Paper 2026/1985
Post-Quantum Private Set Intersection for Small Sets
Abstract
Are private set intersection (PSI) protocols ready for the post-quantum future? We focus on the PSI protocol of Rosulek \& Trieu (``RT21'', ACM CCS 2021), which is the current state-of-the-art for PSI on small sets (less than a thousand items). The RT21 protocol presents some fundamental barriers to post-quantum security. First, although it is written in terms of an arbitrary KEM, it requires certain properties of Diffie-Hellman KEM that simply are not satisfied by any post-quantum candidates. Second, even if adapted to post-quantum KEMs, it would require an ideal permutation with blocklength larger than any known viable candidate. We show how to modify the RT21 to make it compatible with post-quantum KEM candidates like ML-KEM. We also describe a direct domain-extension construction for ideal permutations, showing how to construct a huge-block ideal permutation directly from one with smaller blocklength, such as the Keccak permutation family. Along the way, we also introduce new abstractions for \emph{oblivious key-value stores} (Garimella et al., Crypto 2021) that make the analysis of these kinds of PSI protocols more modular. We implemented our protocol and evaluated its performance across different network settings and instantiations. We achieve PSI from standardized post-quantum primitives with latency as low as $0.25$ ms/item and communication as low as $1.67$ KiB/item. We find that the performance penalty for post-quantum security ranges from 1.25$\times$ to 5.92$\times$ in latency and is 16.7$\times$ in communication, depending on the instantiation.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Major revision. ACM CCS 2026
- Keywords
- private set intersectionpost-quantum
- Contact author(s)
-
liujunx @ oregonstate edu
rosulekm @ eecs oregonstate edu
nitrieu @ asu edu - History
- 2026-09-14: approved
- 2026-09-11: received
- See all versions
- Short URL
- https://ia.cr/2026/1985
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1985,
author = {Junxin Liu and Mike Rosulek and Ni Trieu},
title = {Post-Quantum Private Set Intersection for Small Sets},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1985},
year = {2026},
url = {https://eprint.iacr.org/2026/1985}
}