Paper 2025/2132
Bandwidth Efficient Partial Authorized PSI
Abstract
Recent attacks on private set intersection (PSI) and PSI-like protocols have demonstrated that input privacy can be compromised when parties maliciously choose their inputs, even in protocols proven secure against malicious adversaries. To counter such attacks, Authorized PSI (APSI) introduces a judge who authorizes the elements of the parties before the intersection is computed. Falzon and Markatou (PETS 2025) proposed Partial-APSI, a privacy-preserving variant of APSI that prevents revealing the entire set to a judge. Their Partial-APSI protocol requires significant bandwidth overhead due to the use of bilinear pairings and because the judge must sign each element in the input set. In this work, we present a bandwidth-efficient Partial-APSI protocol that outperforms Falzon and Markatou, both asymptotically and empirically. For example, for sets of size $2^{20}$, we require around $21\times$ less bandwidth and are about $6\times$ faster over a LAN network. In addition to our protocol, we model the real-world behavior of rational parties through a game-theoretic analysis. We introduce payout mechanisms for detected cheating and establish lower bounds on their values, ensuring that the best strategy for rational parties is to provide honest input.
Note: Minor updates, thanks to the feedback of the anonymous reviewers. Additionally, we corrected the security of the Merkle tree variant of our protocol.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published by the IACR in EUROCRYPT 2026
- Keywords
- Authorized PSIInput maliciousAugmented semi-honestRational adversariesGame theoryMPCverkle treePSI
- Contact author(s)
-
t o koster @ tudelft nl
ffalzon @ ethz ch
e a markatou @ tudelft nl - History
- 2026-07-01: revised
- 2025-11-21: received
- See all versions
- Short URL
- https://ia.cr/2025/2132
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2132,
author = {Tjitske Ollie Koster and Francesca Falzon and Evangelia Anna Markatou},
title = {Bandwidth Efficient Partial Authorized {PSI}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2132},
year = {2025},
url = {https://eprint.iacr.org/2025/2132}
}