Skip to main content
QUICK REVIEW

[论文解读] Private Set Intersection: A Multi-Message Symmetric Private Information Retrieval Perspective

Zhusheng Wang, Karim Banawan|arXiv (Cornell University)|Dec 31, 2019
Cryptography and Data Security参考文献 63被引用 21
一句话总结

本文将私有集合交集(PSI)问题重新表述为多消息对称私有信息检索(MM-SPIR)问题,推导出在 $ P \leq K-1 $ 条件下 MM-SPIR 的信息论和容量为 $ C_{\text{MM-SPIR}} = 1 - \frac{1}{N} $,且 PSI 的最优下载成本为 $ \min\left\{\left\lceil\frac{P_1N_2}{N_2-1}\right\rceil, \left\lceil\frac{P_2N_1}{N_1-1}\right\rceil\right\} $。所提出的方案在不依赖逐次使用单消息 SPIR 方案的前提下实现了容量。

ABSTRACT

We study the problem of private set intersection (PSI). In this problem, there are two entities $E_i$, for $i=1, 2$, each storing a set $\mathcal{P}_i$, whose elements are picked from a finite field $\mathbb{F}_K$, on $N_i$ replicated and non-colluding databases. It is required to determine the set intersection $\mathcal{P}_1 \cap \mathcal{P}_2$ without leaking any information about the remaining elements to the other entity with the least amount of downloaded bits. We first show that the PSI problem can be recast as a multi-message symmetric private information retrieval (MM-SPIR) problem. Next, as a stand-alone result, we derive the information-theoretic sum capacity of MM-SPIR, $C_{MM-SPIR}$. We show that with $K$ messages, $N$ databases, and the size of the desired message set $P$, the exact capacity of MM-SPIR is $C_{MM-SPIR} = 1 - \frac{1}{N}$ when $P \leq K-1$, provided that the entropy of the common randomness $S$ satisfies $H(S) \geq \frac{P}{N-1}$ per desired symbol. This result implies that there is no gain for MM-SPIR over successive single-message SPIR (SM-SPIR). For the MM-SPIR problem, we present a novel capacity-achieving scheme that builds on the near-optimal scheme of Banawan-Ulukus originally proposed for the multi-message PIR (MM-PIR) problem without database privacy constraints. Surprisingly, our scheme here is exactly optimal for the MM-SPIR problem for any $P$, in contrast to the scheme for the MM-PIR problem, which was proved only to be near-optimal. Our scheme is an alternative to the SM-SPIR scheme of Sun-Jafar. Based on this capacity result for MM-SPIR, and after addressing the added requirements in its conversion to the PSI problem, we show that the optimal download cost for the PSI problem is $\min\left\{\left\lceil\frac{P_1 N_2}{N_2-1} ight ceil, \left\lceil\frac{P_2 N_1}{N_1-1} ight ceil ight\}$, where $P_i$ is the cardinality of set $\mathcal{P}_i$

研究动机与目标

  • 将多消息对称私有信息检索(MM-SPIR)问题作为独立问题,表征其信息论容量。
  • 通过将 PSI 建模为带有额外约束的 MM-SPIR 问题,建立私有集合交集(PSI)的根本极限。
  • 设计一种 MM-SPIR 的容量达到方案,其性能优于逐次使用的单消息 SPIR 方案。
  • 在信息论隐私保证下,确定 PSI 的最优下载成本。

提出的方法

  • 通过将每个集合元素建模为一个消息,将交集建模为所需消息集合,将 PSI 问题重新表述为 MM-SPIR 问题。
  • 利用信息论反证法推导 MM-SPIR 的和容量,证明当 $ P \leq K-1 $ 且每符号的公共随机性熵满足 $ H(S) \geq \frac{P}{N-1} $ 时,$ C_{\text{MM-SPIR}} = 1 - \frac{1}{N} $。
  • 提出一种新颖的 MM-SPIR 容量达到方案,基于 Banawan 和 Ulukus 的近优 MM-PIR 方案进行改进,使其满足数据库隐私约束。
  • 证明该方案对 MM-SPIR 是严格最优的,而不同于以往的 MM-PIR 方案仅达到近优性能。
  • 通过引入对称隐私和集合成员检索的附加约束,将 MM-SPIR 容量结果应用于 PSI 问题。
  • 通过可达性证明和反证法验证该方案,表明在容量方面无法通过联合检索超越逐次单消息 SPIR 方案。

实验结果

研究问题

  • RQ1对于具有 $ K $ 个消息、$ N $ 个数据库、且所需消息集合大小为 $ P $ 的多消息对称私有信息检索(MM-SPIR)问题,其信息论容量是多少?
  • RQ2MM-SPIR 问题是否能够实现高于逐次单消息 SPIR 方案的容量,或者联合检索是否无性能增益?
  • RQ3如何利用 MM-SPIR 框架最优地解决私有集合交集(PSI)问题,其最小下载成本是多少?
  • RQ4是否存在一种 MM-SPIR 的容量达到方案,既最优又可无缝扩展自现有 MM-PIR 构造?
  • RQ5独立同分布的元素选择假设对容量结果的普适性以及反证法的成立性有何影响?

主要发现

  • 当 $ P \leq K-1 $ 且每所需符号的公共随机性熵满足 $ H(S) \geq \frac{P}{N-1} $ 时,MM-SPIR 问题的和容量为 $ C_{\text{MM-SPIR}} = 1 - \frac{1}{N} $。
  • 当 $ P = K $ 时,MM-SPIR 容量为平凡的 $ 1 $,因为所有消息均为所需消息,不会发生隐私泄露。
  • 所提出的 MM-SPIR 方案对所有 $ P $ 均为精确最优,而以往的 MM-PIR 方案仅达到近优性能。
  • PSI 问题的最优下载成本为 $ \min\left\{\left\lceil\frac{P_1N_2}{N_2-1}\right\rceil, \left\lceil\frac{P_2N_1}{N_1-1}\right\rceil\right\} $,其中 $ P_i $ 为集合 $ \mathcal{P}_i $ 的大小。
  • 该方案在不依赖逐次使用单消息 SPIR 的前提下实现了最优性能,提供了统一且更高效的解决方案。
  • 上传成本降低的示例表明,在一个 2 个数据库、3 个消息的 SPIR 实例中,上传成本可从 6 位减少至 4 位,且不增加下载成本。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。