Paper 2025/1816

Pool: A Practical OT-based OPRF from Learning with Rounding

Alex Davidson, LASIGE, Faculdade de Ciências, Universidade de Lisboa
Amit Deo, Zama
Louis Tremblay Thibault, Zama, École de technologie supérieure
Abstract

We propose Pool: a conceptually simple post-quantum (PQ) oblivious pseudorandom function (OPRF) protocol, that is round-optimal (with input-independent preprocessing), practically efficient, and has security based on the well-understood hardness of the learning with rounding (LWR) problem. Specifically, our design permits oblivious computation of the LWR-based pseudorandom function $F_{\mathsf{sk}}(x) = \lceil H(x)^{\top} \cdot \mathsf{sk} \rfloor_{q,p}$, for random oracle $H: \{0,1\}^* \mapsto \mathbb{Z}_q^n$ and uniformly chosen $\mathsf{sk} \in \{0,1\}^n$. For 128-bits of semi-honest security, the Pool OPRF has an online communication cost of 11.9~kB, and a computational runtime of less than 2~ms on a single thread (via an open-source software implementation). This is more efficient (in either online communication cost or runtime) than constructions from well-known PQ PRFs, and is competitive even with constructions that only conjecture PQ security on lesser-known assumptions. As a result, our design gives high-performance, post-quantum variants of established OPRF applications in multi-party computation and private set operation protocols.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. ACM CCS 2025
DOI
10.1145/3719027.3765054
Keywords
Oblivious Pseudorandom FunctionsOPRFsPost-quantumLatticesLearning with Rounding
Contact author(s)
alex davidson @ fc ul pt
amit deo @ zama ai
louis tremblay thibault @ zama ai
History
2025-10-08: approved
2025-10-03: received
See all versions
Short URL
https://ia.cr/2025/1816
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1816,
      author = {Alex Davidson and Amit Deo and Louis Tremblay Thibault},
      title = {Pool: A Practical {OT}-based {OPRF} from Learning with Rounding},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1816},
      year = {2025},
      doi = {10.1145/3719027.3765054},
      url = {https://eprint.iacr.org/2025/1816}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.