (1 + (M−P)/(PN)) using MDS-coded mixtures of all messages.
  • Proposes a novel achievable scheme for P ≤ M/2 based on unbalanced download stages per round, generalizing the single-message PIR scheme.
  • Establishes an inductive relation for the entropy of answer strings, reducing the M-message MPIR problem to a smaller (M−2P)-message problem.
  • Uses entropy inequalities and the interference conditioning lemma to derive upper bounds on the download cost.
  • Applies the symmetry and alignment principles from single-message PIR to the multi-message setting, extending them to handle multiple desired messages.
  • Evaluates bounds numerically and shows the gap between lower and upper bounds is at most 0.0082, occurring at N=2, M=5, P=2.

Experimental results

Research questions

  • RQ1What is the exact information-theoretic sum capacity of MPIR when the number of desired messages P is at least half the total messages M?
  • RQ2How does the performance of joint multi-message retrieval compare to sequentially applying single-message PIR schemes?
  • RQ3What are the tightest possible lower and upper bounds on the MPIR sum capacity when M is not an integer multiple of P?
  • RQ4Can the sum capacity be expressed in a closed form that generalizes the single-message PIR capacity expression?
  • RQ5What is the maximum gap between the lower and upper bounds on the sum capacity across all parameter values?

Key findings

  • For P ≥ M/2, the exact sum capacity is C_s^P = 1 / (1 + (M−P)/(PN)), achieved via MDS-coded mixtures of all messages.
  • For P ≤ M/2 and when M/P is an integer, the sum capacity is C_s^P = (1 − 1/N) / (1 − (1/N)^{M/P}), which generalizes the single-message PIR capacity.
  • When M/P is not an integer, the gap between the lower and upper bounds on the sum capacity is at most 0.0082, with the worst case occurring at N=2, M=5, P=2.
  • The proposed achievable scheme for P ≤ M/2 uses unbalanced download stages per round, enabling efficient alignment of interference across databases.
  • Joint retrieval of multiple messages strictly outperforms sequential single-message retrieval, demonstrating a fundamental efficiency gain in the information-theoretic setting.
  • The inductive bound on the entropy of answer strings enables a recursive derivation of the sum capacity, generalizing the single-message induction in prior work.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.