Paper 2025/2177

TAPIR: A Two-Server Authenticated PIR Scheme with Preprocessing

Francesca Falzon, ETH Zurich
Laura Hetz, ETH Zurich
Annamira O'Toole, ETH Zurich
Abstract

Authenticated Private Information Retrieval (APIR) enables a client to retrieve a record from a public database and verify that the record is “authentic” without revealing any information about which record was requested. In this work, we propose Tapir: the first two-server APIR scheme to achieve both sublinear communication and computation complexity for queries, while also supporting dates. Our scheme builds upon the unauthenticated two-server PIR scheme SinglePass (Lazzaretti and Papamanthou, USENIX’24). Due to its modular design, Tapir provides different trade-offs depending on the underlying vector commitment scheme used. Moreover, Tapir is the first APIR scheme with preprocessing to support appends and edits in time linear in the database partition size. This makes it an ideal candidate for transparency applications that require support for integrity, database appends, and private lookups. We provide a formal security analysis and a prototype implementation that demonstrates our scheme’s efficiency. Tapir incurs as little as 0.11 % online bandwidth overhead for databases of size $2^{22}$, compared to the unauthenticated SinglePass. For databases of size $\geq 2^{20}$, our scheme, when instantiated with Merkle trees, outperforms all prior multi-server APIR schemes with respect to online runtime.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Major revision. ACNS 2026
Keywords
Private Information RetrievalAuthenticated PIRPIR
Contact author(s)
ffalzon @ ethz ch
lahetz @ ethz ch
aotoole @ ethz ch
History
2025-12-02: approved
2025-12-01: received
See all versions
Short URL
https://ia.cr/2025/2177
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2177,
      author = {Francesca Falzon and Laura Hetz and Annamira O'Toole},
      title = {{TAPIR}: A Two-Server Authenticated {PIR} Scheme with Preprocessing},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2177},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2177}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.