Aug 2026· IACR Communications in Cryptology· Vol 3· 0 citations· 54 references
TL;DR
Leveraging TFSS, ThORY achieves leakage-free keyword search and document identifier retrieval under a (t,p)-threshold model, hiding access, search, and volume patterns against any adversary corrupting fewer than t servers.
Abstract
We propose a novel multi-server threshold oblivious retrieval system (ThORY). Our construction extends DORY (a two-server non-threshold oblivious retrieval system proposed in USENIX OSDI 2020) to support arbitrary threshold access structures. The technical centrepiece of ThORY is threshold function secret sharing (TFSS) – an extension of traditional FSS that allows the key to be secret-shared across multiple servers following any arbitrary threshold access structure. We present novel constructions of TFSS based on either purely symmetric-key cryptoprimitives, or any seed-homomorphic pseudorandom generator (for the latter, we present two concrete instantiations from standard group-theoretic assumptions and plausibly quantum-safe lattice-based assumptions). Leveraging TFSS, ThORY achieves leakage-free keyword search and document identifier retrieval under a (t,p)-threshold model, hiding access, search, and volume patterns against any adversary corrupting fewer than t servers. We analyse and evaluate the security and performance of end-to-end implementations of ThORY based on each of these TFSS constructions. Our experiments demonstrate that ThORY scales efficiently with threshold size, outperforming state-of-the-art literature in query latency over large databases.
This work proposes a fault-tolerant PIR protocol based on a newly designed (t,p)-threshold distributed point function (FT-DPF), and proves that the stateless protocol guarantees (t−1)-computational privacy under the semi-honest model.
Dazeng Yuan, Xi-Heng Liu, Bin Liu· Entropy· 0 citations
A novel VMKSE scheme (VMKSE-BFF) is presented by adopting BFF, which can simultaneously support verifiability of and secure data sharing in a multi-user setting and a comparison with the existing VMKSE schemes is provided.
Yandong Su, Bing-Hang Wang, Yan-Jie Xiang et al.· Mathematics· 0 citations
This paper presents a secure data sharing platform that organises KR-IBI, KR-IBE, KR-PEKS, and KR-PAEKS into an end-to-end Rust/Tauri workflow for registration, authentication, encrypted upload, searchable retrieval, and authorised decryption. The work addresses a deployment-level composition problem rather than proposing a new primitive: practical data sharing requires coordinated credential handling, payload representation, searchable indexing, session control, and record integrity across schemes with distinct interfaces. The platform supports text, file, and image payloads through a hybrid KR-IBE/HKDF-SHA-256/AES-256-GCM layer. Fresh KR-IBE key material is generated by uniformly sampling a nonzero scalar and multiplying the Ed25519 prime-order subgroup generator, providing approximately 252 bits of min-entropy before HKDF derivation. An evaluation with 100 repetitions per configuration over Enron-derived workloads containing 100–10,000 records and 1, 5, 10, or 20 authorised identities achieved 100/100 correctness for authorised retrieval and decryption, wrong-keyword and wrong-scheme rejection, and unauthorised-access rejection. KR-PEKS search latency ranged from 29.26 ms at 100 records to 3023.82 ms at 10,000 records, whereas KR-PAEKS ranged from 775.53 ms to 93,045.52 ms. These results quantify the performance distinction between the lower-latency KR-PEKS mode and the sender-authenticated searchable encryption provided by KR-PAEKS.
Oblivious pseudorandom functions (OPRFs) allow a client to evaluate a keyed pseudorandom function on a private input without revealing that input to the server. In a threshold OPRF, the secret key is distributed among (n) servers so that any qualified set of at least (t) servers can complete an evaluation, while fewer than (t) shares reveal no information about the key. Existing isogeny-based threshold OPRFs, however, are primarily designed for static corruption models. If the same shares remain valid throughout the lifetime of the service, a mobile adversary can compromise different servers over time, accumulate (t) shares from the same sharing state, and eventually recover the master key. We introduce PIVOT (Proactive Isogeny-based Verifiable Oblivious Threshold PRF), a dealerless threshold VOPRF framework based on effective isogeny group actions. PIVOT periodically refreshes the server shares without changing the master key, public key, or previously generated OPRF outputs. The construction combines Shamir secret sharing, additively homomorphic coefficient commitments, sequential Lagrange-weighted group actions, and joint zero-knowledge relations that link certified shares to their corresponding isogeny actions. It also supports coordinated epoch transitions, publicly verifiable blame, secure erasure, and committee resharing under a possibly different threshold. We formalize the functionality of a long-lived proactive threshold VOPRF, prove the correctness of distributed key generation, threshold evaluation, proactive refresh, and committee resharing, and provide a simulation-based security analysis under the vectorization and one-more hidden-group- action assumptions. As an application, we describe a distributed private lookup service whose encrypted database remains valid across repeated share renewals and committee migrations.
This study presents Forward-private and Binary-tree-Revocable PAEKS (FBR-PAEKS), a public-key authenticated encryption with keyword search scheme for secure multi-user cloud environments that integrates forward privacy and cryptographic revocation in a single construction. The proposed scheme supports expressive keyword search policies represented by linear secret-sharing schemes (LSSS), enabling flexible AND, OR, and threshold-based queries over encrypted indexes. FBR-PAEKS integrates a binary-tree-based revocation mechanism using the complete-subtree algorithm
KUNode
, an epoch-bound one-way state evolution chain for forward privacy, and a deletion-tag filter for logical document deletion. To resist insider keyword-guessing attacks by the cloud server, the construction introduces a sender–receiver shared element derived from the Diffie–Hellman value of their secret keys. Furthermore, the receiver's epoch secret is embedded into the trapdoor exponent to prevent current-state compromise from exposing past search information. We formalized the security of the scheme through ciphertext indistinguishability, resistance to insider keyword guessing, revocation unforgeability, forward privacy under state compromise, and trapdoor integrity. The security reductions are established under the CDH, mDLIN, PRF, one-wayness, and signature unforgeability assumptions in the random oracle model. Theoretical and practical evaluations show that FBR-PAEKS achieves strong security and expressive search functionality with competitive performance compared with existing PAEKS schemes.
Mishal Ismaeel, Ali Raza· Frontiers of Computer Scienc...· 0 citations
This work proposes a practical non-interactive encrypted retrieval framework for RAG based on threshold selection, and introduces a precision-stable mask polarization method that ensures accurate recovery of selected documents.
Yang Gao, Gang Quan, Scott Piersall et al.· arXiv.org· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.