• No results found

dvir.pptx

N/A
N/A
Protected

Academic year: 2020

Share "dvir.pptx"

Copied!
37
0
0

Loading.... (view fulltext now)

Full text

(1)

2-Server PIR with

sub-polynomial

communication

Zeev Dvir

Princeton University

Joint work with Sivakanth

(2)

Private Information Retrieval [CKGS98]

User

๐’‚

๐’•

=

?

Server

User wants to retrieve without revealing to

(3)

Private Information Retrieval [CKGS98]

User

๐’‚

๐’•

=

?

Server

Formally: The distribution of

messages sent by the user do not depend on

(4)

Private Information Retrieval [CKGS98]

Two broad types of protocols:

Single Server + Cryptographic assumptions

(5)

Private Information Retrieval [CKGS98]

Focus of this talk: 2-Server PIR

(hardest)

๐’‚

๐’•

=

?

Server 1

Server 2

Distribution of messages sent

to each server is independent

(6)

Private Information Retrieval [CKGS98]

Focus of this talk: 2-Server PIR

(hardest)

๐’‚

๐’•

=

?

Server 1

Server 2

Simplest: One round most protocols)

* User sends one message to each server

(7)

Private Information Retrieval [CKGS98]

Focus of this talk: 2-Server PIR

(hardest)

๐’‚

๐’•

=

?

Server 1

Server 2

Perfect correctness : User always

(8)

Upper bounds:

# Servers Cost Ref method

) [CGKS95 ,BI01, WY05]

Low degree polynomials +Composition ) [CGKS95]

) [Amb97] [BIKR02]

[Yek08, Efr09] Matching-Vector Families

[This work] MV codes viewed as polynomials [DGY10]

(9)

Lower bounds

[WdW05] for 2-Server PIR [RY05] lower bound for 2-server bilinear group-based

schemes.

โ€ข Captures all previous

constructions

โ€ข Our protocol can be made

bilinear but is not group based*

(10)

Talk Outline

โ€ข

Overview of existing

constructions

โ€ข

The new protocol

โ€ข

PIR and LDCs

(11)

A 6-Server scheme

[Yek08,Efr09,

First ingredient: Matching Vector

DGY10

]

Family

mod 6 iff

[Gro99] Exists with Second Ingredient:

Field , with of order (e.g.

(12)

A 6-Server scheme [Yek08,Efr09,DGY10]

,

mod 6 iff of order

Database User wants

ยฟ ๐œธ ยฟ๐’Œ โ‰ˆ ๐’๐Ÿ”๐’Œ

User picks random

๐’›

๐’—๐’•

Restrict of to the `line' :

๐“ (๐’” )=๐‘ท ๐’‚(๐œธ ๐’›+๐’” ๐’—๐’•) ,๐’”

=๐ŸŽ,๐Ÿ,๐Ÿ, โ€ฆ ,๐Ÿ“

Claim: is a degree 5

polynomial in whose value at zero gives

Each server stores values of over

(13)

A 6-Server scheme [Yek08,Efr09,DGY10]

,

mod 6 iff of order

๐“ (๐’”)=๐‘ท ๐’‚ (๐œธ ๐’›+๐’” ๐’—๐’•)

=โˆ‘๐ข๐’=๐Ÿ ๐’‚๐ข(๐œธ ยฟยฟ ๐’› + ๐’” ๐’—๐’•)๐ฎ๐ข

ยฟ

ยฟ

โˆ‘

๐’๐ข=๐Ÿ

๐’‚

๐ข

๐œธ

ยฟ

ยฟ

ยฟ โˆ‘๐’๐ข=๐Ÿ ๐’‚๐ข ๐œธ ยฟ ๐’› , ๐’–๐’Š>ยฟ ๐œธ

ยฟ

ยฟ

ยฟ

ยฟ

๐’‚

๐’•

๐œธ

ยฟ ๐’› , ๐’–๐’•> ยฟ+

โˆ‘

๐Ÿโ‰ค๐’“ โ‰ค ๐Ÿ“

๐’„๐’“ (๐œธ ๐’”)๐’“ ยฟ

= Degree 5 polynomial such that determines

mod 6

(14)

A 6-Server scheme [Yek08,Efr09,DGY10]

,

mod 6 iff of order

Database User wants

Each server stores values of

over ยฟ ๐œธ ยฟ

๐’ โ‰ˆ ๐’

๐Ÿ”

๐’

User picks random

๐’›

๐’—๐’•

๐“ (๐’” )=๐‘ท ๐’‚ (๐œธ ๐’›+๐’” ๐’—๐’•)

=๐’ˆ(๐œธ๐’”)

Ask Server for

Interpolate the polynomial from

(15)

A 6-Server scheme [Yek08,Efr09,DGY10]

,

mod 6 iff of order

Database User wants

Each server stores values of

over ยฟ ๐œธ ยฟ

๐’ โ‰ˆ ๐’

๐Ÿ”

๐’

User picks random

๐’›

๐’—๐’•

๐“ (๐’” )=๐‘ท ๐’‚ (๐œธ ๐’›+๐’” ๐’—๐’•)

=๐’ˆ(๐œธ๐’”)

Ask Server for

Cost: User sends bits

(16)

Talk Outline

โ€ข

Overview of existing

constructions

โ€ข

The new protocol

โ€ข

PIR and LDCs

(17)

High level idea

โ€ข

Instead of obtaining values

of at six different points,

try to evaluate at only two

points

โ€ข

Inspired by existing

2-server protocol of

[WY05]

(18)

Case study: Restriction

to `realโ€™ lines

๐‘ท

(

๐’™

๐Ÿ

,โ€ฆ ,

๐’™

๐’Œ

)

โˆˆ

๐‘ญ

๐’’

[

๐’™

๐Ÿ

, โ€ฆ ,

๐’™

๐’Œ

]

with

a

๐’ƒ

๐› ๐

(

๐ฑ

๐Ÿ

, โ€ฆ ,

๐’™

๐’Œ

)

=

(

๐ ๐‘ท

๐ ๐’™

๐Ÿ

(

๐’™

)

, โ€ฆ ,

๐ ๐‘ท

๐ ๐’™

๐’Œ

(

๐’™

)

)

๐’‰

โ€ฒ

(

๐’•

)

=

ยฟ

๐› ๐

(

๐š

+

๐ญ๐›

)

,

๐›

>

ยฟ

Given user can calculate

(19)

`Nicerโ€™ derivatives

(20)

๐‘ท

(

๐’™

๐Ÿ

,โ€ฆ ,

๐’™

๐’Œ

)

=

๐’™

๐’–

=

๐’™

๐Ÿ๐’–๐Ÿ

๐’™

๐Ÿ

๐’–๐Ÿ

โ‹ฏ

๐’™

๐’Œ ๐’–๐’Œ

๐ ๐‘ท

๐ ๐’™

๐’Š

(

๐’™

)

=

๐’–

๐’Š

๐’™

๐Ÿ ๐’–๐Ÿ

๐’™

๐Ÿ๐’–๐Ÿ

โ‹ฏ

๐’™

๐’Œ ๐’–๐’Œ

๐› ๐

(

๐ฑ

)

=

๐ฎ

๐’™

๐Ÿ๐’–๐Ÿ

๐’™

๐Ÿ

๐’–๐Ÿ

โ‹ฏ

๐’™

๐’Œ๐’–๐’Œ

=

๐ฎ

๐’™

๐ฎ

ยฟ

๐› ๐

(

๐ฑ

)

,

๐ฏ

>

ยฟ

<

๐ฎ

,

๐ฏ

>

๐ฑ

๐ฎ

Inner product

over

Not mod 6 !!

But letโ€™s pretend for

a second that it

is

mod 6โ€ฆ

(21)

๐“ (๐’” )=๐‘ท ๐’‚ (๐œธ ๐’›+๐’” ๐’—๐’•)

=โˆ‘๐ข๐’=๐Ÿ ๐’‚๐ข(๐œธ ยฟยฟ ๐’› + ๐’” ๐’—๐’•)๐ฎ๐ข

ยฟ

ยฟ

๐’‚

๐’•

๐œธ

ยฟ ๐’› , ๐’–๐’•> ยฟ+

โˆ‘

๐Ÿโ‰ค ๐’“ โ‰ค ๐Ÿ“

๐’„๐’“ (๐œธ ๐’”)๐’“ ยฟ

๐’ˆ (๐‘บ)=๐’„๐ŸŽ+ ๐’„๐Ÿ ๐‘บ +๐’„๐Ÿ ๐‘บ๐Ÿ+ โ€ฆ ๐’„๐Ÿ“ ๐‘บ๐Ÿ“ ๐‘บ=๐œธ ๐’”

๐’›

๐’—

๐’•

ยฟ ๐› ๐๐š

(

๐œธ๐ณ+๐ฌ ๐ฏ๐ญ

)

, ๐ฏ

๐ญ> ยฟ โˆ‘๐ข=๐Ÿ

๐’ ๐’‚

๐ข ยฟ ๐’— ๐’• ,๐’–๐’Š>(๐œธ ยฟยฟ ๐’› + ๐’” ๐’— ๐’•)

๐ฎ๐ข

ยฟ

โ€œPretendโ€ mod 6

ยฟ

โ€ฆ

ยฟ

ยฟ ๐’ˆโ€ฒ

(

๐œธ๐’”

)

=๐’„๐Ÿ๐œธ +๐Ÿ ๐’„๐Ÿ๐œธ ๐Ÿ+โ€ฆ+๐Ÿ“ ๐’„๐Ÿ“๐œธ ๐Ÿ“
(22)

Removing the `pretend mod 6โ€™ :

Matching Vector family over with prime

power ??

Does not exist with

Replace with ?? No of order 6

Solution: Construct a

ring

with

characteristic 6

containing an element

(23)

The ring

๐‘น= ๐’ ๐Ÿ”

[

๐œธ

]

๐œธ๐Ÿ”โˆ’๐Ÿ

Polynomial in with coefficient in modulo the equation

๐’’

(

๐œธ

)

=

๐’’

๐ŸŽ

+

๐’’

๐Ÿ

๐œธ

+

โ€ฆ

+

๐’’

๐Ÿ“

๐œธ

๐Ÿ“

Group ring : Linear

combinations of elements of a (multiplicative) group with coefficients in a ring

๐‘น

=

๐’

๐Ÿ”

[

๐‘ช

๐Ÿ”

]

(24)

Question: can we check if

given, say:

with

(zero iff is)

(25)

Matrix notation

(

๐’ˆ๐’ˆโ€ฒ((๐Ÿ๐Ÿ))

๐’ˆโ€ฒ โ€ฒ(๐Ÿ)

๐’ˆ(๐œธ)

๐’ˆโ€ฒ (๐œธ )

๐’ˆโ€ฒ โ€ฒ (๐œธ )

)

=

(

๐Ÿ ๐Ÿ๐ŸŽ ๐Ÿ ๐Ÿ๐Ÿ ๐Ÿ๐Ÿ‘ ๐Ÿ๐Ÿ’ ๐Ÿ๐Ÿ“ ๐ŸŽ ๐Ÿ ๐Ÿ’ ๐Ÿ— ๐Ÿ๐Ÿ” ๐Ÿ๐Ÿ“ ๐Ÿ ๐œธ ๐œธ๐Ÿ ๐œธ๐Ÿ‘ ๐œธ๐Ÿ’ ๐œธ๐Ÿ“

๐ŸŽ ๐œธ ๐Ÿ๐œธ๐Ÿ ๐Ÿ‘๐œธ๐Ÿ‘ ๐Ÿ’ ๐œธ๐Ÿ’ ๐Ÿ“๐œธ๐Ÿ“

๐ŸŽ ๐œธ ๐Ÿ’๐œธ๐Ÿ ๐Ÿ—๐œธ๐Ÿ‘ ๐Ÿ๐Ÿ”๐œธ๐Ÿ’ ๐Ÿ๐Ÿ“๐œธ๐Ÿ“

)

โ‹…

(26)

Matrix notation

(

๐’ˆ๐’ˆโ€ฒ((๐Ÿ๐Ÿ))

๐’ˆ โ€ฒ โ€ฒ(๐Ÿ)

๐’ˆ (๐œธ)

๐’ˆโ€ฒ (๐œธ )

๐’ˆ โ€ฒ โ€ฒ (๐œธ )

)

=

(

๐Ÿ ๐Ÿ๐ŸŽ ๐Ÿ ๐Ÿ๐Ÿ ๐Ÿ๐Ÿ‘ ๐Ÿ๐Ÿ’ ๐Ÿ๐Ÿ“ ๐ŸŽ ๐Ÿ ๐Ÿ’ ๐Ÿ‘ ๐Ÿ’ ๐Ÿ ๐Ÿ ๐œธ ๐œธ๐Ÿ ๐œธ๐Ÿ‘ ๐œธ๐Ÿ’ ๐œธ๐Ÿ“

๐ŸŽ ๐œธ ๐Ÿ ๐œธ๐Ÿ ๐Ÿ‘ ๐œธ๐Ÿ‘ ๐Ÿ’ ๐œธ ๐Ÿ’ ๐Ÿ“๐œธ๐Ÿ“

๐ŸŽ ๐œธ ๐Ÿ’ ๐œธ๐Ÿ ๐Ÿ‘ ๐œธ๐Ÿ‘ ๐Ÿ’ ๐œธ ๐Ÿ’ ๐Ÿ๐œธ๐Ÿ“

)

โ‹…

(

๐’„๐’„๐ŸŽ๐Ÿ ๐’„๐Ÿ ๐’„๐Ÿ‘ ๐’„๐Ÿ’ ๐’„๐Ÿ“

)

๐‘ด

(27)

Over any ring: There always exists a matrix (adjugate) s.t

(

๐’ˆ๐’ˆโ€ฒ((๐Ÿ๐Ÿ))

๐’ˆโ€ฒ โ€ฒ(๐Ÿ)

๐’ˆ(๐œธ)

๐’ˆโ€ฒ(๐œธ )

๐’ˆโ€ฒ โ€ฒ (๐œธ )

)

=

(

๐Ÿ๐ŸŽ ๐Ÿ๐Ÿ ๐Ÿ๐Ÿ ๐Ÿ๐Ÿ‘ ๐Ÿ๐Ÿ’ ๐Ÿ๐Ÿ“ ๐ŸŽ ๐Ÿ ๐Ÿ’ ๐Ÿ‘ ๐Ÿ’ ๐Ÿ ๐Ÿ ๐œธ ๐œธ๐Ÿ ๐œธ๐Ÿ‘ ๐œธ๐Ÿ’ ๐œธ๐Ÿ“

๐ŸŽ ๐œธ ๐Ÿ๐œธ๐Ÿ ๐Ÿ‘๐œธ๐Ÿ‘ ๐Ÿ’๐œธ ๐Ÿ’ ๐Ÿ“๐œธ๐Ÿ“

๐ŸŽ ๐œธ ๐Ÿ’๐œธ๐Ÿ ๐Ÿ‘๐œธ๐Ÿ‘ ๐Ÿ’๐œธ ๐Ÿ’ ๐Ÿ๐œธ๐Ÿ“

)

โ‹…

(

๐’„๐’„๐ŸŽ๐Ÿ ๐’„๐Ÿ ๐’„๐Ÿ‘ ๐’„๐Ÿ’ ๐’„๐Ÿ“

)

=๐‘ด

(

๐’„๐’„๐ŸŽ๐Ÿ ๐’„๐Ÿ ๐’„๐Ÿ‘ ๐’„๐Ÿ’ ๐’„๐Ÿ“

)

๐‘ดยฟ

(

๐’ˆ๐’ˆโ€ฒ((๐Ÿ๐Ÿ))

๐’ˆโ€ฒ โ€ฒ(๐Ÿ)

๐’ˆ(๐œธ )

๐’ˆโ€ฒ (๐œธ )

๐’ˆโ€ฒ โ€ฒ (๐œธ )

)

=๐‘ดยฟ ๐‘ด

(

๐’„๐’„๐ŸŽ๐Ÿ ๐’„๐Ÿ ๐’„๐Ÿ‘ ๐’„๐Ÿ’ ๐’„๐Ÿ“

)

=๐’…๐’†๐’•( ๐‘ด)

(

๐’„๐’„๐ŸŽ๐Ÿ ๐’„๐Ÿ ๐’„๐Ÿ‘ ๐’„๐Ÿ’

๐’„๐Ÿ“

)

?

(28)

A 2-Server scheme

,

mod 6 iff ๐‘น=

๐’ ๐Ÿ” [ ๐œธ ]

๐œธ ๐Ÿ”โˆ’๐Ÿ

Database User wants

Each server stores values of over

ยฟ ๐œธ ยฟ๐’Œ โ‰ˆ ๐’๐Ÿ”๐’Œ

User restricts to for random Sends to server

Server sends for all

(29)

Variations:

โ€ข

Can use only first order

derivatives

โ€ข

Can encode more than

one bit in each coefficient

of

โ€ข

Can replace the ring with

โ€ข

In general can reduce

(30)

Talk Outline

โ€ข

Overview of existing

constructions

โ€ข

The new protocol

โ€ข

PIR and LDCs

(31)

Locally Decodable Codes

[KT00]

Message Encode as

Given corrupted encoding (small)

Can recover a particular bit using only queries to

Challenge: for small, say constant, , find the best

dependence

(๐ŸŽ๐Ÿ๐Ÿ๐ŸŽ๐Ÿ๐ŸŽ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐ŸŽ)

(๐ŸŽ๐Ÿ๐Ÿ๐Ÿ๐ŸŽ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐Ÿ๐Ÿ)

(๐ŸŽ๐Ÿ๐Ÿ๐Ÿ๐Ÿ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ๐Ÿ)

+

๐’˜

๐’‚๐’•=?

Decod er

(w.h.p)

(32)

Locally Decodable Codes

(๐ŸŽ๐Ÿ๐Ÿ๐ŸŽ๐Ÿ๐ŸŽ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐ŸŽ)

(๐ŸŽ๐Ÿ๐Ÿ๐Ÿ๐ŸŽ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐Ÿ๐Ÿ)

(๐ŸŽ๐Ÿ๐Ÿ๐Ÿ๐Ÿ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐ŸŽ๐ŸŽ๐Ÿ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ๐Ÿ)

+

๐’˜

๐’‚๐’•=?

Decod er

(w.h.p)

๐’”

[Fact] -server PIR scheme

with communication

gives an -query LDC with and alphabet size

(Proof: encode the

message as a list of all possible answers by a server)

[Cor] There exists a

2-query LDC with and

[GKST02,KdW03] for

(33)

Talk Outline

โ€ข

Overview of existing

constructions

โ€ข

The new protocol

โ€ข

PIR and LDCs

(34)

Future work (?)

Can we reduce the

communication further by taking more derivatives?[Gro99] If then there is an MV family

over of size

(communication cost )

The polynomial has degree . Can ask each server for derivatives of order

Problem: The determinant of is zero!

(35)

Future work (?)

Can we construct larger MV families over ?

We really don't know:

โ€ข Current upper bounds are*

*Assuming Polynomial Freiman Ruzsa conjecture in [BDL12]

โ€ข If tight would give cost PIR

(36)
(37)

References

Related documents