Paper 2025/1816
Pool: A Practical OT-based OPRF from Learning with Rounding
Abstract
We propose Pool: a conceptually simple post-quantum (PQ) oblivious pseudorandom function (OPRF) protocol, that is round-optimal (with input-independent preprocessing), practically efficient, and has security based on the well-understood hardness of the learning with rounding (LWR) problem. Specifically, our design permits oblivious computation of the LWR-based pseudorandom function $F_{\mathsf{sk}}(x) = \lceil H(x)^{\top} \cdot \mathsf{sk} \rfloor_{q,p}$, for random oracle $H: \{0,1\}^* \mapsto \mathbb{Z}_q^n$ and uniformly chosen $\mathsf{sk} \in \{0,1\}^n$. For 128-bits of semi-honest security, the Pool OPRF has an online communication cost of 11.9~kB, and a computational runtime of less than 2~ms on a single thread (via an open-source software implementation). This is more efficient (in either online communication cost or runtime) than constructions from well-known PQ PRFs, and is competitive even with constructions that only conjecture PQ security on lesser-known assumptions. As a result, our design gives high-performance, post-quantum variants of established OPRF applications in multi-party computation and private set operation protocols.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Minor revision. ACM CCS 2025
- DOI
- 10.1145/3719027.3765054
- Keywords
- Oblivious Pseudorandom FunctionsOPRFsPost-quantumLatticesLearning with Rounding
- Contact author(s)
-
alex davidson @ fc ul pt
amit deo @ zama ai
louis tremblay thibault @ zama ai - History
- 2025-10-08: approved
- 2025-10-03: received
- See all versions
- Short URL
- https://ia.cr/2025/1816
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1816,
author = {Alex Davidson and Amit Deo and Louis Tremblay Thibault},
title = {Pool: A Practical {OT}-based {OPRF} from Learning with Rounding},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1816},
year = {2025},
doi = {10.1145/3719027.3765054},
url = {https://eprint.iacr.org/2025/1816}
}