{"catalogVersion":"pir-dossier-v3-semantic-anchor-backbone","constructions":[{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"information_theoretic","assumption_id":"PIR-ASSUMPTION-NO-COMPUTATIONAL-ASSUMPTION-NON-COLLUSION-IS-A-DEPLOYMENT-ASSUMPTION","assumption_name":"No computational assumption; non-collusion is a deployment assumption","authors":["Benny Chor","Oded Goldreich","Eyal Kushilevitz","Madhu Sudan"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["two-server","sublinear-communication","information-theoretic"],"ciphertext_security":null,"circuit_class":null,"client_storage":"stateless apart from query randomness","communication":null,"construction_family":"replicated_combinatorial","correctness":"perfect in the stated model","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"lightweight reconstruction from server answers"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-1998-CGKS-2S","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Private Information Retrieval","paper_url":"https://madhu.seas.harvard.edu/papers/1995/pir-journ.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"none","primitive":"two-server IT-PIR","privacy_model":"information-theoretic against either server","proof_model":null,"quantum_security":null,"query_communication":"part of O(n^(1/3)) total","resilience":null,"response_communication":"part of O(n^(1/3)) total","robustness":null,"security_mode":"information-theoretic","security_model":"honest non-colluding servers","security_notion":"query privacy","server_model":"two non-colluding replicated servers","server_work":"not promoted as sublinear","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"offline":"not applicable","query_response_total":"O(n^(1/3))"},"statefulness":null,"summary":"The non-collusion condition is shown alongside the absence of computational assumptions; neither dominates the other.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"replicated database updates","verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PIR-PAPER-1998-CGKS","year":1995},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"number_theoretic","assumption_id":"PIR-ASSUMPTION-QUADRATIC-RESIDUOSITY","assumption_name":"Quadratic Residuosity","authors":["Eyal Kushilevitz","Rafail Ostrovsky"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["single-server","sublinear-communication"],"ciphertext_security":null,"circuit_class":null,"client_storage":"polylogarithmic local state; exact audit pending","communication":null,"construction_family":"number_theoretic_recursion","correctness":"standard protocol correctness; exact failure semantics pending","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"recursive number-theoretic recovery; exact count pending"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-1997-KO","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Replication Is Not Needed: Single Database, Computationally-Private Information Retrieval","paper_url":"https://doi.org/10.1109/SFCS.1997.646125","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"none","primitive":"single-server CPIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"O(n^epsilon) in the promoted abstract claim","resilience":null,"response_communication":"included in O(n^epsilon) total","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"query privacy","server_model":"single","server_work":"at least linear database work in the ordinary no-preprocessing model","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"offline":"not applicable","query":"O(n^epsilon)","response":"included in total bound"},"statefulness":null,"summary":"Historical boundary record. The comparison table does not treat this recursion as a practical implementation.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"direct database updates; no stored hint","verification_cost":null,"verification_status":"abstract_reviewed","work_id":"PIR-PAPER-1997-KO","year":1997},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"number_theoretic","assumption_id":"PIR-ASSUMPTION-PHI-HIDING-AND-PHI-SAMPLING-ASSUMPTIONS","assumption_name":"Phi-Hiding and Phi-Sampling assumptions","authors":["Christian Cachin","Silvio Micali","Markus Stadler"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["single-server","polylogarithmic-communication","two-round"],"ciphertext_security":null,"circuit_class":null,"client_storage":"polylogarithmic protocol state","communication":null,"construction_family":"phi_hiding_number_theoretic","correctness":"standard CPIR correctness","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"polylogarithmic-time client recovery"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-1999-CMS","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Computationally Private Information Retrieval with Polylogarithmic Communication","paper_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/pirpolylog.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"none","primitive":"single-server CPIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"part of polylogarithmic total communication","resilience":null,"response_communication":"part of polylogarithmic total communication","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"query privacy","server_model":"single","server_work":"linear in database size","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"total_communication":"polylogarithmic in database size"},"statefulness":null,"summary":"This row records the historical communication frontier without implying a modern standard assumption.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"direct database updates","verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"PIR-PAPER-1999-CMS","year":1999},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"number theoretic","assumption_id":"PIR-ASSUMPTION-HIDDEN-SMOOTH-SUBGROUP-ASSUMPTION","assumption_name":"Hidden smooth subgroup assumption","authors":["Craig Gentry","Zulfikar Ramzan"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["private-block-retrieval","constant-rate-for-large-blocks"],"ciphertext_security":null,"circuit_class":null,"client_storage":"polylogarithmic parameters and query state","communication":null,"construction_family":"hidden_smooth_subgroups","correctness":"negligible error under the stated parameterization","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"smooth-subgroup discrete logarithm"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2005-GR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Single-Database Private Information Retrieval with Constant Communication Rate","paper_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"public parameters; no sublinear-work preprocessing","primitive":"single-server private block retrieval","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"O(k)","resilience":null,"response_communication":"O(k+d) total communication for d-bit blocks","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"computational query privacy","server_model":"single","server_work":"linear in the database","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"total_communication":"O(k+d)"},"statefulness":null,"summary":"The composite-modulus instantiation uses a variant of the Phi-hiding assumption.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"static database in the analyzed protocol","verification_cost":null,"verification_status":"section_reviewed","work_id":"PIR-PAPER-2005-GR","year":2005},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"symmetric_key","assumption_id":"PIR-ASSUMPTION-PSEUDORANDOM-GENERATOR-SECURITY","assumption_name":"Pseudorandom generator security","authors":["Niv Gilboa","Yuval Ishai"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["two-server","compact-query","lightweight-server-operations"],"ciphertext_security":null,"circuit_class":null,"client_storage":"short DPF seeds","communication":null,"construction_family":"distributed_point_function","correctness":"exact additive reconstruction","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"add server responses"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2014-DPF","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Distributed Point Functions and Their Applications","paper_url":"https://doi.org/10.1007/978-3-642-55220-5_20","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"none beyond shared public database","primitive":"two-server computational PIR","privacy_model":"computational query privacy from DPF key privacy","proof_model":null,"quantum_security":null,"query_communication":"compact DPF keys; exact bound pending theorem audit","resilience":null,"response_communication":"one aggregate answer per server","robustness":null,"security_mode":"computational","security_model":"semi-honest non-colluding servers","security_notion":"query privacy","server_model":"two non-colluding servers","server_work":"linear point-function evaluation over the database","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"offline":"not applicable","query":"compact DPF keys","response":"one aggregate per server"},"statefulness":null,"summary":"DPF PIR is retained as a separate deployment branch rather than a baseline score for single-server systems.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"replicated database updates","verification_cost":null,"verification_status":"abstract_reviewed","work_id":"PIR-PAPER-2014-GI-DPF","year":2014},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-RING-LEARNING-WITH-ERRORS","assumption_name":"Ring Learning With Errors","authors":["Sebastian Angel","Hao Chen","Kim Laine","Srinath Setty"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["query-compression","batch-amortization","large-records"],"ciphertext_security":null,"circuit_class":null,"client_storage":"encryption keys and small query state","communication":null,"construction_family":"rlwe_homomorphic_query_expansion","correctness":"negligible decryption failure under selected HE parameters","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"RLWE response decryption and record extraction"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2018-SEALPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"PIR with Compressed Queries and Amortized Query Processing","paper_url":"https://eprint.iacr.org/2017/1142","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"database encoding plus optional probabilistic batch-code layout","primitive":"single-server CPIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"compressed single-ciphertext query with recursive expansion","resilience":null,"response_communication":"depends on recursion depth and record layout","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"query privacy","server_model":"single","server_work":"linear database homomorphic processing; batch amortization available","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"offline":"encoded database","query":"up to 274x source-reported reduction","response":"parameter dependent"},"statefulness":null,"summary":"The 274x and 40x figures are promoted only as source-reported observations in the paper's selected configurations.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"encoded database must track source updates","verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PIR-PAPER-2018-SEALPIR","year":2018},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"mixed","assumption_id":"PIR-ASSUMPTION-VARIANT-DEPENDENT-SINGLE-SERVER-COMPUTATIONAL-ASSUMPTIONS","assumption_name":"Variant-dependent; single-server computational assumptions","authors":["Henry Corrigan-Gibbs","Dmitry Kogan"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["sublinear-online-time","no-extra-server-storage","optimal-tradeoff"],"ciphertext_security":null,"circuit_class":null,"client_storage":"reusable short offline string","communication":null,"construction_family":"client_hint_preprocessing","correctness":"standard correctness in each variant","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"variant-dependent reconstruction"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Private Information Retrieval with Sublinear Online Time","paper_url":"https://eprint.iacr.org/2019/1075","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"client downloads a query-independent short string offline","primitive":"offline-online PIR","privacy_model":"computational single-server; statistical two-server","proof_model":null,"quantum_security":null,"query_communication":"model-dependent sublinear online communication","resilience":null,"response_communication":"model-dependent sublinear online communication","robustness":null,"security_mode":"computational_or_statistical","security_model":"offline-online","security_notion":"query privacy","server_model":"single computational or two-server statistical variants","server_work":"sublinear online after shifting bulk work offline","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"offline":"short query-independent client string","online":"sublinear; exact variant required"},"statefulness":null,"summary":"This row represents the offline/online theoretical profile; it is not merged with any later concrete hint implementation.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"hint freshness cost must be accounted for","verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PIR-PAPER-2020-CK","year":2020},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"mixed","assumption_id":"PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS-AND-INSTANTIATED-PIR-ASSUMPTIONS","assumption_name":"Pseudorandom functions and instantiated PIR assumptions","authors":["Dmitry Kogan","Henry Corrigan-Gibbs"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["sublinear-online-time","dynamic-blocklist","practical-implementation"],"ciphertext_security":null,"circuit_class":null,"client_storage":"sublinear private hint plus blocklist metadata","communication":null,"construction_family":"client_hint_bucketed_updates","correctness":"negligible failure in the stated system","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"client hint reconstruction"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2021-CHECKLIST","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Private Blocklist Lookups with Checklist","paper_url":"https://www.usenix.org/conference/usenixsecurity21/presentation/kogan","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"per-client offline hint computation","primitive":"two-server private blocklist lookup","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"source-reported application-specific communication","resilience":null,"response_communication":"included in total source-reported communication","robustness":null,"security_mode":"computational","security_model":"one honest non-colluding server","security_notion":"query privacy","server_model":"two non-colluding servers","server_work":"sublinear online PIR work","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"implementation":"Go and C","update_cost":"logarithmic amortized"},"statefulness":null,"summary":"Only the PIR and dynamic-update components are compared in the index-PIR atlas.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"logarithmic amortized bucket updates","verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"PIR-PAPER-2021-CHECKLIST","year":2021},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-RING-LEARNING-WITH-ERRORS","assumption_name":"Ring Learning With Errors","authors":["Asra Ali","Tancrède Lepoint","Sarvar Patel","Mariana Raykova","Phillipp Schoppmann","Karn Seth","Kevin Yeo"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["compressed-queries","oblivious-expansion"],"ciphertext_security":null,"circuit_class":null,"client_storage":"cryptographic parameters and query state","communication":null,"construction_family":"compressed_rlwe_pir","correctness":"parameterized HE correctness","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"recursive HE response recovery"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2021-FASTPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Communication–Computation Trade-offs in PIR","paper_url":"https://www.usenix.org/conference/usenixsecurity21/presentation/ali","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"public cryptographic parameters","primitive":"single-server PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"reduced relative to SealPIR in reported settings","resilience":null,"response_communication":"compressed recursive response","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"computational query privacy","server_model":"single","server_work":"essentially SealPIR-like in the reported comparison","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"communication":"setting-dependent improvement over SealPIR"},"statefulness":null,"summary":"FastPIR is represented as a construction; the claimed improvement remains an optimization contribution.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"static database in the evaluated protocol","verification_cost":null,"verification_status":"paper_reviewed","work_id":"PIR-PAPER-2021-ALI-TRADEOFFS","year":2021},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-HOMOMORPHIC-ENCRYPTION-ASSUMPTION","assumption_name":"Homomorphic-encryption assumption","authors":["Asra Ali","Tancrède Lepoint","Sarvar Patel","Mariana Raykova","Phillipp Schoppmann","Karn Seth","Kevin Yeo"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["multiplicative-recursion","tunable-communication-computation-tradeoff"],"ciphertext_security":null,"circuit_class":null,"client_storage":"cryptographic parameters and query state","communication":null,"construction_family":"multiplicative_homomorphic_recursion","correctness":"parameterized HE correctness","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"recursive HE response recovery"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2021-MULPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Communication–Computation Trade-offs in PIR","paper_url":"https://www.usenix.org/conference/usenixsecurity21/presentation/ali","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"public cryptographic parameters","primitive":"single-server PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"reduced through multiplicative recursive packing","resilience":null,"response_communication":"reduced in the targeted large-entry regime","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"computational query privacy","server_model":"single","server_work":"increased relative to additive recursion","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"tradeoff":"lower communication for more server computation"},"statefulness":null,"summary":"MulPIR is not ordered as universally better than FastPIR; the preferred point depends on workload costs.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"static database in the evaluated protocol","verification_cost":null,"verification_status":"paper_reviewed","work_id":"PIR-PAPER-2021-ALI-TRADEOFFS","year":2021},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS","assumption_name":"Learning With Errors","authors":["Elaine Shi","Waqar Aqeel","Balakrishnan Chandrasekaran","Bruce M. Maggs"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["unbounded-queries","polylog-online-bandwidth","no-extra-server-storage","one-roundtrip"],"ciphertext_security":null,"circuit_class":null,"client_storage":"near-square-root private hint","communication":null,"construction_family":"puncturable_pseudorandom_sets","correctness":"negligible failure under the paper's occasional-correctness analysis","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"near-square-root client computation"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2021-SACM","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Puncturable Pseudorandom Sets and Private Information Retrieval with Near-Optimal Online Bandwidth and Time","paper_url":"https://eprint.iacr.org/2020/1592","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"one-time per-client private hint","primitive":"two-server client-preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"polylogarithmic online bandwidth","resilience":null,"response_communication":"included in polylogarithmic online bandwidth","robustness":null,"security_mode":"computational","security_model":"two non-colluding servers","security_notion":"query privacy","server_model":"two non-colluding replicated servers","server_work":"near-square-root online per query","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"client_hint":"near-square-root","online_communication":"polylogarithmic"},"statefulness":null,"summary":"The non-collusion and per-client preprocessing requirements remain part of the row.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"client hint refresh per query; database refresh remains explicit","verification_cost":null,"verification_status":"theorem_reviewed","work_id":"PIR-PAPER-2021-SACM","year":2021},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"mixed","assumption_id":"PIR-ASSUMPTION-LHE-OR-FHE-FROM-STANDARD-ASSUMPTIONS","assumption_name":"LHE or FHE from standard assumptions","authors":["Henry Corrigan-Gibbs","Alexandra Henzinger","Dmitry Kogan"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["adaptive-multi-query","sublinear-amortized-time","sublinear-storage","no-per-client-server-storage"],"ciphertext_security":null,"circuit_class":null,"client_storage":"near-square-root in the optimal FHE construction","communication":null,"construction_family":"homomorphic_two_server_compilation","correctness":"negligible failure in instantiated schemes","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"near-square-root amortized client work in FHE variant"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2022-CHK","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Single-Server Private Information Retrieval with Sublinear Amortized Time","paper_url":"https://eprint.iacr.org/2022/081","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"linear-time per-client hint generation","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"variant-dependent; near-square-root amortized in the FHE construction","resilience":null,"response_communication":"included in the amortized communication bound","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"adaptive query privacy","server_model":"single","server_work":"near-square-root amortized in the optimal FHE construction","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"optimal_tradeoff":"storage times server time near-linear","supported_queries":"bounded per preprocessing epoch"},"statefulness":null,"summary":"The row does not hide state refresh or the query count needed to amortize preprocessing.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"stateful hint consumption and refresh; database changes require new preprocessing","verification_cost":null,"verification_status":"theorem_reviewed","work_id":"PIR-PAPER-2022-CHK","year":2022},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-GSW-STYLE-LATTICE-ENCRYPTION-SECURITY","assumption_name":"Learning With Errors and GSW-style lattice encryption security","authors":["Samir Jordan Menon","David J. Wu"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["ciphertext-translation","response-packing","streaming"],"ciphertext_security":null,"circuit_class":null,"client_storage":"keys and compact client state","communication":null,"construction_family":"lwe_gsw_fhe_composition","correctness":"negligible decryption failure under lattice parameters","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"translated lattice ciphertext recovery"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2022-SPIRAL","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Spiral: Fast, High-Rate Single-Server PIR via FHE Composition","paper_url":"https://eprint.iacr.org/2022/368","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"encoded database and public evaluation material","primitive":"single-server CPIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"Regev ciphertext query translated during evaluation","resilience":null,"response_communication":"high-rate response; source reports rate 0.81 for SpiralStreamPack setting","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"query privacy","server_model":"single","server_work":"linear streaming pass with composed HE operations","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"query":"source reports at least 4.5x reduction versus compared prior systems","response_rate":"0.81 in streaming setting"},"statefulness":null,"summary":"Rate and throughput are kept separate; the streaming variant does not become a universal ranking row.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"encoded database update cost depends on layout","verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PIR-PAPER-2022-SPIRAL","year":2022},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-RING-LEARNING-WITH-ERRORS","assumption_name":"Ring Learning With Errors","authors":["Wei-Kai Lin","Ethan Mook","Daniel Wichs"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["polylog-online-time","polylog-communication","public-preprocessing","updates"],"ciphertext_security":null,"circuit_class":null,"client_storage":"polylogarithmic protocol state; exact vector pending audit","communication":null,"construction_family":"ring_lwe_fast_polynomial_evaluation","correctness":"negligible failure in the Ring-LWE construction","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"polylogarithmic client recovery"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2023-DEPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Doubly Efficient Private Information Retrieval and Fully Homomorphic RAM Computation from Ring LWE","paper_url":"https://eprint.iacr.org/2022/1703","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"deterministic public server preprocessing","primitive":"doubly efficient PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"polylogarithmic in database size","resilience":null,"response_communication":"included in polylogarithmic communication","robustness":null,"security_mode":"computational","security_model":"unkeyed public preprocessing","security_notion":"query privacy","server_model":"single","server_work":"polylogarithmic online after O(N^(1+epsilon)) preprocessing","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"online_communication":"polylog(N)","preprocessed_database":"O(N^(1+epsilon))"},"statefulness":null,"summary":"This is the asymptotic DEPIR endpoint. No implementation or benchmark row is manufactured without an artifact.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"O(N^epsilon) update time in the promoted theorem profile","verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PIR-PAPER-2023-LMW-DEPIR","year":2023},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-ADAPTABLE-PRS-INGREDIENTS","assumption_name":"Learning With Errors and adaptable PRS ingredients","authors":["Arthur Lazzaretti","Charalampos Papamanthou"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["near-optimal-computation","polylog-bandwidth","adaptable-pseudorandom-sets"],"ciphertext_security":null,"circuit_class":null,"client_storage":"near-square-root private state","communication":null,"construction_family":"adaptable_pseudorandom_sets","correctness":"negligible failure under the stated construction","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"near-square-root amortized client work"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Near-Optimal Private Information Retrieval with Preprocessing","paper_url":"https://eprint.iacr.org/2022/830","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"one-time per-client preprocessing","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"polylogarithmic amortized bandwidth","resilience":null,"response_communication":"included in polylogarithmic bandwidth","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"adaptive query privacy","server_model":"single","server_work":"near-square-root amortized per query","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"client_state":"near-square-root","online_bandwidth":"polylogarithmic"},"statefulness":null,"summary":"This independent result is a separate row even though it shares the displayed frontier point with ZLTS23.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"adaptable-set state supports refresh across queries","verification_cost":null,"verification_status":"theorem_reviewed","work_id":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","year":2023},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS","assumption_name":"Learning With Errors","authors":["Alexandra Henzinger","Matthew M. Hong","Henry Corrigan-Gibbs","Sarah Meiklejohn","Vinod Vaikuntanathan"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["memory-bandwidth-throughput","reusable-hint","unbounded-queries-per-hint"],"ciphertext_security":null,"circuit_class":null,"client_storage":"121 MB hint in the promoted 1 GB source setting","communication":null,"construction_family":"lwe_matrix_vector_hint","correctness":"LWE parameter-dependent negligible failure","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"lightweight LWE inner-product recovery"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"One Server for the Price of Two: Simple and Fast Single-Server Private Information Retrieval","paper_url":"https://www.usenix.org/conference/usenixsecurity23/presentation/henzinger","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"query-independent reusable client download","primitive":"single-server preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"242 KB in the promoted 1 GB source setting","resilience":null,"response_communication":"included in the reported 242 KB per-query communication","robustness":null,"security_mode":"computational","security_model":"semi-honest single server with reusable hint","security_notion":"query privacy","server_model":"single","server_work":"near one 32-bit multiply and add per database byte","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"offline_hint":"121 MB for 1 GB database setting","online_total":"242 KB per query"},"statefulness":null,"summary":"The hint and online communication remain separate fields so the fast server pass does not hide client storage or refresh cost.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"hint must track database changes","verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PIR-PAPER-2023-SIMPLEPIR","year":2023},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"group","assumption_id":"PIR-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","assumption_name":"Decisional Diffie-Hellman","authors":["Arthur Lazzaretti","Charalampos Papamanthou"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["sublinear-amortized-time","polylog-bandwidth","weaker-assumption"],"ciphertext_security":null,"circuit_class":null,"client_storage":"sublinear private state","communication":null,"construction_family":"weak_privately_puncturable_prf","correctness":"negligible error under the construction parameters","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"sublinear client work across the two phases"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2023-TREEPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"TreePIR: Sublinear-Time and Polylog-Bandwidth Private Information Retrieval from DDH","paper_url":"https://eprint.iacr.org/2023/204","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"client-specific offline phase","primitive":"two-server client-preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"polylogarithmic","resilience":null,"response_communication":"polylogarithmic total bandwidth","robustness":null,"security_mode":"computational","security_model":"one corrupted server","security_notion":"computational query privacy","server_model":"two non-colluding replicas","server_work":"sublinear amortized","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"online_bandwidth":"polylogarithmic"},"statefulness":null,"summary":"TreePIR composes a simple PRG phase with single-server PIR over a reduced domain.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"static database in the primary construction","verification_cost":null,"verification_status":"section_reviewed","work_id":"PIR-PAPER-2023-TREEPIR","year":2023},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS","assumption_name":"Learning With Errors","authors":["Mingxun Zhou","Wei-Kai Lin","Yiannis Tselekounis","Elaine Shi"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["unbounded-queries","polylog-bandwidth","near-optimal-computation","one-roundtrip"],"ciphertext_security":null,"circuit_class":null,"client_storage":"near-square-root private state","communication":null,"construction_family":"fhe_programmable_pseudorandom_sets","correctness":"negligible failure under the LWE construction","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"near-square-root client computation"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2023-ZLTS","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Optimal Single-Server Private Information Retrieval","paper_url":"https://eprint.iacr.org/2022/609","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"one-time per-client interactive preprocessing","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"polylogarithmic amortized bandwidth","resilience":null,"response_communication":"included in polylogarithmic bandwidth","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"adaptive query privacy","server_model":"single","server_work":"near-square-root amortized per query","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"client_state":"near-square-root","online_bandwidth":"polylogarithmic"},"statefulness":null,"summary":"LP23 independently reaches the same cost point with a different adaptable-PRS mechanism.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"state refreshed across unbounded queries; database-update cost remains nontrivial","verification_cost":null,"verification_status":"theorem_reviewed","work_id":"PIR-PAPER-2023-ZLTS","year":2023},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"symmetric_key","assumption_id":"PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS","assumption_name":"Pseudorandom functions","authors":["Mingxun Zhou","Andrew Park","Elaine Shi","Wenting Zheng"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["prf-only","practical-sublinear-server-time","open-source-implementation"],"ciphertext_security":null,"circuit_class":null,"client_storage":"near-square-root hints","communication":null,"construction_family":"prf_pseudorandom_sets","correctness":"negligible failure with caching/PRP handling for arbitrary queries","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"hint lookup and plaintext reconstruction"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2024-PIANO","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Piano: Extremely Simple, Single-Server PIR with Sublinear Server Computation","paper_url":"https://eprint.iacr.org/2023/452","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"client streams the database once and stores sublinear hints","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"near-square-root online","resilience":null,"response_communication":"included in near-square-root online communication","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"adaptive query privacy","server_model":"single","server_work":"near-square-root amortized online","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"online":"near-square-root","preprocessing_communication":"linear database stream"},"statefulness":null,"summary":"Piano changes the practical mechanism and assumption while accepting linear preprocessing communication.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"hints are stateful and tied to the database snapshot","verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"PIR-PAPER-2024-PIANO","year":2024},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"symmetric_key","assumption_id":"PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS","assumption_name":"Pseudorandom functions","authors":["Arthur Lazzaretti","Charalampos Papamanthou"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["single-pass-preprocessing","constant-time-updates","practical-implementation"],"ciphertext_security":null,"circuit_class":null,"client_storage":"sublinear private hints","communication":null,"construction_family":"single_pass_pseudorandom_sets","correctness":"negligible failure under the stated construction","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"private-hint reconstruction"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2024-SINGLEPASS","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Single Pass Client-Preprocessing Private Information Retrieval","paper_url":"https://www.usenix.org/conference/usenixsecurity24/presentation/lazzaretti","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"exactly one linear pass over the database","primitive":"two-server client-preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"source-specific sublinear communication","resilience":null,"response_communication":"included in reported online communication","robustness":null,"security_mode":"computational","security_model":"two non-colluding servers","security_notion":"query privacy","server_model":"two non-colluding servers","server_work":"sublinear online","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"preprocessing_passes":1,"updates":"constant time"},"statefulness":null,"summary":"The update and preprocessing improvements are kept visible as separate contribution nodes.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"constant-time additions and edits in the paper's dynamic model","verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"PIR-PAPER-2024-SINGLEPASS","year":2024},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-BFV-BGV-STYLE-HOMOMORPHIC-ENCRYPTION","assumption_name":"BFV/BGV-style homomorphic encryption","authors":["Ben Fisch","Arthur Lazzaretti","Zeyu Liu","Charalampos Papamanthou"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["sublinear-offline-bandwidth","constant-depth-preprocessing","parallelizable-fhe"],"ciphertext_security":null,"circuit_class":null,"client_storage":"sublinear hints","communication":null,"construction_family":"homomorphic_thorp_shuffle","correctness":"parameter-dependent negligible failure","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"FHE-derived hint reconstruction"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2024-THORPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"ThorPIR: Single Server PIR via Homomorphic Thorp Shuffles","paper_url":"https://eprint.iacr.org/2024/482","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"sublinear-bandwidth FHE hint generation","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"sublinear","resilience":null,"response_communication":"sublinear profile; exact configuration required","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"query privacy","server_model":"single","server_work":"sublinear online","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"preprocessing_circuit":"linear size and constant depth"},"statefulness":null,"summary":"Concrete preprocessing claims depend on very large accelerator assumptions and are not ranked against ordinary deployments.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"preprocessing remains tied to the database snapshot","verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"PIR-PAPER-2024-THORPIR","year":2024},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-RING-LEARNING-WITH-ERRORS","assumption_name":"Learning With Errors and Ring Learning With Errors","authors":["Samir Jordan Menon","David J. Wu"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["silent-preprocessing","no-client-hint","high-throughput"],"ciphertext_security":null,"circuit_class":null,"client_storage":"no downloaded database hint","communication":null,"construction_family":"lwe_to_rlwe_translation","correctness":"lattice parameter-dependent negligible failure","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"LWE/RLWE translated response recovery"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2024-YPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"YPIR: High-Throughput Single-Server PIR with Silent Preprocessing","paper_url":"https://www.usenix.org/conference/usenixsecurity24/presentation/menon","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"silent server-side preparation with no offline client communication","primitive":"single-server hintless PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"part of 2.5 MB total in promoted 32 GB setting","resilience":null,"response_communication":"part of 2.5 MB total in promoted 32 GB setting","robustness":null,"security_mode":"computational","security_model":"semi-honest single server","security_notion":"query privacy","server_model":"single","server_work":"memory-bandwidth-oriented linear pass plus lightweight translation","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"offline_client_communication":0,"total_communication":"2.5 MB in 32 GB setting"},"statefulness":null,"summary":"YPIR trades higher communication than the matched hint-based baseline for eliminating the large offline client download.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"supports fresher database snapshots without hint redistribution","verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PIR-PAPER-2024-YPIR","year":2024},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"adapter","assumption_id":"PIR-ASSUMPTION-INHERITED-FROM-THE-CLASSIC-PIR-BACKEND","assumption_name":"Inherited from the classic PIR backend","authors":["Ryan Lehmkuhl","Alexandra Henzinger","Henry Corrigan-Gibbs"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["black-box-classic-pir-backend","skew-aware-expected-work","relaxed-correctness"],"ciphertext_security":null,"circuit_class":null,"client_storage":"backend-dependent","communication":null,"construction_family":"popularity_partitioned_classic_pir","correctness":"distribution-dependent success probability; out-of-distribution success may be lower","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"backend recovery plus distributional routing"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Distributional Private Information Retrieval","paper_url":"https://www.usenix.org/conference/usenixsecurity25/presentation/lehmkuhl","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"popularity-dependent database partitioning plus backend preprocessing","primitive":"distributional index PIR","privacy_model":"classic cryptographic query privacy","proof_model":null,"quantum_security":null,"query_communication":"backend-dependent","resilience":null,"response_communication":"backend-dependent","robustness":null,"security_mode":"inherited","security_model":"distributional correctness","security_notion":"classic query privacy","server_model":"inherited from the classic PIR backend","server_work":"reduced in expectation under a skewed public query distribution","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"compatibility_warning":"not directly comparable to errorless classic PIR"},"statefulness":null,"summary":"This row remains outside classic-PIR rankings because the correctness contract differs.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"database and popularity model updates both matter","verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"PIR-PAPER-2025-DISTRIBUTIONAL","year":2025},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"information_theoretic","assumption_id":"PIR-ASSUMPTION-NO-COMPUTATIONAL-ASSUMPTION-SERVER-NON-COLLUSION-REQUIRED","assumption_name":"No computational assumption; server non-collusion required","authors":["Arthur Lazzaretti","Zeyu Liu","Ben Fisch","Peihan Miao","Charalampos Papamanthou"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["information-theoretic-depir","near-linear-preprocessing","unbounded-queries"],"ciphertext_security":null,"circuit_class":null,"client_storage":"theorem-profile dependent","communication":null,"construction_family":"classical_information_theoretic_depir","correctness":"information-theoretic construction correctness","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"subpolynomial client-side profile; exact revision pending"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Multi-server Doubly Efficient PIR in the Classical Model and Beyond","paper_url":"https://eprint.iacr.org/2024/829","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"near-linear server-side preprocessing","primitive":"multi-server doubly efficient PIR","privacy_model":"information-theoretic","proof_model":null,"quantum_security":null,"query_communication":"subpolynomial profile; exact revised theorem required","resilience":null,"response_communication":"subpolynomial profile; exact revised theorem required","robustness":null,"security_mode":"information-theoretic","security_model":"multi-server public preprocessing","security_notion":"query privacy","server_model":"multiple non-colluding servers","server_work":"subpolynomial online query time","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"online_time":"subpolynomial","preprocessing":"near-linear"},"statefulness":null,"summary":"The ePrint-to-TCC version delta is explicit and prevents silently mixing parameters.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"public preprocessed structure; revised update profile pending","verification_cost":null,"verification_status":"fulltext_version_delta_pending","work_id":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR","year":2025},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"hybrid_lattice_number_theoretic","assumption_id":"PIR-ASSUMPTION-LWE-PLUS-PAILLIER-COMPOSITE-RESIDUOSITY-SECURITY","assumption_name":"LWE plus Paillier/composite-residuosity security","authors":["Rasoul Akhavan Mahdavi","Abdulrahman Diaa","Florian Kerschbaum"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["no-client-hint","silent-offline","ciphertext-compression"],"ciphertext_security":null,"circuit_class":null,"client_storage":"no large client hint","communication":null,"construction_family":"lwe_to_paillier_compression","correctness":"parameter-dependent; full audit pending","corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{"primary":"Paillier-compressed response recovery; audit pending"},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"PIR-CONSTRUCTION-2026-ZIPPIR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"ZipPIR: High-Throughput Single-Server PIR without Client-side Storage","paper_url":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":"almost silent offline server work after an initial public key","primitive":"single-server low-client-storage PIR","privacy_model":"computational","proof_model":null,"quantum_security":null,"query_communication":"exact promoted setting pending proceedings audit","resilience":null,"response_communication":"Paillier-compressed response; exact row pending proceedings audit","robustness":null,"security_mode":"computational","security_model":"accepted prepublication","security_notion":"query privacy","server_model":"single","server_work":"source reports over 2 GB/s throughput","setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"client_hint":"none","server_storage_per_client":"less than 200 KB in promoted 1 GB setting"},"statefulness":null,"summary":"Candidate row retained to expose the current branch. It is not eligible for a reproduced or settled-frontier claim at the cutoff.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":"server can generate and update hints during idle time in the stated model","verification_cost":null,"verification_status":"prepublication_abstract_reviewed","work_id":"PIR-PAPER-2026-ZIPPIR","year":2026}],"edges":[{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-00A3A339FD9A4F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2014-GI-DPF","target":"PIR-RESULT-2014-GI-DPF-COMPACT-TWO-SERVER-PIR-QUERIES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-00A7FF9150CB48","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-DISTRIBUTIONAL","target":"PIR-RESULT-2025-DISTRIBUTIONAL-CLASSIC-PIR-BLACK-BOX-COMPILER","type":"HAS_RESULT"},{"evidenceLocator":"ZLTS23 Section 2.2, PDF pp. 8-10","evidenceUrl":"https://eprint.iacr.org/2022/609.pdf","id":"PIR-REL-0291A8C118998E","note":"ZLTS23 says its batched-refresh idea is inspired by CHK22 and strengthens the compilation with privately programmable pseudorandom sets.","resultId":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","target":"PIR-RESULT-2023-ZLTS-PRIVATELY-PROGRAMMABLE-PSEUDORANDOM-SETS","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-039FB7820EBFCD","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","target":"PIR-ASSUMPTION-NO-COMPUTATIONAL-ASSUMPTION-SERVER-NON-COLLUSION-REQUIRED","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-03F41C22FFA630","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-DISTRIBUTIONAL","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"USENIX Security 2026 accepted-paper abstract","evidenceUrl":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","id":"PIR-REL-0570FBFE03C913","note":"The candidate observation binds the accepted abstract's throughput and server-storage claims to its 1 GB database setting without filling missing hardware or parameter fields.","resultId":null,"reviewStatus":"abstract_checked","source":"PIR-IMPL-2026-ZIPPIR","target":"PIR-BENCH-2026-ZIPPIR-1GB","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-0744F24EC01827","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2000-BIM","target":"PIR-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-08803424EF79CF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2000-BIM","target":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-0883D9233135DC","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-ALI-TRADEOFFS","target":"PIR-RESULT-2021-ALI-TRADEOFFS-MULPIR-MULTIPLICATIVE-RECURSION-TRADEOFF","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-08C7D765687F76","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2014-GI-DPF","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"Persiano–Yeo Abstract and Theorems 1-2, PDF pp. 1-2 and 8","evidenceUrl":"https://eprint.iacr.org/2022/235.pdf","id":"PIR-REL-08F2BDECE5644F","note":"Persiano–Yeo analyzes the public-preprocessing PIR model in the BIM line and proves tr = Omega(n log n) for its stated computational cell-probe hint range. The edge connects a model contribution to its lower-bound analysis, not to a separately mapped BIM bound.","resultId":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","target":"PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","type":"ANALYZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-094801542D243B","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-PIANO","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-09DC3FD278FAFD","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2022-SPIRAL-STREAM","target":"PIR-CONSTRUCTION-2022-SPIRAL","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-09ECAC9E5DBD42","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2023-TREEPIR","target":"PIR-PAPER-2023-TREEPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-0AE6DD46382EEF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2005-GR","target":"PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-0C6559FE534A3B","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-WORKLOAD-2026-ZIPPIR-1GB","target":"PIR-PAPER-2026-ZIPPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-0C7182EF5EE4DB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-1998-CGKS","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-0F80D94C326444","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-LMW-DEPIR","target":"PIR-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1134C479F14578","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-YEO","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"Distributional PIR Sections 3, 6, and 7","evidenceUrl":"https://www.usenix.org/system/files/usenixsecurity25-lehmkuhl.pdf","id":"PIR-REL-12711192D079D4","note":"The Distributional PIR system instantiates its black-box compiler with SimplePIR and separately optimizes SimplePIR's encryption and preprocessing path.","resultId":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","target":"PIR-RESULT-2025-DISTRIBUTIONAL-CLASSIC-PIR-BLACK-BOX-COMPILER","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-13C92D9A9E40D5","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-IMPL-2024-YPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1462434C85F1CC","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2024-PIANO","target":"PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-148B10D35C97D2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2020-CK-OFFLINE","target":"PIR-PAPER-2020-CK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-151BB8C93EC17D","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-WORKLOAD-2022-SPIRAL-STREAM","target":"PIR-CONSTRUCTION-2022-SPIRAL","type":"USED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1577E55FAB9244","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-THORPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1628EB06EF5348","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-IMPL-2022-SPIRAL","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-16429C52432012","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2024-PIANO","target":"PIR-PAPER-2024-PIANO","type":"DESCRIBED_IN"},{"evidenceLocator":"KO abstract and introduction","evidenceUrl":"https://doi.org/10.1109/SFCS.1997.646125","id":"PIR-REL-184839976C171A","note":"KO retains the CGKS index-privacy objective but replaces replicated non-colluding servers with one server and computational privacy under quadratic residuosity.","resultId":"PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR","reviewStatus":"abstract_checked","source":"PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR","target":"PIR-RESULT-1997-KO-FIRST-NONTRIVIAL-SINGLE-SERVER-CPIR","type":"CHANGES_SECURITY_MODEL"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1A20F29415C7E2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-YPIR","target":"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1A7C1B9050977A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-YEO","target":"PIR-RESULT-2023-YEO-TIGHT-PRIVATE-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1AC73E0918186F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2024-YPIR","target":"PIR-PAPER-2024-YPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1AE15BAB97F53B","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2021-FASTPIR","target":"PIR-ASSUMPTION-RING-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1AE8741DD7ABA6","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-SIMPLEPIR","target":"PIR-RESULT-2023-SIMPLEPIR-DOUBLEPIR-COMPRESSED-HINT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1E60F79208E5DB","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2022-SPIRAL","target":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-GSW-STYLE-LATTICE-ENCRYPTION-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-1F487E151C10C8","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-1997-KO","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-2096E0F67A636F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-1997-KO","target":"PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-20B6BE82AFC4F9","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-IMPL-2026-ZIPPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-228A292EA1EAA4","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-LMW-BLACKBOX","target":"PIR-RESULT-2025-LMW-BLACKBOX-TWO-ROUND-PASSIVE-SERVER-BLACK-BOX-BARRIER","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-2405EE26C87DFE","note":"","resultId":null,"reviewStatus":"source_derived","source":"PIR-MILESTONE-001-03","target":"PIR-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-24E832E4CBB5AC","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2021-MULPIR","target":"PIR-ASSUMPTION-HOMOMORPHIC-ENCRYPTION-ASSUMPTION","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-28F7626212EA5A","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-1998-CGKS-2S","target":"PIR-ASSUMPTION-NO-COMPUTATIONAL-ASSUMPTION-NON-COLLUSION-IS-A-DEPLOYMENT-ASSUMPTION","type":"RELIES_ON"},{"evidenceLocator":"SinglePass Abstract, Introduction, and Section 4","evidenceUrl":"https://eprint.iacr.org/2024/303.pdf","id":"PIR-REL-28F924025035EC","note":"SinglePass directly compares against Checklist and reduces client preprocessing to one database pass while improving the reported preprocessing and query costs.","resultId":"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS","target":"PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Paper artifact reference and repository","evidenceUrl":"https://github.com/menonsamir/spiral","id":"PIR-REL-29AB61044B57EB","note":"The Spiral repository implements the Regev-to-GSW translation and streaming variants evaluated by the paper.","resultId":"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION","target":"PIR-IMPL-2022-SPIRAL","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-29CCAF72EF963A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2005-GR","target":"PIR-PAPER-2005-GR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-29EBF63241180A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-BARRIER-002","target":"PIR-OP-001","type":"BLOCKS"},{"evidenceLocator":"Piano Section 1.1, PDF p. 3","evidenceUrl":"https://eprint.iacr.org/2023/452.pdf","id":"PIR-REL-2A168526AD5540","note":"Piano explicitly states that its PRF-only construction matches the CHK22 adaptive client-storage times server-time lower bound up to polylogarithmic factors.","resultId":"PIR-RESULT-2022-CHK-ADAPTIVE-STORAGE-TIME-LOWER-BOUND","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2022-CHK-ADAPTIVE-STORAGE-TIME-LOWER-BOUND","target":"PIR-RESULT-2024-PIANO-PRF-ONLY-OPTIMAL-CLIENT-PREPROCESSING","type":"MATCHES_BOUND"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-2A1F409BD2CD36","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-PARAM-2024-YPIR-32GB","target":"PIR-CONSTRUCTION-2024-YPIR","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-2D0C55DFD3E61F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-SINGLEPASS","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-2E06FFF20AD606","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2022-SPIRAL-STREAM","target":"PIR-WORKLOAD-2022-SPIRAL-STREAM","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"Ali et al. USENIX abstract and Sections 4 and 7","evidenceUrl":"https://www.usenix.org/system/files/sec21-ali.pdf","id":"PIR-REL-2E252B1F787EAE","note":"MulPIR changes the recursive response mechanism by using multiplicative homomorphism, exposing an explicit communication-versus-server-computation trade-off.","resultId":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","target":"PIR-RESULT-2021-ALI-TRADEOFFS-MULPIR-MULTIPLICATIVE-RECURSION-TRADEOFF","type":"CHANGES_MECHANISM"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-2E8D7530C41A7E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2026-ZIPPIR","target":"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-2F068A3A76A371","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2014-DPF","target":"PIR-PAPER-2014-GI-DPF","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-301BB058E39EC2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-SIMPLEPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-31173459CF7CE7","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","target":"PIR-ASSUMPTION-INHERITED-FROM-THE-CLASSIC-PIR-BACKEND","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-31F70CD6D3416C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2018-SEALPIR","target":"PIR-RESULT-2018-SEALPIR-PROBABILISTIC-BATCH-CODES-AMORTIZE-PROCESSING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-31FE5CE92183BB","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-PARAM-2024-YPIR-32GB","target":"PIR-PAPER-2024-YPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-324761DBAEA132","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-IMPL-2023-SIMPLEPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-3356F2B9CA8F82","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-PARAM-2026-ZIPPIR-1GB","target":"PIR-CONSTRUCTION-2026-ZIPPIR","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-35205261EEEC85","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-ROUTE-001","target":"PIR-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-37F5E66F72FB3B","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2023-ZLTS","target":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-38BFC0C2BAD77B","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2026-ZIPPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-39E8AA0C973EC2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-1999-CMS","target":"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-3A6A4B2940605B","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-CHECKLIST","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-3AEEAC984264C9","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-1997-KO","target":"PIR-PAPER-1997-KO","type":"DESCRIBED_IN"},{"evidenceLocator":"CK20 abstract and introduction","evidenceUrl":"https://eprint.iacr.org/2019/1075.pdf","id":"PIR-REL-3B519CE22A39D0","note":"CK20 develops the offline/online PIR program using query-independent private client state rather than BIM-style auxiliary server storage, enabling sublinear online lookups without increasing server storage; its lower bound is scoped to the unencoded/no-extra-server-state model.","resultId":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","target":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","type":"CHANGES_PREPROCESSING"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-3B5955735A307D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2024-SINGLEPASS","target":"PIR-PAPER-2024-SINGLEPASS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-3BE7FF203B2E15","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2023-DEPIR","target":"PIR-PAPER-2023-LMW-DEPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"USENIX Security 2026 accepted-paper abstract","evidenceUrl":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","id":"PIR-REL-3D7D253E9C681C","note":"A separate prototype object records the paper-described LWE-to-Paillier system while artifact availability remains unresolved at the cutoff.","resultId":"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION","reviewStatus":"abstract_checked","source":"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION","target":"PIR-IMPL-2026-ZIPPIR","type":"INSTANTIATES"},{"evidenceLocator":"Black-box DEPIR abstract and theorem overview","evidenceUrl":"https://eprint.iacr.org/2025/552.pdf","id":"PIR-REL-3E219B4A05C1DD","note":"LMW25 establishes a construction-power collapse for black-box primitives in its stated SK-DEPIR oracle framework. This provides context for structured DEPIR assumptions but does not rule out LMW23's Ring-LWE construction.","resultId":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","target":"PIR-RESULT-2025-LMW-BLACKBOX-BLACK-BOX-PRIMITIVES-COLLAPSE-TO-ONE-WAY-FUNCTIONS-FOR-SK-DEPIR","type":"EXPOSES_LIMITATION"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-3F57C85E7770CD","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-BARRIER-001","target":"PIR-OP-002","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-405E8922427533","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-SINGLEPASS","target":"PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4122AB1D4E0A5E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-CHK","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4177F1BC889092","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-LMW-BLACKBOX","target":"PIR-RESULT-2025-LMW-BLACKBOX-BLACK-BOX-PRIMITIVES-COLLAPSE-TO-ONE-WAY-FUNCTIONS-FOR-SK-DEPIR","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-41B6830B866760","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-TREEPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-41CC85BBA99AD0","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2021-FASTPIR","target":"PIR-PAPER-2021-ALI-TRADEOFFS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-42D53CFBB724EB","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-WORKLOAD-2023-SIMPLEPIR-1GB","target":"PIR-CONSTRUCTION-2023-SIMPLEPIR","type":"USED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-445A31903780DB","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-1997-KO","target":"PIR-ASSUMPTION-QUADRATIC-RESIDUOSITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-44A61421F583BF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2023-ZLTS","target":"PIR-PAPER-2023-ZLTS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4748E5F5943B68","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2021-CHECKLIST","target":"PIR-PAPER-2021-CHECKLIST","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4766E3ECAFB9AA","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-WORKLOAD-2026-ZIPPIR-1GB","target":"PIR-CONSTRUCTION-2026-ZIPPIR","type":"USED_WITH"},{"evidenceLocator":"Checklist Sections 2.2-3, USENIX PDF pp. 878-881","evidenceUrl":"https://www.usenix.org/system/files/sec21-kogan.pdf","id":"PIR-REL-47F3F34D7FD339","note":"Checklist adapts the CK20 offline/online PIR approach into a concrete two-server blocklist system and evaluates sublinear server-side lookups.","resultId":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","target":"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-49699214216BA3","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-SPIRAL","target":"PIR-RESULT-2022-SPIRAL-SPIRALSTREAM-HIGH-RATE-THROUGHPUT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4A5AFB5ACD2A32","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2020-CK-OFFLINE","target":"PIR-ASSUMPTION-VARIANT-DEPENDENT-SINGLE-SERVER-COMPUTATIONAL-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4B0D094A7E9C69","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-CHK","target":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4D6316A6F3D0F9","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2026-ZIPPIR-1GB","target":"PIR-PAPER-2026-ZIPPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"ZLTS23 Sections 2.1-2.2, PDF pp. 5-10","evidenceUrl":"https://eprint.iacr.org/2022/609.pdf","id":"PIR-REL-4E4D61FF8627CF","note":"ZLTS23 explicitly takes the SACM21 optimal two-server scheme as its starting point and homomorphically compiles its offline and refresh interactions into one server.","resultId":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","target":"PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR","type":"CHANGES_SECURITY_MODEL"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4E8CACB5F36A91","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-BENCH-2026-ZIPPIR-1GB","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-4E8FF8BF26C3FB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-YEO","target":"PIR-OP-002","type":"TARGETS"},{"evidenceLocator":"ThorPIR Introduction and construction overview, PDF pp. 1-4","evidenceUrl":"https://eprint.iacr.org/2024/482.pdf","id":"PIR-REL-4F0DD2A7B76BDE","note":"ThorPIR targets the deep homomorphic hint-generation bottleneck in prior single-server client-preprocessing compilations and replaces it with a constant-depth Thorp-shuffle circuit.","resultId":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","target":"PIR-RESULT-2024-THORPIR-CONSTANT-DEPTH-HOMOMORPHIC-THORP-PREPROCESSING","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-50B7E81030323B","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","target":"PIR-RESULT-2023-LP-NEAR-OPTIMAL-SINGLE-SERVER-PREPROCESSING-FRONTIER","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-521857CA269592","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-WORKLOAD-2024-YPIR-32GB","target":"PIR-CONSTRUCTION-2024-YPIR","type":"USED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-5262B5D96132FF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-ROUTE-002","target":"PIR-OP-002","type":"ENABLES"},{"evidenceLocator":"Spiral abstract","evidenceUrl":"https://eprint.iacr.org/2022/368.pdf","id":"PIR-REL-52D0E17967B7C0","note":"The contextual observation records the implementation's source-reported 1.9 GB/s and 0.81 response-rate streaming setting.","resultId":null,"reviewStatus":"primary_source_checked","source":"PIR-IMPL-2022-SPIRAL","target":"PIR-BENCH-2022-SPIRAL-STREAM","type":"BENCHMARKS"},{"evidenceLocator":"USENIX paper artifact reference","evidenceUrl":"https://github.com/ahenzinger/simplepir","id":"PIR-REL-52F2A93E086DF3","note":"The SimplePIR Go artifact implements the paper's memory-bandwidth-oriented LWE matrix-vector protocol.","resultId":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","target":"PIR-IMPL-2023-SIMPLEPIR","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-54C12D7A63A960","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2022-SPIRAL-STREAM","target":"PIR-PARAM-2022-SPIRAL-STREAM","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-54CB8A924E8679","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2023-SIMPLEPIR-1GB","target":"PIR-IMPL-2023-SIMPLEPIR","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-5561ECF29D8496","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-TREEPIR","target":"PIR-RESULT-2023-TREEPIR-WEAK-PRIVATELY-PUNCTURABLE-PRF","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-563C9C7EB53B3F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-SINGLEPASS","target":"PIR-RESULT-2024-SINGLEPASS-CONSTANT-TIME-DATABASE-UPDATES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-58580E8707DCBD","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","target":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-596A59B1DA74B1","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2018-SEALPIR","target":"PIR-PAPER-2018-SEALPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-5976BB32EEA5C9","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-BARRIER-003","target":"PIR-OP-002","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-59B53A2D9FF1E5","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-1999-CMS","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-59ED7C8C48542C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","target":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-5A351FD2881125","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","target":"PIR-PAPER-2025-DISTRIBUTIONAL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-5A5B25B614E5A4","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-OP-001","target":"PIR-PAPER-2023-SIMPLEPIR","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-5D2306CC22903C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-SPIRAL","target":"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-5E9D91A9DB4C9E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-CHECKLIST","target":"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-5FE7A8C7880DFC","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2023-DEPIR","target":"PIR-ASSUMPTION-RING-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-60356B9E306285","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-THORPIR","target":"PIR-RESULT-2024-THORPIR-CONSTANT-DEPTH-HOMOMORPHIC-THORP-PREPROCESSING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-605E52B24CEA2E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-OP-002","target":"PIR-PAPER-2023-LMW-DEPIR","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-626DD6E69F6BA8","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2023-SIMPLEPIR","target":"PIR-PAPER-2023-SIMPLEPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-62BBC67259CFC6","note":"","resultId":null,"reviewStatus":"source_derived","source":"PIR-MILESTONE-002-01","target":"PIR-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-63E82C97CCC1F0","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2022-CHK","target":"PIR-PAPER-2022-CHK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-642CF1328A4ACD","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-WORKLOAD-2024-YPIR-32GB","target":"PIR-PAPER-2024-YPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-6588438D5A6EE6","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2021-SACM","target":"PIR-PAPER-2021-SACM","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-65F599033469C5","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2024-YPIR-32GB","target":"PIR-PAPER-2024-YPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-67EAF244C9E0EF","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-PARAM-2022-SPIRAL-STREAM","target":"PIR-CONSTRUCTION-2022-SPIRAL","type":"PARAMETERIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-688E5EC6602237","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-PIANO","target":"PIR-RESULT-2024-PIANO-PRF-ONLY-OPTIMAL-CLIENT-PREPROCESSING","type":"HAS_RESULT"},{"evidenceLocator":"LP23 Abstract and Introduction, PDF pp. 1-4","evidenceUrl":"https://eprint.iacr.org/2022/830.pdf","id":"PIR-REL-68C3CEDCEED9E7","note":"LP23 identifies CHK22's near-square-root single-server time but near-square-root bandwidth as the remaining gap and independently reaches polylogarithmic amortized bandwidth.","resultId":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","target":"PIR-RESULT-2023-LP-NEAR-OPTIMAL-SINGLE-SERVER-PREPROCESSING-FRONTIER","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-6BC0412BBFF1D8","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2022-CHK","target":"PIR-ASSUMPTION-LHE-OR-FHE-FROM-STANDARD-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-6C958784500C2F","note":"","resultId":null,"reviewStatus":"source_derived","source":"PIR-MILESTONE-001-01","target":"PIR-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-6DD428DD009249","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2014-DPF","target":"PIR-ASSUMPTION-PSEUDORANDOM-GENERATOR-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-6DF2D563659006","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-WORKLOAD-2023-SIMPLEPIR-1GB","target":"PIR-PAPER-2023-SIMPLEPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-726C3B3154F0D0","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-1999-CMS","target":"PIR-PAPER-1999-CMS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-72B9043045BEA9","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2018-SEALPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7350B37FFBE313","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-YPIR","target":"PIR-RESULT-2024-YPIR-HIGH-THROUGHPUT-LWE-TO-RLWE-TRANSLATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-74EAE7ED79926C","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2026-ZIPPIR-1GB","target":"PIR-WORKLOAD-2026-ZIPPIR-1GB","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"SACM21 Introduction, discussion of CK20, and Theorem 1.1","evidenceUrl":"https://eprint.iacr.org/2020/1592.pdf","id":"PIR-REL-76B4A5327FEE99","note":"SACM21 starts from the CK20 two-server client-preprocessing line and preserves its near-square-root online computation while reducing online bandwidth to polylogarithmic for unbounded queries.","resultId":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","target":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7701C10CFC02EF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2020-CK","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7A0F7C8FF50CAB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-YPIR","target":"PIR-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7A971EF48FA355","note":"","resultId":null,"reviewStatus":"source_derived","source":"PIR-MILESTONE-001-02","target":"PIR-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7AAF0FB2F5519C","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2018-SEALPIR","target":"PIR-CONSTRUCTION-2018-SEALPIR","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7AF6B616C7ED5C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-PY-LIMITS","target":"PIR-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7C9A161F50972A","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2024-YPIR","target":"PIR-PAPER-2024-YPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7DFD47E826E2D3","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-ZLTS","target":"PIR-RESULT-2023-ZLTS-PRIVATELY-PROGRAMMABLE-PSEUDORANDOM-SETS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7E2B8E06E764EC","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2024-THORPIR","target":"PIR-ASSUMPTION-BFV-BGV-STYLE-HOMOMORPHIC-ENCRYPTION","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7FB00D3900C08F","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-PARAM-2023-SIMPLEPIR-1GB","target":"PIR-PAPER-2023-SIMPLEPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-7FF7A449203DCF","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2026-ZIPPIR-1GB","target":"PIR-IMPL-2026-ZIPPIR","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-815612D117CB93","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-DISTRIBUTIONAL","target":"PIR-RESULT-2025-DISTRIBUTIONAL-PROBE-MODEL-SERVER-RUNTIME-LOWER-BOUND","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-8178593277A018","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-BENCH-2023-SIMPLEPIR-1GB","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-8201CEF48712D1","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR","target":"PIR-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-820CCAD3E3AF7F","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2024-YPIR-32GB","target":"PIR-PARAM-2024-YPIR-32GB","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-82E8D20572DD8F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-SIMPLEPIR","target":"PIR-OP-001","type":"APPROACHES"},{"evidenceLocator":"Multi-server DEPIR Abstract and Introduction","evidenceUrl":"https://eprint.iacr.org/2024/829.pdf","id":"PIR-REL-8404E92D3B1CB6","note":"The 2025 work responds to LMW23's standard-assumption single-server DEPIR boundary with information-theoretic DEPIR using roughly logarithmically many non-colluding servers, near-linear preprocessing and subpolynomial online time/communication. It changes the server model rather than strengthening the single-server construction.","resultId":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","target":"PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR","type":"CHANGES_SECURITY_MODEL"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-8701871A3D3A2F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2005-GR","target":"PIR-RESULT-2005-GR-HIDDEN-SMOOTH-SUBGROUP-ENCODING","type":"HAS_RESULT"},{"evidenceLocator":"Spiral abstract and Introduction, comparison with ACLS18","evidenceUrl":"https://eprint.iacr.org/2022/368.pdf","id":"PIR-REL-872AD1092F6B2A","note":"Spiral introduces Regev-to-GSW ciphertext translation and reports query-size, response-rate and throughput improvements relative to prior lattice PIR systems including SealPIR in the paper's evaluated settings; the comparison is not an unconditional ranking across workloads.","resultId":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","target":"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-87A87172AAD664","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-BENCH-2024-YPIR-32GB","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-8859DC296773FB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2026-ZIPPIR","target":"PIR-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-893DE983216D6F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-LMW-DEPIR","target":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-8944E82E7457B2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","target":"PIR-RESULT-2023-LP-NEAR-OPTIMAL-ADAPTABLE-PSEUDORANDOM-SETS","type":"HAS_RESULT"},{"evidenceLocator":"TreePIR Abstract and Introduction","evidenceUrl":"https://eprint.iacr.org/2023/204.pdf","id":"PIR-REL-89CE45C1D0E540","note":"TreePIR explicitly targets SACM's two-server sublinear-time, polylog-bandwidth point and realizes it from DDH using weak privately puncturable PRFs instead of the heavier privately puncturable-set machinery.","resultId":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","target":"PIR-RESULT-2023-TREEPIR-DDH-BASED-SUBLINEAR-TIME-POLYLOG-BANDWIDTH-PIR","type":"CHANGES_ASSUMPTION"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-8A60201D4DEA42","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2024-YPIR","target":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-RING-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"YPIR abstract and Introduction","evidenceUrl":"https://www.usenix.org/system/files/usenixsecurity24-menon.pdf","id":"PIR-REL-8B7ABBBC88BB85","note":"YPIR removes the downloaded client hint present in the SimplePIR line by applying LWE-to-RLWE packing to DoublePIR's response, keeping database-dependent preprocessing at the server and accepting larger online queries. This is a preprocessing-cost progression relative to SimplePIR, not an identification of SimplePIR with DoublePIR.","resultId":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","target":"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","type":"CHANGES_PREPROCESSING"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-8B881AD3BD3C39","note":"","resultId":null,"reviewStatus":"source_derived","source":"PIR-MILESTONE-002-02","target":"PIR-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"Ali et al. USENIX abstract and Sections 3 and 7","evidenceUrl":"https://www.usenix.org/system/files/sec21-ali.pdf","id":"PIR-REL-8D631DEB58F374","note":"FastPIR explicitly improves SealPIR with compression and a new oblivious expansion, reducing communication while preserving essentially the same computation cost in the paper's evaluation.","resultId":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","target":"PIR-RESULT-2021-ALI-TRADEOFFS-FASTPIR-COMPRESSED-SEALPIR-TRADEOFF","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-8DB7D951D77DAA","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-ZLTS","target":"PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR","type":"HAS_RESULT"},{"evidenceLocator":"ZLTS23 Abstract, Table 1, and Theorem 1.1","evidenceUrl":"https://eprint.iacr.org/2022/609.pdf","id":"PIR-REL-900F23C75A55F6","note":"ZLTS23 keeps CHK22's near-square-root single-server computation and storage profile while reducing amortized bandwidth from near-square-root to polylogarithmic.","resultId":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","target":"PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"LMW23 abstract and introduction","evidenceUrl":"https://eprint.iacr.org/2022/1703.pdf","id":"PIR-REL-90369234F20436","note":"LMW23 develops public server preprocessing into unkeyed single-server DEPIR with deterministic client-independent preprocessing and polylogarithmic online time and communication under Ring-LWE. Its preprocessing and update costs remain part of the model.","resultId":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","target":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","type":"CHANGES_PREPROCESSING"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-90AEA33DFA954F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-940EA0B211F256","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2020-CK","target":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-9422BB78015506","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","target":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-ADAPTABLE-PRS-INGREDIENTS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-9520F26AC753A4","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2023-SIMPLEPIR-1GB","target":"PIR-CONSTRUCTION-2023-SIMPLEPIR","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-9540BC834845F6","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2023-SIMPLEPIR","target":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-96D0677C58F5CC","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2024-YPIR-32GB","target":"PIR-WORKLOAD-2024-YPIR-32GB","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-979ED2C25C59AF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2020-CK","target":"PIR-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-97B4CA199A3905","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2026-ZIPPIR","target":"PIR-PAPER-2026-ZIPPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-99557F6E0B55E1","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-BENCH-2022-SPIRAL-STREAM","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-99DD54E52DF600","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-PY-LIMITS","target":"PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","type":"HAS_RESULT"},{"evidenceLocator":"Gentry–Ramzan Introduction, Our Results, PDF pp. 2-3","evidenceUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","id":"PIR-REL-9AC67D01BDFB48","note":"Gentry–Ramzan explicitly starts from the CMS Phi-hiding technique and changes the encoding so one short response recovers a block, obtaining O(k+d) communication and constant rate for large blocks.","resultId":"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION","reviewStatus":"fulltext_checked","source":"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION","target":"PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL","type":"CHANGES_MECHANISM"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-9BA55A8430489A","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2024-YPIR-32GB","target":"PIR-IMPL-2024-YPIR","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-A17C81845B4844","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2026-ZIPPIR","target":"PIR-PAPER-2026-ZIPPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-A1C895237555C8","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-1998-CGKS","target":"PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-A4678B2693A830","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2023-SIMPLEPIR","target":"PIR-CONSTRUCTION-2023-SIMPLEPIR","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-A48C2BC08DD1C7","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-IMPL-2018-SEALPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"SinglePass Abstract and Section 5","evidenceUrl":"https://eprint.iacr.org/2024/303.pdf","id":"PIR-REL-A556882FF069A9","note":"SinglePass replaces the Checklist-style logarithmic update overhead with worst-case constant-time edits and amortized constant-time append additions to its client hint, while ordinary queries avoid Checklist's logarithmic bandwidth overhead; deletion semantics are not generalized.","resultId":"PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES","target":"PIR-RESULT-2024-SINGLEPASS-CONSTANT-TIME-DATABASE-UPDATES","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-A7A87F0955B612","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-YPIR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-A887ADEF6B5809","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-ALI-TRADEOFFS","target":"PIR-RESULT-2021-ALI-TRADEOFFS-FASTPIR-COMPRESSED-SEALPIR-TRADEOFF","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-A978BD204CCEFF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2024-PIANO","target":"PIR-RESULT-2024-PIANO-PRACTICAL-SINGLE-SERVER-SUBLINEAR-TIME-PIR","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-AB80CA5608B269","note":"","resultId":null,"reviewStatus":"source_derived","source":"PIR-MILESTONE-002-03","target":"PIR-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-AC999FF0CC2402","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-PARAM-2023-SIMPLEPIR-1GB","target":"PIR-CONSTRUCTION-2023-SIMPLEPIR","type":"PARAMETERIZES"},{"evidenceLocator":"USENIX artifact appendix A.2-A.4","evidenceUrl":"https://www.usenix.org/system/files/usenixsecurity24-appendix-menon.pdf","id":"PIR-REL-AE2CF321D0E114","note":"The archived b980152 artifact implements YPIR and fixes the Rust, compiler, Docker, and recommended AVX-512 environment used by the evaluation.","resultId":"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","target":"PIR-IMPL-2024-YPIR","type":"INSTANTIATES"},{"evidenceLocator":"YPIR abstract and artifact appendix","evidenceUrl":"https://www.usenix.org/system/files/usenixsecurity24-menon.pdf","id":"PIR-REL-AE5F8056272585","note":"The contextual observation records the artifact's 32 GB small-record setting with 12.1 GB/s/core and 2.5 MB total communication.","resultId":null,"reviewStatus":"primary_source_checked","source":"PIR-IMPL-2024-YPIR","target":"PIR-BENCH-2024-YPIR-32GB","type":"BENCHMARKS"},{"evidenceLocator":"Paper artifact reference and repository README","evidenceUrl":"https://github.com/microsoft/SealPIR","id":"PIR-REL-AF072FF79FC782","note":"The public SealPIR repository implements the paper's compressed RLWE query expansion pipeline.","resultId":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","reviewStatus":"primary_source_checked","source":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","target":"PIR-IMPL-2018-SEALPIR","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-AFB714D2D4353F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2014-GI-DPF","target":"PIR-RESULT-2014-GI-DPF-INTRODUCED-DISTRIBUTED-POINT-FUNCTIONS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-B1807488091D94","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2023-TREEPIR","target":"PIR-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-B3C5DE549584B2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-YEO","target":"PIR-RESULT-2023-YEO-OMV-BARRIER-FOR-GENERAL-PIR-LOWER-BOUNDS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-B771DCE57BD6AF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-CHK","target":"PIR-RESULT-2022-CHK-ADAPTIVE-STORAGE-TIME-LOWER-BOUND","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-B835EFC111111E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-LMW-DEPIR","target":"PIR-OP-002","type":"APPROACHES"},{"evidenceLocator":"CHK22 Introduction, Sections 1.1 and 3-5","evidenceUrl":"https://eprint.iacr.org/2022/081.pdf","id":"PIR-REL-BA927FA817BD57","note":"CHK22 extends the offline/online line from isolated lookups to a single-server, adaptive multi-query scheme with sublinear amortized time and storage.","resultId":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","target":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-C0B9001175A15D","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2021-CHECKLIST","target":"PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS-AND-INSTANTIATED-PIR-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-C27A96D8442019","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-CHK","target":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-C42631AC2CAAD3","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2000-BIM","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-C5CAC04819D112","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2005-GR","target":"PIR-ASSUMPTION-HIDDEN-SMOOTH-SUBGROUP-ASSUMPTION","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-C69EA569E88CB1","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2022-SPIRAL","target":"PIR-CONSTRUCTION-2022-SPIRAL","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-C71E3D6B52F0A5","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2018-SEALPIR","target":"PIR-PAPER-2018-SEALPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CAB75E66C4A852","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2000-BIM","target":"PIR-RESULT-2000-BIM-LINEAR-WORK-BARRIER-WITHOUT-PREPROCESSING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CBE4590D808192","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2024-SINGLEPASS","target":"PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CC96FADB5202AA","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2026-ZIPPIR","target":"PIR-CONSTRUCTION-2026-ZIPPIR","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CDA32D032F27E2","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2018-SEALPIR","target":"PIR-ASSUMPTION-RING-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CDC355B6E0ECBA","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2023-SIMPLEPIR-1GB","target":"PIR-PARAM-2023-SIMPLEPIR-1GB","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CDC51FF6F3D4AE","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-LMW-DEPIR","target":"PIR-RESULT-2023-LMW-DEPIR-POLYLOG-ONLINE-TIME-AND-COMMUNICATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CE5580DCF7043D","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2024-YPIR-32GB","target":"PIR-CONSTRUCTION-2024-YPIR","type":"BENCHMARKS"},{"evidenceLocator":"Yeo23 Sections 1.1 and 3, Theorems 2, 5, and 6","evidenceUrl":"https://eprint.iacr.org/2022/828.pdf","id":"PIR-REL-CE7E9C7CC710DD","note":"Yeo23 closes the multiplicative logarithmic gap in CK20's single-query private-preprocessing storage-time lower bound and generalizes the trade-off to batch queries.","resultId":"PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF","target":"PIR-RESULT-2023-YEO-TIGHT-PRIVATE-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","type":"SHARPENS_BOUND"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CE885E3C0ED2C8","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2022-SPIRAL","target":"PIR-PAPER-2022-SPIRAL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CF6325B6D0179E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-SIMPLEPIR","target":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CF9CCCC852C5EB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-CHECKLIST","target":"PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-CFD9A1FEE6DE40","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-DISTRIBUTIONAL","target":"PIR-RESULT-2025-DISTRIBUTIONAL-DISTRIBUTIONAL-PIR-WITH-RELAXED-CORRECTNESS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-D1025D97DA90CF","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-PARAM-2022-SPIRAL-STREAM","target":"PIR-PAPER-2022-SPIRAL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-D1A1266AB6F742","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-1999-CMS","target":"PIR-ASSUMPTION-PHI-HIDING-AND-PHI-SAMPLING-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-D2DB0C0F9DBF91","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-OP-002","target":"PIR-PAPER-2025-LMW-BLACKBOX","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-D40BBA6DE7D07B","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR","target":"PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-D71B52E13BEB82","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2022-SPIRAL-STREAM","target":"PIR-PAPER-2022-SPIRAL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-D76EAEB360F26B","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2023-SIMPLEPIR","target":"PIR-PAPER-2023-SIMPLEPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-D825E0A523F49D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-SACM","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"SACM21 Introduction and Theorem 1.1, PDF pp. 1-4","evidenceUrl":"https://eprint.iacr.org/2020/1592.pdf","id":"PIR-REL-D9C02C75CAB5B0","note":"SACM21 develops the PIR preprocessing program through two-server private client preprocessing, attaining unbounded queries with near-square-root online work/client storage and polylogarithmic bandwidth. This differs from BIM's auxiliary-server-storage setting.","resultId":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","reviewStatus":"fulltext_checked","source":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","target":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","type":"CHANGES_PREPROCESSING"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-DB2F58FB8771C6","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-1998-CGKS-2S","target":"PIR-PAPER-1998-CGKS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-DB8C2C56021671","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2026-ZIPPIR","target":"PIR-RESULT-2026-ZIPPIR-HIGH-THROUGHPUT-WITHOUT-CLIENT-HINT-STORAGE","type":"HAS_RESULT"},{"evidenceLocator":"USENIX abstract and Table 10","evidenceUrl":"https://www.usenix.org/system/files/usenixsecurity23-henzinger.pdf","id":"PIR-REL-DBAA99A760EFE3","note":"The observation binds the SimplePIR artifact to the paper's 1 GB database, 121 MB hint, 242 KB online communication, and roughly 10 GB/s/core setting.","resultId":null,"reviewStatus":"primary_source_checked","source":"PIR-IMPL-2023-SIMPLEPIR","target":"PIR-BENCH-2023-SIMPLEPIR-1GB","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-DD538FD7B5DFD1","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-OP-001","target":"PIR-PAPER-2024-YPIR","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-DD88FC8CF04FAE","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2026-ZIPPIR-1GB","target":"PIR-PARAM-2026-ZIPPIR-1GB","type":"EVALUATED_WITH"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-DEC6020B8C9E85","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-1997-KO","target":"PIR-RESULT-1997-KO-FIRST-NONTRIVIAL-SINGLE-SERVER-CPIR","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-DF38D242A1DCF4","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-BARRIER-001","target":"PIR-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-E119187D150B19","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-WORKLOAD-2022-SPIRAL-STREAM","target":"PIR-PAPER-2022-SPIRAL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-E18DBD06E8E9EE","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-IMPL-2024-YPIR","target":"PIR-CONSTRUCTION-2024-YPIR","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-E2090D34EB28B7","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2025-LMW-BLACKBOX","target":"PIR-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-E3329C3F1FDBE2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-SACM","target":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","type":"HAS_RESULT"},{"evidenceLocator":"USENIX Security 2026 accepted-paper abstract","evidenceUrl":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","id":"PIR-REL-E348F126E09159","note":"ZipPIR's accepted abstract targets the client-storage and update burden of large hint-based protocols such as SimplePIR through LWE-to-Paillier compression and almost silent offline work.","resultId":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","reviewStatus":"abstract_checked","source":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","target":"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION","type":"CHANGES_PREPROCESSING"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-E82D37FDB519A2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-SACM","target":"PIR-RESULT-2021-SACM-PRIVATELY-PUNCTURABLE-PSEUDORANDOM-SETS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-E8DB8B96167FE3","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-SPIRAL","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-EA4D008A4D5E54","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2026-ZIPPIR-1GB","target":"PIR-CONSTRUCTION-2026-ZIPPIR","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-EACD9E8C411997","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-ZLTS","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-EC780693A8B4B6","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-PARAM-2026-ZIPPIR-1GB","target":"PIR-PAPER-2026-ZIPPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-ECA5B9D5A901E1","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2021-SACM","target":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-ECFCEFE0F7BC64","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2023-SIMPLEPIR-1GB","target":"PIR-PAPER-2023-SIMPLEPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-EDF82F0DFC0367","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PIR-CONSTRUCTION-2026-ZIPPIR","target":"PIR-ASSUMPTION-LWE-PLUS-PAILLIER-COMPOSITE-RESIDUOSITY-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-EF01C624AA6AFB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2022-CHK","target":"PIR-OP-002","type":"TARGETS"},{"evidenceLocator":"CMS99 Introduction and Main Theorem, PDF pp. 2-3","evidenceUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/pirpolylog.pdf","id":"PIR-REL-EF19C12CC8ED36","note":"CMS99 explicitly takes KO97's single-server n^epsilon communication result as its starting boundary and obtains polylogarithmic communication under the new Phi assumptions.","resultId":"PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION","reviewStatus":"fulltext_checked","source":"PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION","target":"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION","type":"CHANGES_ASSUMPTION"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-EFCA4266FEFC19","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2021-ALI-TRADEOFFS","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-F13A534470A30A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2022-SPIRAL","target":"PIR-PAPER-2022-SPIRAL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-F1610144EAED47","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2024-THORPIR","target":"PIR-PAPER-2024-THORPIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-F348935F4A5F29","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2018-SEALPIR","target":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-F568002F353A50","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-OP-001","target":"PIR-PAPER-2026-ZIPPIR","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-F6AB297F8616E0","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2023-SIMPLEPIR-1GB","target":"PIR-WORKLOAD-2023-SIMPLEPIR-1GB","type":"EVALUATES_WORKLOAD"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-F7CCE25FAD1DFF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2020-CK","target":"PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-F7FE14BB12E524","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-CONSTRUCTION-2021-MULPIR","target":"PIR-PAPER-2021-ALI-TRADEOFFS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-FAB13789C413F8","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-1998-CGKS","target":"PIR-RESULT-1998-CGKS-TWO-SERVER-N-ONE-THIRD-COMMUNICATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-FB32F6CB730358","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2005-GR","target":"PIR-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-FBC08290BCA69F","note":"","resultId":null,"reviewStatus":"reported","source":"PIR-BENCH-2022-SPIRAL-STREAM","target":"PIR-IMPL-2022-SPIRAL","type":"MEASURES_IMPLEMENTATION"},{"evidenceLocator":"","evidenceUrl":"","id":"PIR-REL-FF692C9CABF62D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PIR-PAPER-2023-TREEPIR","target":"PIR-RESULT-2023-TREEPIR-DDH-BASED-SUBLINEAR-TIME-POLYLOG-BANDWIDTH-PIR","type":"HAS_RESULT"}],"nodes":[{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-BFV-BGV-STYLE-HOMOMORPHIC-ENCRYPTION","keywords":["lattice"],"metadata":{"family":"lattice","name":"BFV/BGV-style homomorphic encryption"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more PIR construction records: BFV/BGV-style homomorphic encryption.","title":"BFV/BGV-style homomorphic encryption","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-BFV-BGV-STYLE-HOMOMORPHIC-ENCRYPTION"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","keywords":["group"],"metadata":{"family":"group","name":"Decisional Diffie-Hellman"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"group","summary":"Assumption used by one or more PIR construction records: Decisional Diffie-Hellman.","title":"Decisional Diffie-Hellman","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-HIDDEN-SMOOTH-SUBGROUP-ASSUMPTION","keywords":["number theoretic"],"metadata":{"family":"number theoretic","name":"Hidden smooth subgroup assumption"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"number theoretic","summary":"Assumption used by one or more PIR construction records: Hidden smooth subgroup assumption.","title":"Hidden smooth subgroup assumption","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-HIDDEN-SMOOTH-SUBGROUP-ASSUMPTION"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-HOMOMORPHIC-ENCRYPTION-ASSUMPTION","keywords":["lattice"],"metadata":{"family":"lattice","name":"Homomorphic-encryption assumption"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more PIR construction records: Homomorphic-encryption assumption.","title":"Homomorphic-encryption assumption","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-HOMOMORPHIC-ENCRYPTION-ASSUMPTION"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-INHERITED-FROM-THE-CLASSIC-PIR-BACKEND","keywords":["adapter"],"metadata":{"family":"adapter","name":"Inherited from the classic PIR backend"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"adapter","summary":"Assumption used by one or more PIR construction records: Inherited from the classic PIR backend.","title":"Inherited from the classic PIR backend","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-INHERITED-FROM-THE-CLASSIC-PIR-BACKEND"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS","keywords":["lattice"],"metadata":{"family":"lattice","name":"Learning With Errors"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more PIR construction records: Learning With Errors.","title":"Learning With Errors","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-LEARNING-WITH-ERRORS"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-ADAPTABLE-PRS-INGREDIENTS","keywords":["lattice"],"metadata":{"family":"lattice","name":"Learning With Errors and adaptable PRS ingredients"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more PIR construction records: Learning With Errors and adaptable PRS ingredients.","title":"Learning With Errors and adaptable PRS ingredients","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-ADAPTABLE-PRS-INGREDIENTS"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-GSW-STYLE-LATTICE-ENCRYPTION-SECURITY","keywords":["lattice"],"metadata":{"family":"lattice","name":"Learning With Errors and GSW-style lattice encryption security"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more PIR construction records: Learning With Errors and GSW-style lattice encryption security.","title":"Learning With Errors and GSW-style lattice encryption security","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-GSW-STYLE-LATTICE-ENCRYPTION-SECURITY"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-RING-LEARNING-WITH-ERRORS","keywords":["lattice"],"metadata":{"family":"lattice","name":"Learning With Errors and Ring Learning With Errors"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more PIR construction records: Learning With Errors and Ring Learning With Errors.","title":"Learning With Errors and Ring Learning With Errors","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-LEARNING-WITH-ERRORS-AND-RING-LEARNING-WITH-ERRORS"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-LHE-OR-FHE-FROM-STANDARD-ASSUMPTIONS","keywords":["mixed"],"metadata":{"family":"mixed","name":"LHE or FHE from standard assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"mixed","summary":"Assumption used by one or more PIR construction records: LHE or FHE from standard assumptions.","title":"LHE or FHE from standard assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-LHE-OR-FHE-FROM-STANDARD-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-LWE-PLUS-PAILLIER-COMPOSITE-RESIDUOSITY-SECURITY","keywords":["hybrid_lattice_number_theoretic"],"metadata":{"family":"hybrid_lattice_number_theoretic","name":"LWE plus Paillier/composite-residuosity security"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"hybrid_lattice_number_theoretic","summary":"Assumption used by one or more PIR construction records: LWE plus Paillier/composite-residuosity security.","title":"LWE plus Paillier/composite-residuosity security","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-LWE-PLUS-PAILLIER-COMPOSITE-RESIDUOSITY-SECURITY"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-NO-COMPUTATIONAL-ASSUMPTION-NON-COLLUSION-IS-A-DEPLOYMENT-ASSUMPTION","keywords":["information_theoretic"],"metadata":{"family":"information_theoretic","name":"No computational assumption; non-collusion is a deployment assumption"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"information_theoretic","summary":"Assumption used by one or more PIR construction records: No computational assumption; non-collusion is a deployment assumption.","title":"No computational assumption; non-collusion is a deployment assumption","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-NO-COMPUTATIONAL-ASSUMPTION-NON-COLLUSION-IS-A-DEPLOYMENT-ASSUMPTION"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-NO-COMPUTATIONAL-ASSUMPTION-SERVER-NON-COLLUSION-REQUIRED","keywords":["information_theoretic"],"metadata":{"family":"information_theoretic","name":"No computational assumption; server non-collusion required"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"information_theoretic","summary":"Assumption used by one or more PIR construction records: No computational assumption; server non-collusion required.","title":"No computational assumption; server non-collusion required","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-NO-COMPUTATIONAL-ASSUMPTION-SERVER-NON-COLLUSION-REQUIRED"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-PHI-HIDING-AND-PHI-SAMPLING-ASSUMPTIONS","keywords":["number_theoretic"],"metadata":{"family":"number_theoretic","name":"Phi-Hiding and Phi-Sampling assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"number_theoretic","summary":"Assumption used by one or more PIR construction records: Phi-Hiding and Phi-Sampling assumptions.","title":"Phi-Hiding and Phi-Sampling assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-PHI-HIDING-AND-PHI-SAMPLING-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS","keywords":["symmetric_key"],"metadata":{"family":"symmetric_key","name":"Pseudorandom functions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric_key","summary":"Assumption used by one or more PIR construction records: Pseudorandom functions.","title":"Pseudorandom functions","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS-AND-INSTANTIATED-PIR-ASSUMPTIONS","keywords":["mixed"],"metadata":{"family":"mixed","name":"Pseudorandom functions and instantiated PIR assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"mixed","summary":"Assumption used by one or more PIR construction records: Pseudorandom functions and instantiated PIR assumptions.","title":"Pseudorandom functions and instantiated PIR assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-PSEUDORANDOM-FUNCTIONS-AND-INSTANTIATED-PIR-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-PSEUDORANDOM-GENERATOR-SECURITY","keywords":["symmetric_key"],"metadata":{"family":"symmetric_key","name":"Pseudorandom generator security"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric_key","summary":"Assumption used by one or more PIR construction records: Pseudorandom generator security.","title":"Pseudorandom generator security","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-PSEUDORANDOM-GENERATOR-SECURITY"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-QUADRATIC-RESIDUOSITY","keywords":["number_theoretic"],"metadata":{"family":"number_theoretic","name":"Quadratic Residuosity"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"number_theoretic","summary":"Assumption used by one or more PIR construction records: Quadratic Residuosity.","title":"Quadratic Residuosity","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-QUADRATIC-RESIDUOSITY"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-RING-LEARNING-WITH-ERRORS","keywords":["lattice"],"metadata":{"family":"lattice","name":"Ring Learning With Errors"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more PIR construction records: Ring Learning With Errors.","title":"Ring Learning With Errors","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-RING-LEARNING-WITH-ERRORS"},{"evidence":"scheme_declared","id":"PIR-ASSUMPTION-VARIANT-DEPENDENT-SINGLE-SERVER-COMPUTATIONAL-ASSUMPTIONS","keywords":["mixed"],"metadata":{"family":"mixed","name":"Variant-dependent; single-server computational assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"mixed","summary":"Assumption used by one or more PIR construction records: Variant-dependent; single-server computational assumptions.","title":"Variant-dependent; single-server computational assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ASSUMPTION-VARIANT-DEPENDENT-SINGLE-SERVER-COMPUTATIONAL-ASSUMPTIONS"},{"evidence":"bibliographic_checked","id":"PIR-BARRIER-001","keywords":[],"metadata":{"claim":"In the scoped ordinary model, hiding the requested location requires linear aggregate server work; sublinear online time must change the model, usually through preprocessing or client state.","does_not_exclude":["Offline/online client hints","Public server preprocessing and DEPIR","Amortized, batch, distributional, or structured-database variants with explicit changed semantics"],"dossier_type":"barrier","escape_hatches":["preprocessing","client-independent offline work","public data structures","relaxed correctness"],"evidence":"bibliographic_checked","excludes":["Claims of sublinear online server work while retaining the ordinary no-preprocessing model unchanged"],"id":"PIR-BARRIER-001","scope":{"model":"ordinary PIR without database preprocessing","resource":"aggregate server probes/work per query"},"status":"scoped_literature_barrier","targets":["PIR-OP-001","PIR-OP-002"],"title":"Linear online work without preprocessing in the ordinary PIR model"},"primaryUrl":null,"sections":[{"content":"The exact BIM00 theorem locator remains queued. Later audited primary sources consistently state this boundary; the card deliberately avoids extending it beyond their model.","heading":"Evidence note"}],"status":"scoped_literature_barrier","subtitle":"","summary":"The exact BIM00 theorem locator remains queued. Later audited primary sources consistently state this boundary; the card deliberately avoids extending it beyond their model.","title":"Linear online work without preprocessing in the ordinary PIR model","type":"barrier","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-BARRIER-001"},{"evidence":"primary_source_checked","id":"PIR-BARRIER-002","keywords":[],"metadata":{"claim":"Moving work into a reusable hint can make online processing memory-bandwidth fast while leaving a large client download and a database-freshness obligation.","does_not_exclude":["Silent server-side preprocessing","Small server-side per-client state","Incrementally updatable or application-amortized hints"],"dossier_type":"barrier","escape_hatches":["silent preprocessing","ciphertext conversion","incremental hint updates","application-specific update epochs"],"evidence":"primary_source_checked","excludes":["Treating online throughput alone as the complete end-to-end PIR cost","Treating a database-dependent hint as free setup across updates"],"id":"PIR-BARRIER-002","scope":{"model":"high-throughput single-server PIR with a database-dependent client hint","persistent client storage":null,"redistribution after updates":null,"resources":"offline download"},"status":"scoped_literature_barrier","targets":["PIR-OP-001"],"title":"Reusable client hints create storage and freshness debt"},"primaryUrl":null,"sections":[{"content":"SimplePIR and YPIR expose the tradeoff directly in their matched source comparison. It is an accounting barrier, not an impossibility theorem.","heading":"Evidence note"}],"status":"scoped_literature_barrier","subtitle":"","summary":"SimplePIR and YPIR expose the tradeoff directly in their matched source comparison. It is an accounting barrier, not an impossibility theorem.","title":"Reusable client hints create storage and freshness debt","type":"barrier","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-BARRIER-002"},{"evidence":"primary_source_checked","id":"PIR-BARRIER-003","keywords":[],"metadata":{"claim":"In the paper's scope, broad black-box cryptographic access collapses to black-box one-way functions and is insufficient for the two-round passive-server SK-DEPIR format covering known constructions.","does_not_exclude":["Ring-LWE constructions exploiting algebraic structure","Non-black-box techniques, additional rounds, active servers, or different preprocessing interfaces","Practical improvements to existing DEPIR constructions"],"dossier_type":"barrier","escape_hatches":["structured lattice algebra","non-black-box use","altered interaction","altered preprocessing"],"evidence":"primary_source_checked","excludes":["Using a generic black-box primitive alone as an explanation for the structured fast-access mechanism in that format"],"id":"PIR-BARRIER-003","scope":{"model":"secret-key DEPIR using black-box generic or idealized primitives","proved_format":"two-round passive-server schemes"},"status":"proved_scoped_barrier","targets":["PIR-OP-002"],"title":"Black-box cryptography does not supply the missing DEPIR structure"},"primaryUrl":null,"sections":[{"content":"Source: Lin, Mook, and Wichs, EUROCRYPT 2025/ePrint 2025/552, abstract and theorem overview. The card preserves the paper's escape hatches.","heading":"Evidence note"}],"status":"proved_scoped_barrier","subtitle":"","summary":"Source: Lin, Mook, and Wichs, EUROCRYPT 2025/ePrint 2025/552, abstract and theorem overview. The card preserves the paper's escape hatches.","title":"Black-box cryptography does not supply the missing DEPIR structure","type":"barrier","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-BARRIER-003"},{"evidence":"primary_source_checked","id":"PIR-BENCH-2022-SPIRAL-STREAM","keywords":["benchmark","reported","streaming"],"metadata":{"construction_id":"PIR-CONSTRUCTION-2022-SPIRAL","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"paper-reported server; exact model pending table audit","id":"PIR-BENCH-2022-SPIRAL-STREAM","implementation_id":"PIR-IMPL-2022-SPIRAL","keywords":["benchmark","reported","streaming"],"maps_to":["PIR-OP-001"],"metrics":{"communication":"query and response reductions stated relative to source baselines","response_rate":0.81,"throughput":"1.9 GB/s"},"paper_id":"PIR-PAPER-2022-SPIRAL","parameter_set_id":"PIR-PARAM-2022-SPIRAL-STREAM","source_locator":"Abstract; full-version Section 1","status":"reported","title":"SpiralStreamPack million-record reported observation","workload_id":"PIR-WORKLOAD-2022-SPIRAL-STREAM","year":2022},"primaryUrl":null,"sections":[{"content":"Historical source observation. No normalization against later memory-bandwidth systems is performed.","heading":"Interpretation"}],"status":"reported","subtitle":"2022","summary":"Historical source observation. No normalization against later memory-bandwidth systems is performed.","title":"SpiralStreamPack million-record reported observation","type":"benchmark_run","venue":null,"year":2022,"sourcePath":"data/pir-catalog.json#PIR-BENCH-2022-SPIRAL-STREAM"},{"evidence":"primary_source_checked","id":"PIR-BENCH-2023-SIMPLEPIR-1GB","keywords":["benchmark","reported","client-hint"],"metadata":{"construction_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"paper-reported per-core server setting","id":"PIR-BENCH-2023-SIMPLEPIR-1GB","implementation_id":"PIR-IMPL-2023-SIMPLEPIR","keywords":["benchmark","reported","client-hint"],"maps_to":["PIR-OP-001"],"metrics":{"offline_communication":"121 MB hint","online_communication":"242 KB per query","throughput":"approximately 10 GB/s/core"},"paper_id":"PIR-PAPER-2023-SIMPLEPIR","parameter_set_id":"PIR-PARAM-2023-SIMPLEPIR-1GB","source_locator":"USENIX abstract and Table 10","status":"reported","title":"SimplePIR 1 GB reported observation","workload_id":"PIR-WORKLOAD-2023-SIMPLEPIR-1GB","year":2023},"primaryUrl":null,"sections":[{"content":"The online throughput is displayed together with the offline hint. Neither is compared to YPIR without the source's compatibility context.","heading":"Interpretation"}],"status":"reported","subtitle":"2023","summary":"The online throughput is displayed together with the offline hint. Neither is compared to YPIR without the source's compatibility context.","title":"SimplePIR 1 GB reported observation","type":"benchmark_run","venue":null,"year":2023,"sourcePath":"data/pir-catalog.json#PIR-BENCH-2023-SIMPLEPIR-1GB"},{"evidence":"primary_source_checked","id":"PIR-BENCH-2024-YPIR-32GB","keywords":["benchmark","reported","hintless","avx512"],"metadata":{"construction_id":"PIR-CONSTRUCTION-2024-YPIR","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported","hardware":"paper and artifact AWS r6i.16xlarge-class AVX-512 setting","id":"PIR-BENCH-2024-YPIR-32GB","implementation_id":"PIR-IMPL-2024-YPIR","keywords":["benchmark","reported","hintless","avx512"],"maps_to":["PIR-OP-001"],"metrics":{"offline_communication":"none","throughput":"12.1 GB/s/core","total_communication":"2.5 MB"},"paper_id":"PIR-PAPER-2024-YPIR","parameter_set_id":"PIR-PARAM-2024-YPIR-32GB","source_locator":"USENIX abstract; artifact appendix A.2-A.4","status":"reported","title":"YPIR 32 GB reported observation","workload_id":"PIR-WORKLOAD-2024-YPIR-32GB","year":2024},"primaryUrl":null,"sections":[{"content":"Reported source observation with explicit absence of offline client communication; this dossier has not reproduced it.","heading":"Interpretation"}],"status":"reported","subtitle":"2024","summary":"Reported source observation with explicit absence of offline client communication; this dossier has not reproduced it.","title":"YPIR 32 GB reported observation","type":"benchmark_run","venue":null,"year":2024,"sourcePath":"data/pir-catalog.json#PIR-BENCH-2024-YPIR-32GB"},{"evidence":"abstract_checked","id":"PIR-BENCH-2026-ZIPPIR-1GB","keywords":["benchmark","recent-candidate","reported"],"metadata":{"construction_id":"PIR-CONSTRUCTION-2026-ZIPPIR","dossier_type":"benchmark_run","evidence":"abstract_checked","evidence_status":"reported","hardware":"not reported in accepted-page abstract","id":"PIR-BENCH-2026-ZIPPIR-1GB","implementation_id":"PIR-IMPL-2026-ZIPPIR","keywords":["benchmark","recent-candidate","reported"],"maps_to":["PIR-OP-001"],"metrics":{"client_hint":"none","server_storage_per_client":"less than 200 KB","throughput":"over 2 GB/s"},"paper_id":"PIR-PAPER-2026-ZIPPIR","parameter_set_id":"PIR-PARAM-2026-ZIPPIR-1GB","source_locator":"USENIX Security 2026 accepted-paper abstract","status":"accepted_prepublication","title":"ZipPIR 1 GB accepted-abstract observation","workload_id":"PIR-WORKLOAD-2026-ZIPPIR-1GB","year":2026},"primaryUrl":null,"sections":[{"content":"Recent candidate observation. Missing hardware, record shape, and full parameter context make it ineligible for cross-paper comparison.","heading":"Interpretation"}],"status":"accepted_prepublication","subtitle":"2026","summary":"Recent candidate observation. Missing hardware, record shape, and full parameter context make it ineligible for cross-paper comparison.","title":"ZipPIR 1 GB accepted-abstract observation","type":"benchmark_run","venue":null,"year":2026,"sourcePath":"data/pir-catalog.json#PIR-BENCH-2026-ZIPPIR-1GB"},{"evidence":"primary_source_reviewed","id":"PIR-CONSTRUCTION-1998-CGKS-2S","keywords":["two-server it-pir","replicated_combinatorial","two-server","sublinear-communication","information-theoretic"],"metadata":{"assumption":{"family":"information_theoretic","name":"No computational assumption; non-collusion is a deployment assumption"},"capabilities":["two-server","sublinear-communication","information-theoretic"],"client_storage":"stateless apart from query randomness","construction_family":"replicated_combinatorial","correctness":"perfect in the stated model","decrypt_cost":{"primary":"lightweight reconstruction from server answers"},"dossier_type":"construction","evidence":"primary_source_checked","id":"PIR-CONSTRUCTION-1998-CGKS-2S","name":"CGKS two-server information-theoretic PIR","preprocessing":"none","primitive":"two-server IT-PIR","privacy_model":"information-theoretic against either server","query_communication":"part of O(n^(1/3)) total","response_communication":"part of O(n^(1/3)) total","security":{"mode":"information-theoretic","model":"honest non-colluding servers","notion":"query privacy"},"server_model":"two non-colluding replicated servers","server_work":"not promoted as sublinear","sizes":{"offline":"not applicable","query_response_total":"O(n^(1/3))"},"status":"published","title":"CGKS two-server information-theoretic PIR","update_model":"replicated database updates","verification":{"status":"primary_source_reviewed"},"work_id":"PIR-PAPER-1998-CGKS","year":1995},"primaryUrl":"https://madhu.seas.harvard.edu/papers/1995/pir-journ.pdf","sections":[{"content":"The non-collusion condition is shown alongside the absence of computational assumptions; neither dominates the other.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"two-server IT-PIR · 1995","summary":"The non-collusion condition is shown alongside the absence of computational assumptions; neither dominates the other.","title":"CGKS two-server information-theoretic PIR","type":"construction","venue":"Journal of the ACM 45(6); preliminary FOCS 1995","year":1995,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-1998-CGKS-2S"},{"evidence":"abstract_reviewed","id":"PIR-CONSTRUCTION-1997-KO","keywords":["single-server cpir","number_theoretic_recursion","single-server","sublinear-communication"],"metadata":{"assumption":{"family":"number_theoretic","name":"Quadratic Residuosity"},"capabilities":["single-server","sublinear-communication"],"client_storage":"polylogarithmic local state; exact audit pending","construction_family":"number_theoretic_recursion","correctness":"standard protocol correctness; exact failure semantics pending","decrypt_cost":{"primary":"recursive number-theoretic recovery; exact count pending"},"dossier_type":"construction","evidence":"abstract_checked","id":"PIR-CONSTRUCTION-1997-KO","name":"KO97 single-server CPIR","preprocessing":"none","primitive":"single-server CPIR","privacy_model":"computational","query_communication":"O(n^epsilon) in the promoted abstract claim","response_communication":"included in O(n^epsilon) total","security":{"mode":"computational","model":"semi-honest single server","notion":"query privacy"},"server_model":"single","server_work":"at least linear database work in the ordinary no-preprocessing model","sizes":{"offline":"not applicable","query":"O(n^epsilon)","response":"included in total bound"},"status":"published","title":"KO97 single-server CPIR","update_model":"direct database updates; no stored hint","verification":{"status":"abstract_reviewed"},"work_id":"PIR-PAPER-1997-KO","year":1997},"primaryUrl":"https://doi.org/10.1109/SFCS.1997.646125","sections":[{"content":"Historical boundary record. The comparison table does not treat this recursion as a practical implementation.","heading":"Construction note"}],"status":"abstract_reviewed","subtitle":"single-server CPIR · 1997","summary":"Historical boundary record. The comparison table does not treat this recursion as a practical implementation.","title":"KO97 single-server CPIR","type":"construction","venue":"FOCS 1997","year":1997,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-1997-KO"},{"evidence":"fulltext_reviewed","id":"PIR-CONSTRUCTION-1999-CMS","keywords":["single-server cpir","phi_hiding_number_theoretic","single-server","polylogarithmic-communication","two-round"],"metadata":{"assumption":{"family":"number_theoretic","name":"Phi-Hiding and Phi-Sampling assumptions"},"capabilities":["single-server","polylogarithmic-communication","two-round"],"client_storage":"polylogarithmic protocol state","construction_family":"phi_hiding_number_theoretic","correctness":"standard CPIR correctness","decrypt_cost":{"primary":"polylogarithmic-time client recovery"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-1999-CMS","name":"CMS99 polylogarithmic-communication CPIR","preprocessing":"none","primitive":"single-server CPIR","privacy_model":"computational","query_communication":"part of polylogarithmic total communication","response_communication":"part of polylogarithmic total communication","security":{"mode":"computational","model":"semi-honest single server","notion":"query privacy"},"server_model":"single","server_work":"linear in database size","sizes":{"total_communication":"polylogarithmic in database size"},"status":"published","title":"CMS99 polylogarithmic-communication CPIR","update_model":"direct database updates","verification":{"status":"fulltext_reviewed"},"work_id":"PIR-PAPER-1999-CMS","year":1999},"primaryUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/pirpolylog.pdf","sections":[{"content":"This row records the historical communication frontier without implying a modern standard assumption.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"single-server CPIR · 1999","summary":"This row records the historical communication frontier without implying a modern standard assumption.","title":"CMS99 polylogarithmic-communication CPIR","type":"construction","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-1999-CMS"},{"evidence":"section_reviewed","id":"PIR-CONSTRUCTION-2005-GR","keywords":["single-server private block retrieval","hidden_smooth_subgroups","private-block-retrieval","constant-rate-for-large-blocks"],"metadata":{"assumption":{"family":"number theoretic","name":"Hidden smooth subgroup assumption"},"capabilities":["private-block-retrieval","constant-rate-for-large-blocks"],"client_storage":"polylogarithmic parameters and query state","construction_family":"hidden_smooth_subgroups","correctness":"negligible error under the stated parameterization","decrypt_cost":{"primary":"smooth-subgroup discrete logarithm"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2005-GR","name":"Gentry–Ramzan constant-rate PBR","preprocessing":"public parameters; no sublinear-work preprocessing","primitive":"single-server private block retrieval","privacy_model":"computational","query_communication":"O(k)","response_communication":"O(k+d) total communication for d-bit blocks","security":{"mode":"computational","model":"semi-honest single server","notion":"computational query privacy"},"server_model":"single","server_work":"linear in the database","sizes":{"total_communication":"O(k+d)"},"status":"published","title":"Gentry–Ramzan constant-rate PBR","update_model":"static database in the analyzed protocol","verification":{"status":"section_reviewed"},"work_id":"PIR-PAPER-2005-GR","year":2005},"primaryUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","sections":[{"content":"The composite-modulus instantiation uses a variant of the Phi-hiding assumption.","heading":"Construction note"}],"status":"section_reviewed","subtitle":"single-server private block retrieval · 2005","summary":"The composite-modulus instantiation uses a variant of the Phi-hiding assumption.","title":"Gentry–Ramzan constant-rate PBR","type":"construction","venue":"ICALP 2005","year":2005,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2005-GR"},{"evidence":"abstract_reviewed","id":"PIR-CONSTRUCTION-2014-DPF","keywords":["two-server computational pir","distributed_point_function","two-server","compact-query","lightweight-server-operations"],"metadata":{"assumption":{"family":"symmetric_key","name":"Pseudorandom generator security"},"capabilities":["two-server","compact-query","lightweight-server-operations"],"client_storage":"short DPF seeds","construction_family":"distributed_point_function","correctness":"exact additive reconstruction","decrypt_cost":{"primary":"add server responses"},"dossier_type":"construction","evidence":"abstract_checked","id":"PIR-CONSTRUCTION-2014-DPF","name":"DPF-based two-server PIR","preprocessing":"none beyond shared public database","primitive":"two-server computational PIR","privacy_model":"computational query privacy from DPF key privacy","query_communication":"compact DPF keys; exact bound pending theorem audit","response_communication":"one aggregate answer per server","security":{"mode":"computational","model":"semi-honest non-colluding servers","notion":"query privacy"},"server_model":"two non-colluding servers","server_work":"linear point-function evaluation over the database","sizes":{"offline":"not applicable","query":"compact DPF keys","response":"one aggregate per server"},"status":"published","title":"DPF-based two-server PIR","update_model":"replicated database updates","verification":{"status":"abstract_reviewed"},"work_id":"PIR-PAPER-2014-GI-DPF","year":2014},"primaryUrl":"https://doi.org/10.1007/978-3-642-55220-5_20","sections":[{"content":"DPF PIR is retained as a separate deployment branch rather than a baseline score for single-server systems.","heading":"Construction note"}],"status":"abstract_reviewed","subtitle":"two-server computational PIR · 2014","summary":"DPF PIR is retained as a separate deployment branch rather than a baseline score for single-server systems.","title":"DPF-based two-server PIR","type":"construction","venue":"EUROCRYPT 2014","year":2014,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2014-DPF"},{"evidence":"primary_source_reviewed","id":"PIR-CONSTRUCTION-2018-SEALPIR","keywords":["single-server cpir","rlwe_homomorphic_query_expansion","query-compression","batch-amortization","large-records"],"metadata":{"assumption":{"family":"lattice","name":"Ring Learning With Errors"},"capabilities":["query-compression","batch-amortization","large-records"],"client_storage":"encryption keys and small query state","construction_family":"rlwe_homomorphic_query_expansion","correctness":"negligible decryption failure under selected HE parameters","decrypt_cost":{"primary":"RLWE response decryption and record extraction"},"dossier_type":"construction","evidence":"primary_source_checked","id":"PIR-CONSTRUCTION-2018-SEALPIR","name":"SealPIR compressed-query CPIR","preprocessing":"database encoding plus optional probabilistic batch-code layout","primitive":"single-server CPIR","privacy_model":"computational","query_communication":"compressed single-ciphertext query with recursive expansion","response_communication":"depends on recursion depth and record layout","security":{"mode":"computational","model":"semi-honest single server","notion":"query privacy"},"server_model":"single","server_work":"linear database homomorphic processing; batch amortization available","sizes":{"offline":"encoded database","query":"up to 274x source-reported reduction","response":"parameter dependent"},"status":"published","title":"SealPIR compressed-query CPIR","update_model":"encoded database must track source updates","verification":{"status":"primary_source_reviewed"},"work_id":"PIR-PAPER-2018-SEALPIR","year":2018},"primaryUrl":"https://eprint.iacr.org/2017/1142","sections":[{"content":"The 274x and 40x figures are promoted only as source-reported observations in the paper's selected configurations.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"single-server CPIR · 2018","summary":"The 274x and 40x figures are promoted only as source-reported observations in the paper's selected configurations.","title":"SealPIR compressed-query CPIR","type":"construction","venue":"IEEE Symposium on Security and Privacy 2018","year":2018,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2018-SEALPIR"},{"evidence":"primary_source_reviewed","id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","keywords":["offline-online pir","client_hint_preprocessing","sublinear-online-time","no-extra-server-storage","optimal-tradeoff"],"metadata":{"assumption":{"family":"mixed","name":"Variant-dependent; single-server computational assumptions"},"capabilities":["sublinear-online-time","no-extra-server-storage","optimal-tradeoff"],"client_storage":"reusable short offline string","construction_family":"client_hint_preprocessing","correctness":"standard correctness in each variant","decrypt_cost":{"primary":"variant-dependent reconstruction"},"dossier_type":"construction","evidence":"primary_source_checked","id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","name":"CK20 offline/online PIR","preprocessing":"client downloads a query-independent short string offline","primitive":"offline-online PIR","privacy_model":"computational single-server; statistical two-server","query_communication":"model-dependent sublinear online communication","response_communication":"model-dependent sublinear online communication","security":{"mode":"computational_or_statistical","model":"offline-online","notion":"query privacy"},"server_model":"single computational or two-server statistical variants","server_work":"sublinear online after shifting bulk work offline","sizes":{"offline":"short query-independent client string","online":"sublinear; exact variant required"},"status":"published","title":"CK20 offline/online PIR","update_model":"hint freshness cost must be accounted for","verification":{"status":"primary_source_reviewed"},"work_id":"PIR-PAPER-2020-CK","year":2020},"primaryUrl":"https://eprint.iacr.org/2019/1075","sections":[{"content":"This row represents the offline/online theoretical profile; it is not merged with any later concrete hint implementation.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"offline-online PIR · 2020","summary":"This row represents the offline/online theoretical profile; it is not merged with any later concrete hint implementation.","title":"CK20 offline/online PIR","type":"construction","venue":"EUROCRYPT 2020","year":2020,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2020-CK-OFFLINE"},{"evidence":"fulltext_reviewed","id":"PIR-CONSTRUCTION-2021-CHECKLIST","keywords":["two-server private blocklist lookup","client_hint_bucketed_updates","sublinear-online-time","dynamic-blocklist","practical-implementation"],"metadata":{"assumption":{"family":"mixed","name":"Pseudorandom functions and instantiated PIR assumptions"},"capabilities":["sublinear-online-time","dynamic-blocklist","practical-implementation"],"client_storage":"sublinear private hint plus blocklist metadata","construction_family":"client_hint_bucketed_updates","correctness":"negligible failure in the stated system","decrypt_cost":{"primary":"client hint reconstruction"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2021-CHECKLIST","name":"Checklist dynamic two-server preprocessing PIR","preprocessing":"per-client offline hint computation","primitive":"two-server private blocklist lookup","privacy_model":"computational","query_communication":"source-reported application-specific communication","response_communication":"included in total source-reported communication","security":{"mode":"computational","model":"one honest non-colluding server","notion":"query privacy"},"server_model":"two non-colluding servers","server_work":"sublinear online PIR work","sizes":{"implementation":"Go and C","update_cost":"logarithmic amortized"},"status":"published","title":"Checklist dynamic two-server preprocessing PIR","update_model":"logarithmic amortized bucket updates","verification":{"status":"fulltext_reviewed"},"work_id":"PIR-PAPER-2021-CHECKLIST","year":2021},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/kogan","sections":[{"content":"Only the PIR and dynamic-update components are compared in the index-PIR atlas.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"two-server private blocklist lookup · 2021","summary":"Only the PIR and dynamic-update components are compared in the index-PIR atlas.","title":"Checklist dynamic two-server preprocessing PIR","type":"construction","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2021-CHECKLIST"},{"evidence":"paper_reviewed","id":"PIR-CONSTRUCTION-2021-FASTPIR","keywords":["single-server pir","compressed_rlwe_pir","compressed-queries","oblivious-expansion"],"metadata":{"assumption":{"family":"lattice","name":"Ring Learning With Errors"},"capabilities":["compressed-queries","oblivious-expansion"],"client_storage":"cryptographic parameters and query state","construction_family":"compressed_rlwe_pir","correctness":"parameterized HE correctness","decrypt_cost":{"primary":"recursive HE response recovery"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2021-FASTPIR","name":"FastPIR","preprocessing":"public cryptographic parameters","primitive":"single-server PIR","privacy_model":"computational","query_communication":"reduced relative to SealPIR in reported settings","response_communication":"compressed recursive response","security":{"mode":"computational","model":"semi-honest single server","notion":"computational query privacy"},"server_model":"single","server_work":"essentially SealPIR-like in the reported comparison","sizes":{"communication":"setting-dependent improvement over SealPIR"},"status":"published","title":"FastPIR","update_model":"static database in the evaluated protocol","verification":{"status":"paper_reviewed"},"work_id":"PIR-PAPER-2021-ALI-TRADEOFFS","year":2021},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/ali","sections":[{"content":"FastPIR is represented as a construction; the claimed improvement remains an optimization contribution.","heading":"Construction note"}],"status":"paper_reviewed","subtitle":"single-server PIR · 2021","summary":"FastPIR is represented as a construction; the claimed improvement remains an optimization contribution.","title":"FastPIR","type":"construction","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2021-FASTPIR"},{"evidence":"paper_reviewed","id":"PIR-CONSTRUCTION-2021-MULPIR","keywords":["single-server pir","multiplicative_homomorphic_recursion","multiplicative-recursion","tunable-communication-computation-tradeoff"],"metadata":{"assumption":{"family":"lattice","name":"Homomorphic-encryption assumption"},"capabilities":["multiplicative-recursion","tunable-communication-computation-tradeoff"],"client_storage":"cryptographic parameters and query state","construction_family":"multiplicative_homomorphic_recursion","correctness":"parameterized HE correctness","decrypt_cost":{"primary":"recursive HE response recovery"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2021-MULPIR","name":"MulPIR","preprocessing":"public cryptographic parameters","primitive":"single-server PIR","privacy_model":"computational","query_communication":"reduced through multiplicative recursive packing","response_communication":"reduced in the targeted large-entry regime","security":{"mode":"computational","model":"semi-honest single server","notion":"computational query privacy"},"server_model":"single","server_work":"increased relative to additive recursion","sizes":{"tradeoff":"lower communication for more server computation"},"status":"published","title":"MulPIR","update_model":"static database in the evaluated protocol","verification":{"status":"paper_reviewed"},"work_id":"PIR-PAPER-2021-ALI-TRADEOFFS","year":2021},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/ali","sections":[{"content":"MulPIR is not ordered as universally better than FastPIR; the preferred point depends on workload costs.","heading":"Construction note"}],"status":"paper_reviewed","subtitle":"single-server PIR · 2021","summary":"MulPIR is not ordered as universally better than FastPIR; the preferred point depends on workload costs.","title":"MulPIR","type":"construction","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2021-MULPIR"},{"evidence":"theorem_reviewed","id":"PIR-CONSTRUCTION-2021-SACM","keywords":["two-server client-preprocessing pir","puncturable_pseudorandom_sets","unbounded-queries","polylog-online-bandwidth","no-extra-server-storage","one-roundtrip"],"metadata":{"assumption":{"family":"lattice","name":"Learning With Errors"},"capabilities":["unbounded-queries","polylog-online-bandwidth","no-extra-server-storage","one-roundtrip"],"client_storage":"near-square-root private hint","construction_family":"puncturable_pseudorandom_sets","correctness":"negligible failure under the paper's occasional-correctness analysis","decrypt_cost":{"primary":"near-square-root client computation"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2021-SACM","name":"SACM21 near-optimal two-server preprocessing PIR","preprocessing":"one-time per-client private hint","primitive":"two-server client-preprocessing PIR","privacy_model":"computational","query_communication":"polylogarithmic online bandwidth","response_communication":"included in polylogarithmic online bandwidth","security":{"mode":"computational","model":"two non-colluding servers","notion":"query privacy"},"server_model":"two non-colluding replicated servers","server_work":"near-square-root online per query","sizes":{"client_hint":"near-square-root","online_communication":"polylogarithmic"},"status":"published","title":"SACM21 near-optimal two-server preprocessing PIR","update_model":"client hint refresh per query; database refresh remains explicit","verification":{"status":"theorem_reviewed"},"work_id":"PIR-PAPER-2021-SACM","year":2021},"primaryUrl":"https://eprint.iacr.org/2020/1592","sections":[{"content":"The non-collusion and per-client preprocessing requirements remain part of the row.","heading":"Construction note"}],"status":"theorem_reviewed","subtitle":"two-server client-preprocessing PIR · 2021","summary":"The non-collusion and per-client preprocessing requirements remain part of the row.","title":"SACM21 near-optimal two-server preprocessing PIR","type":"construction","venue":"CRYPTO 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2021-SACM"},{"evidence":"theorem_reviewed","id":"PIR-CONSTRUCTION-2022-CHK","keywords":["single-server client-preprocessing pir","homomorphic_two_server_compilation","adaptive-multi-query","sublinear-amortized-time","sublinear-storage","no-per-client-server-storage"],"metadata":{"assumption":{"family":"mixed","name":"LHE or FHE from standard assumptions"},"capabilities":["adaptive-multi-query","sublinear-amortized-time","sublinear-storage","no-per-client-server-storage"],"client_storage":"near-square-root in the optimal FHE construction","construction_family":"homomorphic_two_server_compilation","correctness":"negligible failure in instantiated schemes","decrypt_cost":{"primary":"near-square-root amortized client work in FHE variant"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2022-CHK","name":"CHK22 adaptive single-server preprocessing PIR","preprocessing":"linear-time per-client hint generation","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","query_communication":"variant-dependent; near-square-root amortized in the FHE construction","response_communication":"included in the amortized communication bound","security":{"mode":"computational","model":"semi-honest single server","notion":"adaptive query privacy"},"server_model":"single","server_work":"near-square-root amortized in the optimal FHE construction","sizes":{"optimal_tradeoff":"storage times server time near-linear","supported_queries":"bounded per preprocessing epoch"},"status":"published","title":"CHK22 adaptive single-server preprocessing PIR","update_model":"stateful hint consumption and refresh; database changes require new preprocessing","verification":{"status":"theorem_reviewed"},"work_id":"PIR-PAPER-2022-CHK","year":2022},"primaryUrl":"https://eprint.iacr.org/2022/081","sections":[{"content":"The row does not hide state refresh or the query count needed to amortize preprocessing.","heading":"Construction note"}],"status":"theorem_reviewed","subtitle":"single-server client-preprocessing PIR · 2022","summary":"The row does not hide state refresh or the query count needed to amortize preprocessing.","title":"CHK22 adaptive single-server preprocessing PIR","type":"construction","venue":"EUROCRYPT 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2022-CHK"},{"evidence":"primary_source_reviewed","id":"PIR-CONSTRUCTION-2022-SPIRAL","keywords":["single-server cpir","lwe_gsw_fhe_composition","ciphertext-translation","response-packing","streaming"],"metadata":{"assumption":{"family":"lattice","name":"Learning With Errors and GSW-style lattice encryption security"},"capabilities":["ciphertext-translation","response-packing","streaming"],"client_storage":"keys and compact client state","construction_family":"lwe_gsw_fhe_composition","correctness":"negligible decryption failure under lattice parameters","decrypt_cost":{"primary":"translated lattice ciphertext recovery"},"dossier_type":"construction","evidence":"primary_source_checked","id":"PIR-CONSTRUCTION-2022-SPIRAL","name":"Spiral FHE-composition PIR","preprocessing":"encoded database and public evaluation material","primitive":"single-server CPIR","privacy_model":"computational","query_communication":"Regev ciphertext query translated during evaluation","response_communication":"high-rate response; source reports rate 0.81 for SpiralStreamPack setting","security":{"mode":"computational","model":"semi-honest single server","notion":"query privacy"},"server_model":"single","server_work":"linear streaming pass with composed HE operations","sizes":{"query":"source reports at least 4.5x reduction versus compared prior systems","response_rate":"0.81 in streaming setting"},"status":"published","title":"Spiral FHE-composition PIR","update_model":"encoded database update cost depends on layout","verification":{"status":"primary_source_reviewed"},"work_id":"PIR-PAPER-2022-SPIRAL","year":2022},"primaryUrl":"https://eprint.iacr.org/2022/368","sections":[{"content":"Rate and throughput are kept separate; the streaming variant does not become a universal ranking row.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"single-server CPIR · 2022","summary":"Rate and throughput are kept separate; the streaming variant does not become a universal ranking row.","title":"Spiral FHE-composition PIR","type":"construction","venue":"IEEE Symposium on Security and Privacy 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2022-SPIRAL"},{"evidence":"primary_source_reviewed","id":"PIR-CONSTRUCTION-2023-DEPIR","keywords":["doubly efficient pir","ring_lwe_fast_polynomial_evaluation","polylog-online-time","polylog-communication","public-preprocessing","updates"],"metadata":{"assumption":{"family":"lattice","name":"Ring Learning With Errors"},"capabilities":["polylog-online-time","polylog-communication","public-preprocessing","updates"],"client_storage":"polylogarithmic protocol state; exact vector pending audit","construction_family":"ring_lwe_fast_polynomial_evaluation","correctness":"negligible failure in the Ring-LWE construction","decrypt_cost":{"primary":"polylogarithmic client recovery"},"dossier_type":"construction","evidence":"primary_source_checked","id":"PIR-CONSTRUCTION-2023-DEPIR","name":"Ring-LWE unkeyed doubly efficient PIR","preprocessing":"deterministic public server preprocessing","primitive":"doubly efficient PIR","privacy_model":"computational","query_communication":"polylogarithmic in database size","response_communication":"included in polylogarithmic communication","security":{"mode":"computational","model":"unkeyed public preprocessing","notion":"query privacy"},"server_model":"single","server_work":"polylogarithmic online after O(N^(1+epsilon)) preprocessing","sizes":{"online_communication":"polylog(N)","preprocessed_database":"O(N^(1+epsilon))"},"status":"published","title":"Ring-LWE unkeyed doubly efficient PIR","update_model":"O(N^epsilon) update time in the promoted theorem profile","verification":{"status":"primary_source_reviewed"},"work_id":"PIR-PAPER-2023-LMW-DEPIR","year":2023},"primaryUrl":"https://eprint.iacr.org/2022/1703","sections":[{"content":"This is the asymptotic DEPIR endpoint. No implementation or benchmark row is manufactured without an artifact.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"doubly efficient PIR · 2023","summary":"This is the asymptotic DEPIR endpoint. No implementation or benchmark row is manufactured without an artifact.","title":"Ring-LWE unkeyed doubly efficient PIR","type":"construction","venue":"STOC 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2023-DEPIR"},{"evidence":"theorem_reviewed","id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","keywords":["single-server client-preprocessing pir","adaptable_pseudorandom_sets","near-optimal-computation","polylog-bandwidth","adaptable-pseudorandom-sets"],"metadata":{"assumption":{"family":"lattice","name":"Learning With Errors and adaptable PRS ingredients"},"capabilities":["near-optimal-computation","polylog-bandwidth","adaptable-pseudorandom-sets"],"client_storage":"near-square-root private state","construction_family":"adaptable_pseudorandom_sets","correctness":"negligible failure under the stated construction","decrypt_cost":{"primary":"near-square-root amortized client work"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","name":"LP23 near-optimal single-server preprocessing PIR","preprocessing":"one-time per-client preprocessing","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","query_communication":"polylogarithmic amortized bandwidth","response_communication":"included in polylogarithmic bandwidth","security":{"mode":"computational","model":"semi-honest single server","notion":"adaptive query privacy"},"server_model":"single","server_work":"near-square-root amortized per query","sizes":{"client_state":"near-square-root","online_bandwidth":"polylogarithmic"},"status":"published","title":"LP23 near-optimal single-server preprocessing PIR","update_model":"adaptable-set state supports refresh across queries","verification":{"status":"theorem_reviewed"},"work_id":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","year":2023},"primaryUrl":"https://eprint.iacr.org/2022/830","sections":[{"content":"This independent result is a separate row even though it shares the displayed frontier point with ZLTS23.","heading":"Construction note"}],"status":"theorem_reviewed","subtitle":"single-server client-preprocessing PIR · 2023","summary":"This independent result is a separate row even though it shares the displayed frontier point with ZLTS23.","title":"LP23 near-optimal single-server preprocessing PIR","type":"construction","venue":"TCC 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL"},{"evidence":"primary_source_reviewed","id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","keywords":["single-server preprocessing pir","lwe_matrix_vector_hint","memory-bandwidth-throughput","reusable-hint","unbounded-queries-per-hint"],"metadata":{"assumption":{"family":"lattice","name":"Learning With Errors"},"capabilities":["memory-bandwidth-throughput","reusable-hint","unbounded-queries-per-hint"],"client_storage":"121 MB hint in the promoted 1 GB source setting","construction_family":"lwe_matrix_vector_hint","correctness":"LWE parameter-dependent negligible failure","decrypt_cost":{"primary":"lightweight LWE inner-product recovery"},"dossier_type":"construction","evidence":"primary_source_checked","id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","name":"SimplePIR client-hint protocol","preprocessing":"query-independent reusable client download","primitive":"single-server preprocessing PIR","privacy_model":"computational","query_communication":"242 KB in the promoted 1 GB source setting","response_communication":"included in the reported 242 KB per-query communication","security":{"mode":"computational","model":"semi-honest single server with reusable hint","notion":"query privacy"},"server_model":"single","server_work":"near one 32-bit multiply and add per database byte","sizes":{"offline_hint":"121 MB for 1 GB database setting","online_total":"242 KB per query"},"status":"published","title":"SimplePIR client-hint protocol","update_model":"hint must track database changes","verification":{"status":"primary_source_reviewed"},"work_id":"PIR-PAPER-2023-SIMPLEPIR","year":2023},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity23/presentation/henzinger","sections":[{"content":"The hint and online communication remain separate fields so the fast server pass does not hide client storage or refresh cost.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"single-server preprocessing PIR · 2023","summary":"The hint and online communication remain separate fields so the fast server pass does not hide client storage or refresh cost.","title":"SimplePIR client-hint protocol","type":"construction","venue":"USENIX Security 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2023-SIMPLEPIR"},{"evidence":"section_reviewed","id":"PIR-CONSTRUCTION-2023-TREEPIR","keywords":["two-server client-preprocessing pir","weak_privately_puncturable_prf","sublinear-amortized-time","polylog-bandwidth","weaker-assumption"],"metadata":{"assumption":{"family":"group","name":"Decisional Diffie-Hellman"},"capabilities":["sublinear-amortized-time","polylog-bandwidth","weaker-assumption"],"client_storage":"sublinear private state","construction_family":"weak_privately_puncturable_prf","correctness":"negligible error under the construction parameters","decrypt_cost":{"primary":"sublinear client work across the two phases"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2023-TREEPIR","name":"TreePIR","preprocessing":"client-specific offline phase","primitive":"two-server client-preprocessing PIR","privacy_model":"computational","query_communication":"polylogarithmic","response_communication":"polylogarithmic total bandwidth","security":{"mode":"computational","model":"one corrupted server","notion":"computational query privacy"},"server_model":"two non-colluding replicas","server_work":"sublinear amortized","sizes":{"online_bandwidth":"polylogarithmic"},"status":"published","title":"TreePIR","update_model":"static database in the primary construction","verification":{"status":"section_reviewed"},"work_id":"PIR-PAPER-2023-TREEPIR","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/204","sections":[{"content":"TreePIR composes a simple PRG phase with single-server PIR over a reduced domain.","heading":"Construction note"}],"status":"section_reviewed","subtitle":"two-server client-preprocessing PIR · 2023","summary":"TreePIR composes a simple PRG phase with single-server PIR over a reduced domain.","title":"TreePIR","type":"construction","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2023-TREEPIR"},{"evidence":"theorem_reviewed","id":"PIR-CONSTRUCTION-2023-ZLTS","keywords":["single-server client-preprocessing pir","fhe_programmable_pseudorandom_sets","unbounded-queries","polylog-bandwidth","near-optimal-computation","one-roundtrip"],"metadata":{"assumption":{"family":"lattice","name":"Learning With Errors"},"capabilities":["unbounded-queries","polylog-bandwidth","near-optimal-computation","one-roundtrip"],"client_storage":"near-square-root private state","construction_family":"fhe_programmable_pseudorandom_sets","correctness":"negligible failure under the LWE construction","decrypt_cost":{"primary":"near-square-root client computation"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2023-ZLTS","name":"ZLTS23 optimal single-server preprocessing PIR","preprocessing":"one-time per-client interactive preprocessing","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","query_communication":"polylogarithmic amortized bandwidth","response_communication":"included in polylogarithmic bandwidth","security":{"mode":"computational","model":"semi-honest single server","notion":"adaptive query privacy"},"server_model":"single","server_work":"near-square-root amortized per query","sizes":{"client_state":"near-square-root","online_bandwidth":"polylogarithmic"},"status":"published","title":"ZLTS23 optimal single-server preprocessing PIR","update_model":"state refreshed across unbounded queries; database-update cost remains nontrivial","verification":{"status":"theorem_reviewed"},"work_id":"PIR-PAPER-2023-ZLTS","year":2023},"primaryUrl":"https://eprint.iacr.org/2022/609","sections":[{"content":"LP23 independently reaches the same cost point with a different adaptable-PRS mechanism.","heading":"Construction note"}],"status":"theorem_reviewed","subtitle":"single-server client-preprocessing PIR · 2023","summary":"LP23 independently reaches the same cost point with a different adaptable-PRS mechanism.","title":"ZLTS23 optimal single-server preprocessing PIR","type":"construction","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2023-ZLTS"},{"evidence":"fulltext_reviewed","id":"PIR-CONSTRUCTION-2024-PIANO","keywords":["single-server client-preprocessing pir","prf_pseudorandom_sets","prf-only","practical-sublinear-server-time","open-source-implementation"],"metadata":{"assumption":{"family":"symmetric_key","name":"Pseudorandom functions"},"capabilities":["prf-only","practical-sublinear-server-time","open-source-implementation"],"client_storage":"near-square-root hints","construction_family":"prf_pseudorandom_sets","correctness":"negligible failure with caching/PRP handling for arbitrary queries","decrypt_cost":{"primary":"hint lookup and plaintext reconstruction"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2024-PIANO","name":"Piano PRF-only client-preprocessing PIR","preprocessing":"client streams the database once and stores sublinear hints","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","query_communication":"near-square-root online","response_communication":"included in near-square-root online communication","security":{"mode":"computational","model":"semi-honest single server","notion":"adaptive query privacy"},"server_model":"single","server_work":"near-square-root amortized online","sizes":{"online":"near-square-root","preprocessing_communication":"linear database stream"},"status":"published","title":"Piano PRF-only client-preprocessing PIR","update_model":"hints are stateful and tied to the database snapshot","verification":{"status":"fulltext_reviewed"},"work_id":"PIR-PAPER-2024-PIANO","year":2024},"primaryUrl":"https://eprint.iacr.org/2023/452","sections":[{"content":"Piano changes the practical mechanism and assumption while accepting linear preprocessing communication.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"single-server client-preprocessing PIR · 2024","summary":"Piano changes the practical mechanism and assumption while accepting linear preprocessing communication.","title":"Piano PRF-only client-preprocessing PIR","type":"construction","venue":"IEEE Symposium on Security and Privacy 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2024-PIANO"},{"evidence":"fulltext_reviewed","id":"PIR-CONSTRUCTION-2024-SINGLEPASS","keywords":["two-server client-preprocessing pir","single_pass_pseudorandom_sets","single-pass-preprocessing","constant-time-updates","practical-implementation"],"metadata":{"assumption":{"family":"symmetric_key","name":"Pseudorandom functions"},"capabilities":["single-pass-preprocessing","constant-time-updates","practical-implementation"],"client_storage":"sublinear private hints","construction_family":"single_pass_pseudorandom_sets","correctness":"negligible failure under the stated construction","decrypt_cost":{"primary":"private-hint reconstruction"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2024-SINGLEPASS","name":"SinglePass client-preprocessing PIR","preprocessing":"exactly one linear pass over the database","primitive":"two-server client-preprocessing PIR","privacy_model":"computational","query_communication":"source-specific sublinear communication","response_communication":"included in reported online communication","security":{"mode":"computational","model":"two non-colluding servers","notion":"query privacy"},"server_model":"two non-colluding servers","server_work":"sublinear online","sizes":{"preprocessing_passes":1,"updates":"constant time"},"status":"published","title":"SinglePass client-preprocessing PIR","update_model":"constant-time additions and edits in the paper's dynamic model","verification":{"status":"fulltext_reviewed"},"work_id":"PIR-PAPER-2024-SINGLEPASS","year":2024},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity24/presentation/lazzaretti","sections":[{"content":"The update and preprocessing improvements are kept visible as separate contribution nodes.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"two-server client-preprocessing PIR · 2024","summary":"The update and preprocessing improvements are kept visible as separate contribution nodes.","title":"SinglePass client-preprocessing PIR","type":"construction","venue":"USENIX Security 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2024-SINGLEPASS"},{"evidence":"fulltext_reviewed","id":"PIR-CONSTRUCTION-2024-THORPIR","keywords":["single-server client-preprocessing pir","homomorphic_thorp_shuffle","sublinear-offline-bandwidth","constant-depth-preprocessing","parallelizable-fhe"],"metadata":{"assumption":{"family":"lattice","name":"BFV/BGV-style homomorphic encryption"},"capabilities":["sublinear-offline-bandwidth","constant-depth-preprocessing","parallelizable-fhe"],"client_storage":"sublinear hints","construction_family":"homomorphic_thorp_shuffle","correctness":"parameter-dependent negligible failure","decrypt_cost":{"primary":"FHE-derived hint reconstruction"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2024-THORPIR","name":"ThorPIR homomorphic-shuffle preprocessing PIR","preprocessing":"sublinear-bandwidth FHE hint generation","primitive":"single-server client-preprocessing PIR","privacy_model":"computational","query_communication":"sublinear","response_communication":"sublinear profile; exact configuration required","security":{"mode":"computational","model":"semi-honest single server","notion":"query privacy"},"server_model":"single","server_work":"sublinear online","sizes":{"preprocessing_circuit":"linear size and constant depth"},"status":"published","title":"ThorPIR homomorphic-shuffle preprocessing PIR","update_model":"preprocessing remains tied to the database snapshot","verification":{"status":"fulltext_reviewed"},"work_id":"PIR-PAPER-2024-THORPIR","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/482","sections":[{"content":"Concrete preprocessing claims depend on very large accelerator assumptions and are not ranked against ordinary deployments.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"single-server client-preprocessing PIR · 2024","summary":"Concrete preprocessing claims depend on very large accelerator assumptions and are not ranked against ordinary deployments.","title":"ThorPIR homomorphic-shuffle preprocessing PIR","type":"construction","venue":"ACM CCS 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2024-THORPIR"},{"evidence":"primary_source_reviewed","id":"PIR-CONSTRUCTION-2024-YPIR","keywords":["single-server hintless pir","lwe_to_rlwe_translation","silent-preprocessing","no-client-hint","high-throughput"],"metadata":{"assumption":{"family":"lattice","name":"Learning With Errors and Ring Learning With Errors"},"capabilities":["silent-preprocessing","no-client-hint","high-throughput"],"client_storage":"no downloaded database hint","construction_family":"lwe_to_rlwe_translation","correctness":"lattice parameter-dependent negligible failure","decrypt_cost":{"primary":"LWE/RLWE translated response recovery"},"dossier_type":"construction","evidence":"primary_source_checked","id":"PIR-CONSTRUCTION-2024-YPIR","name":"YPIR silent-preprocessing protocol","preprocessing":"silent server-side preparation with no offline client communication","primitive":"single-server hintless PIR","privacy_model":"computational","query_communication":"part of 2.5 MB total in promoted 32 GB setting","response_communication":"part of 2.5 MB total in promoted 32 GB setting","security":{"mode":"computational","model":"semi-honest single server","notion":"query privacy"},"server_model":"single","server_work":"memory-bandwidth-oriented linear pass plus lightweight translation","sizes":{"offline_client_communication":0,"total_communication":"2.5 MB in 32 GB setting"},"status":"published","title":"YPIR silent-preprocessing protocol","update_model":"supports fresher database snapshots without hint redistribution","verification":{"status":"primary_source_reviewed"},"work_id":"PIR-PAPER-2024-YPIR","year":2024},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity24/presentation/menon","sections":[{"content":"YPIR trades higher communication than the matched hint-based baseline for eliminating the large offline client download.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"single-server hintless PIR · 2024","summary":"YPIR trades higher communication than the matched hint-based baseline for eliminating the large offline client download.","title":"YPIR silent-preprocessing protocol","type":"construction","venue":"USENIX Security 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2024-YPIR"},{"evidence":"fulltext_reviewed","id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","keywords":["distributional index pir","popularity_partitioned_classic_pir","black-box-classic-pir-backend","skew-aware-expected-work","relaxed-correctness"],"metadata":{"assumption":{"family":"adapter","name":"Inherited from the classic PIR backend"},"capabilities":["black-box-classic-pir-backend","skew-aware-expected-work","relaxed-correctness"],"client_storage":"backend-dependent","construction_family":"popularity_partitioned_classic_pir","correctness":"distribution-dependent success probability; out-of-distribution success may be lower","decrypt_cost":{"primary":"backend recovery plus distributional routing"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","name":"Distributional-PIR compiler","preprocessing":"popularity-dependent database partitioning plus backend preprocessing","primitive":"distributional index PIR","privacy_model":"classic cryptographic query privacy","query_communication":"backend-dependent","response_communication":"backend-dependent","security":{"mode":"inherited","model":"distributional correctness","notion":"classic query privacy"},"server_model":"inherited from the classic PIR backend","server_work":"reduced in expectation under a skewed public query distribution","sizes":{"compatibility_warning":"not directly comparable to errorless classic PIR"},"status":"published","title":"Distributional-PIR compiler","update_model":"database and popularity model updates both matter","verification":{"status":"fulltext_reviewed"},"work_id":"PIR-PAPER-2025-DISTRIBUTIONAL","year":2025},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity25/presentation/lehmkuhl","sections":[{"content":"This row remains outside classic-PIR rankings because the correctness contract differs.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"distributional index PIR · 2025","summary":"This row remains outside classic-PIR rankings because the correctness contract differs.","title":"Distributional-PIR compiler","type":"construction","venue":"USENIX Security 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2025-DISTRIBUTIONAL"},{"evidence":"fulltext_version_delta_pending","id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","keywords":["multi-server doubly efficient pir","classical_information_theoretic_depir","information-theoretic-depir","near-linear-preprocessing","unbounded-queries"],"metadata":{"assumption":{"family":"information_theoretic","name":"No computational assumption; server non-collusion required"},"capabilities":["information-theoretic-depir","near-linear-preprocessing","unbounded-queries"],"client_storage":"theorem-profile dependent","construction_family":"classical_information_theoretic_depir","correctness":"information-theoretic construction correctness","decrypt_cost":{"primary":"subpolynomial client-side profile; exact revision pending"},"dossier_type":"construction","evidence":"fulltext_checked","id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","name":"Information-theoretic multi-server DEPIR","preprocessing":"near-linear server-side preprocessing","primitive":"multi-server doubly efficient PIR","privacy_model":"information-theoretic","query_communication":"subpolynomial profile; exact revised theorem required","response_communication":"subpolynomial profile; exact revised theorem required","security":{"mode":"information-theoretic","model":"multi-server public preprocessing","notion":"query privacy"},"server_model":"multiple non-colluding servers","server_work":"subpolynomial online query time","sizes":{"online_time":"subpolynomial","preprocessing":"near-linear"},"status":"published","title":"Information-theoretic multi-server DEPIR","update_model":"public preprocessed structure; revised update profile pending","verification":{"status":"fulltext_version_delta_pending"},"work_id":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR","year":2025},"primaryUrl":"https://eprint.iacr.org/2024/829","sections":[{"content":"The ePrint-to-TCC version delta is explicit and prevents silently mixing parameters.","heading":"Construction note"}],"status":"fulltext_version_delta_pending","subtitle":"multi-server doubly efficient PIR · 2025","summary":"The ePrint-to-TCC version delta is explicit and prevents silently mixing parameters.","title":"Information-theoretic multi-server DEPIR","type":"construction","venue":"TCC 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR"},{"evidence":"prepublication_abstract_reviewed","id":"PIR-CONSTRUCTION-2026-ZIPPIR","keywords":["single-server low-client-storage pir","lwe_to_paillier_compression","no-client-hint","silent-offline","ciphertext-compression"],"metadata":{"assumption":{"family":"hybrid_lattice_number_theoretic","name":"LWE plus Paillier/composite-residuosity security"},"capabilities":["no-client-hint","silent-offline","ciphertext-compression"],"client_storage":"no large client hint","construction_family":"lwe_to_paillier_compression","correctness":"parameter-dependent; full audit pending","decrypt_cost":{"primary":"Paillier-compressed response recovery; audit pending"},"dossier_type":"construction","evidence":"abstract_checked","id":"PIR-CONSTRUCTION-2026-ZIPPIR","name":"ZipPIR LWE-to-Paillier compression protocol","preprocessing":"almost silent offline server work after an initial public key","primitive":"single-server low-client-storage PIR","privacy_model":"computational","query_communication":"exact promoted setting pending proceedings audit","response_communication":"Paillier-compressed response; exact row pending proceedings audit","security":{"mode":"computational","model":"accepted prepublication","notion":"query privacy"},"server_model":"single","server_work":"source reports over 2 GB/s throughput","sizes":{"client_hint":"none","server_storage_per_client":"less than 200 KB in promoted 1 GB setting"},"status":"accepted_prepublication","title":"ZipPIR LWE-to-Paillier compression protocol","update_model":"server can generate and update hints during idle time in the stated model","verification":{"status":"prepublication_abstract_reviewed"},"work_id":"PIR-PAPER-2026-ZIPPIR","year":2026},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","sections":[{"content":"Candidate row retained to expose the current branch. It is not eligible for a reproduced or settled-frontier claim at the cutoff.","heading":"Construction note"}],"status":"prepublication_abstract_reviewed","subtitle":"single-server low-client-storage PIR · 2026","summary":"Candidate row retained to expose the current branch. It is not eligible for a reproduced or settled-frontier claim at the cutoff.","title":"ZipPIR LWE-to-Paillier compression protocol","type":"construction","venue":"USENIX Security 2026","year":2026,"sourcePath":"data/pir-catalog.json#PIR-CONSTRUCTION-2026-ZIPPIR"},{"evidence":"primary_source_checked","id":"PIR-IMPL-2018-SEALPIR","keywords":["implementation","rlwe","query-compression"],"metadata":{"artifact":{"url":"https://github.com/microsoft/SealPIR","version":"paper-era lineage"},"artifact_type":"open-source research prototype","availability":"public repository","backend":"Microsoft SEAL / RLWE homomorphic encryption","construction_ids":["PIR-CONSTRUCTION-2018-SEALPIR"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"PIR-IMPL-2018-SEALPIR","keywords":["implementation","rlwe","query-compression"],"language":"C++","maps_to":["PIR-OP-001"],"paper_id":"PIR-PAPER-2018-SEALPIR","status":"reported","title":"Microsoft SealPIR prototype","year":2018},"primaryUrl":null,"sections":[{"content":"Paper-associated implementation of recursive compressed query expansion and encoded-database response processing. The repository is evidence of an artifact, not an independent reproduction of the paper's performance.","heading":"Scope"}],"status":"reported","subtitle":"2018","summary":"Paper-associated implementation of recursive compressed query expansion and encoded-database response processing. The repository is evidence of an artifact, not an independent reproduction of the paper's performance.","title":"Microsoft SealPIR prototype","type":"implementation","venue":null,"year":2018,"sourcePath":"data/pir-catalog.json#PIR-IMPL-2018-SEALPIR"},{"evidence":"primary_source_checked","id":"PIR-IMPL-2022-SPIRAL","keywords":["implementation","fhe-composition","streaming"],"metadata":{"artifact":{"url":"https://github.com/menonsamir/spiral","version":"paper artifact lineage"},"artifact_type":"open-source research prototype","availability":"public repository","backend":"Regev-to-GSW lattice ciphertext translation","construction_ids":["PIR-CONSTRUCTION-2022-SPIRAL"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"PIR-IMPL-2022-SPIRAL","keywords":["implementation","fhe-composition","streaming"],"language":"C++","maps_to":["PIR-OP-001"],"paper_id":"PIR-PAPER-2022-SPIRAL","status":"reported","title":"Spiral C++ implementation","year":2022},"primaryUrl":null,"sections":[{"content":"Prototype underlying the Spiral and SpiralStreamPack source-reported evaluation.","heading":"Scope"}],"status":"reported","subtitle":"2022","summary":"Prototype underlying the Spiral and SpiralStreamPack source-reported evaluation.","title":"Spiral C++ implementation","type":"implementation","venue":null,"year":2022,"sourcePath":"data/pir-catalog.json#PIR-IMPL-2022-SPIRAL"},{"evidence":"primary_source_checked","id":"PIR-IMPL-2023-SIMPLEPIR","keywords":["implementation","memory-bandwidth","client-hint"],"metadata":{"artifact":{"url":"https://github.com/ahenzinger/simplepir","version":"USENIX Security 2023 artifact lineage"},"artifact_type":"open-source research prototype","availability":"public repository","backend":"32-bit LWE matrix-vector operations","construction_ids":["PIR-CONSTRUCTION-2023-SIMPLEPIR"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"PIR-IMPL-2023-SIMPLEPIR","keywords":["implementation","memory-bandwidth","client-hint"],"language":"Go","maps_to":["PIR-OP-001"],"paper_id":"PIR-PAPER-2023-SIMPLEPIR","status":"reported","title":"SimplePIR Go implementation","year":2023},"primaryUrl":null,"sections":[{"content":"Artifact for the memory-bandwidth-oriented SimplePIR family. Its benchmark record retains the database size and hint cost.","heading":"Scope"}],"status":"reported","subtitle":"2023","summary":"Artifact for the memory-bandwidth-oriented SimplePIR family. Its benchmark record retains the database size and hint cost.","title":"SimplePIR Go implementation","type":"implementation","venue":null,"year":2023,"sourcePath":"data/pir-catalog.json#PIR-IMPL-2023-SIMPLEPIR"},{"evidence":"primary_source_checked","id":"PIR-IMPL-2024-YPIR","keywords":["implementation","hintless","avx512","artifact"],"metadata":{"artifact":{"url":"https://github.com/menonsamir/ypir/tree/b980152","version":"b980152"},"artifact_type":"archived open-source artifact","availability":"repository, Docker image, and Zenodo archive","backend":"LWE-to-RLWE translation with AVX-512 server path","construction_ids":["PIR-CONSTRUCTION-2024-YPIR"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported","id":"PIR-IMPL-2024-YPIR","keywords":["implementation","hintless","avx512","artifact"],"language":"Rust and C/C++","maps_to":["PIR-OP-001"],"paper_id":"PIR-PAPER-2024-YPIR","status":"reported","title":"YPIR Rust implementation at b980152","year":2024},"primaryUrl":null,"sections":[{"content":"The artifact appendix fixes compiler and Docker context and states that the implementation is not production-ready. This dossier has not independently executed its large-memory experiments.","heading":"Scope"}],"status":"reported","subtitle":"2024","summary":"The artifact appendix fixes compiler and Docker context and states that the implementation is not production-ready. This dossier has not independently executed its large-memory experiments.","title":"YPIR Rust implementation at b980152","type":"implementation","venue":null,"year":2024,"sourcePath":"data/pir-catalog.json#PIR-IMPL-2024-YPIR"},{"evidence":"abstract_checked","id":"PIR-IMPL-2026-ZIPPIR","keywords":["implementation","recent-candidate","no-client-storage"],"metadata":{"artifact":{"url":null,"version":"accepted prepublication"},"artifact_type":"paper-described prototype","availability":"artifact audit pending","backend":"LWE-to-Paillier ciphertext compression","construction_ids":["PIR-CONSTRUCTION-2026-ZIPPIR"],"dossier_type":"implementation","evidence":"abstract_checked","evidence_status":"reported","id":"PIR-IMPL-2026-ZIPPIR","keywords":["implementation","recent-candidate","no-client-storage"],"language":"not reported in accepted-page abstract","maps_to":["PIR-OP-001"],"paper_id":"PIR-PAPER-2026-ZIPPIR","status":"accepted_prepublication","title":"ZipPIR paper prototype","year":2026},"primaryUrl":null,"sections":[{"content":"This implementation object is admitted only to keep the accepted paper's construction and measurement claims distinct. No artifact availability is inferred from the abstract.","heading":"Scope"}],"status":"accepted_prepublication","subtitle":"2026","summary":"This implementation object is admitted only to keep the accepted paper's construction and measurement claims distinct. No artifact availability is inferred from the abstract.","title":"ZipPIR paper prototype","type":"implementation","venue":null,"year":2026,"sourcePath":"data/pir-catalog.json#PIR-IMPL-2026-ZIPPIR"},{"evidence":"source_derived","id":"PIR-MILESTONE-001-01","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":1,"parent_problem_id":"PIR-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PIR-OP-001","summary":"Remove offline client communication while retaining at least half of measured memory bandwidth in one public artifact.","title":"Remove offline client communication while retaining at least half of measured memory bandwidth in one public…","type":"milestone","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-MILESTONE-001-01"},{"evidence":"source_derived","id":"PIR-MILESTONE-001-02","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":2,"parent_problem_id":"PIR-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PIR-OP-001","summary":"Keep total communication below one megabyte for a one-byte record from a 32 GB database under the same security profile.","title":"Keep total communication below one megabyte for a one-byte record from a 32 GB database under the same…","type":"milestone","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-MILESTONE-001-02"},{"evidence":"source_derived","id":"PIR-MILESTONE-001-03","keywords":["weaker-target","measurement"],"metadata":{"frontier_track":"measurement","order":3,"parent_problem_id":"PIR-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PIR-OP-001","summary":"Reproduce hintless update and query costs on two independently operated commodity servers.","title":"Reproduce hintless update and query costs on two independently operated commodity servers.","type":"milestone","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-MILESTONE-001-03"},{"evidence":"source_derived","id":"PIR-MILESTONE-002-01","keywords":["weaker-target","construction"],"metadata":{"frontier_track":"construction","order":1,"parent_problem_id":"PIR-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PIR-OP-002","summary":"Extract concrete constants and parameter dependencies from the Ring-LWE DEPIR construction.","title":"Extract concrete constants and parameter dependencies from the Ring-LWE DEPIR construction.","type":"milestone","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-MILESTONE-002-01"},{"evidence":"source_derived","id":"PIR-MILESTONE-002-02","keywords":["weaker-target","practical"],"metadata":{"frontier_track":"practical","order":2,"parent_problem_id":"PIR-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PIR-OP-002","summary":"Implement the preprocessing and one update/query path for a bounded database size.","title":"Implement the preprocessing and one update/query path for a bounded database size.","type":"milestone","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-MILESTONE-002-02"},{"evidence":"source_derived","id":"PIR-MILESTONE-002-03","keywords":["weaker-target","measurement"],"metadata":{"frontier_track":"measurement","order":3,"parent_problem_id":"PIR-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PIR-OP-002","summary":"Publish a compatibility-complete observation even if it demonstrates impracticality.","title":"Publish a compatibility-complete observation even if it demonstrates impracticality.","type":"milestone","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-MILESTONE-002-03"},{"evidence":"normalized_from_literature","id":"PIR-OP-001","keywords":[],"metadata":{"acceptance":{"cost_accounting":"offline and online communication, both endpoint states, server work, and updates","evidence":"public versioned artifact plus independent reproduction","security":"exact assumption, game, parameters, and failure model"},"barriers":["PIR-BARRIER-001","PIR-BARRIER-002"],"closest_results":["PIR-PAPER-2023-SIMPLEPIR","PIR-PAPER-2024-YPIR","PIR-PAPER-2026-ZIPPIR"],"dossier_type":"open_problem","evidence":"normalized_from_literature","hierarchy_links":[],"hierarchy_role":"joint_theory_practice_endpoint","id":"PIR-OP-001","milestone_tracks":["practical","practical","measurement"],"milestones":["Remove offline client communication while retaining at least half of measured memory bandwidth in one public artifact.","Keep total communication below one megabyte for a one-byte record from a 32 GB database under the same security profile.","Reproduce hintless update and query costs on two independently operated commodity servers."],"normalization_delta":"Combines source-exposed tradeoffs in throughput, online communication, offline hint size, client storage, and update freshness; no source states this exact conjunction as one theorem target.","origin_evidence":["PIR-PAPER-2023-SIMPLEPIR","PIR-PAPER-2024-YPIR","PIR-PAPER-2026-ZIPPIR"],"origin_type":"normalized_lineage_gap","profile":{"measurement_rail":"matched update-aware reproducible benchmark","practical_rail":"high throughput without a large client hint","theory_rail":"single-server query privacy under explicit assumptions"},"provenance":["PIR-PAPER-2023-SIMPLEPIR","PIR-PAPER-2024-YPIR","PIR-PAPER-2026-ZIPPIR"],"resolution_condition":"A construction and public artifact jointly meet the declared privacy and correctness profile and report throughput, communication, client/server state, update cost, and parameters in one reproducible database setting.","routes":["PIR-ROUTE-001"],"status":"open","target_profile":{"assumptions":"conservative and explicitly parameterized","client_state":"no database-sized or square-root-sized downloaded hint","communication":"low enough for small records","privacy":"computational index privacy","server_model":"one semi-honest server","server_online":"close to memory bandwidth","updates":"no full hint redistribution after ordinary updates"},"title":"High-throughput single-server PIR without a large or stale client hint"},"primaryUrl":null,"sections":[{"content":"Build and independently reproduce a single-server PIR system that combines explicit computational query privacy, no large downloaded client hint, memory-bandwidth-class online processing, small-record communication below the declared threshold, and incremental database freshness without hidden full-state redistribution.","heading":"Exact normalized target"},{"content":"SimplePIR makes online server work exceptionally cheap but exposes a large reusable hint. YPIR removes offline client communication while increasing total communication in its matched setting. ZipPIR targets client storage but remains a prepublication candidate at the cutoff.","heading":"Why the conjunction matters"}],"status":"open","subtitle":"","summary":"Build and independently reproduce a single-server PIR system that combines explicit computational query privacy, no large downloaded client hint, memory-bandwidth-class online processing, small-record communication below the declared threshold, and incremental database freshness without hidden full-state redistribution.","title":"High-throughput single-server PIR without a large or stale client hint","type":"open_problem","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-OP-001"},{"evidence":"normalized_from_literature","id":"PIR-OP-002","keywords":[],"metadata":{"acceptance":{"artifact":"public deterministic compiler or preprocessing implementation","evidence":"reproduced end-to-end run at security parameters stated by the construction","theorem":"exact preprocessing, storage, update, communication, and online-work dependencies"},"barriers":["PIR-BARRIER-001","PIR-BARRIER-003"],"closest_results":["PIR-PAPER-2023-LMW-DEPIR"],"dossier_type":"open_problem","evidence":"normalized_from_literature","hierarchy_links":[],"hierarchy_role":"theory_to_practice_endpoint","id":"PIR-OP-002","milestone_tracks":["construction","practical","measurement"],"milestones":["Extract concrete constants and parameter dependencies from the Ring-LWE DEPIR construction.","Implement the preprocessing and one update/query path for a bounded database size.","Publish a compatibility-complete observation even if it demonstrates impracticality."],"normalization_delta":"Refines asymptotic unkeyed DEPIR into a joint theorem-and-artifact target with near-linear preprocessing/storage, explicit updates, and concrete parameter evidence.","origin_evidence":["PIR-PAPER-2023-LMW-DEPIR","PIR-PAPER-2025-LMW-BLACKBOX"],"origin_type":"stated_limitation","profile":{"measurement_rail":"full storage/time/communication compatibility key","practical_rail":"executable preprocessing, update, and online query pipeline","theory_rail":"Ring-LWE or comparably standard public-preprocessing DEPIR"},"provenance":["PIR-PAPER-2023-LMW-DEPIR","PIR-PAPER-2025-LMW-BLACKBOX"],"resolution_condition":"A source-audited construction and executable implementation satisfy the same profile, including preprocessing/storage constants, online work, updates, parameters, and reproducible measurements.","routes":["PIR-ROUTE-002"],"status":"open","target_profile":{"assumptions":"standard, non-heuristic, and explicitly instantiated","communication":"polylogarithmic or concretely low for the selected workload","online_server_work":"polylogarithmic or demonstrated sublinear","preprocessing":"deterministic and executable by the public database server","storage":"near-linear with explicit constants","updates":"sublinear with a versioned consistency rule"},"title":"Deployable public-preprocessing DEPIR under standard assumptions"},"primaryUrl":null,"sections":[{"content":"Turn public-preprocessing DEPIR into a versioned system whose theorem and artifact share the same assumption, preprocessing, storage, update, online-work, communication, and correctness profile, with independent reproduction at a declared security level.","heading":"Exact normalized target"},{"content":"The Ring-LWE result reaches strong asymptotic online bounds, while the 2025 barrier narrows broad black-box routes. Neither source supplies the end-to-end implementation evidence required by this normalized endpoint.","heading":"Why it remains open in this dossier"}],"status":"open","subtitle":"","summary":"Turn public-preprocessing DEPIR into a versioned system whose theorem and artifact share the same assumption, preprocessing, storage, update, online-work, communication, and correctness profile, with independent reproduction at a declared security level.","title":"Deployable public-preprocessing DEPIR under standard assumptions","type":"open_problem","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-OP-002"},{"evidence":"primary_source_checked","id":"PIR-PAPER-1998-CGKS","keywords":["foundations","information-theoretic","multi-server","two-server"],"metadata":{"authors":["Benny Chor","Oded Goldreich","Eyal Kushilevitz","Madhu Sudan"],"citation_key":"CGKS95","dossier_type":"paper","evidence":"primary_source_checked","id":"PIR-PAPER-1998-CGKS","keywords":["foundations","information-theoretic","multi-server","two-server"],"maps_to":["PIR-OP-001"],"primary_url":"https://madhu.seas.harvard.edu/papers/1995/pir-journ.pdf","status":"published","title":"Private Information Retrieval","venue":"Journal of the ACM 45(6); preliminary FOCS 1995","versions":["FOCS 1995","JACM 1998"],"year":1995},"primaryUrl":"https://madhu.seas.harvard.edu/papers/1995/pir-journ.pdf","sections":[{"content":"The paper formalizes PIR over replicated non-communicating databases and gives a two-server protocol with communication O(n^(1/3)). It also isolates why information-theoretic single-server PIR cannot beat downloading the database.","heading":"Atomic claims"},{"content":"Privacy is against each individual server in the stated replicated model; robustness, malicious-server behavior, and database privacy are separate notions.","heading":"Scope caution"}],"status":"published","subtitle":"Benny Chor, Oded Goldreich, Eyal Kushilevitz et al. · 1995","summary":"The paper formalizes PIR over replicated non-communicating databases and gives a two-server protocol with communication O(n^(1/3)). It also isolates why information-theoretic single-server PIR cannot beat downloading the database.","title":"Private Information Retrieval","type":"paper","venue":"Journal of the ACM 45(6); preliminary FOCS 1995","year":1995,"sourcePath":"data/pir-catalog.json#PIR-PAPER-1998-CGKS"},{"evidence":"abstract_checked","id":"PIR-PAPER-1997-KO","keywords":["single-server","computational-privacy","quadratic-residuosity"],"metadata":{"authors":["Eyal Kushilevitz","Rafail Ostrovsky"],"dossier_type":"paper","evidence":"abstract_checked","id":"PIR-PAPER-1997-KO","keywords":["single-server","computational-privacy","quadratic-residuosity"],"maps_to":["PIR-OP-001"],"primary_url":"https://doi.org/10.1109/SFCS.1997.646125","status":"published","title":"Replication Is Not Needed: Single Database, Computationally-Private Information Retrieval","venue":"FOCS 1997","versions":["FOCS extended abstract"],"year":1997},"primaryUrl":"https://doi.org/10.1109/SFCS.1997.646125","sections":[{"content":"Under the quadratic residuosity assumption, the paper removes replicated non-colluding servers and gives single-server computational PIR with O(n^epsilon) communication for any fixed epsilon greater than zero.","heading":"Atomic claims"}],"status":"published","subtitle":"Eyal Kushilevitz, Rafail Ostrovsky · 1997","summary":"Under the quadratic residuosity assumption, the paper removes replicated non-colluding servers and gives single-server computational PIR with O(n^epsilon) communication for any fixed epsilon greater than zero.","title":"Replication Is Not Needed: Single Database, Computationally-Private Information Retrieval","type":"paper","venue":"FOCS 1997","year":1997,"sourcePath":"data/pir-catalog.json#PIR-PAPER-1997-KO"},{"evidence":"fulltext_checked","id":"PIR-PAPER-1999-CMS","keywords":["single-server","computational-privacy","polylogarithmic-communication","phi-hiding"],"metadata":{"authors":["Christian Cachin","Silvio Micali","Markus Stadler"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-1999-CMS","keywords":["single-server","computational-privacy","polylogarithmic-communication","phi-hiding"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/pirpolylog.pdf","status":"published","title":"Computationally Private Information Retrieval with Polylogarithmic Communication","venue":"EUROCRYPT 1999","versions":["EUROCRYPT 1999 proceedings","author full version dated 1999-08-09"],"year":1999},"primaryUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/pirpolylog.pdf","sections":[{"content":"Under the Phi-hiding and Phi-sampling assumptions, the paper gives a two-round single-database CPIR protocol with communication polylogarithmic in the database size and linear server computation.","heading":"Atomic claims"},{"content":"The communication transition relies on a paper-specific number-theoretic assumption and does not change the linear server-work boundary for ordinary PIR.","heading":"Scope caution"}],"status":"published","subtitle":"Christian Cachin, Silvio Micali, Markus Stadler · 1999","summary":"Under the Phi-hiding and Phi-sampling assumptions, the paper gives a two-round single-database CPIR protocol with communication polylogarithmic in the database size and linear server computation.","title":"Computationally Private Information Retrieval with Polylogarithmic Communication","type":"paper","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/pir-catalog.json#PIR-PAPER-1999-CMS"},{"evidence":"bibliographic_checked","id":"PIR-PAPER-2000-BIM","keywords":["preprocessing","lower-bound","server-work"],"metadata":{"authors":["Amos Beimel","Yuval Ishai","Tal Malkin"],"dossier_type":"paper","evidence":"bibliographic_checked","id":"PIR-PAPER-2000-BIM","keywords":["preprocessing","lower-bound","server-work"],"maps_to":["PIR-OP-001","PIR-OP-002"],"primary_url":"https://doi.org/10.1007/3-540-44598-6_4","status":"published","title":"Reducing the Servers' Computation in Private Information Retrieval: PIR with Preprocessing","venue":"CRYPTO 2000","versions":["CRYPTO 2000 proceedings"],"year":2000},"primaryUrl":"https://doi.org/10.1007/3-540-44598-6_4","sections":[{"content":"The work introduces PIR with preprocessing as a way around the scoped linear server-work barrier for ordinary PIR. Later primary sources in this dossier consistently use it as the origin of the preprocessing model and lower-bound boundary.","heading":"Atomic claims"}],"status":"published","subtitle":"Amos Beimel, Yuval Ishai, Tal Malkin · 2000","summary":"The work introduces PIR with preprocessing as a way around the scoped linear server-work barrier for ordinary PIR. Later primary sources in this dossier consistently use it as the origin of the preprocessing model and lower-bound boundary.","title":"Reducing the Servers' Computation in Private Information Retrieval: PIR with Preprocessing","type":"paper","venue":"CRYPTO 2000","year":2000,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2000-BIM"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2005-GR","keywords":["single-server","private-block-retrieval","constant-rate","hidden-smooth-subgroups","phi-hiding"],"metadata":{"authors":["Craig Gentry","Zulfikar Ramzan"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2005-GR","keywords":["single-server","private-block-retrieval","constant-rate","hidden-smooth-subgroups","phi-hiding"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","status":"published","title":"Single-Database Private Information Retrieval with Constant Communication Rate","venue":"ICALP 2005","versions":["ICALP 2005 proceedings"],"year":2005},"primaryUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","sections":[{"content":"The paper gives single-database private block retrieval with communication O(k + d) for security parameter k and retrieved block length d, yielding constant communication rate for large blocks. Its general construction uses groups with hidden smooth subgroups; the composite-modulus instantiation rests on a variant of the Phi-hiding assumption.","heading":"Atomic claims"},{"content":"The rate statement concerns block retrieval and the server still performs linear work. Concrete security and rate depend on the group instantiation and parameter regime.","heading":"Scope caution"}],"status":"published","subtitle":"Craig Gentry, Zulfikar Ramzan · 2005","summary":"The paper gives single-database private block retrieval with communication O(k + d) for security parameter k and retrieved block length d, yielding constant communication rate for large blocks. Its general construction uses groups with hidden smooth subgroups; the composite-modulus instantiation rests on a variant of the Phi-hiding assumption.","title":"Single-Database Private Information Retrieval with Constant Communication Rate","type":"paper","venue":"ICALP 2005","year":2005,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2005-GR"},{"evidence":"abstract_checked","id":"PIR-PAPER-2014-GI-DPF","keywords":["two-server","information-theoretic-pir","dpf","function-secret-sharing"],"metadata":{"authors":["Niv Gilboa","Yuval Ishai"],"dossier_type":"paper","evidence":"abstract_checked","id":"PIR-PAPER-2014-GI-DPF","keywords":["two-server","information-theoretic-pir","dpf","function-secret-sharing"],"maps_to":["PIR-OP-001"],"primary_url":"https://doi.org/10.1007/978-3-642-55220-5_20","status":"published","title":"Distributed Point Functions and Their Applications","venue":"EUROCRYPT 2014","versions":["EUROCRYPT proceedings"],"year":2014},"primaryUrl":"https://doi.org/10.1007/978-3-642-55220-5_20","sections":[{"content":"The paper introduces distributed point functions: compact additive shares of a point function whose combination evaluates the hidden selector. The construction yields a lightweight two-server PIR query mechanism and becomes a reusable systems primitive.","heading":"Atomic claims"},{"content":"DPF query privacy assumes non-colluding servers; implementation efficiency does not remove that deployment assumption.","heading":"Scope caution"}],"status":"published","subtitle":"Niv Gilboa, Yuval Ishai · 2014","summary":"The paper introduces distributed point functions: compact additive shares of a point function whose combination evaluates the hidden selector. The construction yields a lightweight two-server PIR query mechanism and becomes a reusable systems primitive.","title":"Distributed Point Functions and Their Applications","type":"paper","venue":"EUROCRYPT 2014","year":2014,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2014-GI-DPF"},{"evidence":"primary_source_checked","id":"PIR-PAPER-2018-SEALPIR","keywords":["single-server","rlwe","homomorphic-encryption","query-compression","batching"],"metadata":{"authors":["Sebastian Angel","Hao Chen","Kim Laine","Srinath Setty"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PIR-PAPER-2018-SEALPIR","keywords":["single-server","rlwe","homomorphic-encryption","query-compression","batching"],"maps_to":["PIR-OP-001"],"primary_url":"https://eprint.iacr.org/2017/1142","status":"published","title":"PIR with Compressed Queries and Amortized Query Processing","venue":"IEEE Symposium on Security and Privacy 2018","versions":["IACR ePrint 2017/1142","IEEE S&P 2018"],"year":2018},"primaryUrl":"https://eprint.iacr.org/2017/1142","sections":[{"content":"SealPIR compresses a lattice-HE PIR query and reports up to 274x query-size reduction. Probabilistic batch codes amortize repeated-query processing and report up to 40x improvement over separate processing in the paper's settings.","heading":"Atomic claims"},{"content":"These are source-reported comparisons, not hardware-normalized or independently reproduced observations in this dossier.","heading":"Evidence boundary"}],"status":"published","subtitle":"Sebastian Angel, Hao Chen, Kim Laine et al. · 2018","summary":"SealPIR compresses a lattice-HE PIR query and reports up to 274x query-size reduction. Probabilistic batch codes amortize repeated-query processing and report up to 40x improvement over separate processing in the paper's settings.","title":"PIR with Compressed Queries and Amortized Query Processing","type":"paper","venue":"IEEE Symposium on Security and Privacy 2018","year":2018,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2018-SEALPIR"},{"evidence":"primary_source_checked","id":"PIR-PAPER-2020-CK","keywords":["preprocessing","offline-online","sublinear-online-time","single-server","two-server"],"metadata":{"authors":["Henry Corrigan-Gibbs","Dmitry Kogan"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PIR-PAPER-2020-CK","keywords":["preprocessing","offline-online","sublinear-online-time","single-server","two-server"],"maps_to":["PIR-OP-001","PIR-OP-002"],"primary_url":"https://eprint.iacr.org/2019/1075","status":"published","title":"Private Information Retrieval with Sublinear Online Time","venue":"EUROCRYPT 2020","versions":["IACR ePrint 2019/1075","revised full version 2022"],"year":2020},"primaryUrl":"https://eprint.iacr.org/2019/1075","sections":[{"content":"The paper gives the first sublinear-time database lookups without increasing server storage by having the client fetch a query-independent short string offline. It gives statistical two-server and computational single-server variants and proves an optimal communication/runtime tradeoff in the model.","heading":"Atomic claims"},{"content":"The offline phase, client state, and database-update consequences remain part of the cost profile; online sublinearity is not a claim of zero preprocessing cost.","heading":"Scope caution"}],"status":"published","subtitle":"Henry Corrigan-Gibbs, Dmitry Kogan · 2020","summary":"The paper gives the first sublinear-time database lookups without increasing server storage by having the client fetch a query-independent short string offline. It gives statistical two-server and computational single-server variants and proves an optimal communication/runtime tradeoff in the model.","title":"Private Information Retrieval with Sublinear Online Time","type":"paper","venue":"EUROCRYPT 2020","year":2020,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2020-CK"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2021-ALI-TRADEOFFS","keywords":["fastpir","mulpir","sealpir","communication-computation-tradeoff","keyword-pir"],"metadata":{"authors":["Asra Ali","Tancrède Lepoint","Sarvar Patel","Mariana Raykova","Phillipp Schoppmann","Karn Seth","Kevin Yeo"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2021-ALI-TRADEOFFS","keywords":["fastpir","mulpir","sealpir","communication-computation-tradeoff","keyword-pir"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.usenix.org/conference/usenixsecurity21/presentation/ali","status":"published","title":"Communication–Computation Trade-offs in PIR","venue":"USENIX Security 2021","versions":["USENIX Security 2021 proceedings"],"year":2021},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/ali","sections":[{"content":"FastPIR improves SealPIR with compression and oblivious expansion, while MulPIR uses multiplicative homomorphism for recursion to trade more server computation for less communication. The paper also optimizes the Gentry–Ramzan path and evaluates the constructions across application settings.","heading":"Atomic claims"},{"content":"The reported percentage and monetary improvements are setting-dependent; the atlas promotes the architectural trade-offs rather than universal rankings.","heading":"Scope caution"}],"status":"published","subtitle":"Asra Ali, Tancrède Lepoint, Sarvar Patel et al. · 2021","summary":"FastPIR improves SealPIR with compression and oblivious expansion, while MulPIR uses multiplicative homomorphism for recursion to trade more server computation for less communication. The paper also optimizes the Gentry–Ramzan path and evaluates the constructions across application settings.","title":"Communication–Computation Trade-offs in PIR","type":"paper","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2021-ALI-TRADEOFFS"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2021-CHECKLIST","keywords":["two-server","client-preprocessing","blocklist","dynamic-database","implementation"],"metadata":{"authors":["Dmitry Kogan","Henry Corrigan-Gibbs"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2021-CHECKLIST","keywords":["two-server","client-preprocessing","blocklist","dynamic-database","implementation"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.usenix.org/conference/usenixsecurity21/presentation/kogan","status":"published","title":"Private Blocklist Lookups with Checklist","venue":"USENIX Security 2021","versions":["USENIX Security 2021 proceedings"],"year":2021},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/kogan","sections":[{"content":"Checklist turns the CK20-style two-server offline/online idea into a concrete private blocklist system with sublinear server work. Its bucketed dynamic layer reduces amortized update work from a naive linear refresh to logarithmic cost.","heading":"Atomic claims"},{"content":"The system targets private membership/blocklist lookups and requires two non-colluding servers; the atlas promotes its PIR and update transitions rather than treating the whole application as generic index PIR.","heading":"Scope caution"}],"status":"published","subtitle":"Dmitry Kogan, Henry Corrigan-Gibbs · 2021","summary":"Checklist turns the CK20-style two-server offline/online idea into a concrete private blocklist system with sublinear server work. Its bucketed dynamic layer reduces amortized update work from a naive linear refresh to logarithmic cost.","title":"Private Blocklist Lookups with Checklist","type":"paper","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2021-CHECKLIST"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2021-SACM","keywords":["two-server","private-preprocessing","puncturable-pseudorandom-sets","lwe","polylog-bandwidth"],"metadata":{"authors":["Elaine Shi","Waqar Aqeel","Balakrishnan Chandrasekaran","Bruce M. Maggs"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2021-SACM","keywords":["two-server","private-preprocessing","puncturable-pseudorandom-sets","lwe","polylog-bandwidth"],"maps_to":["PIR-OP-001"],"primary_url":"https://eprint.iacr.org/2020/1592","status":"published","title":"Puncturable Pseudorandom Sets and Private Information Retrieval with Near-Optimal Online Bandwidth and Time","venue":"CRYPTO 2021","versions":["IACR ePrint 2020/1592","CRYPTO 2021"],"year":2021},"primaryUrl":"https://eprint.iacr.org/2020/1592","sections":[{"content":"The paper gives a two-server private-preprocessing PIR supporting unbounded queries with near-square-root online computation and client storage, polylogarithmic online bandwidth, no extra server storage, and one online round trip under LWE. It also introduces generalized privately puncturable pseudorandom sets as the central reusable mechanism.","heading":"Atomic claims"},{"content":"The near-optimal costs assume two non-colluding database replicas and amortize a per-client offline phase.","heading":"Scope caution"}],"status":"published","subtitle":"Elaine Shi, Waqar Aqeel, Balakrishnan Chandrasekaran et al. · 2021","summary":"The paper gives a two-server private-preprocessing PIR supporting unbounded queries with near-square-root online computation and client storage, polylogarithmic online bandwidth, no extra server storage, and one online round trip under LWE. It also introduces generalized privately puncturable pseudorandom sets as the central reusable mechanism.","title":"Puncturable Pseudorandom Sets and Private Information Retrieval with Near-Optimal Online Bandwidth and Time","type":"paper","venue":"CRYPTO 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2021-SACM"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2022-CHK","keywords":["single-server","client-preprocessing","adaptive-queries","sublinear-amortized-time","lower-bound"],"metadata":{"authors":["Henry Corrigan-Gibbs","Alexandra Henzinger","Dmitry Kogan"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2022-CHK","keywords":["single-server","client-preprocessing","adaptive-queries","sublinear-amortized-time","lower-bound"],"maps_to":["PIR-OP-001","PIR-OP-002"],"primary_url":"https://eprint.iacr.org/2022/081","status":"published","title":"Single-Server Private Information Retrieval with Sublinear Amortized Time","venue":"EUROCRYPT 2022","versions":["IACR ePrint 2022/081","EUROCRYPT 2022 full version"],"year":2022},"primaryUrl":"https://eprint.iacr.org/2022/081","sections":[{"content":"The paper gives the first single-server PIR schemes simultaneously supporting adaptive multi-query access, sublinear amortized server time, and sublinear additional storage under standard assumptions. It provides an LHE route, an FHE-based square-root trade-off, and a matching lower bound for adaptive schemes in its model.","heading":"Atomic claims"},{"content":"The schemes require client-specific preprocessing, persistent mutable client state, and sufficiently many queries to amortize the initial linear server work; the paper explicitly says the constructions were not yet concretely practical.","heading":"Scope caution"}],"status":"published","subtitle":"Henry Corrigan-Gibbs, Alexandra Henzinger, Dmitry Kogan · 2022","summary":"The paper gives the first single-server PIR schemes simultaneously supporting adaptive multi-query access, sublinear amortized server time, and sublinear additional storage under standard assumptions. It provides an LHE route, an FHE-based square-root trade-off, and a matching lower bound for adaptive schemes in its model.","title":"Single-Server Private Information Retrieval with Sublinear Amortized Time","type":"paper","venue":"EUROCRYPT 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2022-CHK"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2022-PY-LIMITS","keywords":["single-server","public-preprocessing","lower-bound","cell-probe","storage-time-tradeoff"],"metadata":{"authors":["Giuseppe Persiano","Kevin Yeo"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2022-PY-LIMITS","keywords":["single-server","public-preprocessing","lower-bound","cell-probe","storage-time-tradeoff"],"maps_to":["PIR-OP-002"],"primary_url":"https://eprint.iacr.org/2022/235","status":"published","title":"Limits of Preprocessing for Single-Server PIR","venue":"SODA 2022","versions":["SODA 2022 proceedings","IACR ePrint 2022/235 revised version"],"year":2022},"primaryUrl":"https://eprint.iacr.org/2022/235","sections":[{"content":"For single-server computational PIR with a public preprocessing hint of r bits and expected query probes t, the revised paper proves tr = Omega(n log n) in its stated parameter range and linear query work for logarithmic hints. It also explains why this public-hint model is strictly more constrained than private client preprocessing.","heading":"Atomic claims"},{"content":"The result is a cell-probe lower bound with explicit correctness, privacy, and hint-size conditions; it is not a blanket impossibility for every encoded or keyed DEPIR model.","heading":"Scope caution"}],"status":"published","subtitle":"Giuseppe Persiano, Kevin Yeo · 2022","summary":"For single-server computational PIR with a public preprocessing hint of r bits and expected query probes t, the revised paper proves tr = Omega(n log n) in its stated parameter range and linear query work for logarithmic hints. It also explains why this public-hint model is strictly more constrained than private client preprocessing.","title":"Limits of Preprocessing for Single-Server PIR","type":"paper","venue":"SODA 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2022-PY-LIMITS"},{"evidence":"primary_source_checked","id":"PIR-PAPER-2022-SPIRAL","keywords":["single-server","lwe","gsw","fhe-composition","streaming"],"metadata":{"authors":["Samir Jordan Menon","David J. Wu"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PIR-PAPER-2022-SPIRAL","keywords":["single-server","lwe","gsw","fhe-composition","streaming"],"maps_to":["PIR-OP-001"],"primary_url":"https://eprint.iacr.org/2022/368","status":"published","title":"Spiral: Fast, High-Rate Single-Server PIR via FHE Composition","venue":"IEEE Symposium on Security and Privacy 2022","versions":["IACR ePrint 2022/368","IEEE S&P 2022"],"year":2022},"primaryUrl":"https://eprint.iacr.org/2022/368","sections":[{"content":"Spiral composes Regev and GSW-style lattice encryption using ciphertext translation to expose new query, response, and throughput tradeoffs. SpiralStreamPack reports 1.9 GB/s server throughput and rate 0.81 for databases with more than one million records.","heading":"Atomic claims"},{"content":"The performance claim is source-reported and tied to the paper's streaming database settings.","heading":"Evidence boundary"}],"status":"published","subtitle":"Samir Jordan Menon, David J. Wu · 2022","summary":"Spiral composes Regev and GSW-style lattice encryption using ciphertext translation to expose new query, response, and throughput tradeoffs. SpiralStreamPack reports 1.9 GB/s server throughput and rate 0.81 for databases with more than one million records.","title":"Spiral: Fast, High-Rate Single-Server PIR via FHE Composition","type":"paper","venue":"IEEE Symposium on Security and Privacy 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2022-SPIRAL"},{"evidence":"primary_source_checked","id":"PIR-PAPER-2023-LMW-DEPIR","keywords":["single-server","preprocessing","depir","ring-lwe","polylog-online"],"metadata":{"authors":["Wei-Kai Lin","Ethan Mook","Daniel Wichs"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PIR-PAPER-2023-LMW-DEPIR","keywords":["single-server","preprocessing","depir","ring-lwe","polylog-online"],"maps_to":["PIR-OP-002"],"primary_url":"https://eprint.iacr.org/2022/1703","status":"published","title":"Doubly Efficient Private Information Retrieval and Fully Homomorphic RAM Computation from Ring LWE","venue":"STOC 2023","versions":["IACR ePrint 2022/1703","STOC 2023"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2022/1703","sections":[{"content":"The work constructs unkeyed DEPIR under Ring-LWE: deterministic server preprocessing takes O(N^(1+epsilon)) time and space, while each query has polylogarithmic server time and communication; updates take O(N^epsilon).","heading":"Atomic claims"},{"content":"This is an asymptotic construction result. The dossier does not infer an end-to-end practical implementation from the theorem.","heading":"Scope caution"}],"status":"published","subtitle":"Wei-Kai Lin, Ethan Mook, Daniel Wichs · 2023","summary":"The work constructs unkeyed DEPIR under Ring-LWE: deterministic server preprocessing takes O(N^(1+epsilon)) time and space, while each query has polylogarithmic server time and communication; updates take O(N^epsilon).","title":"Doubly Efficient Private Information Retrieval and Fully Homomorphic RAM Computation from Ring LWE","type":"paper","venue":"STOC 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2023-LMW-DEPIR"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","keywords":["single-server","client-preprocessing","adaptable-pseudorandom-sets","lwe","near-optimal"],"metadata":{"authors":["Arthur Lazzaretti","Charalampos Papamanthou"],"citation_key":"LP23a","dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","keywords":["single-server","client-preprocessing","adaptable-pseudorandom-sets","lwe","near-optimal"],"maps_to":["PIR-OP-001"],"primary_url":"https://eprint.iacr.org/2022/830","status":"published","title":"Near-Optimal Private Information Retrieval with Preprocessing","venue":"TCC 2023","versions":["IACR ePrint 2022/830","TCC 2023"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2022/830","sections":[{"content":"The paper independently fills the near-optimal single-server client-preprocessing gap with near-square-root amortized server time and polylogarithmic amortized bandwidth. It introduces adaptable pseudorandom sets that support succinct addition and removal while preserving pseudorandomness.","heading":"Atomic claims"}],"status":"published","subtitle":"Arthur Lazzaretti, Charalampos Papamanthou · 2023","summary":"The paper independently fills the near-optimal single-server client-preprocessing gap with near-square-root amortized server time and polylogarithmic amortized bandwidth. It introduces adaptable pseudorandom sets that support succinct addition and removal while preserving pseudorandomness.","title":"Near-Optimal Private Information Retrieval with Preprocessing","type":"paper","venue":"TCC 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2023-LP-NEAR-OPTIMAL"},{"evidence":"primary_source_checked","id":"PIR-PAPER-2023-SIMPLEPIR","keywords":["single-server","lwe","client-hint","memory-bandwidth","certificate-transparency"],"metadata":{"authors":["Alexandra Henzinger","Matthew M. Hong","Henry Corrigan-Gibbs","Sarah Meiklejohn","Vinod Vaikuntanathan"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PIR-PAPER-2023-SIMPLEPIR","keywords":["single-server","lwe","client-hint","memory-bandwidth","certificate-transparency"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.usenix.org/conference/usenixsecurity23/presentation/henzinger","status":"published","title":"One Server for the Price of Two: Simple and Fast Single-Server Private Information Retrieval","venue":"USENIX Security 2023","versions":["USENIX proceedings","prepublication and artifact"],"year":2023},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity23/presentation/henzinger","sections":[{"content":"SimplePIR uses an LWE matrix-vector structure and reports 10 GB/s/core throughput on a 1 GB database, with a 121 MB reusable hint and 242 KB per online query. DoublePIR reduces the hint to 16 MB with 345 KB per query and 7.4 GB/s/core.","heading":"Atomic claims"},{"content":"The large reusable hint and update cadence are part of the construction profile rather than free setup. Comparisons remain tied to the source's database and hardware context.","heading":"Scope caution"}],"status":"published","subtitle":"Alexandra Henzinger, Matthew M. Hong, Henry Corrigan-Gibbs et al. · 2023","summary":"SimplePIR uses an LWE matrix-vector structure and reports 10 GB/s/core throughput on a 1 GB database, with a 121 MB reusable hint and 242 KB per online query. DoublePIR reduces the hint to 16 MB with 345 KB per query and 7.4 GB/s/core.","title":"One Server for the Price of Two: Simple and Fast Single-Server Private Information Retrieval","type":"paper","venue":"USENIX Security 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2023-SIMPLEPIR"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2023-TREEPIR","keywords":["two-server","client-preprocessing","ddh","weak-privately-puncturable-prf","polylog-bandwidth"],"metadata":{"authors":["Arthur Lazzaretti","Charalampos Papamanthou"],"citation_key":"LP23b","dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2023-TREEPIR","keywords":["two-server","client-preprocessing","ddh","weak-privately-puncturable-prf","polylog-bandwidth"],"maps_to":["PIR-OP-001"],"primary_url":"https://eprint.iacr.org/2023/204","status":"published","title":"TreePIR: Sublinear-Time and Polylog-Bandwidth Private Information Retrieval from DDH","venue":"CRYPTO 2023","versions":["IACR ePrint 2023/204","CRYPTO 2023"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2023/204","sections":[{"content":"TreePIR gives two-server client-preprocessing PIR with sublinear amortized server time and polylogarithmic bandwidth from DDH. It replaces the heavier privately puncturable-set machinery of SACM with a weak privately puncturable PRF and a two-phase composition.","heading":"Atomic claims"}],"status":"published","subtitle":"Arthur Lazzaretti, Charalampos Papamanthou · 2023","summary":"TreePIR gives two-server client-preprocessing PIR with sublinear amortized server time and polylogarithmic bandwidth from DDH. It replaces the heavier privately puncturable-set machinery of SACM with a weak privately puncturable PRF and a two-phase composition.","title":"TreePIR: Sublinear-Time and Polylog-Bandwidth Private Information Retrieval from DDH","type":"paper","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2023-TREEPIR"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2023-YEO","keywords":["private-preprocessing","lower-bound","batch-pir","storage-time-tradeoff","omv"],"metadata":{"authors":["Kevin Yeo"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2023-YEO","keywords":["private-preprocessing","lower-bound","batch-pir","storage-time-tradeoff","omv"],"maps_to":["PIR-OP-001","PIR-OP-002"],"primary_url":"https://eprint.iacr.org/2022/828","status":"published","title":"Lower Bounds for (Batch) PIR with Private Preprocessing","venue":"EUROCRYPT 2023","versions":["IACR ePrint 2022/828","EUROCRYPT 2023"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2022/828","sections":[{"content":"In the standard replication model, the paper proves a tight trade-off between private hint size and online probes for single and batch PIR, including tr = Omega(n) for the scoped single-query setting and tr = Omega(nk) for batch size k when the hint is sufficiently large. It also relates stronger general-model lower bounds to the online matrix-vector conjecture.","heading":"Atomic claims"},{"content":"The lower bounds constrain the paper's replication/probe model and do not rule out arbitrary encoded databases or every preprocessing model.","heading":"Scope caution"}],"status":"published","subtitle":"Kevin Yeo · 2023","summary":"In the standard replication model, the paper proves a tight trade-off between private hint size and online probes for single and batch PIR, including tr = Omega(n) for the scoped single-query setting and tr = Omega(nk) for batch size k when the hint is sufficiently large. It also relates stronger general-model lower bounds to the online matrix-vector conjecture.","title":"Lower Bounds for (Batch) PIR with Private Preprocessing","type":"paper","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2023-YEO"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2023-ZLTS","keywords":["single-server","client-preprocessing","optimal-bandwidth","lwe","programmable-prf"],"metadata":{"authors":["Mingxun Zhou","Wei-Kai Lin","Yiannis Tselekounis","Elaine Shi"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2023-ZLTS","keywords":["single-server","client-preprocessing","optimal-bandwidth","lwe","programmable-prf"],"maps_to":["PIR-OP-001"],"primary_url":"https://eprint.iacr.org/2022/609","status":"published","title":"Optimal Single-Server Private Information Retrieval","venue":"EUROCRYPT 2023","versions":["IACR ePrint 2022/609","EUROCRYPT 2023"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2022/609","sections":[{"content":"Under LWE, the paper gives single-server private-preprocessing PIR with near-square-root amortized server/client computation and client storage, polylogarithmic bandwidth, one round trip, and unbounded queries. The construction combines FHE with privately programmable pseudorandom functions.","heading":"Atomic claims"},{"content":"Lazzaretti and Papamanthou independently reached the same near-optimal single-server cost point with a different adaptable-pseudorandom-set mechanism; that result is retained as reviewed-related rather than erased.","heading":"Attribution note"}],"status":"published","subtitle":"Mingxun Zhou, Wei-Kai Lin, Yiannis Tselekounis et al. · 2023","summary":"Under LWE, the paper gives single-server private-preprocessing PIR with near-square-root amortized server/client computation and client storage, polylogarithmic bandwidth, one round trip, and unbounded queries. The construction combines FHE with privately programmable pseudorandom functions.","title":"Optimal Single-Server Private Information Retrieval","type":"paper","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2023-ZLTS"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2024-PIANO","keywords":["single-server","client-preprocessing","prf","sublinear-server-time","implementation"],"metadata":{"authors":["Mingxun Zhou","Andrew Park","Elaine Shi","Wenting Zheng"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2024-PIANO","keywords":["single-server","client-preprocessing","prf","sublinear-server-time","implementation"],"maps_to":["PIR-OP-001"],"primary_url":"https://eprint.iacr.org/2023/452","status":"published","title":"Piano: Extremely Simple, Single-Server PIR with Sublinear Server Computation","venue":"IEEE Symposium on Security and Privacy 2024","versions":["IACR ePrint 2023/452 revised version","IEEE S&P 2024"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2023/452","sections":[{"content":"Piano gives a PRF-only single-server client-preprocessing construction matching the storage–server-time lower bound up to polylogarithmic factors. Its open-source Go implementation is the first practical transition to sublinear single-server query work in this model and reports millisecond-scale online work on a 100 GB database in the paper's WAN setting.","heading":"Atomic claims"},{"content":"The client streams the database during preprocessing, stores sublinear hints, and needs many queries to amortize setup. Reported timings are version- and environment-specific and are not compared as universal scheme properties.","heading":"Scope caution"}],"status":"published","subtitle":"Mingxun Zhou, Andrew Park, Elaine Shi et al. · 2024","summary":"Piano gives a PRF-only single-server client-preprocessing construction matching the storage–server-time lower bound up to polylogarithmic factors. Its open-source Go implementation is the first practical transition to sublinear single-server query work in this model and reports millisecond-scale online work on a 100 GB database in the paper's WAN setting.","title":"Piano: Extremely Simple, Single-Server PIR with Sublinear Server Computation","type":"paper","venue":"IEEE Symposium on Security and Privacy 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2024-PIANO"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2024-SINGLEPASS","keywords":["client-preprocessing","single-pass","dynamic-database","constant-time-updates","implementation"],"metadata":{"authors":["Arthur Lazzaretti","Charalampos Papamanthou"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2024-SINGLEPASS","keywords":["client-preprocessing","single-pass","dynamic-database","constant-time-updates","implementation"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.usenix.org/conference/usenixsecurity24/presentation/lazzaretti","status":"published","title":"Single Pass Client-Preprocessing Private Information Retrieval","venue":"USENIX Security 2024","versions":["IACR ePrint 2024/303","USENIX Security 2024"],"year":2024},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity24/presentation/lazzaretti","sections":[{"content":"SinglePass makes client preprocessing exactly one linear pass over the database and reports large preprocessing/query speedups over Checklist. It also gives constant-time additions and edits, improving the update contract of prior client-preprocessing systems.","heading":"Atomic claims"},{"content":"The primary construction is two-server client-preprocessing PIR and inherits a non-collusion deployment assumption.","heading":"Scope caution"}],"status":"published","subtitle":"Arthur Lazzaretti, Charalampos Papamanthou · 2024","summary":"SinglePass makes client preprocessing exactly one linear pass over the database and reports large preprocessing/query speedups over Checklist. It also gives constant-time additions and edits, improving the update contract of prior client-preprocessing systems.","title":"Single Pass Client-Preprocessing Private Information Retrieval","type":"paper","venue":"USENIX Security 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2024-SINGLEPASS"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2024-THORPIR","keywords":["single-server","client-preprocessing","fhe","thorp-shuffle","offline-bandwidth"],"metadata":{"authors":["Ben Fisch","Arthur Lazzaretti","Zeyu Liu","Charalampos Papamanthou"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2024-THORPIR","keywords":["single-server","client-preprocessing","fhe","thorp-shuffle","offline-bandwidth"],"maps_to":["PIR-OP-001"],"primary_url":"https://eprint.iacr.org/2024/482","status":"published","title":"ThorPIR: Single Server PIR via Homomorphic Thorp Shuffles","venue":"ACM CCS 2024","versions":["IACR ePrint 2024/482","ACM CCS 2024"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/482","sections":[{"content":"ThorPIR uses homomorphic Thorp shuffles to obtain single-server client-preprocessing PIR with sublinear server time, sublinear offline communication, and a linear-size constant-depth hint-generation circuit suited to SIMD FHE evaluation.","heading":"Atomic claims"}],"status":"published","subtitle":"Ben Fisch, Arthur Lazzaretti, Zeyu Liu et al. · 2024","summary":"ThorPIR uses homomorphic Thorp shuffles to obtain single-server client-preprocessing PIR with sublinear server time, sublinear offline communication, and a linear-size constant-depth hint-generation circuit suited to SIMD FHE evaluation.","title":"ThorPIR: Single Server PIR via Homomorphic Thorp Shuffles","type":"paper","venue":"ACM CCS 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2024-THORPIR"},{"evidence":"primary_source_checked","id":"PIR-PAPER-2024-YPIR","keywords":["single-server","lwe","rlwe","silent-preprocessing","hintless"],"metadata":{"authors":["Samir Jordan Menon","David J. Wu"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PIR-PAPER-2024-YPIR","keywords":["single-server","lwe","rlwe","silent-preprocessing","hintless"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.usenix.org/conference/usenixsecurity24/presentation/menon","status":"published","title":"YPIR: High-Throughput Single-Server PIR with Silent Preprocessing","venue":"USENIX Security 2024","versions":["USENIX proceedings","artifact appendix"],"year":2024},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity24/presentation/menon","sections":[{"content":"YPIR removes offline client communication from the high-throughput branch through lightweight LWE-to-RLWE translation. For one-bit or one-byte retrieval from a 32 GB database it reports 12.1 GB/s/core and 2.5 MB total communication.","heading":"Atomic claims"},{"content":"The artifact is versioned and available, but this dossier records paper-reported rather than independently reproduced measurements.","heading":"Evidence boundary"}],"status":"published","subtitle":"Samir Jordan Menon, David J. Wu · 2024","summary":"YPIR removes offline client communication from the high-throughput branch through lightweight LWE-to-RLWE translation. For one-bit or one-byte retrieval from a 32 GB database it reports 12.1 GB/s/core and 2.5 MB total communication.","title":"YPIR: High-Throughput Single-Server PIR with Silent Preprocessing","type":"paper","venue":"USENIX Security 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2024-YPIR"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2025-DISTRIBUTIONAL","keywords":["distributional-pir","relaxed-correctness","classic-privacy","simplepir","lower-bound"],"metadata":{"authors":["Ryan Lehmkuhl","Alexandra Henzinger","Henry Corrigan-Gibbs"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2025-DISTRIBUTIONAL","keywords":["distributional-pir","relaxed-correctness","classic-privacy","simplepir","lower-bound"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.usenix.org/conference/usenixsecurity25/presentation/lehmkuhl","status":"published","title":"Distributional Private Information Retrieval","venue":"USENIX Security 2025","versions":["USENIX Security 2025 proceedings and artifact appendix"],"year":2025},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity25/presentation/lehmkuhl","sections":[{"content":"The paper defines distributional PIR, preserving classic cryptographic query privacy while relaxing correctness according to a public popularity distribution. It gives a black-box compiler from classic PIR, a probe-model server-runtime lower bound, SimplePIR optimizations, and an evaluated system.","heading":"Atomic claims"},{"content":"Distributional PIR is not directly comparable to errorless classic PIR because its speedups depend on accepting distribution-dependent retrieval failures. It is therefore a reviewed-related correctness branch rather than a default efficiency successor.","heading":"Scope caution"}],"status":"published","subtitle":"Ryan Lehmkuhl, Alexandra Henzinger, Henry Corrigan-Gibbs · 2025","summary":"The paper defines distributional PIR, preserving classic cryptographic query privacy while relaxing correctness according to a public popularity distribution. It gives a black-box compiler from classic PIR, a probe-model server-runtime lower bound, SimplePIR optimizations, and an evaluated system.","title":"Distributional Private Information Retrieval","type":"paper","venue":"USENIX Security 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2025-DISTRIBUTIONAL"},{"evidence":"fulltext_checked","id":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR","keywords":["multi-server","depir","information-theoretic","public-preprocessing","subpolynomial-query-time"],"metadata":{"authors":["Arthur Lazzaretti","Zeyu Liu","Ben Fisch","Peihan Miao","Charalampos Papamanthou"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR","keywords":["multi-server","depir","information-theoretic","public-preprocessing","subpolynomial-query-time"],"maps_to":["PIR-OP-002"],"primary_url":"https://eprint.iacr.org/2024/829","status":"published","title":"Multi-server Doubly Efficient PIR in the Classical Model and Beyond","venue":"TCC 2025","versions":["IACR ePrint 2024/829 initial four-author version","TCC 2025 revised five-author version"],"year":2025},"primaryUrl":"https://eprint.iacr.org/2024/829","sections":[{"content":"The revised work gives the first information-theoretic multi-server DEPIR with near-linear preprocessing and subpolynomial query time for an unbounded number of queries, approaching the scoped Persiano–Yeo lower bound up to a subpolynomial factor.","heading":"Atomic claims"},{"content":"The ePrint title/author list predates the TCC 2025 revision. The technical claim used here is checked against the publicly available ePrint abstract and the published-version metadata; a version-delta audit remains recorded in coverage.","heading":"Version caution"}],"status":"published","subtitle":"Arthur Lazzaretti, Zeyu Liu, Ben Fisch et al. · 2025","summary":"The revised work gives the first information-theoretic multi-server DEPIR with near-linear preprocessing and subpolynomial query time for an unbounded number of queries, approaching the scoped Persiano–Yeo lower bound up to a subpolynomial factor.","title":"Multi-server Doubly Efficient PIR in the Classical Model and Beyond","type":"paper","venue":"TCC 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR"},{"evidence":"primary_source_checked","id":"PIR-PAPER-2025-LMW-BLACKBOX","keywords":["depir","lower-bound","black-box","secret-key"],"metadata":{"authors":["Wei-Kai Lin","Ethan Mook","Daniel Wichs"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PIR-PAPER-2025-LMW-BLACKBOX","keywords":["depir","lower-bound","black-box","secret-key"],"maps_to":["PIR-OP-002"],"primary_url":"https://eprint.iacr.org/2025/552","status":"published","title":"Black Box Crypto Is Useless for Doubly Efficient PIR","venue":"EUROCRYPT 2025","versions":["IACR ePrint 2025/552","EUROCRYPT 2025"],"year":2025},"primaryUrl":"https://eprint.iacr.org/2025/552","sections":[{"content":"The paper shows that black-box use of a broad class of generic and idealized cryptographic primitives gives no more power than black-box one-way functions for general SK-DEPIR. It proves an insufficiency result for the stated two-round passive-server format covering known schemes.","heading":"Atomic claims"},{"content":"This is not an impossibility theorem for DEPIR, Ring-LWE constructions, non-black-box methods, extra rounds, or active preprocessing formats.","heading":"Scope caution"}],"status":"published","subtitle":"Wei-Kai Lin, Ethan Mook, Daniel Wichs · 2025","summary":"The paper shows that black-box use of a broad class of generic and idealized cryptographic primitives gives no more power than black-box one-way functions for general SK-DEPIR. It proves an insufficiency result for the stated two-round passive-server format covering known schemes.","title":"Black Box Crypto Is Useless for Doubly Efficient PIR","type":"paper","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2025-LMW-BLACKBOX"},{"evidence":"abstract_checked","id":"PIR-PAPER-2026-ZIPPIR","keywords":["single-server","lwe","paillier","silent-offline","no-client-storage","recent-candidate"],"metadata":{"authors":["Rasoul Akhavan Mahdavi","Abdulrahman Diaa","Florian Kerschbaum"],"citation_key":"ADK26","citation_note":"Atlas author-year label using the compound family name Akhavan Mahdavi; not a claim of an established community abbreviation.","citation_sources":["https://uwspace.uwaterloo.ca/items/278bdf05-6b84-4e6a-a26f-a2cf2d64bfb8"],"dossier_type":"paper","evidence":"abstract_checked","id":"PIR-PAPER-2026-ZIPPIR","keywords":["single-server","lwe","paillier","silent-offline","no-client-storage","recent-candidate"],"maps_to":["PIR-OP-001"],"primary_url":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","status":"accepted_prepublication","title":"ZipPIR: High-Throughput Single-Server PIR without Client-side Storage","venue":"USENIX Security 2026","versions":["USENIX accepted prepublication","arXiv 2603.09190"],"year":2026},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","sections":[{"content":"The accepted-paper abstract describes LWE-to-Paillier ciphertext compression with an almost silent offline phase. It reports over 2 GB/s throughput and less than 200 KB server storage per client for PIR over a 1 GB database.","heading":"Atomic claims"},{"content":"At the 2026-08-07 cutoff the conference was scheduled for 2026-08-12 through 2026-08-14. This record is a recent candidate pending proceedings and artifact audit and is not used to claim a settled best result.","heading":"Publication boundary"}],"status":"accepted_prepublication","subtitle":"Rasoul Akhavan Mahdavi, Abdulrahman Diaa, Florian Kerschbaum · 2026","summary":"The accepted-paper abstract describes LWE-to-Paillier ciphertext compression with an almost silent offline phase. It reports over 2 GB/s throughput and less than 200 KB server storage per client for PIR over a 1 GB database.","title":"ZipPIR: High-Throughput Single-Server PIR without Client-side Storage","type":"paper","venue":"USENIX Security 2026","year":2026,"sourcePath":"data/pir-catalog.json#PIR-PAPER-2026-ZIPPIR"},{"evidence":"primary_source_checked","id":"PIR-PARAM-2022-SPIRAL-STREAM","keywords":[],"metadata":{"construction_id":"PIR-CONSTRUCTION-2022-SPIRAL","database_shape":"more than one million records","dossier_type":"parameter_set","estimator":"source parameters","evidence":"primary_source_checked","evidence_status":"reported","failure_model":"source-declared lattice decryption correctness","id":"PIR-PARAM-2022-SPIRAL-STREAM","paper_id":"PIR-PAPER-2022-SPIRAL","record_shape":"streaming large records","security_bits":"paper parameter set; exact estimator audit pending","status":"reported","title":"SpiralStreamPack million-record source setting","year":2022},"primaryUrl":null,"sections":[{"content":"Sufficient to bind the promoted abstract numbers; not sufficient for cross-paper normalization.","heading":"Boundary"}],"status":"reported","subtitle":"2022","summary":"Sufficient to bind the promoted abstract numbers; not sufficient for cross-paper normalization.","title":"SpiralStreamPack million-record source setting","type":"parameter_set","venue":null,"year":2022,"sourcePath":"data/pir-catalog.json#PIR-PARAM-2022-SPIRAL-STREAM"},{"evidence":"primary_source_checked","id":"PIR-PARAM-2023-SIMPLEPIR-1GB","keywords":[],"metadata":{"construction_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","database_shape":"1 GB database","dossier_type":"parameter_set","estimator":"source appendix; independent estimator audit pending","evidence":"primary_source_checked","evidence_status":"reported","failure_model":"source-declared correctness","id":"PIR-PARAM-2023-SIMPLEPIR-1GB","paper_id":"PIR-PAPER-2023-SIMPLEPIR","record_shape":"source comparison setting; exact row retained in paper","security_bits":"paper-selected LWE parameters","status":"reported","title":"SimplePIR 1 GB database source setting","year":2023},"primaryUrl":null,"sections":[{"content":"The 121 MB hint, 242 KB online communication, and 10 GB/s/core figure are only attached to this source setting.","heading":"Boundary"}],"status":"reported","subtitle":"2023","summary":"The 121 MB hint, 242 KB online communication, and 10 GB/s/core figure are only attached to this source setting.","title":"SimplePIR 1 GB database source setting","type":"parameter_set","venue":null,"year":2023,"sourcePath":"data/pir-catalog.json#PIR-PARAM-2023-SIMPLEPIR-1GB"},{"evidence":"primary_source_checked","id":"PIR-PARAM-2024-YPIR-32GB","keywords":[],"metadata":{"construction_id":"PIR-CONSTRUCTION-2024-YPIR","database_shape":"32 GB database","dossier_type":"parameter_set","estimator":"source artifact configuration","evidence":"primary_source_checked","evidence_status":"reported","failure_model":"source-declared correctness","id":"PIR-PARAM-2024-YPIR-32GB","paper_id":"PIR-PAPER-2024-YPIR","record_shape":"one bit or one byte","security_bits":"paper-selected LWE and RLWE parameters","status":"reported","title":"YPIR 32 GB one-bit/byte source setting","year":2024},"primaryUrl":null,"sections":[{"content":"The artifact appendix recommends an AWS r6i.16xlarge-class AVX-512 setting and large memory; the observation is not generalized to commodity clients or other record shapes.","heading":"Boundary"}],"status":"reported","subtitle":"2024","summary":"The artifact appendix recommends an AWS r6i.16xlarge-class AVX-512 setting and large memory; the observation is not generalized to commodity clients or other record shapes.","title":"YPIR 32 GB one-bit/byte source setting","type":"parameter_set","venue":null,"year":2024,"sourcePath":"data/pir-catalog.json#PIR-PARAM-2024-YPIR-32GB"},{"evidence":"abstract_checked","id":"PIR-PARAM-2026-ZIPPIR-1GB","keywords":[],"metadata":{"construction_id":"PIR-CONSTRUCTION-2026-ZIPPIR","database_shape":"1 GB database","dossier_type":"parameter_set","estimator":"not reported","evidence":"abstract_checked","evidence_status":"reported","failure_model":"not reported","id":"PIR-PARAM-2026-ZIPPIR-1GB","paper_id":"PIR-PAPER-2026-ZIPPIR","record_shape":"pending proceedings audit","security_bits":"not reported in accepted-page abstract","status":"accepted_prepublication","title":"ZipPIR 1 GB accepted-abstract setting","year":2026},"primaryUrl":null,"sections":[{"content":"Candidate context only. Missing parameter details prohibit comparison eligibility beyond the accepted abstract's own statement.","heading":"Boundary"}],"status":"accepted_prepublication","subtitle":"2026","summary":"Candidate context only. Missing parameter details prohibit comparison eligibility beyond the accepted abstract's own statement.","title":"ZipPIR 1 GB accepted-abstract setting","type":"parameter_set","venue":null,"year":2026,"sourcePath":"data/pir-catalog.json#PIR-PARAM-2026-ZIPPIR-1GB"},{"evidence":"primary_source_checked","id":"PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR","keywords":["atomic-result","foundations","information-theoretic","multi-server","two-server"],"metadata":{"claim_slug":"defined-information-theoretic-pir","contribution_kind":"definition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"object":["index-pir"],"privacy":["information-theoretic"],"server_model":["multi-server"]},"historical_context":{"narrative":"Before this work, a user who wanted information-theoretic query privacy from a single database had no communication-efficient alternative to downloading the database. CGKS formalized PIR for a replicated database: the user recovers one indexed bit, while each non-communicating server's individual query view is independent of that index. Replication and non-collusion make sublinear total communication possible without a computational assumption. This definition fixed the core interface for the field and exposed server count and collusion as cryptographic resources. The paper's concrete two-server O(n^(1/3)) protocol is kept as a separate atomic contribution rather than folded into the definition.","prior_boundary":"Hiding a requested index from one information-theoretic server required downloading essentially the entire database, so privacy had no communication-efficient formulation in that setting.","significance_at_publication":"Establishes the field's base problem and makes server count and collusion pattern explicit resources rather than implementation details.","technical_delta":"Defines the PIR interface over replicated databases and shows that queries can be hidden information-theoretically from each non-colluding server with sublinear total communication."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR","keywords":["foundations","information-theoretic","multi-server","two-server"],"limitations":["does not yield sublinear communication with one information-theoretic server","does not imply database privacy or malicious-server robustness"],"paper_id":"PIR-PAPER-1998-CGKS","qualifiers":["replicated database","non-colluding servers","information-theoretic query privacy"],"source_locator":{"dossier_section":"PIR-PAPER-1998-CGKS § Atomic claims","primary_source":"Abstract and Introduction","primary_source_url":"https://madhu.seas.harvard.edu/papers/1995/pir-journ.pdf","status":"primary_source_checked"},"statement":"The work defines private information retrieval and gives sublinear-communication protocols when the database is replicated across non-colluding servers with information-theoretic query privacy.","statement_status":"source_normalized_statement","status":"published","title":"Defined information-theoretic PIR over replicated servers","work_id":"PIR-PAPER-1998-CGKS"},"primaryUrl":"https://madhu.seas.harvard.edu/papers/1995/pir-journ.pdf","sections":[{"content":"Information-theoretic PIR","heading":"Overview"},{"content":"defined-information-theoretic-pir is the atomic contribution identifier normalized from PIR-PAPER-1998-CGKS. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Private Information Retrieval","summary":"The work defines private information retrieval and gives sublinear-communication protocols when the database is replicated across non-colluding servers with information-theoretic query privacy.","title":"Defined information-theoretic PIR over replicated servers","type":"result","venue":"Journal of the ACM 45(6); preliminary FOCS 1995","year":1995,"sourcePath":"data/pir-catalog.json#PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR"},{"evidence":"primary_source_checked","id":"PIR-RESULT-1998-CGKS-TWO-SERVER-N-ONE-THIRD-COMMUNICATION","keywords":["atomic-result","foundations","information-theoretic","multi-server","two-server"],"metadata":{"claim_slug":"two-server-n-one-third-communication","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"communication":["n-one-third"],"privacy":["information-theoretic"],"server_model":["two"]},"historical_context":{"narrative":"In the one-server information-theoretic setting, hiding the requested index required essentially linear communication. Within the newly defined replicated-server model, CGKS gave a two-server protocol whose total query-and-answer communication is O(n^(1/3)) for an n-bit database. The saving comes from the two servers' non-collusion, not from a computational assumption or a claim about sublinear server work. This concrete cost point demonstrated that even two replicas suffice for a nontrivial information-theoretic communication gain. The broader PIR definition and privacy interface remain a separate contribution card, so the model-level and quantitative contributions are not conflated.","prior_boundary":"Information-theoretic privacy from one server required linear communication, while the replicated-server PIR model had not yet supplied this concrete two-server asymptotic point.","significance_at_publication":"Provides the defining paper's concrete evidence that a small amount of replicated trust can yield genuinely sublinear information-theoretic PIR.","technical_delta":"Uses two replicated non-colluding servers to reduce total query-and-answer communication to O(n^(1/3)) for retrieving one bit."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-1998-CGKS-TWO-SERVER-N-ONE-THIRD-COMMUNICATION","keywords":["foundations","information-theoretic","multi-server","two-server"],"limitations":["does not reduce server work below a database scan","does not apply to one information-theoretic server"],"paper_id":"PIR-PAPER-1998-CGKS","qualifiers":["two replicated non-colluding servers","information-theoretic query privacy","one-bit retrieval"],"source_locator":{"dossier_section":"PIR-PAPER-1998-CGKS § Atomic claims","primary_source":"Abstract; Introduction, PDF pp. 1–2","primary_source_url":"https://madhu.seas.harvard.edu/papers/1995/pir-journ.pdf","status":"primary_source_checked"},"statement":"The CGKS construction gives information-theoretic PIR over two replicated non-colluding servers with total communication O(n^(1/3)) for an n-bit database.","statement_status":"source_normalized_statement","status":"published","title":"O(n^(1/3)) communication for two-server PIR","work_id":"PIR-PAPER-1998-CGKS"},"primaryUrl":"https://madhu.seas.harvard.edu/papers/1995/pir-journ.pdf","sections":[{"content":"Two-server n^(1/3)","heading":"Overview"},{"content":"two-server-n-one-third-communication is the atomic contribution identifier normalized from PIR-PAPER-1998-CGKS. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Private Information Retrieval","summary":"The CGKS construction gives information-theoretic PIR over two replicated non-colluding servers with total communication O(n^(1/3)) for an n-bit database.","title":"O(n^(1/3)) communication for two-server PIR","type":"result","venue":"Journal of the ACM 45(6); preliminary FOCS 1995","year":1995,"sourcePath":"data/pir-catalog.json#PIR-RESULT-1998-CGKS-TWO-SERVER-N-ONE-THIRD-COMMUNICATION"},{"evidence":"abstract_checked","id":"PIR-RESULT-1997-KO-FIRST-NONTRIVIAL-SINGLE-SERVER-CPIR","keywords":["atomic-result","single-server","computational-privacy","quadratic-residuosity"],"metadata":{"claim_slug":"first-nontrivial-single-server-cpir","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"normalized","facets":{"assumption":["quadratic-residuosity"],"communication":["sublinear"],"privacy":["computational"],"server_model":["single"]},"historical_context":{"narrative":"CGKS had made information-theoretic PIR communication-efficient by spreading trust across replicated, non-colluding databases; with one information-theoretic server, privacy still forced the client to download the database. Kushilevitz and Ostrovsky changed the security model rather than the retrieval objective. Under quadratic residuosity, one computationally bounded database can hide the requested index while communicating sublinearly. The historical transition is the removal of replication and non-collusion, not a claim of sublinear server work. It established single-server CPIR as a distinct research setting. The companion card isolates the construction's precise O(n^epsilon) communication point and its later improvement by CMS99.","prior_boundary":"CGKS obtained sublinear information-theoretic PIR by replicating the database across non-colluding servers; with one information-theoretic server, privacy still forced linear communication.","significance_at_publication":"Establishes single-server CPIR as a feasible research setting; the separate quantitative contribution records its O(n^epsilon) communication point.","technical_delta":"Replaces replicated-server non-collusion with computational query privacy under quadratic residuosity while retaining sublinear communication from one database."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-1997-KO-FIRST-NONTRIVIAL-SINGLE-SERVER-CPIR","keywords":["single-server","computational-privacy","quadratic-residuosity"],"limitations":["relies on quadratic residuosity","retains linear server computation","exact recursion theorem locator remains pending"],"paper_id":"PIR-PAPER-1997-KO","qualifiers":["single semi-honest server","computational query privacy","every fixed epsilon greater than zero"],"source_locator":{"dossier_section":"PIR-PAPER-1997-KO § Atomic claims","primary_source":"Abstract","primary_source_url":"https://doi.org/10.1109/SFCS.1997.646125","status":"abstract_checked"},"statement":"Under quadratic residuosity, a single database can answer computationally private queries with O(n^epsilon) communication for every fixed epsilon greater than zero.","statement_status":"source_normalized_statement","status":"published","title":"First nontrivial single-server computational PIR","work_id":"PIR-PAPER-1997-KO"},"primaryUrl":"https://doi.org/10.1109/SFCS.1997.646125","sections":[{"content":"Single-server CPIR","heading":"Overview"},{"content":"first-nontrivial-single-server-cpir is the atomic contribution identifier normalized from PIR-PAPER-1997-KO. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Replication Is Not Needed: Single Database, Computationally-Private Information Retrieval","summary":"Under quadratic residuosity, a single database can answer computationally private queries with O(n^epsilon) communication for every fixed epsilon greater than zero.","title":"First nontrivial single-server computational PIR","type":"result","venue":"FOCS 1997","year":1997,"sourcePath":"data/pir-catalog.json#PIR-RESULT-1997-KO-FIRST-NONTRIVIAL-SINGLE-SERVER-CPIR"},{"evidence":"abstract_checked","id":"PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION","keywords":["atomic-result","single-server","computational-privacy","quadratic-residuosity"],"metadata":{"claim_slug":"quadratic-residuosity-n-epsilon-communication","contribution_kind":"optimization","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"normalized","facets":{"assumption":["quadratic-residuosity"],"communication":["n-to-epsilon"],"privacy":["computational"],"server_model":["single"]},"historical_context":{"narrative":"Before KO97, sublinear communication was available only by distributing trust across replicated, non-colluding databases; a single information-theoretic server could not beat sending essentially the whole database. Under quadratic residuosity, the construction achieves total communication O(n^epsilon) for every fixed positive epsilon with one computationally bounded server. This card isolates that cost result from the paper's broader security-model transition: it improves communication, but does not make the server's work sublinear. CMS99 later names this n^epsilon dependence as its starting point and reduces the communication to polylogarithmic size under different number-theoretic assumptions.","prior_boundary":"The one-server information-theoretic boundary was linear communication; the only established sublinear protocols used replicated, non-colluding databases.","significance_at_publication":"Supplies the first nontrivial quantitative communication point for single-server CPIR, which CMS99 explicitly takes as the boundary to improve.","technical_delta":"Gives one-server computational PIR with total communication O(n^epsilon) for every fixed positive epsilon under quadratic residuosity."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION","keywords":["single-server","computational-privacy","quadratic-residuosity"],"limitations":["quadratic-residuosity assumption","linear server computation","exact theorem locator remains pending"],"paper_id":"PIR-PAPER-1997-KO","qualifiers":["single semi-honest server","every fixed epsilon greater than zero"],"source_locator":{"dossier_section":"PIR-PAPER-1997-KO § Atomic claims","primary_source":"Abstract","primary_source_url":"https://doi.org/10.1109/SFCS.1997.646125","status":"abstract_checked"},"statement":"For every fixed epsilon greater than zero, the quadratic-residuosity construction gives single-server computational PIR with O(n^epsilon) communication.","statement_status":"source_normalized_statement","status":"published","title":"O(n^ε) communication for single-server CPIR","work_id":"PIR-PAPER-1997-KO"},"primaryUrl":"https://doi.org/10.1109/SFCS.1997.646125","sections":[{"content":"n^ε communication","heading":"Overview"},{"content":"quadratic-residuosity-n-epsilon-communication is the atomic contribution identifier normalized from PIR-PAPER-1997-KO. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Replication Is Not Needed: Single Database, Computationally-Private Information Retrieval","summary":"For every fixed epsilon greater than zero, the quadratic-residuosity construction gives single-server computational PIR with O(n^epsilon) communication.","title":"O(n^ε) communication for single-server CPIR","type":"result","venue":"FOCS 1997","year":1997,"sourcePath":"data/pir-catalog.json#PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION"},{"evidence":"fulltext_checked","id":"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION","keywords":["atomic-result","single-server","polylog-communication","phi-hiding"],"metadata":{"claim_slug":"polylogarithmic-single-server-communication","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"assumption":["phi-hiding"],"communication":["polylogarithmic"],"privacy":["computational"],"server_model":["single"]},"historical_context":{"narrative":"KO97 had removed database replication, but its O(n^epsilon) communication still grew polynomially with the database size for every fixed epsilon. CMS99 changed the number-theoretic assumption and the protocol machinery: under Phi-hiding and Phi-sampling, its two-round single-server CPIR communicates only polylogarithmically many bits. The result improves the communication axis; the server still performs linear work, so it does not solve the later server-computation problem. This established the classical polylogarithmic single-server frontier. Gentry and Ramzan subsequently start from the CMS Phi-hiding technique and change the encoding so that one short response can recover a block at constant communication rate.","prior_boundary":"KO97 established single-server CPIR with O(n^epsilon) communication under quadratic residuosity, leaving a polynomial dependence on database size for every fixed epsilon.","significance_at_publication":"Establishes the classical polylogarithmic single-server communication point and provides the Phi-hiding technique that Gentry–Ramzan later reworks for constant-rate block retrieval.","technical_delta":"Uses the Phi-hiding and Phi-sampling assumptions to reduce two-round single-server communication to polylogarithmic size while leaving server work linear."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION","keywords":["single-server","polylog-communication","phi-hiding"],"limitations":["linear server work","does not use a standard modern assumption"],"paper_id":"PIR-PAPER-1999-CMS","qualifiers":["single-server computational privacy","two rounds","paper-specific Phi assumptions"],"source_locator":{"dossier_section":"PIR-PAPER-1999-CMS § Atomic claims","primary_source":"Abstract; Main Theorem; PDF pp. 1–3","primary_source_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/pirpolylog.pdf","status":"theorem_checked"},"statement":"Under the Phi assumptions, two-round single-server CPIR has communication polylogarithmic in the database size while retaining linear server work.","statement_status":"source_normalized_statement","status":"published","title":"Polylogarithmic communication for single-server CPIR","work_id":"PIR-PAPER-1999-CMS"},"primaryUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/pirpolylog.pdf","sections":[{"content":"Polylogarithmic communication for single-server CPIR This is the communication-frontier contribution, separate from the paper's CS-proof application.","heading":"Overview"}],"status":"published","subtitle":"Computationally Private Information Retrieval with Polylogarithmic Communication","summary":"Under the Phi assumptions, two-round single-server CPIR has communication polylogarithmic in the database size while retaining linear server work.","title":"Polylogarithmic communication for single-server CPIR","type":"result","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/pir-catalog.json#PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","keywords":["atomic-result","preprocessing","lower-bound","server-work"],"metadata":{"claim_slug":"formalized-pir-with-preprocessing","contribution_kind":"definition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"cost_axes":["hint-size","online-work"],"database":["static"],"preprocessing":["public-server"]},"historical_context":{"narrative":"Earlier PIR research had reduced communication, but the known protocols still had the servers collectively read at least a linear number of database bits for each retrieval. BIM made a new resource explicit: before queries arrive, each server may preprocess the static database and retain polynomially many extra bits. Online work can then be studied as a trade-off against this server-side representation instead of being conflated with communication. The model opened a distinct server-preprocessing program. CK20 later moves query-independent state to each client, while doubly efficient PIR asks for stronger public- preprocessing guarantees. Those variants change who holds or can generate the state and should not be identified with BIM's original model.","prior_boundary":"Earlier PIR optimized communication, yet every known protocol still made the servers perform at least linear work per retrieval in the standard model.","significance_at_publication":"Opens the server-preprocessing program later extended by private client preprocessing and doubly efficient PIR, while keeping preprocessing ownership explicit.","technical_delta":"Allows each server to preprocess the database into polynomial-size auxiliary state, making preprocessing storage and online query work separate resources."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","keywords":["preprocessing","lower-bound","server-work"],"limitations":["not the same as a private client hint","preprocessing storage and work remain part of the cost"],"paper_id":"PIR-PAPER-2000-BIM","qualifiers":["static database","server-visible preprocessing state","separate offline and online costs"],"source_locator":{"dossier_section":"PIR-PAPER-2000-BIM § Atomic claims","primary_source":"Abstract; Introduction, PDF pp. 1–3","primary_source_url":"https://www.cs.bgu.ac.il/~beimel/Papers/BIM.pdf","status":"section_checked"},"statement":"The model permits a server to preprocess a static database into auxiliary state before queries, separating preprocessing space and work from online query time.","statement_status":"dossier_normalized_title","status":"published","title":"Introduced server preprocessing as a PIR cost model","work_id":"PIR-PAPER-2000-BIM"},"primaryUrl":"https://doi.org/10.1007/3-540-44598-6_4","sections":[{"content":"Preprocessing PIR model","heading":"Overview"},{"content":"formalized-pir-with-preprocessing is the atomic contribution identifier normalized from PIR-PAPER-2000-BIM. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Reducing the Servers' Computation in Private Information Retrieval: PIR with Preprocessing","summary":"The model permits a server to preprocess a static database into auxiliary state before queries, separating preprocessing space and work from online query time.","title":"Introduced server preprocessing as a PIR cost model","type":"result","venue":"CRYPTO 2000","year":2000,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2000-BIM-LINEAR-WORK-BARRIER-WITHOUT-PREPROCESSING","keywords":["atomic-result","preprocessing","lower-bound","server-work"],"metadata":{"claim_slug":"linear-work-barrier-without-preprocessing","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"preprocessing":["none"],"result":["lower-bound"],"server_work":["linear"]},"historical_context":{"narrative":"By 2000, PIR protocols could communicate much less than the database size, but that did not mean the servers could avoid processing the database. BIM shows that in the standard model, where the servers hold only replicas of the original database, their total expected bit-probe work per retrieval is at least linear. The contribution is a boundary on aggregate server access, not on communication and not a universal time lower bound for every PIR storage model. Its importance was to make the hidden work cost explicit and to explain why preprocessing, batching, or a separate offline interaction can evade the conclusion. Later preprocessing results change the representation or accounting model rather than contradicting this bound.","prior_boundary":"PIR protocols had achieved sublinear communication, but all known schemes still incurred at least linear server computation per retrieval.","significance_at_publication":"Establishes the boundary that motivates preprocessing, batching, or offline interaction as explicit ways to change the cost model rather than apparent counterexamples.","technical_delta":"Shows that the servers' total expected bit-probe work is at least linear when they store only the original database in the standard model, separating communication efficiency from server-work efficiency."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2000-BIM-LINEAR-WORK-BARRIER-WITHOUT-PREPROCESSING","keywords":["preprocessing","lower-bound","server-work"],"limitations":["does not rule out preprocessing","encoding","amortization","or other changes to the storage and access model"],"paper_id":"PIR-PAPER-2000-BIM","qualifiers":["ordinary PIR access model","online server work"],"source_locator":{"dossier_section":"PIR-PAPER-2000-BIM § Atomic claims","primary_source":"Abstract; Introduction, PDF pp. 1–3","primary_source_url":"https://www.cs.bgu.ac.il/~beimel/Papers/BIM.pdf","status":"section_checked"},"statement":"In the scoped ordinary-PIR model, reducing online server work below a linear database scan requires preprocessing or another change to the access model.","statement_status":"dossier_normalized_title","status":"published","title":"Linear server-work barrier without preprocessing","work_id":"PIR-PAPER-2000-BIM"},"primaryUrl":"https://doi.org/10.1007/3-540-44598-6_4","sections":[{"content":"Linear-work barrier","heading":"Overview"},{"content":"linear-work-barrier-without-preprocessing is the atomic contribution identifier normalized from PIR-PAPER-2000-BIM. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Reducing the Servers' Computation in Private Information Retrieval: PIR with Preprocessing","summary":"In the scoped ordinary-PIR model, reducing online server work below a linear database scan requires preprocessing or another change to the access model.","title":"Linear server-work barrier without preprocessing","type":"result","venue":"CRYPTO 2000","year":2000,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2000-BIM-LINEAR-WORK-BARRIER-WITHOUT-PREPROCESSING"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL","keywords":["atomic-result","constant-rate","block-retrieval","communication"],"metadata":{"claim_slug":"constant-rate-single-database-block-retrieval","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"assumption":["hidden-smooth-subgroups","phi-hiding-variant"],"communication":["constant-rate-block-retrieval"],"server_model":["single"]},"historical_context":{"narrative":"CMS99 made the communication for a private bit query polylogarithmic, but repeating a bit-oriented protocol was a poor way to retrieve a long record. Gentry and Ramzan changed both the retrieval unit and its encoding: hidden smooth subgroups and a Chinese-remainder representation let one short response carry a d-bit block with total communication O(k+d), where k is the security parameter. For sufficiently large blocks this gives constant communication rate, rather than merely a small absolute bit-query cost. The server's computation remains linear, so the result belongs to the communication lineage. Its direct predecessor is CMS's Phi-hiding technique, which the paper explicitly reworks rather than simply reusing unchanged.","prior_boundary":"CMS99 achieved polylogarithmic communication for a private bit query, but repeatedly applying a bit-oriented protocol did not give good communication rate for long records.","significance_at_publication":"Reframes the frontier around block-retrieval rate and attains constant rate once the requested block is sufficiently large, while retaining linear server work.","technical_delta":"Uses hidden smooth subgroups and Chinese-remainder encoding to retrieve d bits with total communication O(k+d), where k is the security parameter."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL","keywords":["constant-rate","block-retrieval","communication"],"limitations":["linear server computation","instantiation-specific concrete security"],"paper_id":"PIR-PAPER-2005-GR","qualifiers":["block retrieval","security parameter at least logarithmic in database size"],"source_locator":{"dossier_section":"PIR-PAPER-2005-GR § Atomic claims","primary_source":"Abstract; Introduction, Our Results; PDF pp. 1–3","primary_source_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","status":"primary_source_checked"},"statement":"Single-database private block retrieval achieves O(k+d) communication and therefore constant rate for sufficiently large retrieved blocks.","statement_status":"source_normalized_statement","status":"published","title":"Constant-rate single-database private block retrieval","work_id":"PIR-PAPER-2005-GR"},"primaryUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","sections":[{"content":"Constant-rate private block retrieval This node records the change in retrieval unit and rate, not a sublinear-server-work result.","heading":"Overview"}],"status":"published","subtitle":"Single-Database Private Information Retrieval with Constant Communication Rate","summary":"Single-database private block retrieval achieves O(k+d) communication and therefore constant rate for sufficiently large retrieved blocks.","title":"Constant-rate single-database private block retrieval","type":"result","venue":"ICALP 2005","year":2005,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2005-GR-HIDDEN-SMOOTH-SUBGROUP-ENCODING","keywords":["atomic-result","mechanism","hidden-subgroup","chinese-remainder"],"metadata":{"claim_slug":"hidden-smooth-subgroup-encoding","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"mechanism":["hidden-smooth-subgroups","chinese-remainder-encoding"],"retrieval_unit":["block"]},"historical_context":{"narrative":"The CMS Phi-hiding approach was designed around recovering a selected bit; repeating that mechanism for every bit of a long record did not yield an attractive rate. Gentry and Ramzan introduce a different encoding layer: the database block is represented through Chinese remaindering across hidden smooth subgroups, so a compact response can carry many selected bits at once. This is the algebraic mechanism, not the rate claim itself and not a reduction in server work. Its immediate consequence in the same paper is the O(k+d) communication construction, which reaches constant rate for sufficiently large blocks. Keeping the mechanism separate explains exactly what changed relative to CMS99.","prior_boundary":"CMS-style Phi-hiding protocols encoded the answer to a private bit query, so obtaining a long block by repetition gave poor communication rate.","significance_at_publication":"Supplies the mechanism behind Gentry–Ramzan's O(k+d) block-retrieval result, separating the algebraic encoding from the resulting rate theorem.","technical_delta":"Combines hidden smooth subgroups with Chinese-remainder block encoding so a compact group element can carry many selected database bits."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2005-GR-HIDDEN-SMOOTH-SUBGROUP-ENCODING","keywords":["mechanism","hidden-subgroup","chinese-remainder"],"limitations":["requires hidden smooth subgroup structure"],"paper_id":"PIR-PAPER-2005-GR","qualifiers":["general-group presentation","composite-modulus instantiation"],"source_locator":{"dossier_section":"PIR-PAPER-2005-GR § Atomic claims","primary_source":"Introduction, Our Results; PDF p. 3; Sections 3–4","primary_source_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","status":"section_checked"},"statement":"Hidden smooth subgroups and Chinese-remainder block encoding let a short response carry an entire private block rather than one database bit.","statement_status":"source_normalized_statement","status":"published","title":"Hidden-smooth-subgroup block encoding","work_id":"PIR-PAPER-2005-GR"},"primaryUrl":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","sections":[{"content":"Hidden-smooth-subgroup encoding This mechanism is kept separate from the paper's rate result.","heading":"Overview"}],"status":"published","subtitle":"Single-Database Private Information Retrieval with Constant Communication Rate","summary":"Hidden smooth subgroups and Chinese-remainder block encoding let a short response carry an entire private block rather than one database bit.","title":"Hidden-smooth-subgroup block encoding","type":"result","venue":"ICALP 2005","year":2005,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2005-GR-HIDDEN-SMOOTH-SUBGROUP-ENCODING"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2014-GI-DPF-COMPACT-TWO-SERVER-PIR-QUERIES","keywords":["atomic-result","two-server","information-theoretic-pir","dpf","function-secret-sharing"],"metadata":{"claim_slug":"compact-two-server-pir-queries","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"communication":["compact-key-query"],"mechanism":["distributed-point-function"],"server_model":["two"]},"historical_context":{"narrative":"Binary two-server PIR with information-theoretic privacy required a linear- length query, and the earlier computational two-server construction still had query length superpolynomial in the index length. Gilboa and Ishai instead let the client generate two short DPF keys for the point function at its desired index. Each non-colluding server evaluates one key across the database and returns a single answer bit; XORing the answers recovers the selected bit. With an exponentially hard one-way function in the paper's one-parameter formulation—or a standard one-way function in its two-parameter formulation— this gives polylogarithmic queries. It improves query and answer communication, but retains two-server non-collusion and a database-wide server pass. The companion card records the reusable DPF primitive itself.","prior_boundary":"Binary two-server PIR with information-theoretic privacy required linear query length, while the earlier computational two-server point had query length superpolynomial in the index length.","significance_at_publication":"Gives an immediate lightweight two-server PIR application of DPFs while keeping the reusable DPF abstraction separate from this protocol consequence.","technical_delta":"Replaces the explicit selector shares with compact computationally private DPF keys whose local evaluations generate the two answer shares."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2014-GI-DPF-COMPACT-TWO-SERVER-PIR-QUERIES","keywords":["two-server","information-theoretic-pir","dpf","function-secret-sharing"],"limitations":["each server still evaluates across the database","does not remove replicated-server non-collusion"],"paper_id":"PIR-PAPER-2014-GI-DPF","qualifiers":["two non-colluding servers","computational DPF-key privacy","one-bit retrieval"],"source_locator":{"dossier_section":"PIR-PAPER-2014-GI-DPF § Atomic claims","primary_source":"Introduction and PIR application, PDF pp. 1–3","primary_source_url":"https://www.iacr.org/archive/eurocrypt2014/84410245/84410245.pdf","status":"section_checked"},"statement":"A client can encode its desired index as two short DPF keys; each non-colluding server evaluates one key across the database, and combining their answer shares recovers the selected bit.","statement_status":"source_normalized_statement","status":"published","title":"Compact two-server PIR queries from DPF keys","work_id":"PIR-PAPER-2014-GI-DPF"},"primaryUrl":"https://doi.org/10.1007/978-3-642-55220-5_20","sections":[{"content":"Compact DPF queries","heading":"Overview"},{"content":"compact-two-server-pir-queries is the atomic contribution identifier normalized from PIR-PAPER-2014-GI-DPF. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Distributed Point Functions and Their Applications","summary":"A client can encode its desired index as two short DPF keys; each non-colluding server evaluates one key across the database, and combining their answer shares recovers the selected bit.","title":"Compact two-server PIR queries from DPF keys","type":"result","venue":"EUROCRYPT 2014","year":2014,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2014-GI-DPF-COMPACT-TWO-SERVER-PIR-QUERIES"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2014-GI-DPF-INTRODUCED-DISTRIBUTED-POINT-FUNCTIONS","keywords":["atomic-result","two-server","information-theoretic-pir","dpf","function-secret-sharing"],"metadata":{"claim_slug":"introduced-distributed-point-functions","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"application":["pir","function-secret-sharing"],"mechanism":["distributed-point-function"],"server_model":["two"]},"historical_context":{"narrative":"Before DPFs, two parties could additively share a point function by sharing its entire truth table, but each share was as large as the represented domain. Gilboa and Ishai defined a reusable Gen/Eval interface in which two short keys individually hide the point and their evaluations combine to the target point function. Their main construction obtains polynomial-size keys from the minimal assumption that one-way functions exist, using recursive PRG-based compression. This separated compact selector sharing from any one PIR protocol and made it a cryptographic component in its own right. The same paper's compact two-server PIR query is cataloged separately as the immediate application of that mechanism.","prior_boundary":"Additively sharing a point function by sharing its full truth table produced keys exponential in the input length, or linear in the represented domain.","significance_at_publication":"Extracts compact selector sharing into a reusable primitive for two-server PIR and the broader function-secret-sharing line.","technical_delta":"Defines DPF generation and evaluation and constructs polynomial-size computationally private point-function shares from one-way functions via recursive PRG-based compression."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2014-GI-DPF-INTRODUCED-DISTRIBUTED-POINT-FUNCTIONS","keywords":["two-server","information-theoretic-pir","dpf","function-secret-sharing"],"limitations":["computational rather than information-theoretic key privacy at polynomial key size","does not by itself remove two-server non-collusion"],"paper_id":"PIR-PAPER-2014-GI-DPF","qualifiers":["two non-colluding evaluators","point-function interface","computational key privacy"],"source_locator":{"dossier_section":"PIR-PAPER-2014-GI-DPF § Atomic claims","primary_source":"Introduction and Our contribution, PDF pp. 1–4","primary_source_url":"https://www.iacr.org/archive/eurocrypt2014/84410245/84410245.pdf","status":"section_checked"},"statement":"A distributed point function splits a point function into short keys whose local evaluations combine to the original function, enabling compact two-server PIR queries.","statement_status":"source_normalized_statement","status":"published","title":"Introduced distributed point functions for compact selector sharing","work_id":"PIR-PAPER-2014-GI-DPF"},"primaryUrl":"https://doi.org/10.1007/978-3-642-55220-5_20","sections":[{"content":"Distributed point functions","heading":"Overview"},{"content":"introduced-distributed-point-functions is the atomic contribution identifier normalized from PIR-PAPER-2014-GI-DPF. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Distributed Point Functions and Their Applications","summary":"A distributed point function splits a point function into short keys whose local evaluations combine to the original function, enabling compact two-server PIR queries.","title":"Introduced distributed point functions for compact selector sharing","type":"result","venue":"EUROCRYPT 2014","year":2014,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2014-GI-DPF-INTRODUCED-DISTRIBUTED-POINT-FUNCTIONS"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2018-SEALPIR-PROBABILISTIC-BATCH-CODES-AMORTIZE-PROCESSING","keywords":["atomic-result","single-server","rlwe","homomorphic-encryption","query-compression","batching"],"metadata":{"claim_slug":"probabilistic-batch-codes-amortize-processing","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["probabilistic-batch-codes"],"optimization":["amortized-server-processing"],"track":["practice"]},"historical_context":{"narrative":"Processing several CPIR requests independently repeats expensive server-side work, while existing batch-code designs imposed unattractive communication overhead for this use. SealPIR relaxes the coding guarantee and introduces a probabilistic batch code that lets a batch of requests from the same client share computation, at a small probability that not every requested item is recovered in one interaction. The paper reports up to a 40-fold speedup over processing its test queries separately and applies the technique in Pung. That number is parameter-dependent, not a universal asymptotic gain. This card records batching and amortization; the companion card records compressed RLWE queries and homomorphic expansion.","prior_boundary":"Practical CPIR systems processed repeated queries independently, repeating much of the server-side computation for each request.","significance_at_publication":"Makes repeated-query amortization a separate systems optimization and reports up to a 40-fold source-measured speedup, distinct from SealPIR's query-compression contribution.","technical_delta":"Encodes the database with probabilistic batch codes so a batch of one client's requests can share server work rather than being evaluated one at a time."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2018-SEALPIR-PROBABILISTIC-BATCH-CODES-AMORTIZE-PROCESSING","keywords":["single-server","rlwe","homomorphic-encryption","query-compression","batching"],"limitations":["speedup depends on batch size and paper parameters","does not reduce the cost of an isolated query by the same factor"],"paper_id":"PIR-PAPER-2018-SEALPIR","qualifiers":["multiple requests from the same client","source-reported evaluation"],"source_locator":{"dossier_section":"PIR-PAPER-2018-SEALPIR § Atomic claims","primary_source":"Abstract; probabilistic batch-code construction and evaluation","primary_source_url":"https://eprint.iacr.org/2017/1142","status":"primary_source_checked"},"statement":"SealPIR introduces probabilistic batch codes to amortize server computation across multiple requests from the same client, reporting up to a 40-fold speedup over processing those queries separately in the paper's settings.","statement_status":"source_normalized_statement","status":"published","title":"Probabilistic batch codes for amortized PIR processing","work_id":"PIR-PAPER-2018-SEALPIR"},"primaryUrl":"https://eprint.iacr.org/2017/1142","sections":[{"content":"Batch-code amortization","heading":"Overview"},{"content":"probabilistic-batch-codes-amortize-processing is the atomic contribution identifier normalized from PIR-PAPER-2018-SEALPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"PIR with Compressed Queries and Amortized Query Processing","summary":"SealPIR introduces probabilistic batch codes to amortize server computation across multiple requests from the same client, reporting up to a 40-fold speedup over processing those queries separately in the paper's settings.","title":"Probabilistic batch codes for amortized PIR processing","type":"result","venue":"IEEE Symposium on Security and Privacy 2018","year":2018,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2018-SEALPIR-PROBABILISTIC-BATCH-CODES-AMORTIZE-PROCESSING"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","keywords":["atomic-result","single-server","rlwe","homomorphic-encryption","query-compression","batching"],"metadata":{"claim_slug":"sealpir-compressed-rlwe-queries","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"assumption":["ring-lwe"],"mechanism":["homomorphic-query-expansion"],"server_model":["single"],"track":["practice"]},"historical_context":{"narrative":"Before SealPIR, a practical class of CPU-efficient single-server CPIR schemes sent a number of ciphertexts proportional to the database, so the client's encrypted selector dominated query size. SealPIR transmits a compact RLWE query and moves reconstruction to the server through homomorphic expansion. The paper reports query-size reductions of up to 274-fold in its own parameter settings; the server still performs database-wide homomorphic computation, so this is not a sublinear-work result. The architecture became a concrete baseline: FastPIR later optimizes its compression and expansion, MulPIR changes the recursive response mechanism, and Spiral reports comparisons against the SealPIR line.","prior_boundary":"CPU-efficient single-server CPIR protocols still sent encrypted query material proportional to the database, making the request itself a practical bottleneck.","significance_at_publication":"Establishes query expansion as a practical lattice-PIR architecture later modified by FastPIR and MulPIR and compared against by Spiral.","technical_delta":"Compresses the client's RLWE query and homomorphically expands it at the server into the encrypted selector needed for database processing."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","keywords":["single-server","rlwe","homomorphic-encryption","query-compression","batching"],"limitations":["server still performs a database-wide homomorphic computation","reported compression depends on source parameters"],"paper_id":"PIR-PAPER-2018-SEALPIR","qualifiers":["single semi-honest server","lattice homomorphic encryption","source-reported comparison"],"source_locator":{"dossier_section":"PIR-PAPER-2018-SEALPIR § Atomic claims","primary_source":"Abstract and query-expansion overview","primary_source_url":"https://eprint.iacr.org/2017/1142","status":"primary_source_checked"},"statement":"SealPIR compresses the client's lattice-HE query and homomorphically expands it at the server, reporting up to a 274-fold query-size reduction in the paper's settings.","statement_status":"source_normalized_statement","status":"published","title":"Compressed RLWE queries through homomorphic expansion","work_id":"PIR-PAPER-2018-SEALPIR"},"primaryUrl":"https://eprint.iacr.org/2017/1142","sections":[{"content":"Compressed RLWE queries","heading":"Overview"},{"content":"sealpir-compressed-rlwe-queries is the atomic contribution identifier normalized from PIR-PAPER-2018-SEALPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"PIR with Compressed Queries and Amortized Query Processing","summary":"SealPIR compresses the client's lattice-HE query and homomorphically expands it at the server, reporting up to a 274-fold query-size reduction in the paper's settings.","title":"Compressed RLWE queries through homomorphic expansion","type":"result","venue":"IEEE Symposium on Security and Privacy 2018","year":2018,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF","keywords":["atomic-result","preprocessing","offline-online","sublinear-online-time","single-server","two-server"],"metadata":{"claim_slug":"optimal-offline-online-tradeoff","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"cost_axes":["offline-communication","online-probes"],"preprocessing":["client-specific"],"result":["lower-bound"]},"historical_context":{"narrative":"Once CK20 moved query-independent work offline, it became possible to make the online phase sublinear, but the offline download and online database probes could not be treated as independent free parameters. For an unencoded database with no additional server state, the paper proves that offline communication C and online probes T satisfy C·T = tilde-Omega(n). Its two-server construction and FHE-based single-server construction meet this tradeoff up to logarithmic factors. The result is scoped to that storage and access model; it is not a lower bound against encoded or stateful servers. Yeo23 later closes a logarithmic gap and extends the private-preprocessing tradeoff to batch queries.","prior_boundary":"Moving work into a query-independent offline phase raised the question of whether both the client's offline download and the server's online probes could be made simultaneously small.","significance_at_publication":"Certifies the paper's two-server and FHE-based single-server tradeoffs as optimal up to logarithmic factors in that model; Yeo23 later sharpens and generalizes the private-preprocessing bound.","technical_delta":"Proves C·T = tilde-Omega(n) for offline communication C and online database probes T when the server stores the database unencoded and keeps no extra state."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF","keywords":["preprocessing","offline-online","sublinear-online-time","single-server","two-server"],"limitations":["does not cover encoded or stateful server representations","hides logarithmic factors"],"paper_id":"PIR-PAPER-2020-CK","qualifiers":["unencoded database","no additional server state","offline communication versus online bit probes"],"source_locator":{"dossier_section":"PIR-PAPER-2020-CK § Atomic claims","primary_source":"Section 1.2, A lower bound; PDF pp. 4–5","primary_source_url":"https://eprint.iacr.org/2019/1075.pdf","status":"theorem_checked"},"statement":"In the CK20 model with an unencoded database and no additional server state, any offline/online PIR using C bits of offline communication and T online database probes satisfies C·T = tilde-Omega(n); the paper's two-server and FHE-based single-server schemes match this tradeoff up to logarithmic factors.","statement_status":"source_normalized_statement","status":"published","title":"Offline communication × online probes lower bound","work_id":"PIR-PAPER-2020-CK"},"primaryUrl":"https://eprint.iacr.org/2019/1075","sections":[{"content":"Optimal offline/online tradeoff","heading":"Overview"},{"content":"optimal-offline-online-tradeoff is the atomic contribution identifier normalized from PIR-PAPER-2020-CK. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Private Information Retrieval with Sublinear Online Time","summary":"In the CK20 model with an unencoded database and no additional server state, any offline/online PIR using C bits of offline communication and T online database probes satisfies C·T = tilde-Omega(n); the paper's two-server and FHE-based single-server schemes match this tradeoff up to logarithmic factors.","title":"Offline communication × online probes lower bound","type":"result","venue":"EUROCRYPT 2020","year":2020,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","keywords":["atomic-result","preprocessing","offline-online","sublinear-online-time","single-server","two-server"],"metadata":{"claim_slug":"sublinear-online-lookups-without-extra-server-storage","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"preprocessing":["client-specific"],"server_model":["single","two"],"server_work":["sublinear-online"]},"historical_context":{"narrative":"Communication-efficient PIR still made the server scan the database, while BIM-style preprocessing reduced online work by allowing extra server-side state. CK20 instead has the client fetch a short, query-independent string before choosing the desired index. With that private client state, the online lookup runs in sublinear time without increasing server storage. The reusable two-server construction supports polynomially many adaptive queries from one hint; the single-server construction supports only one online query after each offline interaction. The offline work and client state remain part of the accounting. This client-preprocessing model became the starting point for SACM's polylog-bandwidth unbounded-query improvement, Checklist's dynamic blocklist system, and CHK22's adaptive single-server amortized construction.","prior_boundary":"Communication-efficient PIR still required linear per-query server work, while BIM-style server preprocessing reduced work by storing extra server-side auxiliary information.","significance_at_publication":"Establishes the modern private client-preprocessing line later extended to unbounded-query, adaptive single-server, and concrete blocklist systems.","technical_delta":"Moves a query-independent short string to private client state before the index is chosen, enabling sublinear online work without increasing server storage in statistical two-server and computational single-server variants."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","keywords":["preprocessing","offline-online","sublinear-online-time","single-server","two-server"],"limitations":["offline work and client state are not free","single-server and two-server variants have different security assumptions"],"paper_id":"PIR-PAPER-2020-CK","qualifiers":["query-independent offline phase","private client hint","static database between refreshes"],"source_locator":{"dossier_section":"PIR-PAPER-2020-CK § Atomic claims","primary_source":"Abstract and Introduction","primary_source_url":"https://eprint.iacr.org/2019/1075","status":"primary_source_checked"},"statement":"A query-independent offline client fetch enables sublinear online database lookups without increasing server storage, with statistical two-server and computational single-server variants.","statement_status":"source_normalized_statement","status":"published","title":"Sublinear online PIR through private client preprocessing","work_id":"PIR-PAPER-2020-CK"},"primaryUrl":"https://eprint.iacr.org/2019/1075","sections":[{"content":"Sublinear online work","heading":"Overview"},{"content":"sublinear-online-lookups-without-extra-server-storage is the atomic contribution identifier normalized from PIR-PAPER-2020-CK. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Private Information Retrieval with Sublinear Online Time","summary":"A query-independent offline client fetch enables sublinear online database lookups without increasing server storage, with statistical two-server and computational single-server variants.","title":"Sublinear online PIR through private client preprocessing","type":"result","venue":"EUROCRYPT 2020","year":2020,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2021-ALI-TRADEOFFS-FASTPIR-COMPRESSED-SEALPIR-TRADEOFF","keywords":["atomic-result","fastpir","optimization","communication"],"metadata":{"claim_slug":"fastpir-compressed-sealpir-tradeoff","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"comparison":["sealpir"],"mechanism":["compression","oblivious-expansion"],"server_model":["single"]},"historical_context":{"narrative":"SealPIR had made compressed RLWE queries practical through server-side homomorphic expansion, but its communication remained substantial in the evaluated regimes. FastPIR retains that architecture but combines symmetric- key upload compression, modulus switching, and a new oblivious-expansion procedure. In the paper's matched evaluation, these changes reduce communication while preserving essentially the same computation cost. The contribution is therefore a concrete optimization of SealPIR, not a new privacy model or a proof of sublinear server work. It adds an explicit, measured communication–computation design point to the lattice-PIR branch; the reported advantage remains dependent on database shape, cryptographic parameters, and the source's comparison setting.","prior_boundary":"SealPIR made lattice-PIR queries compact through homomorphic expansion, but communication remained a significant cost in practical parameter regimes.","significance_at_publication":"Demonstrates a concrete optimization of the established SealPIR branch and makes the communication–computation comparison explicit rather than claiming a new PIR capability.","technical_delta":"Combines symmetric-key upload compression, modulus switching, and a new oblivious-expansion method in the SealPIR architecture, reducing communication while keeping essentially the same reported computation cost."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2021-ALI-TRADEOFFS-FASTPIR-COMPRESSED-SEALPIR-TRADEOFF","keywords":["fastpir","optimization","communication"],"limitations":["reported trade-off depends on database shape and parameters"],"paper_id":"PIR-PAPER-2021-ALI-TRADEOFFS","qualifiers":["single-server","homomorphic-encryption PIR"],"source_locator":{"dossier_section":"PIR-PAPER-2021-ALI-TRADEOFFS § Atomic claims","primary_source":"USENIX abstract; paper Sections 3 and 7","primary_source_url":"https://www.usenix.org/system/files/sec21-ali.pdf","status":"section_checked"},"statement":"FastPIR combines compression and a new oblivious expansion to reduce SealPIR communication while preserving essentially the same computation cost in the reported evaluation.","statement_status":"source_normalized_statement","status":"published","title":"FastPIR compressed-SealPIR trade-off","work_id":"PIR-PAPER-2021-ALI-TRADEOFFS"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/ali","sections":[{"content":"FastPIR communication optimization This is an optimization object connected to its paper and construction records.","heading":"Overview"}],"status":"published","subtitle":"Communication–Computation Trade-offs in PIR","summary":"FastPIR combines compression and a new oblivious expansion to reduce SealPIR communication while preserving essentially the same computation cost in the reported evaluation.","title":"FastPIR compressed-SealPIR trade-off","type":"result","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2021-ALI-TRADEOFFS-FASTPIR-COMPRESSED-SEALPIR-TRADEOFF"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2021-ALI-TRADEOFFS-MULPIR-MULTIPLICATIVE-RECURSION-TRADEOFF","keywords":["atomic-result","mulpir","recursion","tradeoff"],"metadata":{"claim_slug":"mulpir-multiplicative-recursion-tradeoff","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"mechanism":["multiplicative-homomorphism","recursion"],"server_model":["single"],"tradeoff":["communication-vs-computation"]},"historical_context":{"narrative":"SealPIR's recursive response generation fixed one balance between response size and homomorphic server work. MulPIR changes that mechanism by using multiplicative homomorphism in the recursion, which can reduce communication for large database entries but increases server computation. The result is not a universal improvement: its benefit depends on record size, parameters, and which cost the deployment values more. At publication, it made this communication–computation tradeoff an explicit construction choice alongside FastPIR's more direct optimization of SealPIR. This card therefore represents a mechanism branch in the design space, not a new security model or capability frontier.","prior_boundary":"SealPIR's recursive response construction offered one practical balance between ciphertext communication and server computation for single-server HE-PIR.","significance_at_publication":"Adds a distinct mechanism-level branch to the lattice-PIR design space and shows that lower communication is a chosen tradeoff, not an across-the-board efficiency gain.","technical_delta":"Uses multiplicative homomorphism during recursive response generation to reduce communication for large records while accepting more server computation."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2021-ALI-TRADEOFFS-MULPIR-MULTIPLICATIVE-RECURSION-TRADEOFF","keywords":["mulpir","recursion","tradeoff"],"limitations":["higher server computation","setting-dependent benefit"],"paper_id":"PIR-PAPER-2021-ALI-TRADEOFFS","qualifiers":["single-server","large-entry regime"],"source_locator":{"dossier_section":"PIR-PAPER-2021-ALI-TRADEOFFS § Atomic claims","primary_source":"USENIX abstract; paper Sections 4 and 7","primary_source_url":"https://www.usenix.org/system/files/sec21-ali.pdf","status":"section_checked"},"statement":"MulPIR uses multiplicative homomorphism in recursive PIR response generation to reduce communication at the price of increased server computation for large database entries.","statement_status":"source_normalized_statement","status":"published","title":"MulPIR multiplicative-recursion trade-off","work_id":"PIR-PAPER-2021-ALI-TRADEOFFS"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/ali","sections":[{"content":"MulPIR recursion trade-off The node records a mechanism-level branch, not a blanket efficiency improvement.","heading":"Overview"}],"status":"published","subtitle":"Communication–Computation Trade-offs in PIR","summary":"MulPIR uses multiplicative homomorphism in recursive PIR response generation to reduce communication at the price of increased server computation for large database entries.","title":"MulPIR multiplicative-recursion trade-off","type":"result","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2021-ALI-TRADEOFFS-MULPIR-MULTIPLICATIVE-RECURSION-TRADEOFF"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES","keywords":["atomic-result","dynamic-database","updates","optimization"],"metadata":{"claim_slug":"logarithmic-amortized-updates","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"cost":["logarithmic_amortized"],"update_model":["dynamic_bucketed"]},"historical_context":{"narrative":"Client-preprocessing PIR is naturally described for a static database, but a security blocklist changes frequently and cannot afford a full preprocessing refresh after every edit. Checklist adds a bucketed dynamic dictionary layer around its offline/online PIR core, reducing amortized update work from a linear rebuild to logarithmic cost. This is an application data-structure result, not a generic theorem that every PIR database supports logarithmic updates. Its importance is to expose freshness as a first-class cost in a concrete private blocklist system. SinglePass later compares against this update branch and reports constant-time additions and edits within its own dynamic model.","prior_boundary":"Applying a static client-preprocessing PIR design to a changing blocklist would require rebuilding or redistributing preprocessing after database changes.","significance_at_publication":"Makes database freshness an explicit systems cost for the Checklist workload; SinglePass later targets this branch and reports constant-time additions and edits in its model.","technical_delta":"Layers a bucketed dynamic dictionary over the offline/online PIR core so blocklist changes incur logarithmic amortized update work rather than a linear refresh."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES","keywords":["dynamic-database","updates","optimization"],"limitations":["application data structure cost is not a generic PIR theorem"],"paper_id":"PIR-PAPER-2021-CHECKLIST","qualifiers":["dynamic dictionary layered over offline-online PIR"],"source_locator":{"dossier_section":"PIR-PAPER-2021-CHECKLIST § Atomic claims","primary_source":"Section 2.2; USENIX PDF pp. 878–879","primary_source_url":"https://www.usenix.org/system/files/sec21-kogan.pdf","status":"section_checked"},"statement":"A bucketed dynamic layer reduces amortized blocklist update work to logarithmic cost instead of rerunning linear preprocessing after each change.","statement_status":"source_normalized_statement","status":"published","title":"Logarithmic amortized blocklist updates","work_id":"PIR-PAPER-2021-CHECKLIST"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/kogan","sections":[{"content":"Logarithmic amortized blocklist updates The update contribution is distinct from the core two-server PIR protocol.","heading":"Overview"}],"status":"published","subtitle":"Private Blocklist Lookups with Checklist","summary":"A bucketed dynamic layer reduces amortized blocklist update work to logarithmic cost instead of rerunning linear preprocessing after each change.","title":"Logarithmic amortized blocklist updates","type":"result","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS","keywords":["atomic-result","checklist","implementation","practice-transition"],"metadata":{"claim_slug":"practical-sublinear-two-server-lookups","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"application":["blocklist"],"server_model":["two_non_colluding"],"track":["practice"]},"historical_context":{"narrative":"CK20 established asymptotic sublinear online PIR after a query-independent client preprocessing, but did not provide a dynamic browser-scale system. Checklist constructs a two-server offline/online core that removes a factor of the security parameter from the prior online server work, then integrates it with private blocklist membership and evaluates a modified Firefox Safe Browsing client. This is a theory-to-practice bridge under two-server non- collusion, not a generic index-PIR benchmark or an independently reproduced deployment. The paper treats database updates as a separate systems cost. SinglePass later compares directly against Checklist and targets lower preprocessing and query costs, making the lineage link explicit.","prior_boundary":"CK20 proved that private client preprocessing could yield sublinear online lookups, but it did not supply a complete dynamic system for a browser-scale membership workload.","significance_at_publication":"Provides the first systems bridge in this corpus from CK20's asymptotic model to a dynamic application; SinglePass later directly optimizes its preprocessing and query costs.","technical_delta":"Removes a security-parameter factor from the CK20-style two-server online work, integrates the protocol with private blocklist membership, and evaluates it in Firefox Safe Browsing."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS","keywords":["checklist","implementation","practice-transition"],"limitations":["membership application rather than a generic index-PIR benchmark","reported not reproduced"],"paper_id":"PIR-PAPER-2021-CHECKLIST","qualifiers":["two non-colluding servers","dynamic blocklist application"],"source_locator":{"dossier_section":"PIR-PAPER-2021-CHECKLIST § Atomic claims","primary_source":"Abstract; Sections 1–2; USENIX PDF pp. 875–879","primary_source_url":"https://www.usenix.org/system/files/sec21-kogan.pdf","status":"section_checked"},"statement":"Checklist implements a two-server private blocklist system whose online PIR server work is sublinear after client-specific preprocessing and evaluates it in a Firefox Safe Browsing setting.","statement_status":"source_normalized_statement","status":"published","title":"Practical sublinear two-server lookups","work_id":"PIR-PAPER-2021-CHECKLIST"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity21/presentation/kogan","sections":[{"content":"Practical sublinear two-server lookups This is the theory-to-practice bridge from client-preprocessing PIR to a deployed browser-shaped workload.","heading":"Overview"}],"status":"published","subtitle":"Private Blocklist Lookups with Checklist","summary":"Checklist implements a two-server private blocklist system whose online PIR server work is sublinear after client-specific preprocessing and evaluates it in a Firefox Safe Browsing setting.","title":"Practical sublinear two-server lookups","type":"result","venue":"USENIX Security 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","keywords":["atomic-result","two-server","private-preprocessing","near-optimal"],"metadata":{"claim_slug":"near-optimal-two-server-preprocessing-pir","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"assumption":["lwe"],"communication":["polylogarithmic_online"],"preprocessing":["client_specific"],"server_model":["two_non_colluding"]},"historical_context":{"narrative":"CK20 showed how private client preprocessing could make online work sublinear, but its reusable two-server tradeoff did not simultaneously reach near-square-root online work and client storage with polylogarithmic bandwidth for unbounded queries. Under LWE, SACM combines those costs with one online round trip and no extra server storage, using privately puncturable pseudorandom sets to support hint refresh. The result still assumes two non-colluding replicas and a per-client offline phase. It established a precise cost point that later work treats as an object to transform: ZLTS23 compiles the interactions to one server, while TreePIR targets the same point from DDH with a different puncturing mechanism.","prior_boundary":"CK20 obtained sublinear online work from private client preprocessing, but its reusable two-server point did not simultaneously provide near-square-root online work and client storage with polylogarithmic bandwidth for unbounded queries.","significance_at_publication":"Establishes the two-server near-optimal cost point later compiled to one server by ZLTS23 and re-instantiated from DDH with a different puncturing mechanism by TreePIR.","technical_delta":"Under LWE, combines near-square-root online computation and client storage with polylogarithmic bandwidth, one round trip, unbounded queries, and no extra server storage using privately puncturable pseudorandom sets."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","keywords":["two-server","private-preprocessing","near-optimal"],"limitations":["non-collusion","per-client offline phase and state"],"paper_id":"PIR-PAPER-2021-SACM","qualifiers":["two non-colluding servers","client-specific preprocessing","unbounded adaptive queries"],"source_locator":{"dossier_section":"PIR-PAPER-2021-SACM § Atomic claims","primary_source":"Abstract; Theorem 1.1; PDF pp. 1–4","primary_source_url":"https://eprint.iacr.org/2020/1592.pdf","status":"theorem_checked"},"statement":"Under LWE, two-server private-preprocessing PIR supports unbounded queries with near-square-root online computation and client storage, polylogarithmic bandwidth, one round trip, and no extra server storage.","statement_status":"source_normalized_statement","status":"published","title":"Near-optimal two-server private preprocessing","work_id":"PIR-PAPER-2021-SACM"},"primaryUrl":"https://eprint.iacr.org/2020/1592","sections":[{"content":"Near-optimal two-server private preprocessing The theorem-level cost point is separated from the PRSet mechanism.","heading":"Overview"}],"status":"published","subtitle":"Puncturable Pseudorandom Sets and Private Information Retrieval with Near-Optimal Online Bandwidth and Time","summary":"Under LWE, two-server private-preprocessing PIR supports unbounded queries with near-square-root online computation and client storage, polylogarithmic bandwidth, one round trip, and no extra server storage.","title":"Near-optimal two-server private preprocessing","type":"result","venue":"CRYPTO 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2021-SACM-PRIVATELY-PUNCTURABLE-PSEUDORANDOM-SETS","keywords":["atomic-result","prset","reusable-mechanism","hint-refresh"],"metadata":{"claim_slug":"privately-puncturable-pseudorandom-sets","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"mechanism":["privately_puncturable_pseudorandom_set"],"role":["hint_refresh"]},"historical_context":{"narrative":"Reusing a private client hint for unbounded queries requires refreshing hidden query-dependent structure without asking each server to retain linear state for every client. SACM generalizes privately puncturable pseudorandom sets and uses their puncture-and-refresh interface to maintain the hint while preserving the paper's two-server privacy guarantees. This card records that cryptographic mechanism, not the complete PIR theorem or its full cost profile. The object is central to SACM's near-optimal construction and also became a clear comparison point for later work: TreePIR targets the same PIR cost regime while replacing the heavier set machinery with weak privately puncturable PRFs under DDH.","prior_boundary":"Reusable private client preprocessing needed a way to refresh hidden query-dependent structure without storing linear per-client state at the servers.","significance_at_publication":"Supplies the reusable mechanism behind SACM's near-optimal two-server construction and the heavier object that TreePIR later replaces with weak privately puncturable PRFs under DDH.","technical_delta":"Generalizes privately puncturable pseudorandom sets and uses their puncture-and-refresh interface to maintain client hints for unbounded queries without extra per-client server storage."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2021-SACM-PRIVATELY-PUNCTURABLE-PSEUDORANDOM-SETS","keywords":["prset","reusable-mechanism","hint-refresh"],"limitations":["security and occasional-correctness definitions are paper-specific"],"paper_id":"PIR-PAPER-2021-SACM","qualifiers":["used inside the two-server construction"],"source_locator":{"dossier_section":"PIR-PAPER-2021-SACM § Atomic claims","primary_source":"Sections 4–5; PDF pp. 10–19","primary_source_url":"https://eprint.iacr.org/2020/1592.pdf","status":"section_checked"},"statement":"The paper generalizes privately puncturable pseudorandom sets and constructs the mechanism used to refresh private-preprocessing PIR hints without extra per-client server storage.","statement_status":"source_normalized_statement","status":"published","title":"Privately puncturable pseudorandom sets","work_id":"PIR-PAPER-2021-SACM"},"primaryUrl":"https://eprint.iacr.org/2020/1592","sections":[{"content":"Privately puncturable pseudorandom sets This node records the reusable cryptographic object, not the complete PIR configuration.","heading":"Overview"}],"status":"published","subtitle":"Puncturable Pseudorandom Sets and Private Information Retrieval with Near-Optimal Online Bandwidth and Time","summary":"The paper generalizes privately puncturable pseudorandom sets and constructs the mechanism used to refresh private-preprocessing PIR hints without extra per-client server storage.","title":"Privately puncturable pseudorandom sets","type":"result","venue":"CRYPTO 2021","year":2021,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2021-SACM-PRIVATELY-PUNCTURABLE-PSEUDORANDOM-SETS"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","keywords":["atomic-result","adaptive","single-server","sublinear-amortized"],"metadata":{"claim_slug":"adaptive-single-server-sublinear-amortized-pir","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"preprocessing":["client_specific"],"query_semantics":["adaptive_multi_query"],"server_model":["single"],"server_work":["sublinear_amortized"]},"historical_context":{"narrative":"CK20-style offline/online PIR allowed only one lookup after each linear setup, while SACM21 obtained a strong multi-query point using two non-colluding servers. CHK22 shows that one server can instead support an adaptive sequence: the client downloads a sublinear database-dependent hint, maintains private state, and periodically refreshes it while the server answers in sublinear time, yielding sublinear amortized server time. The construction adds no per-client server storage, but increases client storage and computation. This established the standard-assumption one-server capability later preserved by ZLTS23 and LP23, which reduced CHK22's near-square-root amortized communication to polylogarithmic.","prior_boundary":"CK20-style offline/online PIR gave sublinear work for one lookup after each linear setup, and SACM21 obtained a strong multi-query point with two non-colluding servers, but neither supplied the one-server adaptive contract under standard assumptions.","significance_at_publication":"Establishes feasibility for stateful adaptive single-server PIR and defines the cost profile whose near-square-root bandwidth ZLTS23 and LP23 later reduce to polylogarithmic.","technical_delta":"Introduces a sublinear client hint, persistent mutable client state, and periodic refresh so one server can answer adaptive query sequences with sublinear amortized server time and no per-client server storage."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","keywords":["adaptive","single-server","sublinear-amortized"],"limitations":["persistent mutable client state","preprocessing amortization","not concretely practical in the paper"],"paper_id":"PIR-PAPER-2022-CHK","qualifiers":["bounded queries per preprocessing epoch","adaptive query choice","client-specific hint"],"source_locator":{"dossier_section":"PIR-PAPER-2022-CHK § Atomic claims","primary_source":"Abstract; Section 1.1; Theorems 4.1 and 5.1; PDF pp. 1–4, 14, 19","primary_source_url":"https://eprint.iacr.org/2022/081.pdf","status":"theorem_checked"},"statement":"The first single-server PIR simultaneously achieves adaptive multi-query access, sublinear amortized server time, and sublinear additional storage under standard assumptions.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive single-server sublinear amortized PIR","work_id":"PIR-PAPER-2022-CHK"},"primaryUrl":"https://eprint.iacr.org/2022/081","sections":[{"content":"Adaptive single-server sublinear amortized PIR This capability change is the omission that triggered the 2026-08-17 backbone repair.","heading":"Overview"}],"status":"published","subtitle":"Single-Server Private Information Retrieval with Sublinear Amortized Time","summary":"The first single-server PIR simultaneously achieves adaptive multi-query access, sublinear amortized server time, and sublinear additional storage under standard assumptions.","title":"Adaptive single-server sublinear amortized PIR","type":"result","venue":"EUROCRYPT 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2022-CHK-ADAPTIVE-STORAGE-TIME-LOWER-BOUND","keywords":["atomic-result","lower-bound","storage-time","adaptive"],"metadata":{"claim_slug":"adaptive-storage-time-lower-bound","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"coordinates":["client_storage","online_server_time"],"query_semantics":["adaptive"],"result":["lower_bound"]},"historical_context":{"narrative":"Client-preprocessing schemes already traded a larger client hint for less online server work, but the adaptive single-server setting lacked a matching boundary. CHK22 proves that, when the server stores the database unmodified, client storage S and amortized online server time T satisfy ST = Omega(n). Its FHE construction meets this product trade-off up to logarithmic and security-parameter factors. This is a model-specific lower bound, not another construction or a universal PIR impossibility: it makes client state part of any honest sublinear-time comparison in this setting. Piano later cites and matches the bound up to polylogarithmic factors; public-hint and arbitrarily encoded-database models are outside its automatic scope.","prior_boundary":"Client-preprocessing constructions exposed a client-storage-versus-online-server-time trade-off, but the adaptive single-server model lacked a matching bound for an unmodified server database.","significance_at_publication":"Makes client state part of any honest sublinear-time comparison and supplies the boundary that Piano later matches up to polylogarithmic factors.","technical_delta":"Proves that client storage S and amortized online server time T satisfy ST = Omega(n) in the paper's adaptive multi-query model when the server stores the database unmodified."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2022-CHK-ADAPTIVE-STORAGE-TIME-LOWER-BOUND","keywords":["lower-bound","storage-time","adaptive"],"limitations":["not a universal lower bound for encoded-database or public-preprocessing models"],"paper_id":"PIR-PAPER-2022-CHK","qualifiers":["adaptive schemes","unmodified server database","scoped computational model"],"source_locator":{"dossier_section":"PIR-PAPER-2022-CHK § Atomic claims","primary_source":"Section 6.1; Theorem 6.2; PDF pp. 22–23","primary_source_url":"https://eprint.iacr.org/2022/081.pdf","status":"theorem_checked"},"statement":"In the paper's adaptive multi-query model with an unmodified database, client storage S and amortized online server time T satisfy ST = Omega(n), matching the best FHE-based trade-off up to logarithmic factors.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive storage–time lower bound","work_id":"PIR-PAPER-2022-CHK"},"primaryUrl":"https://eprint.iacr.org/2022/081","sections":[{"content":"Adaptive storage–time lower bound This boundary explains why later constructions target the square-root point.","heading":"Overview"}],"status":"published","subtitle":"Single-Server Private Information Retrieval with Sublinear Amortized Time","summary":"In the paper's adaptive multi-query model with an unmodified database, client storage S and amortized online server time T satisfy ST = Omega(n), matching the best FHE-based trade-off up to logarithmic factors.","title":"Adaptive storage–time lower bound","type":"result","venue":"EUROCRYPT 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2022-CHK-ADAPTIVE-STORAGE-TIME-LOWER-BOUND"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","keywords":["atomic-result","compiler","homomorphic-encryption","transform"],"metadata":{"claim_slug":"two-server-to-single-server-compilation","contribution_kind":"transform","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"mechanism":["homomorphic_evaluation"],"transform":["two_server_to_single_server"]},"historical_context":{"narrative":"Strong two-server preprocessing schemes could use non-collusion during setup and refresh, leaving open how to preserve their online advantages with only one server. CHK22 compiles such a starting point into single-server multi-query PIR by homomorphically evaluating the offline interaction, with LHE and FHE variants determining the supported cost and query regimes. This mechanism is distinct from the paper's headline feasibility theorem: it explains how the second server is removed and where the homomorphic cost enters. ZLTS23 explicitly strengthens this line with privately programmable batched refresh, while ThorPIR later targets the deep homomorphic hint-generation bottleneck of these single-server compilations.","prior_boundary":"Strong two-server preprocessing schemes obtained favorable online costs, but their offline and refresh interactions relied on a second non-colluding server.","significance_at_publication":"Exposes a reusable compilation strategy that ZLTS23 strengthens with batched programmable refresh and that ThorPIR later revisits at the hint-generation bottleneck.","technical_delta":"Homomorphically evaluates the offline interaction, with LHE and FHE variants, to compile the two-server starting point into single-server multi-query PIR."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","keywords":["compiler","homomorphic-encryption","transform"],"limitations":["cost and supported query count depend on the instantiated variant"],"paper_id":"PIR-PAPER-2022-CHK","qualifiers":["LHE and FHE variants"],"source_locator":{"dossier_section":"PIR-PAPER-2022-CHK § Atomic claims","primary_source":"Sections 3–5; PDF pp. 11–21","primary_source_url":"https://eprint.iacr.org/2022/081.pdf","status":"section_checked"},"statement":"The construction compiles a two-server scheme with a single-server online phase into single-server multi-query PIR using homomorphic evaluation of the offline interaction.","statement_status":"source_normalized_statement","status":"published","title":"Two-server-to-single-server compilation","work_id":"PIR-PAPER-2022-CHK"},"primaryUrl":"https://eprint.iacr.org/2022/081","sections":[{"content":"Two-server-to-single-server compilation This mechanism node is related work; the adaptive capability result is the paper's primary map node.","heading":"Overview"}],"status":"published","subtitle":"Single-Server Private Information Retrieval with Sublinear Amortized Time","summary":"The construction compiles a two-server scheme with a single-server online phase into single-server multi-query PIR using homomorphic evaluation of the offline interaction.","title":"Two-server-to-single-server compilation","type":"result","venue":"EUROCRYPT 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","keywords":["atomic-result","lower-bound","public-preprocessing","storage-time"],"metadata":{"claim_slug":"public-preprocessing-storage-time-lower-bound","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"cost_axes":["hint-size","online-probes"],"preprocessing":["public"],"result":["lower-bound"],"server_model":["single"]},"historical_context":{"narrative":"BIM had formalized PIR with public preprocessing and proved a tr = Omega(n) storage-time bound, but that left a logarithmic gap and was often discussed alongside private-hint schemes whose preprocessing state is hidden from the server. Persiano and Yeo strengthen the computational public-hint result to tr = Omega(n log n) in their stated cell-probe parameter range and obtain linear query probes when the public hint is only logarithmic. The result mattered because it sharpened the cost boundary for a hint stored by the server and visible to the adversary; a private client hint is a different resource and cannot be placed on the same trade-off curve without changing the model. The theorem is deliberately scoped to its public-hint cell-probe setting and does not rule out every keyed or encoded DEPIR construction.","prior_boundary":"BIM's public-preprocessing framework had a tr = Omega(n) storage-time bound, while private client hints could attain different trade-offs because their preprocessing state was hidden from the server.","significance_at_publication":"Sharpens the public-preprocessing frontier and shows why its storage-time points cannot be compared with private client preprocessing without accounting for who stores and sees the hint.","technical_delta":"Strengthens the computational public-hint bound to tr = Omega(n log n) in the paper's stated cell-probe range and proves linear probes when the public hint is logarithmic."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","keywords":["lower-bound","public-preprocessing","storage-time"],"limitations":["does not cover every keyed or encoded DEPIR model"],"paper_id":"PIR-PAPER-2022-PY-LIMITS","qualifiers":["public hint","computational privacy","cell-probe model","bounded error and distinguishing advantage"],"source_locator":{"dossier_section":"PIR-PAPER-2022-PY-LIMITS § Atomic claims","primary_source":"Abstract; Theorem 1 / Theorem 2; PDF pp. 1–2 and 8","primary_source_url":"https://eprint.iacr.org/2022/235.pdf","status":"theorem_checked"},"statement":"In the paper's cell-probe model, computational single-server PIR with a public r-bit preprocessing hint and expected t probes satisfies tr = Omega(n log n) over the stated hint range, with linear probes for logarithmic hints.","statement_status":"source_normalized_statement","status":"published","title":"Public-preprocessing storage–time lower bound","work_id":"PIR-PAPER-2022-PY-LIMITS"},"primaryUrl":"https://eprint.iacr.org/2022/235","sections":[{"content":"Public-preprocessing lower bound The model distinction from private client preprocessing is part of the displayed claim.","heading":"Overview"}],"status":"published","subtitle":"Limits of Preprocessing for Single-Server PIR","summary":"In the paper's cell-probe model, computational single-server PIR with a public r-bit preprocessing hint and expected t probes satisfies tr = Omega(n log n) over the stated hint range, with linear probes for logarithmic hints.","title":"Public-preprocessing storage–time lower bound","type":"result","venue":"SODA 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION","keywords":["atomic-result","single-server","lwe","gsw","fhe-composition","streaming"],"metadata":{"claim_slug":"regev-gsw-ciphertext-translation","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["ciphertext-translation"],"representations":["regev","gsw"],"track":["practice"]},"historical_context":{"narrative":"Earlier lattice PIR systems such as the SealPIR line compressed encrypted selectors, but a ciphertext representation convenient for the client was not necessarily the one best suited to homomorphic server evaluation. Spiral introduces an in-server Regev-to-GSW translation, keeping queries compact in the Regev form and switching representations where GSW-style operations are useful. The contribution mattered because it was an architectural change, rather than a parameter-only optimization, behind Spiral's reported improvements in query size, response size, and throughput. The public Spiral artifact instantiates this translation and its streaming variants; the mechanism improves linear-scan systems performance but does not make online server work sublinear.","prior_boundary":"Earlier lattice PIR systems, including the SealPIR line, compressed encrypted selectors but faced a tension between compact client ciphertexts and ciphertext forms convenient for homomorphic server computation.","significance_at_publication":"Makes ciphertext translation the architectural move behind Spiral's simultaneous query-size, response-rate, and throughput improvements and its public implementation.","technical_delta":"Converts compact Regev-style query ciphertexts into GSW-style ciphertexts inside the server computation, allowing the protocol to use different representations for communication and evaluation."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION","keywords":["single-server","lwe","gsw","fhe-composition","streaming"],"limitations":["reported throughput and rate are workload-specific","translation does not make server work sublinear"],"paper_id":"PIR-PAPER-2022-SPIRAL","qualifiers":["single semi-honest server","lattice-based FHE composition"],"source_locator":{"dossier_section":"PIR-PAPER-2022-SPIRAL § Atomic claims","primary_source":"Abstract and Introduction","primary_source_url":"https://eprint.iacr.org/2022/368","status":"primary_source_checked"},"statement":"Spiral translates compact Regev-style query ciphertexts into GSW-style ciphertexts inside the server computation, enabling new query-size, response-rate, and throughput trade-offs.","statement_status":"source_normalized_statement","status":"published","title":"Regev-to-GSW ciphertext translation for high-rate PIR","work_id":"PIR-PAPER-2022-SPIRAL"},"primaryUrl":"https://eprint.iacr.org/2022/368","sections":[{"content":"Regev→GSW translation","heading":"Overview"},{"content":"regev-gsw-ciphertext-translation is the atomic contribution identifier normalized from PIR-PAPER-2022-SPIRAL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Spiral: Fast, High-Rate Single-Server PIR via FHE Composition","summary":"Spiral translates compact Regev-style query ciphertexts into GSW-style ciphertexts inside the server computation, enabling new query-size, response-rate, and throughput trade-offs.","title":"Regev-to-GSW ciphertext translation for high-rate PIR","type":"result","venue":"IEEE Symposium on Security and Privacy 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2022-SPIRAL-SPIRALSTREAM-HIGH-RATE-THROUGHPUT","keywords":["atomic-result","single-server","lwe","gsw","fhe-composition","streaming"],"metadata":{"claim_slug":"spiralstream-high-rate-throughput","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"metrics":["server-throughput","response-rate"],"track":["practice"],"workload":["streaming"]},"historical_context":{"narrative":"Streaming PIR had a particularly visible throughput-versus-response-rate gap: in Spiral's comparison, previous protocols reached about 200 MB/s and rate 0.24. SpiralStreamPack specializes the Spiral family for streaming large records and reports 1.9 GB/s server throughput with rate 0.81 on databases containing more than one million records. This contribution is a source-bound operating point, not a general asymptotic theorem or a hardware-independent ranking. It mattered because it showed that the paper's ciphertext-composition architecture could improve throughput and response efficiency together, and the linked Spiral implementation is the artifact in which this streaming variant is instantiated.","prior_boundary":"Previous streaming PIR protocols reported about 200 MB/s server throughput and response rate 0.24 in the comparison summarized by the Spiral paper.","significance_at_publication":"Demonstrates that the Regev-to-GSW architecture can deliver both high throughput and high response rate in a concrete streaming regime, rather than optimizing only one metric.","technical_delta":"Specializes the Spiral family for streaming large records and reports a 1.9 GB/s, rate-0.81 operating point on databases exceeding one million records."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2022-SPIRAL-SPIRALSTREAM-HIGH-RATE-THROUGHPUT","keywords":["single-server","lwe","gsw","fhe-composition","streaming"],"limitations":["not hardware-normalized","does not imply sublinear server work","performance is workload-specific"],"paper_id":"PIR-PAPER-2022-SPIRAL","qualifiers":["single semi-honest server","streaming setting","more than one million records","source-reported measurement"],"source_locator":{"dossier_section":"PIR-PAPER-2022-SPIRAL § Atomic claims","primary_source":"Abstract; SpiralStreamPack evaluation summary","primary_source_url":"https://eprint.iacr.org/2022/368","status":"primary_source_checked"},"statement":"In the paper's streaming setting with more than one million records, SpiralStreamPack reports 1.9 GB/s server throughput and response rate 0.81, compared with 200 MB/s and rate 0.24 for previous protocols.","statement_status":"source_normalized_statement","status":"published","title":"SpiralStreamPack high-rate throughput","work_id":"PIR-PAPER-2022-SPIRAL"},"primaryUrl":"https://eprint.iacr.org/2022/368","sections":[{"content":"SpiralStream throughput","heading":"Overview"},{"content":"spiralstream-high-rate-throughput is the atomic contribution identifier normalized from PIR-PAPER-2022-SPIRAL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Spiral: Fast, High-Rate Single-Server PIR via FHE Composition","summary":"In the paper's streaming setting with more than one million records, SpiralStreamPack reports 1.9 GB/s server throughput and response rate 0.81, compared with 200 MB/s and rate 0.24 for previous protocols.","title":"SpiralStreamPack high-rate throughput","type":"result","venue":"IEEE Symposium on Security and Privacy 2022","year":2022,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2022-SPIRAL-SPIRALSTREAM-HIGH-RATE-THROUGHPUT"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","keywords":["atomic-result","single-server","preprocessing","depir","ring-lwe","polylog-online"],"metadata":{"claim_slug":"first-unkeyed-depir-from-ring-lwe","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"assumption":["ring-lwe"],"online_cost":["polylogarithmic"],"preprocessing":["public-unkeyed"],"server_model":["single"]},"historical_context":{"narrative":"Before LMW23, the closest public-key DEPIR candidate required a trusted party to preprocess the database and relied on a non-standard code assumption plus heuristic ideal obfuscation; private-hint PIR, meanwhile, did not create reusable public database state. LMW23 changes the setup contract by making preprocessing deterministic and executable by the server itself, giving an unkeyed single-server DEPIR construction from standard Ring-LWE. The capability change is distinct from the paper's online-cost claim: any client can reuse the resulting public state without per-client enrollment. Later work takes this result as the computational single-server baseline when obtaining information-theoretic multi-server DEPIR and when explaining limits of black-box replacements for DEPIR's structured ingredients.","prior_boundary":"Earlier DEPIR candidates used keyed preprocessing generated by a trusted party and relied on a non-standard code assumption plus heuristic ideal obfuscation, while client-preprocessing PIR kept state private and client-specific.","significance_at_publication":"Establishes the first standard-assumption single-server unkeyed DEPIR boundary later used as the baseline for information-theoretic multi-server DEPIR and for black-box limitation results.","technical_delta":"Replaces keyed setup with deterministic, client-independent server preprocessing and proves the stronger unkeyed notion from the standard Ring-LWE assumption."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","keywords":["single-server","preprocessing","depir","ring-lwe","polylog-online"],"limitations":["near-linear preprocessing is not eliminated","result is asymptotic rather than an end-to-end practical implementation"],"paper_id":"PIR-PAPER-2023-LMW-DEPIR","qualifiers":["single server","deterministic public preprocessing","unbounded queries","Ring-LWE"],"source_locator":{"dossier_section":"PIR-PAPER-2023-LMW-DEPIR § Atomic claims","primary_source":"Abstract and Introduction","primary_source_url":"https://eprint.iacr.org/2022/1703","status":"primary_source_checked"},"statement":"Under Ring-LWE, deterministic public server preprocessing of near-linear size and time supports single-server PIR queries with polylogarithmic online server time and communication.","statement_status":"source_normalized_statement","status":"published","title":"Unkeyed single-server DEPIR from Ring-LWE","work_id":"PIR-PAPER-2023-LMW-DEPIR"},"primaryUrl":"https://eprint.iacr.org/2022/1703","sections":[{"content":"Unkeyed DEPIR","heading":"Overview"},{"content":"first-unkeyed-depir-from-ring-lwe is the atomic contribution identifier normalized from PIR-PAPER-2023-LMW-DEPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Doubly Efficient Private Information Retrieval and Fully Homomorphic RAM Computation from Ring LWE","summary":"Under Ring-LWE, deterministic public server preprocessing of near-linear size and time supports single-server PIR queries with polylogarithmic online server time and communication.","title":"Unkeyed single-server DEPIR from Ring-LWE","type":"result","venue":"STOC 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2023-LMW-DEPIR-POLYLOG-ONLINE-TIME-AND-COMMUNICATION","keywords":["atomic-result","single-server","preprocessing","depir","ring-lwe","polylog-online"],"metadata":{"claim_slug":"polylog-online-time-and-communication","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"communication":["polylogarithmic"],"online_server_time":["polylogarithmic"],"preprocessing":["public-unkeyed"],"updates":["sublinear"]},"historical_context":{"narrative":"DEPIR sought to make both communication and online server work small after a reusable preprocessing phase, but the prior public-key candidate was keyed and lacked a standard-assumption unkeyed construction. LMW23 preprocesses an N-size database in O(N^(1+epsilon)) time and space and then answers each query with polylog(N) server time and communication, with O(N^epsilon) update time. The technical step is to express PIR server work as multivariate-polynomial evaluation and apply fast preprocessing for later evaluations. This atomic contribution records the cost separation rather than the unkeyed capability: it shows how the expensive near-linear setup is traded for polylogarithmic online service, and it remains an asymptotic result rather than a practical benchmark claim.","prior_boundary":"The earlier public-key DEPIR candidate did not give a standard-assumption unkeyed construction, and ordinary PIR still required online work linear in the database unless preprocessing costs or trust changed.","significance_at_publication":"Demonstrates the doubly efficient cost separation for unkeyed public preprocessing, making explicit that very small online cost is purchased with O(N^(1+epsilon)) preprocessing time and space.","technical_delta":"Uses fast multivariate-polynomial evaluation after near-linear deterministic preprocessing to obtain polylogarithmic per-query server time and communication, together with sublinear updates."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-LMW-DEPIR-POLYLOG-ONLINE-TIME-AND-COMMUNICATION","keywords":["single-server","preprocessing","depir","ring-lwe","polylog-online"],"limitations":["O(N^(1+epsilon)) preprocessing time and space","asymptotic result","no end-to-end implementation claim"],"paper_id":"PIR-PAPER-2023-LMW-DEPIR","qualifiers":["single server","deterministic public preprocessing","any constant epsilon greater than zero","Ring-LWE"],"source_locator":{"dossier_section":"PIR-PAPER-2023-LMW-DEPIR § Atomic claims","primary_source":"Abstract; construction overview","primary_source_url":"https://eprint.iacr.org/2022/1703","status":"primary_source_checked"},"statement":"For any constant epsilon > 0, LMW23 preprocesses an N-size database in O(N^(1+epsilon)) time and space so each unkeyed DEPIR query has polylog(N) server time and communication, with O(N^epsilon) update time.","statement_status":"source_normalized_statement","status":"published","title":"Polylogarithmic online time and communication for unkeyed DEPIR","work_id":"PIR-PAPER-2023-LMW-DEPIR"},"primaryUrl":"https://eprint.iacr.org/2022/1703","sections":[{"content":"Polylog online cost","heading":"Overview"},{"content":"polylog-online-time-and-communication is the atomic contribution identifier normalized from PIR-PAPER-2023-LMW-DEPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Doubly Efficient Private Information Retrieval and Fully Homomorphic RAM Computation from Ring LWE","summary":"For any constant epsilon > 0, LMW23 preprocesses an N-size database in O(N^(1+epsilon)) time and space so each unkeyed DEPIR query has polylog(N) server time and communication, with O(N^epsilon) update time.","title":"Polylogarithmic online time and communication for unkeyed DEPIR","type":"result","venue":"STOC 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-LMW-DEPIR-POLYLOG-ONLINE-TIME-AND-COMMUNICATION"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2023-LP-NEAR-OPTIMAL-ADAPTABLE-PSEUDORANDOM-SETS","keywords":["atomic-result","adaptable-prs","mechanism","set-update"],"metadata":{"claim_slug":"adaptable-pseudorandom-sets","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"mechanism":["adaptable_pseudorandom_set"],"operations":["add","remove"]},"historical_context":{"narrative":"The earlier preprocessing-PIR line used puncturable pseudorandom-set machinery, but LP23's independent single-server route needed a succinct set representation that could be adjusted as the refresh state changed. Adaptable pseudorandom sets provide a short key for a represented set and support a prespecified number of adaptive additions or removals, up to logarithmic in the set size, while protecting the intermediate keys under the paper's security definitions. This is the mechanism card, not the near-optimal PIR theorem: the delta is the controlled update interface used inside that construction. At publication it also made the independent route technically legible, because LP23 reaches the same broad cost frontier as ZLTS23 through adaptable sets rather than ZLTS23's privately programmable pseudorandom-set mechanism.","prior_boundary":"Existing puncturable-set machinery supported the earlier two-server refresh program, but the independent LP23 single-server route needed a succinct pseudorandom set representation that could absorb small changes.","significance_at_publication":"Supplies the mechanism behind LP23's independent near-optimal construction and distinguishes that route from ZLTS23's privately programmable pseudorandom sets.","technical_delta":"Defines and constructs adaptable pseudorandom sets whose succinct key supports a prespecified number of adaptive additions or removals, up to logarithmic in the set size, while preserving the paper's intermediate-key security properties."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-LP-NEAR-OPTIMAL-ADAPTABLE-PSEUDORANDOM-SETS","keywords":["adaptable-prs","mechanism","set-update"],"limitations":["security definition and update interface are paper-specific"],"paper_id":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","qualifiers":["central mechanism in the paper's PIR construction"],"source_locator":{"dossier_section":"PIR-PAPER-2023-LP-NEAR-OPTIMAL § Atomic claims","primary_source":"Abstract; adaptable-PRS definitions and construction","primary_source_url":"https://eprint.iacr.org/2022/830.pdf","status":"section_checked"},"statement":"Adaptable pseudorandom sets give a succinct key whose represented set supports a prespecified logarithmic number of additions or removals while retaining the paper's security guarantees for intermediate keys.","statement_status":"source_normalized_statement","status":"published","title":"Adaptable pseudorandom sets","work_id":"PIR-PAPER-2023-LP-NEAR-OPTIMAL"},"primaryUrl":"https://eprint.iacr.org/2022/830","sections":[{"content":"Adaptable pseudorandom sets The mechanism distinguishes LP23 from the independently developed ZLTS23 route.","heading":"Overview"}],"status":"published","subtitle":"Near-Optimal Private Information Retrieval with Preprocessing","summary":"Adaptable pseudorandom sets give a succinct key whose represented set supports a prespecified logarithmic number of additions or removals while retaining the paper's security guarantees for intermediate keys.","title":"Adaptable pseudorandom sets","type":"result","venue":"TCC 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-LP-NEAR-OPTIMAL-ADAPTABLE-PSEUDORANDOM-SETS"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2023-LP-NEAR-OPTIMAL-SINGLE-SERVER-PREPROCESSING-FRONTIER","keywords":["atomic-result","near-optimal","independent-result","client-preprocessing"],"metadata":{"claim_slug":"single-server-preprocessing-frontier","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"communication":["polylogarithmic"],"preprocessing":["client_specific"],"server_model":["single"]},"historical_context":{"narrative":"CHK22 had established adaptive single-server preprocessing PIR with near-square-root amortized server time and storage, but its amortized bandwidth remained near square root. LP23 independently reduces that bandwidth to polylogarithmic while retaining near-square-root amortized server time and client space, with no additional server storage. Its construction uses adaptable pseudorandom sets, so the technical route is not a duplicate of ZLTS23's privately programmable-set compiler even though the two papers reach the same broad asymptotic point. The result mattered because it closed the remaining single-server bandwidth gap independently of ZLTS23; it is an asymptotic construction result, not a claim of concrete practicality.","prior_boundary":"CHK22 established adaptive single-server PIR with near-square-root amortized server time and storage, but its amortized bandwidth remained near square root rather than polylogarithmic.","significance_at_publication":"Closes the remaining bandwidth gap at the same frontier independently reached by ZLTS23 while preserving a technically distinct mechanism and attribution.","technical_delta":"Independently obtains single-server client-preprocessing PIR with near-square-root amortized server time and client space, polylogarithmic amortized bandwidth, and no additional server storage, using adaptable pseudorandom sets."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-LP-NEAR-OPTIMAL-SINGLE-SERVER-PREPROCESSING-FRONTIER","keywords":["near-optimal","independent-result","client-preprocessing"],"limitations":["heavy cryptographic preprocessing","no practical implementation claim"],"paper_id":"PIR-PAPER-2023-LP-NEAR-OPTIMAL","qualifiers":["single-server","client-specific preprocessing","amortized costs"],"source_locator":{"dossier_section":"PIR-PAPER-2023-LP-NEAR-OPTIMAL § Atomic claims","primary_source":"Abstract; main construction theorem; PDF pp. 1–4","primary_source_url":"https://eprint.iacr.org/2022/830.pdf","status":"theorem_checked"},"statement":"An independent single-server client-preprocessing construction achieves near-square-root amortized server time and polylogarithmic amortized bandwidth.","statement_status":"source_normalized_statement","status":"published","title":"Independent near-optimal single-server preprocessing PIR","work_id":"PIR-PAPER-2023-LP-NEAR-OPTIMAL"},"primaryUrl":"https://eprint.iacr.org/2022/830","sections":[{"content":"Independent near-optimal single-server preprocessing PIR This record preserves the independent result even though ZLTS23 represents the shared transition in the default reading path.","heading":"Overview"}],"status":"published","subtitle":"Near-Optimal Private Information Retrieval with Preprocessing","summary":"An independent single-server client-preprocessing construction achieves near-square-root amortized server time and polylogarithmic amortized bandwidth.","title":"Independent near-optimal single-server preprocessing PIR","type":"result","venue":"TCC 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-LP-NEAR-OPTIMAL-SINGLE-SERVER-PREPROCESSING-FRONTIER"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2023-SIMPLEPIR-DOUBLEPIR-COMPRESSED-HINT","keywords":["atomic-result","single-server","lwe","client-hint","memory-bandwidth","certificate-transparency"],"metadata":{"claim_slug":"doublepir-compressed-hint","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"optimization":["client-hint-compression"],"server_model":["single"],"tradeoff":["client-storage","communication","throughput"]},"historical_context":{"narrative":"SimplePIR showed that a linear server scan could approach memory bandwidth, but its reported 1 GB configuration required a 121 MB reusable client hint. DoublePIR introduces a different operating point in the same system family: it reduces the hint to 16 MB, while the matched source setting reports 345 KB per query and 7.4 GB/s per core rather than SimplePIR's smaller communication and higher throughput. The contribution is therefore hint compression with an explicit three-way trade-off, not an across-the-board speedup. It mattered because it made client storage a first-class practical cost and prevented the headline throughput number from obscuring the state that the client must download and retain.","prior_boundary":"SimplePIR reached near-memory-bandwidth online throughput but used a 121 MB reusable client hint in the paper's reported 1 GB database setting.","significance_at_publication":"Turns client storage, communication, and throughput into an explicit family trade-off instead of presenting SimplePIR's fastest configuration as uniformly preferable.","technical_delta":"DoublePIR reduces that hint to 16 MB in the matched setting, while query communication rises to 345 KB and throughput falls to 7.4 GB/s per core."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-SIMPLEPIR-DOUBLEPIR-COMPRESSED-HINT","keywords":["single-server","lwe","client-hint","memory-bandwidth","certificate-transparency"],"limitations":["measurements are not hardware-normalized","hint refresh and update cost remain part of the system profile"],"paper_id":"PIR-PAPER-2023-SIMPLEPIR","qualifiers":["single semi-honest server","source-reported 1 GB setting","reusable client hint"],"source_locator":{"dossier_section":"PIR-PAPER-2023-SIMPLEPIR § Atomic claims","primary_source":"Abstract and Table 10","primary_source_url":"https://www.usenix.org/conference/usenixsecurity23/presentation/henzinger","status":"primary_source_checked"},"statement":"In the paper's 1 GB setting, DoublePIR reduces SimplePIR's reusable client hint from 121 MB to 16 MB while reporting 345 KB per query and 7.4 GB/s per core.","statement_status":"source_normalized_statement","status":"published","title":"Smaller reusable client hint in DoublePIR","work_id":"PIR-PAPER-2023-SIMPLEPIR"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity23/presentation/henzinger","sections":[{"content":"DoublePIR compressed hint","heading":"Overview"},{"content":"doublepir-compressed-hint is the atomic contribution identifier normalized from PIR-PAPER-2023-SIMPLEPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"One Server for the Price of Two: Simple and Fast Single-Server Private Information Retrieval","summary":"In the paper's 1 GB setting, DoublePIR reduces SimplePIR's reusable client hint from 121 MB to 16 MB while reporting 345 KB per query and 7.4 GB/s per core.","title":"Smaller reusable client hint in DoublePIR","type":"result","venue":"USENIX Security 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-SIMPLEPIR-DOUBLEPIR-COMPRESSED-HINT"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","keywords":["atomic-result","single-server","lwe","client-hint","memory-bandwidth","certificate-transparency"],"metadata":{"claim_slug":"simplepir-memory-bandwidth-lwe-matvec","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["lwe-matrix-vector"],"preprocessing":["reusable-client-hint"],"server_model":["single"],"track":["practice"]},"historical_context":{"narrative":"Before SimplePIR, the fastest known single-server PIR systems had not approached either host memory bandwidth or the throughput of the fastest two-server systems. SimplePIR reorganizes the online response as an LWE matrix-vector product backed by a reusable client hint, reporting roughly 10 GB/s per core on a 1 GB database in the paper's setting. The architectural choice is explicit: server work remains linear in the database, but each byte requires less than one 32-bit multiplication and addition. This became the high-throughput hint branch later changed by YPIR's silent preprocessing, instantiated by Distributional PIR, and revisited by ZipPIR to reduce client hint and update costs.","prior_boundary":"Before SimplePIR, the fastest known single-server PIR systems had not approached either the host's memory bandwidth or the throughput of the fastest two-server systems.","significance_at_publication":"Reframes practical PIR around cheap linear work near the memory-bandwidth limit and creates the high-throughput hint branch later modified by YPIR, Distributional PIR, and ZipPIR.","technical_delta":"Restructures the online response as a simple LWE matrix-vector product backed by a reusable client hint, reporting roughly 10 GB/s per core on a 1 GB database."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","keywords":["single-server","lwe","client-hint","memory-bandwidth","certificate-transparency"],"limitations":["online work remains linear in the database","121 MB hint and update/refresh costs remain part of the profile"],"paper_id":"PIR-PAPER-2023-SIMPLEPIR","qualifiers":["single semi-honest server","reusable client hint","source-reported 1 GB setting"],"source_locator":{"dossier_section":"PIR-PAPER-2023-SIMPLEPIR § Atomic claims","primary_source":"Abstract and Table 10","primary_source_url":"https://www.usenix.org/conference/usenixsecurity23/presentation/henzinger","status":"primary_source_checked"},"statement":"SimplePIR restructures single-server LWE PIR around a matrix-vector product and reusable client hint, reporting roughly 10 GB/s per core on a 1 GB database in the paper's setting.","statement_status":"source_normalized_statement","status":"published","title":"Memory-bandwidth-oriented LWE matrix-vector PIR","work_id":"PIR-PAPER-2023-SIMPLEPIR"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity23/presentation/henzinger","sections":[{"content":"Memory-bound LWE matvec","heading":"Overview"},{"content":"simplepir-memory-bandwidth-lwe-matvec is the atomic contribution identifier normalized from PIR-PAPER-2023-SIMPLEPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"One Server for the Price of Two: Simple and Fast Single-Server Private Information Retrieval","summary":"SimplePIR restructures single-server LWE PIR around a matrix-vector product and reusable client hint, reporting roughly 10 GB/s per core on a 1 GB database in the paper's setting.","title":"Memory-bandwidth-oriented LWE matrix-vector PIR","type":"result","venue":"USENIX Security 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2023-TREEPIR-DDH-BASED-SUBLINEAR-TIME-POLYLOG-BANDWIDTH-PIR","keywords":["atomic-result","treepir","ddh","weak-assumption"],"metadata":{"claim_slug":"ddh-based-sublinear-time-polylog-bandwidth-pir","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"assumption":["ddh"],"communication":["polylogarithmic"],"preprocessing":["client_specific"],"server_model":["two"]},"historical_context":{"narrative":"SACM21 had reached a strong two-server client-preprocessing point with sublinear amortized server time and polylogarithmic bandwidth, but it relied on heavier privately puncturable-set machinery. TreePIR realizes the same cost program from DDH, using a purpose-built weak privately puncturable PRF in a two-phase construction. Its novelty is therefore primarily an assumption and mechanism change, not the discovery of a strictly better cost frontier. The result mattered because it showed that the SACM-style efficiency profile could rest on a weaker and more familiar assumption, but it still requires two non-colluding servers and client-specific preprocessing.","prior_boundary":"SACM21 reached the two-server sublinear-time, polylogarithmic-bandwidth point using heavier privately puncturable-set machinery.","significance_at_publication":"Shows that the SACM-style frontier does not require the earlier puncturable-set assumption stack, while retaining the two non-colluding servers and client preprocessing.","technical_delta":"Realizes that cost program from the weaker DDH assumption using a weak privately puncturable PRF and a two-phase composition."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-TREEPIR-DDH-BASED-SUBLINEAR-TIME-POLYLOG-BANDWIDTH-PIR","keywords":["treepir","ddh","weak-assumption"],"limitations":["does not remove the replicated-server assumption"],"paper_id":"PIR-PAPER-2023-TREEPIR","qualifiers":["two non-colluding servers","client preprocessing"],"source_locator":{"dossier_section":"PIR-PAPER-2023-TREEPIR § Atomic claims","primary_source":"Abstract; Introduction and theorem summary","primary_source_url":"https://eprint.iacr.org/2023/204.pdf","status":"section_checked"},"statement":"TreePIR obtains two-server client-preprocessing PIR with sublinear amortized server time and polylogarithmic bandwidth under DDH.","statement_status":"source_normalized_statement","status":"published","title":"DDH-based sublinear-time, polylog-bandwidth PIR","work_id":"PIR-PAPER-2023-TREEPIR"},"primaryUrl":"https://eprint.iacr.org/2023/204","sections":[{"content":"TreePIR cost point from DDH The node is compared to SACM as an assumption/mechanism transition.","heading":"Overview"}],"status":"published","subtitle":"TreePIR: Sublinear-Time and Polylog-Bandwidth Private Information Retrieval from DDH","summary":"TreePIR obtains two-server client-preprocessing PIR with sublinear amortized server time and polylogarithmic bandwidth under DDH.","title":"DDH-based sublinear-time, polylog-bandwidth PIR","type":"result","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-TREEPIR-DDH-BASED-SUBLINEAR-TIME-POLYLOG-BANDWIDTH-PIR"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2023-TREEPIR-WEAK-PRIVATELY-PUNCTURABLE-PRF","keywords":["atomic-result","mechanism","puncturable-prf","ddh"],"metadata":{"claim_slug":"weak-privately-puncturable-prf","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"assumption":["ddh"],"mechanism":["weak-privately-puncturable-prf"]},"historical_context":{"narrative":"SACM's two-server construction used a privately puncturable-set abstraction with more structure than TreePIR's route required. TreePIR isolates a weak privately puncturable PRF interface tailored to its two-phase composition and realizes that interface from DDH. This card records the reusable mechanism, not the full PIR theorem: the technical change is the weaker private puncturing primitive and the assumption under which it is obtained. At publication, the mechanism made TreePIR's relationship to SACM precise by explaining how the same broad sublinear-time, polylogarithmic-bandwidth target could be reached without carrying over SACM's heavier puncturable-set machinery.","prior_boundary":"SACM's privately puncturable-set abstraction provided more functionality than the TreePIR construction needed and came with a heavier assumption route.","significance_at_publication":"Isolates the mechanism responsible for TreePIR's assumption improvement and explains how its construction differs from SACM despite targeting the same cost point.","technical_delta":"Defines a weaker private-puncturing interface tailored to TreePIR and realizes it from DDH for use in the paper's two-phase PIR composition."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-TREEPIR-WEAK-PRIVATELY-PUNCTURABLE-PRF","keywords":["mechanism","puncturable-prf","ddh"],"limitations":["security and usefulness are tied to the paper's interface"],"paper_id":"PIR-PAPER-2023-TREEPIR","qualifiers":["purpose-built weak puncturing interface"],"source_locator":{"dossier_section":"PIR-PAPER-2023-TREEPIR § Atomic claims","primary_source":"Abstract; construction overview","primary_source_url":"https://eprint.iacr.org/2023/204.pdf","status":"section_checked"},"statement":"TreePIR introduces weak privately puncturable pseudorandom functions to realize the targeted two-server PIR costs from DDH.","statement_status":"source_normalized_statement","status":"published","title":"Weak privately puncturable PRF","work_id":"PIR-PAPER-2023-TREEPIR"},"primaryUrl":"https://eprint.iacr.org/2023/204","sections":[{"content":"Weak privately puncturable PRF The mechanism is retained even though the paper's main construction is the mapped node.","heading":"Overview"}],"status":"published","subtitle":"TreePIR: Sublinear-Time and Polylog-Bandwidth Private Information Retrieval from DDH","summary":"TreePIR introduces weak privately puncturable pseudorandom functions to realize the targeted two-server PIR costs from DDH.","title":"Weak privately puncturable PRF","type":"result","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-TREEPIR-WEAK-PRIVATELY-PUNCTURABLE-PRF"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2023-YEO-OMV-BARRIER-FOR-GENERAL-PIR-LOWER-BOUNDS","keywords":["atomic-result","omv","barrier","lower-bound-techniques"],"metadata":{"claim_slug":"omv-barrier-for-general-pir-lower-bounds","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"conjecture":["online_matrix_vector"],"result":["conditional_barrier"]},"historical_context":{"narrative":"Tight storage-time lower bounds could be proved in the standard replication model, but more general computational PIR models do not expose the same structure to existing proof techniques. Yeo shows that specified stronger lower bounds for two-server preprocessing PIR in that broader setting would imply the online matrix-vector conjecture. The contribution is thus a barrier for lower-bound methodology, not a claim that efficient PIR itself is impossible. It mattered because it explains both the scope of the paper's tight replication-model theorem and why closing analogous gaps in a more general model likely requires either a breakthrough on OMV or a substantially different route.","prior_boundary":"Tight hint-probe lower bounds were available in the standard replication model, but more general computational models could evade the structure used by those proofs.","significance_at_publication":"Explains why the paper's tight replication-model theorem should not be casually generalized and identifies a conditional barrier rather than an unconditional PIR impossibility.","technical_delta":"Shows that obtaining specified stronger lower bounds for two-server preprocessing PIR in the more general model would imply the online matrix-vector conjecture."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-YEO-OMV-BARRIER-FOR-GENERAL-PIR-LOWER-BOUNDS","keywords":["omv","barrier","lower-bound-techniques"],"limitations":["not an unconditional PIR impossibility"],"paper_id":"PIR-PAPER-2023-YEO","qualifiers":["conditional barrier via OMV"],"source_locator":{"dossier_section":"PIR-PAPER-2023-YEO § Atomic claims","primary_source":"Section 5; Theorem 9; PDF pp. 25–28","primary_source_url":"https://eprint.iacr.org/2022/828.pdf","status":"theorem_checked"},"statement":"Stronger lower bounds for two-server preprocessing PIR in more general computational models would imply the online matrix-vector conjecture, exposing a barrier to current lower-bound techniques.","statement_status":"source_normalized_statement","status":"published","title":"OMV barrier for general PIR lower bounds","work_id":"PIR-PAPER-2023-YEO"},"primaryUrl":"https://eprint.iacr.org/2022/828","sections":[{"content":"OMV barrier for general PIR lower bounds The claim is kept explicitly conditional.","heading":"Overview"}],"status":"published","subtitle":"Lower Bounds for (Batch) PIR with Private Preprocessing","summary":"Stronger lower bounds for two-server preprocessing PIR in more general computational models would imply the online matrix-vector conjecture, exposing a barrier to current lower-bound techniques.","title":"OMV barrier for general PIR lower bounds","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-YEO-OMV-BARRIER-FOR-GENERAL-PIR-LOWER-BOUNDS"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2023-YEO-TIGHT-PRIVATE-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","keywords":["atomic-result","tight-lower-bound","private-preprocessing","probes"],"metadata":{"claim_slug":"tight-private-preprocessing-storage-time-lower-bound","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"coordinates":["private_hint_size","online_probes"],"model":["replication"],"result":["lower_bound"]},"historical_context":{"narrative":"CK20 gave an apparently optimal private-preprocessing trade-off, but the single-query lower bound still had a multiplicative logarithmic gap and the corresponding batch costs were not tightly characterized. Yeo closes that gap in the standard replication model, proving a hint-size times online-probe bound of tr = Omega(n) for one query and tr = Omega(nk) for the paper's scoped batch setting. The theorem mattered because it supplied the matching lower boundary needed to describe nearby construction points as near-optimal rather than merely sublinear. Its interpretation remains precise: the proof constrains replicated-database probe models and does not automatically rule out schemes built around arbitrary database encodings.","prior_boundary":"CK20 supplied an optimal-looking private-hint trade-off, but its single-query lower bound retained a multiplicative logarithmic gap and batch retrieval lacked a matching characterization.","significance_at_publication":"Provides the matching boundary needed to call construction points near-optimal while making explicit that the conclusion is tied to replication rather than arbitrary database encodings.","technical_delta":"Proves a tight hint-size times online-probes lower bound in the replication model, including tr = Omega(n) for one query and the scoped tr = Omega(nk) batch bound."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-YEO-TIGHT-PRIVATE-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","keywords":["tight-lower-bound","private-preprocessing","probes"],"limitations":["does not cover arbitrary database encodings"],"paper_id":"PIR-PAPER-2023-YEO","qualifiers":["constant number of servers","bounded error","one-server corruption privacy","replication model"],"source_locator":{"dossier_section":"PIR-PAPER-2023-YEO § Atomic claims","primary_source":"Section 1.1; Theorems 1–2 and 5–6; PDF pp. 3–5, 11–13","primary_source_url":"https://eprint.iacr.org/2022/828.pdf","status":"theorem_checked"},"statement":"In the standard replication model, private-preprocessing PIR obeys a tight hint-size times online-probes lower bound, including tr = Omega(n) for one query and tr = Omega(nk) for scoped batch PIR.","statement_status":"source_normalized_statement","status":"published","title":"Tight private-preprocessing storage–time bound","work_id":"PIR-PAPER-2023-YEO"},"primaryUrl":"https://eprint.iacr.org/2022/828","sections":[{"content":"Tight private-preprocessing storage–time bound This sharpens the earlier polylogarithmically loose bound and supplies the matching barrier anchor.","heading":"Overview"}],"status":"published","subtitle":"Lower Bounds for (Batch) PIR with Private Preprocessing","summary":"In the standard replication model, private-preprocessing PIR obeys a tight hint-size times online-probes lower bound, including tr = Omega(n) for one query and tr = Omega(nk) for scoped batch PIR.","title":"Tight private-preprocessing storage–time bound","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-YEO-TIGHT-PRIVATE-PREPROCESSING-STORAGE-TIME-LOWER-BOUND"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR","keywords":["atomic-result","optimal","single-server","client-preprocessing"],"metadata":{"claim_slug":"optimal-single-server-preprocessing-pir","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"assumption":["lwe"],"communication":["polylogarithmic"],"preprocessing":["client_specific"],"server_model":["single"]},"historical_context":{"narrative":"SACM21 obtained near-square-root work with polylogarithmic bandwidth using two servers, whereas CHK22 achieved the adaptive single-server setting but still paid near-square-root amortized bandwidth. ZLTS23 combines FHE with privately programmable pseudorandom sets to homomorphically compile the two-server refresh structure into one server, retaining near-square-root amortized server and client computation and near-square-root client storage while reducing bandwidth to polylogarithmic. This closed the principal efficiency gap for unbounded adaptive single-server client-preprocessing PIR under LWE. LP23 independently reached the same broad cost point through adaptable pseudorandom sets, so the frontier is shared even though the mechanisms and attribution remain distinct.","prior_boundary":"SACM21 reached near-square-root work and polylogarithmic bandwidth with two servers, while CHK22 removed the second server but retained near-square-root amortized bandwidth.","significance_at_publication":"Closes the single-server bandwidth gap for unbounded adaptive queries and reaches, independently alongside LP23, the near-optimal client-preprocessing frontier.","technical_delta":"Uses FHE and privately programmable pseudorandom sets to compile the two-server refresh structure into one server, attaining polylogarithmic bandwidth with near-square-root amortized computation and storage."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR","keywords":["optimal","single-server","client-preprocessing"],"limitations":["FHE and programmable-PRF machinery","asymptotic rather than practical result"],"paper_id":"PIR-PAPER-2023-ZLTS","qualifiers":["single round trip","unbounded queries","client-specific preprocessing"],"source_locator":{"dossier_section":"PIR-PAPER-2023-ZLTS § Atomic claims","primary_source":"Abstract; Theorem 1.1; PDF pp. 1–3","primary_source_url":"https://eprint.iacr.org/2022/609.pdf","status":"theorem_checked"},"statement":"Under LWE, single-server client-preprocessing PIR reaches polylogarithmic bandwidth with near-square-root amortized server/client computation and client storage for unbounded adaptive queries.","statement_status":"source_normalized_statement","status":"published","title":"Near-optimal single-server preprocessing PIR","work_id":"PIR-PAPER-2023-ZLTS"},"primaryUrl":"https://eprint.iacr.org/2022/609","sections":[{"content":"Near-optimal single-server preprocessing PIR ZLTS23 is the default representative of a cost point independently attained by LP23.","heading":"Overview"}],"status":"published","subtitle":"Optimal Single-Server Private Information Retrieval","summary":"Under LWE, single-server client-preprocessing PIR reaches polylogarithmic bandwidth with near-square-root amortized server/client computation and client storage for unbounded adaptive queries.","title":"Near-optimal single-server preprocessing PIR","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2023-ZLTS-PRIVATELY-PROGRAMMABLE-PSEUDORANDOM-SETS","keywords":["atomic-result","programmable-prf","prset","mechanism"],"metadata":{"claim_slug":"privately-programmable-pseudorandom-sets","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"mechanism":["privately_programmable_pseudorandom_set"],"role":["batched_refresh"]},"historical_context":{"narrative":"CHK22 had shown how homomorphic evaluation could remove a second server, but efficiently realizing repeated refresh operations remained the obstacle to a polylogarithmic-bandwidth single-server construction. ZLTS23 develops privately programmable pseudorandom sets, built from programmable PRFs, so the relevant refresh work can be batched and carried out homomorphically. This is a mechanism contribution rather than a complete PIR protocol: its role is to make the earlier compilation strategy efficient enough for the paper's near-optimal theorem. It also separates ZLTS23's technical route from the independently developed LP23 construction, which reaches a similar cost point using adaptable pseudorandom sets instead.","prior_boundary":"CHK22 showed how homomorphic evaluation could remove a second server, but repeated refresh and hint-generation work remained the central cost obstacle to reaching polylogarithmic bandwidth.","significance_at_publication":"Supplies the mechanism that turns the earlier compilation idea into ZLTS23's near-optimal bandwidth result and distinguishes it from LP23's adaptable-set route.","technical_delta":"Builds privately programmable pseudorandom sets from programmable PRFs so refresh operations can be batched and homomorphically realized inside the single-server compiler."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2023-ZLTS-PRIVATELY-PROGRAMMABLE-PSEUDORANDOM-SETS","keywords":["programmable-prf","prset","mechanism"],"limitations":["not a complete PIR protocol by itself"],"paper_id":"PIR-PAPER-2023-ZLTS","qualifiers":["used with FHE in the final single-server construction"],"source_locator":{"dossier_section":"PIR-PAPER-2023-ZLTS § Atomic claims","primary_source":"Sections 2.1–2.2 and 4; PDF pp. 5–10, 15–18","primary_source_url":"https://eprint.iacr.org/2022/609.pdf","status":"section_checked"},"statement":"The paper develops privately programmable pseudorandom sets, built from programmable PRFs, to batch and homomorphically realize the refresh operations of the two-server starting point.","statement_status":"source_normalized_statement","status":"published","title":"Privately programmable pseudorandom sets","work_id":"PIR-PAPER-2023-ZLTS"},"primaryUrl":"https://eprint.iacr.org/2022/609","sections":[{"content":"Privately programmable pseudorandom sets The mechanism is shown separately from the cost-frontier theorem.","heading":"Overview"}],"status":"published","subtitle":"Optimal Single-Server Private Information Retrieval","summary":"The paper develops privately programmable pseudorandom sets, built from programmable PRFs, to batch and homomorphically realize the refresh operations of the two-server starting point.","title":"Privately programmable pseudorandom sets","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2023-ZLTS-PRIVATELY-PROGRAMMABLE-PSEUDORANDOM-SETS"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2024-PIANO-PRACTICAL-SINGLE-SERVER-SUBLINEAR-TIME-PIR","keywords":["atomic-result","implementation","practice-transition","sublinear-time"],"metadata":{"claim_slug":"practical-single-server-sublinear-time-pir","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"artifact":["open_source"],"server_work":["sublinear_online"],"track":["practice"]},"historical_context":{"narrative":"Before Piano, concretely efficient single-server PIR systems such as SimplePIR still scanned the full database online; known sublinear-time alternatives depended on heavyweight machinery and had not yielded a comparable implementation. Piano's open-source Go artifact instantiates its PRF-only client-preprocessing construction, and the paper reports a 73 ms response on a 100 GB database with 60 ms network latency, versus an extrapolated 11 seconds or more for SimplePIR. This made sublinear online work a concrete systems result rather than only an asymptotic possibility. The point remains scoped: the client streams the database during setup, stores a sublinear hint, and amortizes preprocessing across many queries.","prior_boundary":"Practical single-server PIR systems such as SimplePIR still scanned the full database online, while known sublinear-time constructions relied on heavyweight cryptographic machinery and had not produced a comparable implementation point.","significance_at_publication":"Establishes a concrete systems point for sublinear single-server PIR, with the remaining database-streaming setup, client state, and square-root communication costs stated explicitly.","technical_delta":"Implements Piano's PRF-only client-preprocessing construction in Go and reports sublinear online work on databases up to 100 GB, while keeping the construction and system result distinct."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2024-PIANO-PRACTICAL-SINGLE-SERVER-SUBLINEAR-TIME-PIR","keywords":["implementation","practice-transition","sublinear-time"],"limitations":["reported not independently reproduced","preprocessing streams the database"],"paper_id":"PIR-PAPER-2024-PIANO","qualifiers":["Go implementation","AES-NI PRFs","source-reported AWS evaluation"],"source_locator":{"dossier_section":"PIR-PAPER-2024-PIANO § Atomic claims","primary_source":"Sections 4.1–4.4; Tables 1–2; PDF pp. 9–12","primary_source_url":"https://eprint.iacr.org/2023/452.pdf","status":"section_checked"},"statement":"The paper's open-source Go implementation reports concretely practical sublinear online server work for single-server client-preprocessing PIR on databases as large as 100 GB.","statement_status":"source_normalized_statement","status":"published","title":"Practical single-server sublinear-time PIR","work_id":"PIR-PAPER-2024-PIANO"},"primaryUrl":"https://eprint.iacr.org/2023/452","sections":[{"content":"Practical single-server sublinear-time PIR This is the paper's primary map node because it changed what was concretely implementable.","heading":"Overview"}],"status":"published","subtitle":"Piano: Extremely Simple, Single-Server PIR with Sublinear Server Computation","summary":"The paper's open-source Go implementation reports concretely practical sublinear online server work for single-server client-preprocessing PIR on databases as large as 100 GB.","title":"Practical single-server sublinear-time PIR","type":"result","venue":"IEEE Symposium on Security and Privacy 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2024-PIANO-PRACTICAL-SINGLE-SERVER-SUBLINEAR-TIME-PIR"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2024-PIANO-PRF-ONLY-OPTIMAL-CLIENT-PREPROCESSING","keywords":["atomic-result","piano","prf","optimal-tradeoff"],"metadata":{"claim_slug":"prf-only-optimal-client-preprocessing","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"mechanism":["prf"],"preprocessing":["client_streaming"],"server_model":["single"]},"historical_context":{"narrative":"Adaptive single-server client-preprocessing PIR already achieved sublinear online work, but the strongest communication points relied on homomorphic encryption or other heavyweight primitives, while lighter schemes missed the known storage-time frontier. Piano gives a self-contained construction using only pseudorandom functions and plaintext operations. Its client storage and amortized online server time match the CHK22 product lower bound up to polylogarithmic factors, making the technical advance an optimality result rather than merely a faster implementation. The same paper's Go system shows that this simpler mechanism is implementable. The construction still has roughly square-root online communication and requires the client to stream the database during preprocessing, so it does not subsume the polylogarithmic-communication line.","prior_boundary":"Earlier adaptive single-server client-preprocessing schemes achieved sublinear online work, but the best communication points used homomorphic encryption or other heavyweight primitives, while lighter constructions missed the optimal client-storage times server-time trade-off.","significance_at_publication":"Separates the optimal storage-time shape from heavyweight public-key machinery and supplies the construction instantiated by Piano's practical Go system.","technical_delta":"Gives a self-contained PRF-only construction whose client storage and amortized online server time match the CHK22 product lower bound up to polylogarithmic factors."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2024-PIANO-PRF-ONLY-OPTIMAL-CLIENT-PREPROCESSING","keywords":["piano","prf","optimal-tradeoff"],"limitations":["square-root online communication","client-specific state"],"paper_id":"PIR-PAPER-2024-PIANO","qualifiers":["single-server","client streams database during preprocessing"],"source_locator":{"dossier_section":"PIR-PAPER-2024-PIANO § Atomic claims","primary_source":"Abstract; Section 1.1; Theorem 3.4; PDF pp. 1–3, 8–9","primary_source_url":"https://eprint.iacr.org/2023/452.pdf","status":"theorem_checked"},"statement":"Piano matches the client-storage times server-time lower bound up to polylogarithmic factors using only pseudorandom functions and plaintext operations.","statement_status":"source_normalized_statement","status":"published","title":"PRF-only optimal client preprocessing","work_id":"PIR-PAPER-2024-PIANO"},"primaryUrl":"https://eprint.iacr.org/2023/452","sections":[{"content":"PRF-only optimal client preprocessing This is Piano's construction result, separate from its implementation transition.","heading":"Overview"}],"status":"published","subtitle":"Piano: Extremely Simple, Single-Server PIR with Sublinear Server Computation","summary":"Piano matches the client-storage times server-time lower bound up to polylogarithmic factors using only pseudorandom functions and plaintext operations.","title":"PRF-only optimal client preprocessing","type":"result","venue":"IEEE Symposium on Security and Privacy 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2024-PIANO-PRF-ONLY-OPTIMAL-CLIENT-PREPROCESSING"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2024-SINGLEPASS-CONSTANT-TIME-DATABASE-UPDATES","keywords":["atomic-result","updates","dynamic-database","capability"],"metadata":{"claim_slug":"constant-time-database-updates","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"setting":["dynamic_database"],"update_model":["constant_time_add_edit"]},"historical_context":{"narrative":"Before SinglePass, the strongest dynamic client-preprocessing approach in the Checklist line supported additions and edits with logarithmic amortized update time while also adding a logarithmic factor to query bandwidth. SinglePass updates its preprocessed client hint in worst-case constant time for an edit. Appending records takes amortized constant time because a new permutation is sampled periodically, and the paper explains how to deamortize that work. Ordinary queries do not inherit Checklist's logarithmic bandwidth overhead. This contribution is separate from SinglePass's one-pass enrollment result: it lowers the cost of maintaining a retained hint after database changes, not the initial preprocessing cost. The guarantee remains within the paper's dynamic two-server model, including replicated, non-colluding servers; it is not a constant-time update theorem for arbitrary PIR schemes.","prior_boundary":"Checklist-style dynamic client-preprocessing PIR handled additions and edits with logarithmic amortized update time and an additional logarithmic factor in query bandwidth.","significance_at_publication":"Makes database-change cost a separate capability of the PIR design and improves the viability of retaining client state across updates in the paper's two-server model.","technical_delta":"Defines a worst-case constant-time edit procedure and an amortized constant-time append procedure for SinglePass's client hint; the append work can be deamortized, and ordinary queries avoid Checklist's logarithmic bandwidth overhead."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2024-SINGLEPASS-CONSTANT-TIME-DATABASE-UPDATES","keywords":["updates","dynamic-database","capability"],"limitations":["deletions and full update semantics follow the paper's scoped model"],"paper_id":"PIR-PAPER-2024-SINGLEPASS","qualifiers":["dynamic client-preprocessing PIR"],"source_locator":{"dossier_section":"PIR-PAPER-2024-SINGLEPASS § Atomic claims","primary_source":"Abstract; Section 5; USENIX PDF pp. 5967–5969, 5980–5982","primary_source_url":"https://www.usenix.org/system/files/usenixsecurity24-lazzaretti.pdf","status":"section_checked"},"statement":"SinglePass updates its preprocessed client hint in constant time for edits and amortized constant time for append-only additions, without Checklist's logarithmic query-bandwidth overhead.","statement_status":"source_normalized_statement","status":"published","title":"Constant-time edits and amortized-constant appends","work_id":"PIR-PAPER-2024-SINGLEPASS"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity24/presentation/lazzaretti","sections":[{"content":"Constant-time edits and amortized-constant appends The update contract is a separate capability from faster preprocessing.","heading":"Overview"}],"status":"published","subtitle":"Single Pass Client-Preprocessing Private Information Retrieval","summary":"SinglePass updates its preprocessed client hint in constant time for edits and amortized constant time for append-only additions, without Checklist's logarithmic query-bandwidth overhead.","title":"Constant-time edits and amortized-constant appends","type":"result","venue":"USENIX Security 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2024-SINGLEPASS-CONSTANT-TIME-DATABASE-UPDATES"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING","keywords":["atomic-result","singlepass","preprocessing","optimization"],"metadata":{"claim_slug":"single-pass-client-preprocessing","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"preprocessing":["single_linear_pass"],"server_model":["two_non_colluding"],"track":["practice"]},"historical_context":{"narrative":"Checklist made two-server client-preprocessing PIR fast online, but its setup formed many random subsets and touched the database roughly a security-parameter number of times. That cost was difficult to amortize in short sessions or on changing databases. SinglePass reorganizes the hint around permutations so preprocessing visits every database element exactly once, which is asymptotically optimal, and the paper reports 45–100× setup speedups plus faster queries against Checklist. The advance therefore moves the practical boundary of enrollment rather than changing the privacy model. It still requires two replicated, non-colluding servers and linear client storage; the paper's constant-time update procedures are recorded as a separate atomic contribution.","prior_boundary":"Checklist made two-server client-preprocessing PIR fast online, but its preprocessing touched the database roughly once per security-parameter repetition, making enrollment expensive for short sessions or changing databases.","significance_at_publication":"Makes preprocessing pass count a first-class systems cost and lowers the break-even point for session-based use, while retaining two-server non-collusion and linear client storage.","technical_delta":"Reorganizes the preprocessed state so enrollment touches every database element exactly once, achieving the asymptotically optimal single linear pass while retaining fast multi-query operation."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING","keywords":["singlepass","preprocessing","optimization"],"limitations":["non-collusion","session-based amortization"],"paper_id":"PIR-PAPER-2024-SINGLEPASS","qualifiers":["two-server client preprocessing","source-reported implementation"],"source_locator":{"dossier_section":"PIR-PAPER-2024-SINGLEPASS § Atomic claims","primary_source":"Abstract; Sections 1 and 4; USENIX PDF pp. 5967–5970, 5977–5980","primary_source_url":"https://www.usenix.org/system/files/usenixsecurity24-lazzaretti.pdf","status":"section_checked"},"statement":"SinglePass reduces client-specific preprocessing to exactly one linear pass over the database and reports large concrete preprocessing and query speedups over Checklist.","statement_status":"source_normalized_statement","status":"published","title":"Single-pass client preprocessing","work_id":"PIR-PAPER-2024-SINGLEPASS"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity24/presentation/lazzaretti","sections":[{"content":"Single-pass client preprocessing This is the displayed practice transition for cheaper enrollment/setup.","heading":"Overview"}],"status":"published","subtitle":"Single Pass Client-Preprocessing Private Information Retrieval","summary":"SinglePass reduces client-specific preprocessing to exactly one linear pass over the database and reports large concrete preprocessing and query speedups over Checklist.","title":"Single-pass client preprocessing","type":"result","venue":"USENIX Security 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2024-THORPIR-CONSTANT-DEPTH-HOMOMORPHIC-THORP-PREPROCESSING","keywords":["atomic-result","thorpir","fhe","preprocessing-circuit"],"metadata":{"claim_slug":"constant-depth-homomorphic-thorp-preprocessing","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"circuit_depth":["constant"],"mechanism":["homomorphic_thorp_shuffle"],"preprocessing":["sublinear_bandwidth"]},"historical_context":{"narrative":"The main single-server client-preprocessing paths either streamed the full database to the client or used sublinear-bandwidth FHE preprocessing whose circuit depth grew with the database; an existing shallow exception still had unattractive concrete offline bandwidth. ThorPIR uses the weaker mixing guarantee sufficient for its bounded-query setting, sharpens the Thorp-shuffle analysis, and maps the shuffle to SIMD-friendly homomorphic evaluation. Its hint circuit is linear in size and has depth independent of the database size, while offline communication stays sublinear. This isolated depth as a tractable bottleneck in the encrypted-preprocessing branch. It was not a routine deployment result: the headline end-to-end estimates use roughly 128,000 GPUs and remain model-based estimates.","prior_boundary":"The main single-server client-preprocessing paths either streamed the database to the client or used sublinear-bandwidth FHE preprocessing with circuits whose depth grew with the database; a shallow prior exception retained unattractive concrete offline bandwidth.","significance_at_publication":"Isolates circuit depth as the bottleneck in the encrypted-preprocessing branch and substantially improves it without presenting the resulting resource estimates as routine deployment performance.","technical_delta":"Uses a security-sufficient Thorp shuffle, a sharper mixing analysis, and SIMD-friendly homomorphic evaluation to obtain a linear-size constant-depth hint-generation circuit with sublinear offline communication."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2024-THORPIR-CONSTANT-DEPTH-HOMOMORPHIC-THORP-PREPROCESSING","keywords":["thorpir","fhe","preprocessing-circuit"],"limitations":["paper reports estimates for very large accelerator resources","not a routine deployment"],"paper_id":"PIR-PAPER-2024-THORPIR","qualifiers":["SIMD FHE preprocessing","single-server"],"source_locator":{"dossier_section":"PIR-PAPER-2024-THORPIR § Atomic claims","primary_source":"Abstract; Introduction; construction overview; PDF pp. 1–4","primary_source_url":"https://eprint.iacr.org/2024/482.pdf","status":"section_checked"},"statement":"Homomorphic Thorp shuffles yield a linear-size constant-depth hint-generation circuit with sublinear offline communication for single-server client-preprocessing PIR.","statement_status":"source_normalized_statement","status":"published","title":"Constant-depth homomorphic Thorp preprocessing","work_id":"PIR-PAPER-2024-THORPIR"},"primaryUrl":"https://eprint.iacr.org/2024/482","sections":[{"content":"Constant-depth homomorphic Thorp preprocessing This reviewed-related node captures an important mechanism without overstating deployment maturity.","heading":"Overview"}],"status":"published","subtitle":"ThorPIR: Single Server PIR via Homomorphic Thorp Shuffles","summary":"Homomorphic Thorp shuffles yield a linear-size constant-depth hint-generation circuit with sublinear offline communication for single-server client-preprocessing PIR.","title":"Constant-depth homomorphic Thorp preprocessing","type":"result","venue":"ACM CCS 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2024-THORPIR-CONSTANT-DEPTH-HOMOMORPHIC-THORP-PREPROCESSING"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2024-YPIR-HIGH-THROUGHPUT-LWE-TO-RLWE-TRANSLATION","keywords":["atomic-result","single-server","lwe","rlwe","silent-preprocessing","hintless"],"metadata":{"claim_slug":"high-throughput-lwe-to-rlwe-translation","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"mechanism":["lwe-to-rlwe-translation"],"server_work":["linear_scan"],"track":["practice"]},"historical_context":{"narrative":"Tiptoe and HintlessPIR had already removed the downloaded hint from the SimplePIR family, but their bootstrapping-based route paid substantial throughput or communication overhead. YPIR instead appends a lightweight packing step to DoublePIR, translating its LWE-style response into a compact polynomial-ring representation. For one-bit or one-byte retrieval from a 32 GB database, the paper reports 12.1 GB/s/core and 2.5 MB total communication, retaining 97% of SimplePIR's throughput. This contribution is the mechanism-and-performance result; the change to silent preprocessing is recorded separately. ZipPIR later treats YPIR as its fastest close comparison among systems without a client-stored hint, rather than as a sublinear-server-time scheme.","prior_boundary":"Tiptoe and HintlessPIR removed SimplePIR-family hints through bootstrapping, but paid substantial throughput or communication overhead relative to the hint-based SimplePIR and DoublePIR systems.","significance_at_publication":"Shows that removing the downloaded hint need not forfeit most of SimplePIR's throughput and becomes a concrete comparison point for later storage-free systems such as ZipPIR.","technical_delta":"Adds a lightweight polynomial-ring packing step that translates the LWE-style DoublePIR response into a compact RLWE representation, preserving the memory-bandwidth-oriented online path."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2024-YPIR-HIGH-THROUGHPUT-LWE-TO-RLWE-TRANSLATION","keywords":["single-server","lwe","rlwe","silent-preprocessing","hintless"],"limitations":["linear online database scan","larger queries than SimplePIR and DoublePIR","measurements not independently reproduced"],"paper_id":"PIR-PAPER-2024-YPIR","qualifiers":["single semi-honest server","small-record retrieval","source-reported measurements"],"source_locator":{"dossier_section":"PIR-PAPER-2024-YPIR § Atomic claims","primary_source":"Abstract; Sections 1.1–1.2 and 3–4; USENIX PDF pp. 5985–5999","primary_source_url":"https://www.usenix.org/system/files/usenixsecurity24-menon.pdf","status":"section_checked"},"statement":"YPIR packs a DoublePIR response into an RLWE representation and reports 12.1 GB/s/core with 2.5 MB total communication for one-bit or one-byte retrieval from a 32 GB database.","statement_status":"source_normalized_statement","status":"published","title":"High-throughput LWE-to-RLWE response translation","work_id":"PIR-PAPER-2024-YPIR"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity24/presentation/menon","sections":[{"content":"High-throughput LWE-to-RLWE response translation","heading":"Overview"},{"content":"high-throughput-lwe-to-rlwe-translation is the atomic contribution identifier normalized from PIR-PAPER-2024-YPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"YPIR: High-Throughput Single-Server PIR with Silent Preprocessing","summary":"YPIR packs a DoublePIR response into an RLWE representation and reports 12.1 GB/s/core with 2.5 MB total communication for one-bit or one-byte retrieval from a 32 GB database.","title":"High-throughput LWE-to-RLWE response translation","type":"result","venue":"USENIX Security 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2024-YPIR-HIGH-THROUGHPUT-LWE-TO-RLWE-TRANSLATION"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","keywords":["atomic-result","single-server","lwe","rlwe","silent-preprocessing","hintless"],"metadata":{"claim_slug":"silent-preprocessing-removes-hint-download","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"client_state":["no-downloaded-hint"],"mechanism":["lwe-to-rlwe-translation"],"preprocessing":["silent"],"server_model":["single"]},"historical_context":{"narrative":"SimplePIR and DoublePIR approached memory bandwidth by asking each client to download and retain a large database-derived hint, whose refresh traffic followed database updates. Tiptoe and HintlessPIR removed that download but gave up more throughput or communication efficiency. YPIR keeps the database-dependent preprocessing on the server and uses lightweight LWE-to-RLWE packing to return the full DoublePIR response, eliminating the downloaded client hint and its update traffic. It preserves the memory-bandwidth-oriented online path, but does not make the database scan sublinear, and its queries are larger than SimplePIR's and DoublePIR's. This created a distinct high-throughput, no-client-hint comparison point; ZipPIR later uses YPIR as its fastest close comparison in that setting.","prior_boundary":"SimplePIR and DoublePIR obtained memory-bandwidth-class throughput by having the client download and retain a large database-derived hint, while earlier hint-removal systems lost more throughput or communication efficiency.","significance_at_publication":"Removes database-derived client state and its refresh traffic from the high-throughput branch, so database updates do not require redistributing hints; ZipPIR later treats YPIR as a principal no-client-hint comparison point.","technical_delta":"Keeps the database-dependent preprocessing at the server and applies LWE-to-RLWE packing to the full DoublePIR response, eliminating the downloaded client hint at the cost of larger online queries."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","keywords":["single-server","lwe","rlwe","silent-preprocessing","hintless"],"limitations":["higher total communication in the matched setting","artifact results are reported rather than independently reproduced"],"paper_id":"PIR-PAPER-2024-YPIR","qualifiers":["single semi-honest server","LWE-to-RLWE translation","source-reported measurements"],"source_locator":{"dossier_section":"PIR-PAPER-2024-YPIR § Atomic claims","primary_source":"Abstract and system overview","primary_source_url":"https://www.usenix.org/conference/usenixsecurity24/presentation/menon","status":"primary_source_checked"},"statement":"YPIR uses lightweight LWE-to-RLWE translation to remove offline client communication from the high-throughput hint-based PIR branch.","statement_status":"source_normalized_statement","status":"published","title":"Removed the offline client-hint download with silent preprocessing","work_id":"PIR-PAPER-2024-YPIR"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity24/presentation/menon","sections":[{"content":"Silent preprocessing","heading":"Overview"},{"content":"silent-preprocessing-removes-hint-download is the atomic contribution identifier normalized from PIR-PAPER-2024-YPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"YPIR: High-Throughput Single-Server PIR with Silent Preprocessing","summary":"YPIR uses lightweight LWE-to-RLWE translation to remove offline client communication from the high-throughput hint-based PIR branch.","title":"Removed the offline client-hint download with silent preprocessing","type":"result","venue":"USENIX Security 2024","year":2024,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2025-DISTRIBUTIONAL-CLASSIC-PIR-BLACK-BOX-COMPILER","keywords":["atomic-result","compiler","distributional-pir","expected-work"],"metadata":{"claim_slug":"classic-pir-black-box-compiler","contribution_kind":"transform","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"cost":["expected_server_work"],"transform":["classic_to_distributional_pir"]},"historical_context":{"narrative":"Classic and batch PIR backends treated all records uniformly, so their server work could not benefit from a public, highly skewed popularity distribution. The distributional-PIR compiler copies popular records into a smaller database and randomizes between querying that subset and the full database; crucially, this routing decision is independent of the requested index. It therefore uses an arbitrary classic batch-PIR scheme as a black box while reducing expected server work under skew. The contribution mattered because the new correctness model became an adapter rather than a replacement cryptosystem: the evaluated system instantiates it with SimplePIR. Its speedup is distribution-dependent and buys relaxed correctness, so it must not be compared as an unconditional efficiency successor to classic PIR.","prior_boundary":"Classic and batch PIR backends treated every record uniformly, so they could not exploit a public skewed popularity distribution without changing how queries were formed or exposing the requested index.","significance_at_publication":"Makes distributional correctness an adapter over existing PIR rather than a new cryptographic backend, yielding lower expected server work when the declared distribution is sufficiently skewed.","technical_delta":"Wraps an arbitrary classic batch-PIR backend around a popularity-partitioned database and randomizes between the popular subset and the full database independently of the requested index."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2025-DISTRIBUTIONAL-CLASSIC-PIR-BLACK-BOX-COMPILER","keywords":["compiler","distributional-pir","expected-work"],"limitations":["speedup relies on relaxed correctness and distribution skew"],"paper_id":"PIR-PAPER-2025-DISTRIBUTIONAL","qualifiers":["expected cost under a declared distribution"],"source_locator":{"dossier_section":"PIR-PAPER-2025-DISTRIBUTIONAL § Atomic claims","primary_source":"Section 3; USENIX PDF pp. 3382–3385","primary_source_url":"https://www.usenix.org/system/files/usenixsecurity25-lehmkuhl.pdf","status":"section_checked"},"statement":"A black-box transform applies classic PIR to popularity-partitioned databases to reduce expected server work under skewed query distributions.","statement_status":"source_normalized_statement","status":"published","title":"Classic-PIR black-box compiler","work_id":"PIR-PAPER-2025-DISTRIBUTIONAL"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity25/presentation/lehmkuhl","sections":[{"content":"Classic-PIR black-box compiler The transform can instantiate with different classic PIR backends.","heading":"Overview"}],"status":"published","subtitle":"Distributional Private Information Retrieval","summary":"A black-box transform applies classic PIR to popularity-partitioned databases to reduce expected server work under skewed query distributions.","title":"Classic-PIR black-box compiler","type":"result","venue":"USENIX Security 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2025-DISTRIBUTIONAL-CLASSIC-PIR-BLACK-BOX-COMPILER"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2025-DISTRIBUTIONAL-DISTRIBUTIONAL-PIR-WITH-RELAXED-CORRECTNESS","keywords":["atomic-result","distributional-pir","correctness-model","capability"],"metadata":{"claim_slug":"distributional-pir-with-relaxed-correctness","contribution_kind":"definition","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"correctness":["distributional"],"privacy":["classic_query_privacy"],"workload":["skewed_popularity"]},"historical_context":{"narrative":"Classic PIR required essentially the same correctness guarantee for every record, so a server could not exploit popularity skew as a non-private cache would. Distributional PIR keeps the classic cryptographic privacy condition on requested indices but defines correctness relative to a public query distribution, separating explicit, worst-case, and average-case recovery. This made sublinear expected work possible for sufficiently skewed distributions, but only by allowing some queries to fail more often. The contribution was important because it exposed a new correctness contract, not a universally faster PIR scheme. Its privacy statement also assumes the client's query schedule is independent of both the requested indices and earlier success or failure; adaptive retry behavior can violate that condition. The model is therefore appropriate only where best-effort retrieval or an index-independent retry schedule is acceptable.","prior_boundary":"Classic PIR required essentially the same correctness guarantee for every requested record and therefore could not use popularity skew in the way a non-private cache does.","significance_at_publication":"Opens a best-effort retrieval design space in which expected server work can fall with distribution skew, while making failure semantics and query scheduling part of the security-relevant contract.","technical_delta":"Defines PIR relative to a public popularity distribution, retaining classic indistinguishability of requested indices while separating explicit, worst-case, and average-case correctness guarantees."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2025-DISTRIBUTIONAL-DISTRIBUTIONAL-PIR-WITH-RELAXED-CORRECTNESS","keywords":["distributional-pir","correctness-model","capability"],"limitations":["relaxed correctness is not equivalent to classic errorless PIR"],"paper_id":"PIR-PAPER-2025-DISTRIBUTIONAL","qualifiers":["query decision independent of past success","public distribution"],"source_locator":{"dossier_section":"PIR-PAPER-2025-DISTRIBUTIONAL § Atomic claims","primary_source":"Introduction; Section 2.1; USENIX PDF pp. 3377–3382","primary_source_url":"https://www.usenix.org/system/files/usenixsecurity25-lehmkuhl.pdf","status":"section_checked"},"statement":"Distributional PIR preserves classic cryptographic query privacy while permitting success probability to depend on a public query-popularity distribution.","statement_status":"source_normalized_statement","status":"published","title":"Distributional PIR correctness model","work_id":"PIR-PAPER-2025-DISTRIBUTIONAL"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity25/presentation/lehmkuhl","sections":[{"content":"Distributional PIR correctness model The node is related rather than backbone so the map does not compare unlike correctness contracts as one efficiency race.","heading":"Overview"}],"status":"published","subtitle":"Distributional Private Information Retrieval","summary":"Distributional PIR preserves classic cryptographic query privacy while permitting success probability to depend on a public query-popularity distribution.","title":"Distributional PIR correctness model","type":"result","venue":"USENIX Security 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2025-DISTRIBUTIONAL-DISTRIBUTIONAL-PIR-WITH-RELAXED-CORRECTNESS"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2025-DISTRIBUTIONAL-PROBE-MODEL-SERVER-RUNTIME-LOWER-BOUND","keywords":["atomic-result","lower-bound","distributional-pir","probe-model"],"metadata":{"claim_slug":"probe-model-server-runtime-lower-bound","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"correctness":["distributional"],"model":["unencoded_database_probes"],"result":["lower_bound"]},"historical_context":{"narrative":"Distributional correctness made large expected-work reductions possible, but it left open whether a better popularity-aware probing strategy could substantially outperform the paper's compiler. The lower-bound contribution answers that question for a natural class: schemes whose answer algorithm probes records in the unencoded original database. For the real-world distributions evaluated in the paper, the construction runs within 1.4x of this bound. This mattered because it distinguished room for parameter tuning from the need for a different technical idea. The theorem is deliberately model-scoped: it does not rule out schemes that encode or otherwise transform the database, nor does it restore the classic errorless-correctness lower bound under the distributional contract.","prior_boundary":"The new distributional correctness model produced large expected-work savings, but it was unclear whether a different popularity-aware probing strategy could substantially improve on the paper's compiler.","significance_at_publication":"Places the construction within 1.4 times of the bound on the paper's evaluated distributions and identifies database encoding, rather than another probe schedule, as the principal escape from this scoped barrier.","technical_delta":"Proves a distribution-dependent expected-runtime lower bound for schemes whose answer algorithm probes the unencoded original database."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2025-DISTRIBUTIONAL-PROBE-MODEL-SERVER-RUNTIME-LOWER-BOUND","keywords":["lower-bound","distributional-pir","probe-model"],"limitations":["does not exclude encoded-database techniques"],"paper_id":"PIR-PAPER-2025-DISTRIBUTIONAL","qualifiers":["natural probe class","distribution-dependent"],"source_locator":{"dossier_section":"PIR-PAPER-2025-DISTRIBUTIONAL § Atomic claims","primary_source":"Section 5; USENIX PDF pp. 3386–3388","primary_source_url":"https://www.usenix.org/system/files/usenixsecurity25-lehmkuhl.pdf","status":"theorem_checked"},"statement":"The paper lower-bounds expected server runtime for distributional-PIR schemes that answer by probing the unencoded original database.","statement_status":"source_normalized_statement","status":"published","title":"Distributional probe-model lower bound","work_id":"PIR-PAPER-2025-DISTRIBUTIONAL"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity25/presentation/lehmkuhl","sections":[{"content":"Distributional probe-model lower bound The model restriction is retained explicitly.","heading":"Overview"}],"status":"published","subtitle":"Distributional Private Information Retrieval","summary":"The paper lower-bounds expected server runtime for distributional-PIR schemes that answer by probing the unencoded original database.","title":"Distributional probe-model lower bound","type":"result","venue":"USENIX Security 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2025-DISTRIBUTIONAL-PROBE-MODEL-SERVER-RUNTIME-LOWER-BOUND"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR","keywords":["atomic-result","multi-server","depir","information-theoretic"],"metadata":{"claim_slug":"information-theoretic-multi-server-depir","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"preprocessing":["server_public"],"privacy":["information_theoretic"],"server_model":["multi_server"],"server_work":["subpolynomial_online"]},"historical_context":{"narrative":"LMW23 had reached unkeyed doubly efficient PIR in the single-server setting from Ring-LWE, while an information-theoretic construction with near-linear preprocessing and subpolynomial queries remained open. This work changes the server model rather than weakening the assumption inside LMW23: replicated, non-colluding, non-communicating servers obtain near-linear preprocessing and subpolynomial online time and communication for unboundedly many queries, using a roughly logarithmic number of servers. The result is within a subpolynomial factor of the Persiano--Yeo bound in that model. It therefore identifies what server non-collusion can replace at the DEPIR frontier, not an assumption-free single-server construction. Exact server counts and the revised TCC parameters remain version-sensitive.","prior_boundary":"LMW23 had obtained standard-assumption single-server DEPIR using Ring-LWE, while information-theoretic server-preprocessing PIR with a constrained number of servers did not simultaneously have near-linear preprocessing and subpolynomial query time.","significance_at_publication":"Shows that non-collusion can replace computational hardness at the DEPIR frontier and approaches the Persiano-Yeo bound up to a subpolynomial factor in the stated multi-server model.","technical_delta":"In the replicated, non-colluding and non-communicating server model, gives an information-theoretic scheme with near-linear preprocessing, subpolynomial online time and communication, and unboundedly many queries using roughly logarithmically many servers."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR","keywords":["multi-server","depir","information-theoretic"],"limitations":["server count and exact revised TCC parameters require version-specific reading"],"paper_id":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR","qualifiers":["multiple non-colluding servers","information-theoretic privacy","server preprocessing"],"source_locator":{"dossier_section":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR § Atomic claims","primary_source":"Abstract; Introduction; ePrint PDF pp. 1–4","primary_source_url":"https://eprint.iacr.org/2024/829.pdf","status":"section_checked"},"statement":"The first information-theoretic multi-server DEPIR supports unbounded queries with near-linear server preprocessing and subpolynomial query time.","statement_status":"source_normalized_statement","status":"published","title":"Information-theoretic multi-server DEPIR","work_id":"PIR-PAPER-2025-LLFMP-MULTISERVER-DEPIR"},"primaryUrl":"https://eprint.iacr.org/2024/829","sections":[{"content":"Information-theoretic multi-server DEPIR This is a capability-boundary node in the public/server-preprocessing thread.","heading":"Overview"}],"status":"published","subtitle":"Multi-server Doubly Efficient PIR in the Classical Model and Beyond","summary":"The first information-theoretic multi-server DEPIR supports unbounded queries with near-linear server preprocessing and subpolynomial query time.","title":"Information-theoretic multi-server DEPIR","type":"result","venue":"TCC 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR"},{"evidence":"primary_source_checked","id":"PIR-RESULT-2025-LMW-BLACKBOX-BLACK-BOX-PRIMITIVES-COLLAPSE-TO-ONE-WAY-FUNCTIONS-FOR-SK-DEPIR","keywords":["atomic-result","depir","lower-bound","black-box","secret-key"],"metadata":{"claim_slug":"black-box-primitives-collapse-to-one-way-functions-for-sk-depir","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"model":["black-box"],"result":["barrier"],"target":["secret-key-depir"]},"historical_context":{"narrative":"Known DEPIR constructions relied on structured algebraic assumptions such as Ring-LWE, yet it was unclear whether powerful generic primitives could yield secret-key DEPIR through black-box use. The paper compiles an SK-DEPIR using its broad crypto-oracle class into a passive-server scheme with a secret random function, which can then be instantiated from one-way functions while preserving the relevant locality, correctness, and security guarantees. Thus key agreement, oblivious transfer, idealized obfuscation, and the other covered primitives add no black-box construction power beyond one-way functions in this framework. The result redirects the search toward structured or non-black-box methods, but is not itself a DEPIR impossibility; the stronger two-round passive-server exclusion is a separate contribution.","prior_boundary":"Known DEPIR constructions used structured algebraic assumptions such as Ring-LWE, while no generic implication from powerful cryptographic primitives to secret-key DEPIR was known.","significance_at_publication":"Shows that generic black-box access to primitives such as key agreement, oblivious transfer, or idealized obfuscation adds no construction power beyond one-way functions for SK-DEPIR in the framework.","technical_delta":"Compiles any SK-DEPIR that uses the paper's broad crypto-oracle class into a passive-server secret-random-function scheme and hence into a black-box construction from one-way functions, preserving the relevant efficiency and security parameters."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2025-LMW-BLACKBOX-BLACK-BOX-PRIMITIVES-COLLAPSE-TO-ONE-WAY-FUNCTIONS-FOR-SK-DEPIR","keywords":["depir","lower-bound","black-box","secret-key"],"limitations":["not an impossibility theorem for DEPIR","does not exclude Ring-LWE","non-black-box techniques","extra rounds","or active preprocessing"],"paper_id":"PIR-PAPER-2025-LMW-BLACKBOX","qualifiers":["secret-key DEPIR","black-box construction framework","stated passive-server format"],"source_locator":{"dossier_section":"PIR-PAPER-2025-LMW-BLACKBOX § Atomic claims","primary_source":"Abstract and main theorem discussion","primary_source_url":"https://eprint.iacr.org/2025/552","status":"primary_source_checked"},"statement":"For general secret-key DEPIR, black-box access to a broad class of generic and idealized cryptographic primitives gives no more construction power than black-box one-way functions in the paper's framework.","statement_status":"source_normalized_statement","status":"published","title":"Black-box primitives collapse to one-way functions for SK-DEPIR","work_id":"PIR-PAPER-2025-LMW-BLACKBOX"},"primaryUrl":"https://eprint.iacr.org/2025/552","sections":[{"content":"Black-box collapse","heading":"Overview"},{"content":"black-box-primitives-collapse-to-one-way-functions-for-sk-depir is the atomic contribution identifier normalized from PIR-PAPER-2025-LMW-BLACKBOX. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Black Box Crypto Is Useless for Doubly Efficient PIR","summary":"For general secret-key DEPIR, black-box access to a broad class of generic and idealized cryptographic primitives gives no more construction power than black-box one-way functions in the paper's framework.","title":"Black-box primitives collapse to one-way functions for SK-DEPIR","type":"result","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2025-LMW-BLACKBOX-BLACK-BOX-PRIMITIVES-COLLAPSE-TO-ONE-WAY-FUNCTIONS-FOR-SK-DEPIR"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2025-LMW-BLACKBOX-TWO-ROUND-PASSIVE-SERVER-BLACK-BOX-BARRIER","keywords":["atomic-result","depir","lower-bound","black-box","secret-key"],"metadata":{"claim_slug":"two-round-passive-server-black-box-barrier","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"model":["two_round_passive_server","black_box"],"result":["barrier"],"target":["secret_key_depir"]},"historical_context":{"narrative":"The paper's general collapse shows that covered crypto oracles add no more power than one-way functions, but that statement alone does not exclude a black-box one-way-function construction. The second result closes this gap for the format used by all known schemes in the paper's survey. It proves that no two-round passive-server secret-random-function DEPIR can have the stated small correctness error, negligible information-theoretic leakage, and sublinear locality, then combines the theorem with the collapse to rule out black-box constructions from the covered primitives. The barrier is strong but scoped: it leaves additional rounds, active-server protocols, non-black-box techniques, and constructions exploiting concrete structured assumptions such as Ring-LWE outside its conclusion.","prior_boundary":"The general collapse reduced crypto-oracle-based SK-DEPIR to one-way functions, but did not by itself rule out a black-box one-way-function construction.","significance_at_publication":"Rules out the format used by all known DEPIR schemes in the paper's survey while leaving extra rounds, active-server formats, concrete structured assumptions, and non-black-box techniques open.","technical_delta":"Proves that two-round passive-server secret-random-function DEPIR with sublinear locality cannot meet the stated correctness and information-theoretic security conditions, then combines this with the collapse to exclude the covered black-box constructions."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2025-LMW-BLACKBOX-TWO-ROUND-PASSIVE-SERVER-BLACK-BOX-BARRIER","keywords":["depir","lower-bound","black-box","secret-key"],"limitations":["does not exclude extra rounds","active-server formats","non-black-box techniques","or concrete structured assumptions"],"paper_id":"PIR-PAPER-2025-LMW-BLACKBOX","qualifiers":["secret-key DEPIR","two rounds","passive server","sublinear locality","crypto-oracle black-box framework"],"source_locator":{"dossier_section":"PIR-PAPER-2025-LMW-BLACKBOX § Atomic claims","primary_source":"Section 5; Theorem 5.1 and Corollary 5.2; PDF pp. 16–17","primary_source_url":"https://eprint.iacr.org/2025/552.pdf","status":"theorem_checked"},"statement":"In the paper's locality and correctness regime, no two-round passive-server SK-DEPIR can be constructed by black-box use of any primitive covered by its crypto-oracle framework.","statement_status":"source_normalized_statement","status":"published","title":"No two-round passive-server black-box SK-DEPIR","work_id":"PIR-PAPER-2025-LMW-BLACKBOX"},"primaryUrl":"https://eprint.iacr.org/2025/552","sections":[{"content":"No two-round passive-server black-box SK-DEPIR","heading":"Overview"},{"content":"two-round-passive-server-black-box-barrier is the atomic contribution identifier normalized from PIR-PAPER-2025-LMW-BLACKBOX. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Black Box Crypto Is Useless for Doubly Efficient PIR","summary":"In the paper's locality and correctness regime, no two-round passive-server SK-DEPIR can be constructed by black-box use of any primitive covered by its crypto-oracle framework.","title":"No two-round passive-server black-box SK-DEPIR","type":"result","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2025-LMW-BLACKBOX-TWO-ROUND-PASSIVE-SERVER-BLACK-BOX-BARRIER"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2026-ZIPPIR-HIGH-THROUGHPUT-WITHOUT-CLIENT-HINT-STORAGE","keywords":["atomic-result","single-server","lwe","paillier","silent-offline","no-client-storage","recent-candidate"],"metadata":{"claim_slug":"high-throughput-without-client-hint-storage","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"client_state":["no_database_hint"],"server_model":["single"],"server_state":["small_per_client"],"track":["practice"]},"historical_context":{"narrative":"SimplePIR-class systems approached memory bandwidth by making each client store a large database-derived hint, while prior no-client-storage systems performed more public-key work online and ran more slowly; YPIR was the closest high-throughput comparison. ZipPIR moves the refreshable hint state to the server, pushes expensive Paillier operations into an almost-silent offline phase, and leaves two plaintext matrix-vector products online. On a 1 GB database, the paper reports 3 GB/s throughput, 120 KB of per-client server state, and a 400-byte one-time offline message. This is a concrete capability result, distinct from the ciphertext-compression mechanism. The measurements come from the 2026 preprint and remain source-reported rather than independently reproduced.","prior_boundary":"SimplePIR-class systems approached memory bandwidth by storing large database-derived hints at clients, while systems without client-side storage used more public-key work and delivered lower throughput; YPIR narrowed but did not close that gap.","significance_at_publication":"Reports a new concrete point combining no client-side hint with multi-gigabyte-per-second throughput, while making server-side per-client state and prepublication measurement maturity explicit.","technical_delta":"Moves the hint to small refreshable per-client server state, confines expensive Paillier operations to an almost-silent offline phase, and leaves two plaintext matrix-vector multiplications online."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2026-ZIPPIR-HIGH-THROUGHPUT-WITHOUT-CLIENT-HINT-STORAGE","keywords":["single-server","lwe","paillier","silent-offline","no-client-storage","recent-candidate"],"limitations":["small per-client server state refreshed per query","preprint and artifact audit pending","measurements not independently reproduced"],"paper_id":"PIR-PAPER-2026-ZIPPIR","qualifiers":["single server","no client-side hint","almost-silent offline phase","source-reported measurements"],"source_locator":{"dossier_section":"PIR-PAPER-2026-ZIPPIR § Atomic claims","primary_source":"Abstract; Sections 1.1 and 5.3; Tables 1 and 4; arXiv v1 PDF pp. 1–2, 9–11","primary_source_url":"https://arxiv.org/pdf/2603.09190","status":"section_checked"},"statement":"ZipPIR reports 3 GB/s throughput on a 1 GB database without client-side hint storage, using 120 KB of per-client server state and a 400-byte one-time offline message.","statement_status":"source_normalized_statement","status":"accepted_prepublication","title":"High throughput without client-side hint storage","work_id":"PIR-PAPER-2026-ZIPPIR"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","sections":[{"content":"High throughput without client-side hint storage","heading":"Overview"},{"content":"high-throughput-without-client-hint-storage is the atomic contribution identifier normalized from PIR-PAPER-2026-ZIPPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"accepted_prepublication","subtitle":"ZipPIR: High-Throughput Single-Server PIR without Client-side Storage","summary":"ZipPIR reports 3 GB/s throughput on a 1 GB database without client-side hint storage, using 120 KB of per-client server state and a 400-byte one-time offline message.","title":"High throughput without client-side hint storage","type":"result","venue":"USENIX Security 2026","year":2026,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2026-ZIPPIR-HIGH-THROUGHPUT-WITHOUT-CLIENT-HINT-STORAGE"},{"evidence":"fulltext_checked","id":"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION","keywords":["atomic-result","single-server","lwe","paillier","silent-offline","no-client-storage","recent-candidate"],"metadata":{"claim_slug":"lwe-to-paillier-ciphertext-compression","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"maturity":["prepublication"],"mechanism":["lwe-to-paillier-compression"],"preprocessing":["almost-silent"],"representation":["lwe","rlwe","paillier"]},"historical_context":{"narrative":"Before ZipPIR, lattice-ciphertext compression changed parameters or packed ciphertexts into RLWE, while direct Paillier-based PIR remained too slow for a high-throughput online path. ZipPIR exploits the fact that the first phase of LWE and RLWE decryption is linear: the server evaluates that phase under additive encryption and returns one or a batch of much smaller Paillier ciphertexts. It then moves the expensive Paillier operations into an offline phase, leaving plaintext matrix work online. This is the reusable mechanism behind, but not identical to, ZipPIR's no-client-hint performance claim. The paper reports about 89% compression for one representative LWE ciphertext and larger savings when batching; those figures and the resulting PIR measurements remain source-reported.","prior_boundary":"Existing lattice-ciphertext compression reduced parameters or packed into RLWE, while high-throughput SimplePIR-family protocols still faced a large client hint and direct Paillier PIR was too expensive online.","significance_at_publication":"Supplies a reusable scheme-switching mechanism behind ZipPIR's no-client-hint operating point and demonstrates that Paillier can participate in a competitive PIR online path when its cost is isolated offline.","technical_delta":"Homomorphically evaluates the linear part of LWE or RLWE decryption under additive encryption, batching lattice ciphertexts into smaller Paillier ciphertexts and precomputing the expensive additive-cryptography operations offline."},"historical_context_status":"curator_synthesis","id":"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION","keywords":["single-server","lwe","paillier","silent-offline","no-client-storage","recent-candidate"],"limitations":["compression shifts expensive Paillier work offline","proceedings and artifact audit remain pending","performance not independently reproduced"],"paper_id":"PIR-PAPER-2026-ZIPPIR","qualifiers":["accepted prepublication","additive homomorphic compression","LWE and RLWE ciphertexts","offline-online split"],"source_locator":{"dossier_section":"PIR-PAPER-2026-ZIPPIR § Atomic claims","primary_source":"Abstract; Sections 1.1, 3, and 4; Theorems 1–4; arXiv v1 PDF pp. 1–8","primary_source_url":"https://arxiv.org/pdf/2603.09190","status":"theorem_checked"},"statement":"ZipPIR homomorphically evaluates the linear phase of LWE or RLWE decryption under additive encryption, compressing lattice ciphertexts into Paillier ciphertexts and moving the expensive work offline.","statement_status":"source_normalized_statement","status":"accepted_prepublication","title":"LWE-to-Paillier compression for almost-silent PIR","work_id":"PIR-PAPER-2026-ZIPPIR"},"primaryUrl":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","sections":[{"content":"LWE→Paillier compression","heading":"Overview"},{"content":"lwe-to-paillier-ciphertext-compression is the atomic contribution identifier normalized from PIR-PAPER-2026-ZIPPIR. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"accepted_prepublication","subtitle":"ZipPIR: High-Throughput Single-Server PIR without Client-side Storage","summary":"ZipPIR homomorphically evaluates the linear phase of LWE or RLWE decryption under additive encryption, compressing lattice ciphertexts into Paillier ciphertexts and moving the expensive work offline.","title":"LWE-to-Paillier compression for almost-silent PIR","type":"result","venue":"USENIX Security 2026","year":2026,"sourcePath":"data/pir-catalog.json#PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION"},{"evidence":"source_grounded_route","id":"PIR-ROUTE-001","keywords":[],"metadata":{"current_bottleneck":"Communication, conversion keys, per-client server state, and update cost move differently across YPIR and ZipPIR.","dossier_type":"route","entry_results":["PIR-PAPER-2024-YPIR","PIR-PAPER-2026-ZIPPIR"],"evidence":"source_grounded_route","falsifiable_next_test":"Reproduce YPIR and the published ZipPIR artifact when available on one 1 GB small-record compatibility key and account for every offline and online byte.","id":"PIR-ROUTE-001","mechanism":"Translate compact LWE selectors into an arithmetic domain suited to fast streaming, then compress responses without downloading a database-dependent client hint.","status":"proposed","targets":["PIR-OP-001"],"title":"Silent ciphertext conversion and response compression"},"primaryUrl":null,"sections":[{"content":"This route does not assert that LWE-to-RLWE and LWE-to-Paillier conversions are interchangeable; it identifies the shared goal of server-side conversion without a large client hint.","heading":"Route boundary"}],"status":"proposed","subtitle":"","summary":"This route does not assert that LWE-to-RLWE and LWE-to-Paillier conversions are interchangeable; it identifies the shared goal of server-side conversion without a large client hint.","title":"Silent ciphertext conversion and response compression","type":"route","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ROUTE-001"},{"evidence":"source_grounded_route","id":"PIR-ROUTE-002","keywords":[],"metadata":{"current_bottleneck":"Asymptotic preprocessing hides constants, memory layout, Ring-LWE parameter growth, and the cost of polynomial evaluation data structures.","dossier_type":"route","entry_results":["PIR-PAPER-2023-LMW-DEPIR"],"evidence":"source_grounded_route","falsifiable_next_test":"Produce an executable parameter workbook and memory estimate for one N before implementing; a result showing infeasibility is an acceptable output.","id":"PIR-ROUTE-002","mechanism":"Isolate the fast multivariate-polynomial evaluation layer in the Ring-LWE DEPIR proof and implement one bounded preprocessing/update/query pipeline with dependency-aware accounting.","status":"proposed","targets":["PIR-OP-002"],"title":"Compile asymptotic DEPIR preprocessing into a bounded artifact"},"primaryUrl":null,"sections":[{"content":"The task is not to claim a practical DEPIR system. It first tests whether the theorem's instantiated memory and preprocessing profile survives concrete accounting.","heading":"Route boundary"}],"status":"proposed","subtitle":"","summary":"The task is not to claim a practical DEPIR system. It first tests whether the theorem's instantiated memory and preprocessing profile survives concrete accounting.","title":"Compile asymptotic DEPIR preprocessing into a bounded artifact","type":"route","venue":null,"year":null,"sourcePath":"data/pir-catalog.json#PIR-ROUTE-002"},{"evidence":"primary_source_checked","id":"PIR-WORKLOAD-2022-SPIRAL-STREAM","keywords":[],"metadata":{"construction_ids":["PIR-CONSTRUCTION-2022-SPIRAL"],"dossier_type":"workload","evidence":"primary_source_checked","evidence_status":"reported","id":"PIR-WORKLOAD-2022-SPIRAL-STREAM","input_shape":"more than one million records","output_measure":"server throughput and response rate","paper_id":"PIR-PAPER-2022-SPIRAL","status":"reported","title":"Streaming retrieval from a million-record database","workload_class":"streaming large-record PIR","year":2022},"primaryUrl":null,"sections":[{"content":"Streaming workload used for the SpiralStreamPack abstract claim.","heading":"Scope"}],"status":"reported","subtitle":"2022","summary":"Streaming workload used for the SpiralStreamPack abstract claim.","title":"Streaming retrieval from a million-record database","type":"workload","venue":null,"year":2022,"sourcePath":"data/pir-catalog.json#PIR-WORKLOAD-2022-SPIRAL-STREAM"},{"evidence":"primary_source_checked","id":"PIR-WORKLOAD-2023-SIMPLEPIR-1GB","keywords":[],"metadata":{"construction_ids":["PIR-CONSTRUCTION-2023-SIMPLEPIR"],"dossier_type":"workload","evidence":"primary_source_checked","evidence_status":"reported","id":"PIR-WORKLOAD-2023-SIMPLEPIR-1GB","input_shape":"1 GB public database","output_measure":"per-core server throughput, hint bytes, and per-query communication","paper_id":"PIR-PAPER-2023-SIMPLEPIR","status":"reported","title":"Repeated retrieval from a 1 GB hinted database","workload_class":"repeated online query after hint download","year":2023},"primaryUrl":null,"sections":[{"content":"The workload makes amortization over an unbounded sequence of queries visible; it does not set an update frequency.","heading":"Scope"}],"status":"reported","subtitle":"2023","summary":"The workload makes amortization over an unbounded sequence of queries visible; it does not set an update frequency.","title":"Repeated retrieval from a 1 GB hinted database","type":"workload","venue":null,"year":2023,"sourcePath":"data/pir-catalog.json#PIR-WORKLOAD-2023-SIMPLEPIR-1GB"},{"evidence":"primary_source_checked","id":"PIR-WORKLOAD-2024-YPIR-32GB","keywords":[],"metadata":{"construction_ids":["PIR-CONSTRUCTION-2024-YPIR"],"dossier_type":"workload","evidence":"primary_source_checked","evidence_status":"reported","id":"PIR-WORKLOAD-2024-YPIR-32GB","input_shape":"32 GB database with one-bit or one-byte records","output_measure":"per-core throughput and total communication","paper_id":"PIR-PAPER-2024-YPIR","status":"reported","title":"Hintless one-bit/byte retrieval from 32 GB","workload_class":"hintless small-record PIR","year":2024},"primaryUrl":null,"sections":[{"content":"Source workload underlying the YPIR abstract comparison with SimplePIR.","heading":"Scope"}],"status":"reported","subtitle":"2024","summary":"Source workload underlying the YPIR abstract comparison with SimplePIR.","title":"Hintless one-bit/byte retrieval from 32 GB","type":"workload","venue":null,"year":2024,"sourcePath":"data/pir-catalog.json#PIR-WORKLOAD-2024-YPIR-32GB"},{"evidence":"abstract_checked","id":"PIR-WORKLOAD-2026-ZIPPIR-1GB","keywords":[],"metadata":{"construction_ids":["PIR-CONSTRUCTION-2026-ZIPPIR"],"dossier_type":"workload","evidence":"abstract_checked","evidence_status":"reported","id":"PIR-WORKLOAD-2026-ZIPPIR-1GB","input_shape":"1 GB database; record shape pending audit","output_measure":"throughput and per-client server storage","paper_id":"PIR-PAPER-2026-ZIPPIR","status":"accepted_prepublication","title":"Low-client-storage PIR over a 1 GB database","workload_class":"no-large-client-hint PIR","year":2026},"primaryUrl":null,"sections":[{"content":"Accepted-abstract workload retained as a recent candidate, not a normalized benchmark.","heading":"Scope"}],"status":"accepted_prepublication","subtitle":"2026","summary":"Accepted-abstract workload retained as a recent candidate, not a normalized benchmark.","title":"Low-client-storage PIR over a 1 GB database","type":"workload","venue":null,"year":2026,"sourcePath":"data/pir-catalog.json#PIR-WORKLOAD-2026-ZIPPIR-1GB"}],"propertyAssertions":[{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-0023C804027243","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"polylogarithmic"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-00E41F0ECF28E6","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"lwe_to_paillier_compression"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-020D98AD475C55","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"public cryptographic parameters"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-047028ECA3430A","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"per-client offline hint computation"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-0518EE1874AC79","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"prf-only"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-05A01E9553DBF1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"high-rate response; source reports rate 0.81 for SpiralStreamPack setting"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-06DF9FDE587028","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"streaming"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-0743949BB0B00D","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"computational"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-07C3A101627163","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"backend-dependent"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-07F6946EF912BD","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"compact-query"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-088DBA344A9A3A","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"computational"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-0A33099CB44FD5","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"logarithmic amortized bucket updates"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-0AEA7F816EDAD4","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"ciphertext-compression"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-0C837259661893","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"lwe_to_rlwe_translation"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-0C846C7C24CE28","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"sublinear amortized"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-0C871C138CACA5","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"compressed_rlwe_pir"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-0FA9E63B184F45","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"ring_lwe_fast_polynomial_evaluation"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-10401F07D47DE5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"supports fresher database snapshots without hint redistribution"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-10F861CA7326A9","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"standard CPIR correctness"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-1138DC8F44A363","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"included in polylogarithmic bandwidth"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-11B4551B3F5BE3","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"computational"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-11DAC96B563062","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"information-theoretic"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-12050A5ABE7DEF","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"sublinear-bandwidth FHE hint generation"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-129B7340491551","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"exactly one linear pass over the database"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-144CEF598DDD70","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"prf_pseudorandom_sets"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-146D7C5FFA98D8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"single"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-15D0607C221581","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"large-records"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-1765263E356F89","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"sublinear-storage"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-1794BDA1BFED46","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"polylog-bandwidth"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-199E1C7CC8E3D5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"client downloads a query-independent short string offline"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-19E403509F26F4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"single"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-1A7F9BE7763358","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"single-server hintless PIR"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-1B8ED6528E345D","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"practical-implementation"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-1C5310BA7AC230","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"adaptable-set state supports refresh across queries"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-1ED6F9A1CFD752","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"fhe_programmable_pseudorandom_sets"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-1FA84BB69CF794","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"server can generate and update hints during idle time in the stated model"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-2050DA0CB1D827","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"no-client-hint"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-2092F8400D48E1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"near one 32-bit multiply and add per database byte"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-2151D1BA473682","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"lightweight-server-operations"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-2196581FDF8AA0","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"sublinear-communication"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-2277120FC3F2F7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"encoded database must track source updates"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-230CBCA473DF3A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"121 MB hint in the promoted 1 GB source setting"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-24C2C4CCDA9D8B","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"computational"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-257762B3798298","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"negligible decryption failure under selected HE parameters"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-25E5FB09D77581","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"linear in the database"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-25EB75C7F9F382","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"encoded database and public evaluation material"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-263F41BE723AB5","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"client streams the database once and stores sublinear hints"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-26482977053CFA","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"black-box-classic-pir-backend"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-26C0C4753E1F59","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"one-roundtrip"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-284B8ED2A8AE60","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"near-square-root online per query"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-298734B8F16E7A","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"near-optimal-computation"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-29BFF31A358634","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"unbounded-queries-per-hint"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-2D2D1B2E4F22F4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"single-server CPIR"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-2DF0B3BE677C55","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"weaker-assumption"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-2E3997F1CD59AB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"included in the reported 242 KB per-query communication"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-2FB8025A7E8610","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"deterministic public server preprocessing"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-2FE4295B759888","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"reusable short offline string"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-30156D74207D0D","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"single"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-321A0BD39A732D","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"single"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-323DDD550B69E3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"single-server CPIR"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-32FFF2BDFA113E","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"none"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-35DA50115C4B88","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"ciphertext-translation"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-369EF181969BF6","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"computational query privacy from DPF key privacy"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-384FA2407875CB","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"reduced in the targeted large-entry regime"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-39EB1739F2FC75","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"essentially SealPIR-like in the reported comparison"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-3A5A171DE72FE4","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"one-roundtrip"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-3A751423A86318","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"near-optimal-computation"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-3AF17038B8394B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"perfect in the stated model"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-3BD777C9428B9C","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"static database in the evaluated protocol"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-3BDCFEEB99BA33","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"negligible failure under the stated construction"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-3C3F13AE74AAA9","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"backend-dependent"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-3D0AFDDB1B420F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"silent server-side preparation with no offline client communication"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-3D18E145882869","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"sublinear-amortized-time"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-3D2591A2D1052B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"single"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-3D36CB852541B5","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"updates"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-3ECF06CD1F298D","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"polylogarithmic amortized bandwidth"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-3ED04CA693668B","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"information-theoretic-depir"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-3F04C77D5939BC","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"polylogarithmic-communication"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-3F5824EA4549A3","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"increased relative to additive recursion"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-40198768D84D85","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"computational"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-41456B059D138D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"part of 2.5 MB total in promoted 32 GB setting"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-41EA7159A34BA3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"two non-colluding servers"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-42716E25B370D9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"two-server IT-PIR"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-42AA0A6FBF6A44","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"practical-sublinear-server-time"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-43249C2C964F48","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"two-server client-preprocessing PIR"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-465FC31D24E152","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"two-round"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-481F02813177FF","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"phi_hiding_number_theoretic"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-49B1428DB1709D","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"theorem-profile dependent"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-4A0D62ECED7B96","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"one-time per-client interactive preprocessing"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-4AA3E6E295F813","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"cryptographic parameters and query state"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-4B152780124460","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"static database in the evaluated protocol"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-4B62574F300ED0","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"computational"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-4C4B14273251D2","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"single-server client-preprocessing PIR"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-4C7310C54C50AB","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"source-specific sublinear communication"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-5136978F333C46","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"one-time per-client preprocessing"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-528F90F2D598C9","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"direct database updates"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-54B27514DD1349","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"single_pass_pseudorandom_sets"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-54D7657E817C7B","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"sublinear private hints"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-54DE6E4888D0FA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"rlwe_homomorphic_query_expansion"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-55A47EBCE196B6","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"near-square-root hints"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-55C88D6CB32711","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"unbounded-queries"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-5661422447358F","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"negligible error under the construction parameters"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-58483B94DC1431","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"constant-time additions and edits in the paper's dynamic model"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-58AED5C612C84B","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"reduced in expectation under a skewed public query distribution"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-59E66645C21C11","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"preprocessing remains tied to the database snapshot"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-5BB21E694A4E3D","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"public parameters; no sublinear-work preprocessing"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-5CC2EB49C004F5","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"near-linear server-side preprocessing"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-5D00F38091F99D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"information-theoretic against either server"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-5E1403DD02415B","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"sublinear online"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-5E309CFDC0BF78","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"polylog-bandwidth"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-5FA357ABA16925","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"client_hint_bucketed_updates"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-603BFE5B977780","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"stateful hint consumption and refresh; database changes require new preprocessing"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-613C9C5DFF04E4","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"polylogarithmic local state; exact audit pending"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-61DD994F9EAD07","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"O(N^epsilon) update time in the promoted theorem profile"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-62CC3E665E1B17","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"negligible failure under the LWE construction"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-634F0976A3E512","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"client_hint_preprocessing"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-64CEBA54FD83E3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"polylogarithmic online after O(N^(1+epsilon)) preprocessing"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-6547464E16C9D0","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"computational"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-65624DD6BE46D1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"LWE parameter-dependent negligible failure"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-6638C4A0EAF483","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"part of O(n^(1/3)) total"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-69939BA1AAAD7E","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"computational"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-69DEBF9A1204C3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"parameter-dependent negligible failure"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-6B8AE335C84954","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"single"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-6C21990A767031","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"compressed-queries"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-6FD5AB7A0132BB","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"none beyond shared public database"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-6FE8FAFA6CCDCF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"offline-online PIR"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-71670DFFF9AF47","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"parameterized HE correctness"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-71B24CDBBF3FEB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"242 KB in the promoted 1 GB source setting"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-71F0B601265403","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"one aggregate answer per server"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-7413E52EFA354B","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"two-server computational PIR"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-74BFE8EA3B601B","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"polylog-bandwidth"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-75D53536B33BFF","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"dynamic-blocklist"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-768A8CF8F2E0D7","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"inherited from the classic PIR backend"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-76EFB31D5FBA02","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"O(k)"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-7704872BB2569B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"doubly efficient PIR"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-772BABAC882FAB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"no downloaded database hint"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-77CAFF6C4B0E32","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"public cryptographic parameters"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-78308E70376D32","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"polylogarithmic online bandwidth"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-783A5CBA284C0B","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"two-server"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-78769F1BCEE578","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"near-square-root private hint"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-799C5FEDDBCB8B","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"variant-dependent; near-square-root amortized in the FHE construction"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-7B417C2EFB9781","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"negligible failure under the paper's occasional-correctness analysis"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-7C0F7861F6972E","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"exact promoted setting pending proceedings audit"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-7D87145D1E7D51","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"skew-aware-expected-work"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-7DC179D68D99F6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"computational"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-7EBD39C190AF12","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"distribution-dependent success probability; out-of-distribution success may be lower"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-7EF8BF4BF7ECCE","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"single-server"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-7FBBE98006C28B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"computational single-server; statistical two-server"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-8091DA21F3A43D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"two non-colluding replicated servers"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-80B308BFE7149B","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"unbounded-queries"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-80E07EFA788DE9","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"number_theoretic_recursion"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-81DDA9911B5FCA","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"near-square-root in the optimal FHE construction"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-81F4A6ED8D20E7","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"computational"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-82227B32ADD141","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"sublinear profile; exact configuration required"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-82B283CC1028DE","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"client-specific offline phase"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-83B77B91DDF8F2","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"sublinear-online-time"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-84728D047102E8","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"single"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-847E3462FAB9CD","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"single-server PIR"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-84EBDA84527972","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"two non-colluding servers"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-84FBA653C4C06F","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"open-source-implementation"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-856AB0E07C31FE","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"not promoted as sublinear"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-85AC80742449D9","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"single"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-86B8226001D3D3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"negligible failure in the stated system"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-88C8E335398F0B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"negligible failure in the Ring-LWE construction"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-88FE3E878DC882","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"unbounded-queries"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-895CABC355AD7C","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"two-server"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-895CBD95FB0515","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"computational"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-8A12D7B3EE424B","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"memory-bandwidth-throughput"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-8A260D357E7284","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"negligible failure under the stated construction"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-8A3CFDAD98B132","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"part of 2.5 MB total in promoted 32 GB setting"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-8A542D1465DAD9","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"polylog-online-time"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-8B4CC3A41BA7DC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"part of O(n^(1/3)) total"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-8B5C5899E7FB17","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"parameter-dependent; full audit pending"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-8C369DC07AA85F","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"computational"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-8C75B923E9B53C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"sublinear"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-8C9C76B7974785","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"multiple non-colluding servers"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-8CE94EFCD32E2F","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"silent-offline"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-8D12B96A5414C0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"hint freshness cost must be accounted for"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-8DB09875620AB3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"computational"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-8F99DDA6C95A4A","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"optimal-tradeoff"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-8FD83F59A8077B","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"no-client-hint"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-91D1F3583AF25D","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"practical-implementation"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-927B8D7E942F2D","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"information-theoretic construction correctness"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-940775222325E3","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"single-server client-preprocessing PIR"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-94F83E6D9937F5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"computational"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-975F94CBE0D593","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"reduced relative to SealPIR in reported settings"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-98F1005B70E8CB","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"multiplicative-recursion"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-98F1E66DF599A1","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"sublinear-amortized-time"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-99AADA051B3E41","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"compressed recursive response"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-9A86FE0E222E90","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"query-compression"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-9AE3AD231D72DA","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"constant-rate-for-large-blocks"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-9B0109BAFD180E","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"two non-colluding replicated servers"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-9B89D0D21E8894","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"single-server PIR"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-9C675BC4AF6BC9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"replicated database updates"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-9CBAC98FC90F72","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"information-theoretic"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-9CBC37F84EF1F0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"model-dependent sublinear online communication"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-9D08FDC3977F5C","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"none"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-9D2755DBFF5342","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"sublinear-online-time"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-9D39D980C3A56A","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"single"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-9F44BE2D5C1D9E","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"multi-server doubly efficient PIR"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-9FA5072D6D7961","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"popularity-dependent database partitioning plus backend preprocessing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-A049C2F089D878","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"no-per-client-server-storage"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-A05C69C6C7D4C2","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"single"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-A1E36141DC493F","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"constant-time-updates"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-A23AF443A45E11","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"computational"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-A27B11BE8F2DF5","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"short DPF seeds"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-A290B6B04DED35","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"model-dependent sublinear online communication"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-A2CEB76C9E1337","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"silent-preprocessing"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-A3415CF856CDE8","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"linear point-function evaluation over the database"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-A3E228670B6E53","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"reusable-hint"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-A3F19F5B39B021","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"sublinear-offline-bandwidth"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-A6344B5B52967C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"polylogarithmic protocol state; exact vector pending audit"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-A6D4AF7CF23674","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"high-throughput"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-A812A0C4411EEC","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"Paillier-compressed response; exact row pending proceedings audit"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-A81B6A4F648122","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"client hint refresh per query; database refresh remains explicit"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-A898E531C45370","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"keys and compact client state"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-A9FA94C624BFEC","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"oblivious-expansion"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-AA6AF435F541BE","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"polylogarithmic amortized bandwidth"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-AB35903CB26BB3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"source-reported application-specific communication"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-AB9F8BE6FBCA2D","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"linear-time per-client hint generation"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-AC3352CC147A56","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"distributional index PIR"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-ACB3119EF7F703","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"near-square-root amortized per query"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-AD9436C18EBCF8","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"O(k+d) total communication for d-bit blocks"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-AE0D8502ADD096","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"adaptive-multi-query"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-AEA38D074FF24F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"single-server CPIR"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-AF88A130369E07","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"single computational or two-server statistical variants"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-AFA9EA9B133982","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"replicated database updates"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-B11033457F78EE","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"single-server client-preprocessing PIR"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-B1C085A104CCA0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"lattice parameter-dependent negligible failure"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-B4025744C2729B","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"near-square-root amortized online"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-B53B74C2DA3E57","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"adaptable-pseudorandom-sets"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-B61AAE15FE6B47","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"negligible decryption failure under lattice parameters"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-B7130179F299DD","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"public-preprocessing"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-B94A2203BCAAAE","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"O(n^epsilon) in the promoted abstract claim"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-BB96D14BDD689E","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"weak_privately_puncturable_prf"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-BC037A7A078F65","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"relaxed-correctness"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-BC8176B1CCFA7B","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"included in O(n^epsilon) total"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-BC8D92A7047B68","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"popularity_partitioned_classic_pir"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-BE16868E036876","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"no-extra-server-storage"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-BE995C20377F19","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"computational"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-C04220BDFAFD13","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"one-time per-client private hint"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-C1363F4BAB7FFB","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"included in the amortized communication bound"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-C2C876454CA190","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"computational"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-C328CC6D0E6F13","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"polylog-communication"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-C3E8C07F970906","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"Regev ciphertext query translated during evaluation"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-C40A593ACAD549","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"response-packing"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-C5007BA73403DE","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"subpolynomial profile; exact revised theorem required"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-C538E72433012C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"polylogarithmic protocol state"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-C54E002C117CB1","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"almost silent offline server work after an initial public key"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-C56C9AA08FBCD1","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"sublinear private hint plus blocklist metadata"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-C709FE4EA545E8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"included in polylogarithmic communication"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-C71C25484D57DB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"hint must track database changes"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-C8C0215BC02D6D","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"single"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-C8C236B85D060F","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"hints are stateful and tied to the database snapshot"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-C902F75C11F303","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"private-block-retrieval"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-C92BF12AB307A3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"lwe_gsw_fhe_composition"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-C9E13A79382CE6","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"single-server"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-C9E42AB94BFF2A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"compressed single-ciphertext query with recursive expansion"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-CA26CEC2527532","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"classic cryptographic query privacy"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-CAA38D72C4A956","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"lwe_matrix_vector_hint"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-CB085984014610","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"single-server private block retrieval"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-CC12D0B22CE6B3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"query-independent reusable client download"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-CC3A29528D9E8C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"replicated_combinatorial"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-CC5010E34A1938","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"reduced through multiplicative recursive packing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-CDE13FE8DB2651","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"no-extra-server-storage"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-CEE3C69C8A9703","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"single-server client-preprocessing PIR"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-D134B0AA1359FD","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"single-pass-preprocessing"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-D216E50D9D0472","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"included in near-square-root online communication"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-D3983050CCAEB9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"database encoding plus optional probabilistic batch-code layout"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-D4A674D71BB733","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"linear streaming pass with composed HE operations"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-D5805617577CB3","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"exact additive reconstruction"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-D66DFF954B4641","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"distributed_point_function"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-YPIR.md","id":"PIR-PROP-D6B62CB1FF2759","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-YPIR","value":"memory-bandwidth-oriented linear pass plus lightweight translation"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-D6C9F4815BC02A","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"part of polylogarithmic total communication"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-D755C8CF3F8EFF","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"negligible error under the stated parameterization"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-D78EA3599E62E4","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"compact DPF keys; exact bound pending theorem audit"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-D804480A3FCC56","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"single-server client-preprocessing PIR"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-D837271E593A40","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"cryptographic parameters and query state"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-D83DBB55C45D91","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"none"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-D8E605527A169B","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"direct database updates; no stored hint"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-D9D6FF6D1AC5A9","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"near-linear-preprocessing"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-D9DA8560C2FF46","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"source reports over 2 GB/s throughput"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-DA25BBC4C5902C","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"near-square-root private state"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-DA55DA86081D7D","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"sublinear hints"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-DB794F63C6823D","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"puncturable_pseudorandom_sets"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-DB871E5415F747","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"linear database homomorphic processing; batch amortization available"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-DB8816F6849446","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"sublinear private state"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-DBF979FC4BE931","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"polylog-online-bandwidth"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-DBFFECE1A46D71","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"backend-dependent"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-DC39BBBF9652F1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"single"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-DC479E4C313007","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"single"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-DCB31A7B71B209","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"two non-colluding replicas"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-DD03B58E73021E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"depends on recursion depth and record layout"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-DE4F1B58277771","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"batch-amortization"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-DE9C52D609C71F","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"constant-depth-preprocessing"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-DEC4D603385AF3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"single-server preprocessing PIR"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-DF06E3287315AD","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"static database in the primary construction"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-E0E106D3F112A2","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"homomorphic_thorp_shuffle"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-E141E462E0BFE6","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"sublinear online"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-E2AAA251242FBF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"sublinear online after shifting bulk work offline"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-E3436640F1B094","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"sublinear-communication"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-SIMPLEPIR.md","id":"PIR-PROP-E39CA342CBB70F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-SIMPLEPIR","value":"computational"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-E3FD42F6AEE7DB","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"public preprocessed structure; revised update profile pending"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-E487A8B1E6104B","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"polylogarithmic parameters and query state"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-E4CDE46ABDB72A","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"two-server client-preprocessing PIR"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-E5EC3B268B9B0A","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"two-server private blocklist lookup"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-E69C2F77023C01","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"single"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-THORPIR.md","id":"PIR-PROP-E74541E309F15C","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-THORPIR","value":"parallelizable-fhe"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-E751B5C36230FF","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"negligible failure in instantiated schemes"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-E7E1E5C4D55540","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"classical_information_theoretic_depir"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-E821C447F42042","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"subpolynomial profile; exact revised theorem required"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-E8CFEF00B63584","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"included in reported online communication"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-E9046FBE558A6B","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"single"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1998-CGKS-2S.md","id":"PIR-PROP-EA92F0EA0DA957","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1998-CGKS-2S","value":"stateless apart from query randomness"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-EB82A14101C97D","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"standard protocol correctness; exact failure semantics pending"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-EBE660614368AD","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"static database in the analyzed protocol"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-EC6ABFDD72A225","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"included in total source-reported communication"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-TREEPIR.md","id":"PIR-PROP-ECD9A1544911F6","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-TREEPIR","value":"polylogarithmic total bandwidth"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-ECFAC28F6DF753","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"near-square-root private state"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-ED0BEB248957A0","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"negligible failure with caching/PRP handling for arbitrary queries"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-ED5776D0400DB4","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"at least linear database work in the ordinary no-preprocessing model"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-DISTRIBUTIONAL.md","id":"PIR-PROP-EEC07E151DA140","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-DISTRIBUTIONAL","value":"database and popularity model updates both matter"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-DEPIR.md","id":"PIR-PROP-EF9537B8497BE7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-DEPIR","value":"polylogarithmic in database size"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-EFE51FD709BD20","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"multiplicative_homomorphic_recursion"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR.md","id":"PIR-PROP-F022F32ED70181","review_status":"fulltext_version_delta_pending","scope":"construction","subject_id":"PIR-CONSTRUCTION-2025-LLFMP-MULTISERVER-DEPIR","value":"subpolynomial online query time"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-F087C8B4B6509F","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"near-square-root amortized in the optimal FHE construction"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-F0C0A10444E288","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"adaptable_pseudorandom_sets"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-SPIRAL.md","id":"PIR-PROP-F0C603EEBCFAA9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-SPIRAL","value":"encoded database update cost depends on layout"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2022-CHK.md","id":"PIR-PROP-F164CF4C71B8A7","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2022-CHK","value":"homomorphic_two_server_compilation"},{"dimension":"update_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-ZLTS.md","id":"PIR-PROP-F1C904583BB554","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-ZLTS","value":"state refreshed across unbounded queries; database-update cost remains nontrivial"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-F26C621AA4830C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"linear in database size"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1999-CMS.md","id":"PIR-PROP-F2F1887031700B","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1999-CMS","value":"part of polylogarithmic total communication"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-F51980532D072B","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"sublinear online PIR work"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2014-DPF.md","id":"PIR-PROP-F5BBE1E6BDE5AC","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2014-DPF","value":"two non-colluding servers"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-CHECKLIST.md","id":"PIR-PROP-F6A0D63D98D815","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-CHECKLIST","value":"computational"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-F7BFCDB16CC39B","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"included in polylogarithmic online bandwidth"},{"dimension":"server_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-F812646667DEBE","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"single"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-FASTPIR.md","id":"PIR-PROP-F8B1898CD6CB73","review_status":"paper_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-FASTPIR","value":"parameterized HE correctness"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-SINGLEPASS.md","id":"PIR-PROP-F98CF54A93CBE9","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-SINGLEPASS","value":"two-server client-preprocessing PIR"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-1997-KO.md","id":"PIR-PROP-F9A5072247BF93","review_status":"abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-1997-KO","value":"single-server CPIR"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-MULPIR.md","id":"PIR-PROP-F9B2D4F135B27E","review_status":"scheme_declared","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-MULPIR","value":"tunable-communication-computation-tradeoff"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2005-GR.md","id":"PIR-PROP-F9E4C10E276DE3","review_status":"section_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2005-GR","value":"hidden_smooth_subgroups"},{"dimension":"correctness","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2020-CK-OFFLINE.md","id":"PIR-PROP-FA21976553410D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2020-CK-OFFLINE","value":"standard correctness in each variant"},{"dimension":"privacy_model","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2021-SACM.md","id":"PIR-PROP-FA247DEA1AFE31","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2021-SACM","value":"computational"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2018-SEALPIR.md","id":"PIR-PROP-FAE9CFE95BD49E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2018-SEALPIR","value":"encryption keys and small query state"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-FBECF4236CC98B","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"single-server low-client-storage PIR"},{"dimension":"query_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2024-PIANO.md","id":"PIR-PROP-FC004FE536357B","review_status":"fulltext_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2024-PIANO","value":"near-square-root online"},{"dimension":"server_work","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-FD74720355BC8A","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"near-square-root amortized per query"},{"dimension":"response_communication","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL.md","id":"PIR-PROP-FED6BDD1E48DF0","review_status":"theorem_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2023-LP-NEAR-OPTIMAL","value":"included in polylogarithmic bandwidth"},{"dimension":"client_storage","evidence_ref":"knowledge/primitives/pir/schemes/PIR-CONSTRUCTION-2026-ZIPPIR.md","id":"PIR-PROP-FFF8A4C9AE6075","review_status":"prepublication_abstract_reviewed","scope":"construction","subject_id":"PIR-CONSTRUCTION-2026-ZIPPIR","value":"no large client hint"}],"researchMap":{"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"nodes":{"PIR-RESULT-1997-KO-FIRST-NONTRIVIAL-SINGLE-SERVER-CPIR":{"anchor_roles":["first_feasibility","capability_boundary"],"group":"construction","label":"Single-server CPIR","lane_rationale":"Gives the first single-server computational PIR construction under quadratic residuosity; the concrete realization is its primary map role.","lenses":["communication"],"primary":true,"selection_rationale":"Removes replicated non-colluding servers by changing from information-theoretic to computational privacy.","thread":"roots_privacy","visibility":"backbone"},"PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION":{"group":"efficiency","label":"n^ε communication","lane_rationale":"This separately stored cost result states O(n^epsilon) single-server communication for each fixed positive epsilon, with unchanged linear server work and QR conditions.","lenses":["communication"],"selection_rationale":"Quantifies KO97's communication point and links it to the later CMS99 refinement.","thread":"roots_privacy","visibility":"reviewed_related"},"PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR":{"anchor_roles":["model_definition","first_feasibility"],"group":"foundation","label":"Information-theoretic PIR","lane_rationale":"Defines PIR and its replicated non-colluding-server privacy contract, establishing the field's research object.","lenses":["communication"],"primary":true,"selection_rationale":"Defines the PIR interface and the information-theoretic replicated-server starting point.","thread":"roots_privacy","visibility":"backbone"},"PIR-RESULT-1998-CGKS-TWO-SERVER-N-ONE-THIRD-COMMUNICATION":{"group":"efficiency","label":"Two-server n^(1/3)","lane_rationale":"The independently specified result is O(n^(1/3)) communication for two-server information-theoretic bit retrieval, not a new privacy model.","lenses":["communication"],"selection_rationale":"Retains the first concrete communication point from the defining paper without duplicating its definition node on the backbone.","thread":"multi_server_dpf","visibility":"reviewed_related"},"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION":{"anchor_roles":["capability_boundary"],"group":"efficiency","label":"Single-server CPIR with polylog communication","lane_rationale":"Reduces single-server communication from n^epsilon to polylogarithmic size under Phi assumptions while retaining linear server work.","lenses":["communication"],"primary":true,"selection_rationale":"Without CMS99, the map incorrectly jumps from KO97's n^epsilon communication directly to modern mechanisms and hides the classical polylogarithmic single-server frontier.","thread":"roots_privacy","visibility":"backbone"},"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING":{"anchor_roles":["model_definition"],"group":"foundation","label":"Preprocessing PIR model","lane_rationale":"Introduces server preprocessing as a model with separate auxiliary storage, offline work and online-query resources.","lenses":["preprocessing"],"primary":true,"selection_rationale":"Makes preprocessing ownership a first-class model axis and opens both the client-specific and public/server-preprocessing programs.","thread":"preprocessing_theory","threads":["public_preprocessing_depir"],"visibility":"backbone"},"PIR-RESULT-2000-BIM-LINEAR-WORK-BARRIER-WITHOUT-PREPROCESSING":{"anchor_roles":["lower_bound_or_barrier"],"group":"foundation","label":"Linear-work barrier","lane_rationale":"Proves a linear total server bit-probe lower bound in the original-database/no-preprocessing model, not an implementation bottleneck claim.","lenses":["server_work","preprocessing"],"selection_rationale":"Explains why ordinary PIR cannot obtain sublinear server work without moving cost into preprocessing or another model change.","thread":"preprocessing_theory","threads":["public_preprocessing_depir"],"visibility":"backbone"},"PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL":{"anchor_roles":["capability_boundary"],"group":"efficiency","label":"Constant-rate private blocks","lane_rationale":"The node's principal delta is O(k+d) block-retrieval communication and constant rate for sufficiently large blocks, not a new general PIR model.","lenses":["communication"],"primary":true,"selection_rationale":"Changes the retrieval unit from a bit to a block and makes communication rate, rather than only absolute communication, part of the single-server PIR frontier.","thread":"roots_privacy","visibility":"backbone"},"PIR-RESULT-2014-GI-DPF-COMPACT-TWO-SERVER-PIR-QUERIES":{"group":"construction","label":"Compact DPF queries","lane_rationale":"Instantiates PIR selectors with two DPF keys whose local evaluations produce answer shares, a reusable protocol-construction mechanism.","lenses":["communication"],"selection_rationale":"Records the PIR efficiency consequence of the DPF mechanism without treating it as a separate historical transition.","thread":"multi_server_dpf","visibility":"reviewed_related"},"PIR-RESULT-2014-GI-DPF-INTRODUCED-DISTRIBUTED-POINT-FUNCTIONS":{"anchor_roles":["reusable_mechanism"],"group":"foundation","label":"Distributed point functions","lane_rationale":"Defines distributed point functions and their share-generation/evaluation contract; the separate PIR application realizes compact queries.","lenses":["communication"],"primary":true,"selection_rationale":"Introduces a compact selector-sharing mechanism repeatedly reused in lightweight two-server systems.","thread":"multi_server_dpf","visibility":"backbone"},"PIR-RESULT-2018-SEALPIR-PROBABILISTIC-BATCH-CODES-AMORTIZE-PROCESSING":{"group":"efficiency","label":"Batch-code amortization","lane_rationale":"Amortizes server work across one client's batch through probabilistic batch codes; its speedup is not an isolated-query claim.","lenses":["server_work","deployment_performance"],"selection_rationale":"Important optimization within SealPIR, but batching does not replace the compressed-query architecture as the paper's default transition.","thread":"he_query_compression","visibility":"reviewed_related"},"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES":{"anchor_roles":["practice_transition","reusable_mechanism"],"group":"efficiency","label":"Compressed RLWE queries","lane_rationale":"The node's principal delta compresses client queries and shifts expansion work to the server; the claimed query-size gain is parameter specific.","lenses":["communication","deployment_performance"],"primary":true,"selection_rationale":"Marks the practical single-server lattice-PIR transition through recursive encrypted-query expansion and compression.","thread":"he_query_compression","visibility":"backbone"},"PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF":{"group":"foundation","label":"Optimal offline/online tradeoff","lane_rationale":"Proves the offline-communication times online-probes lower bound for unencoded stateless server storage; matching constructions do not change its lower-bound role.","lenses":["server_work","preprocessing"],"selection_rationale":"Supplies CK20's trade-off theorem and the predecessor bound later sharpened by Yeo23.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE":{"anchor_roles":["first_feasibility","capability_boundary"],"group":"efficiency","label":"Sublinear online work","lane_rationale":"Moves query-independent data to private client state to reduce online probes without additional server storage, with offline costs and variants explicit.","lenses":["server_work","preprocessing"],"primary":true,"selection_rationale":"Establishes sublinear online lookups without extra server storage and starts the modern client-preprocessing chain.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2021-ALI-TRADEOFFS-FASTPIR-COMPRESSED-SEALPIR-TRADEOFF":{"group":"efficiency","label":"FastPIR compression trade-off","lane_rationale":"Reduces SealPIR communication through compression/expansion changes while preserving essentially the same computation in the evaluated settings.","lenses":["communication","server_work","deployment_performance"],"primary":true,"selection_rationale":"Preserves the important SealPIR optimization branch and its explicit communication-versus-computation comparison without treating it as a new capability boundary.","thread":"he_query_compression","visibility":"reviewed_related"},"PIR-RESULT-2021-ALI-TRADEOFFS-MULPIR-MULTIPLICATIVE-RECURSION-TRADEOFF":{"group":"efficiency","label":"MulPIR recursive multiplication","lane_rationale":"Uses multiplicative recursion to trade additional server computation for reduced communication on large records; the trade-off is the primary claim.","lenses":["communication","server_work","deployment_performance"],"selection_rationale":"Records a distinct multiplicative-recursion mechanism whose preferred operating point depends on entry size and server cost.","thread":"he_query_compression","visibility":"reviewed_related"},"PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES":{"group":"efficiency","label":"Logarithmic updates","lane_rationale":"A bucketed dynamic layer reduces blocklist update work to logarithmic amortized cost; the gain is scoped to the application data structure.","lenses":["preprocessing","updates"],"selection_rationale":"Makes the hidden database-refresh cost explicit and supplies the baseline later improved by SinglePass.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS":{"anchor_roles":["practice_transition"],"group":"efficiency","label":"Checklist practice bridge","lane_rationale":"Beyond an artifact, the contribution removes a security-parameter factor from CK-style online work and evaluates the resulting blocklist protocol in its application setting.","lenses":["server_work","preprocessing","deployment_performance","adaptivity_state","updates"],"primary":true,"selection_rationale":"First concrete systems bridge in this corpus from CK20-style sublinear private preprocessing to a browser-shaped dynamic blocklist workload.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR":{"anchor_roles":["capability_boundary","current_frontier"],"group":"efficiency","label":"Near-optimal two-server preprocessing","lane_rationale":"Combines near-square-root online work/client storage with polylogarithmic bandwidth for unbounded queries in the two-server private-preprocessing setting.","lenses":["communication","server_work","preprocessing","adaptivity_state"],"primary":true,"selection_rationale":"Establishes the unbounded-query two-server square-root-time and polylog-bandwidth point that later single-server compilers explicitly use.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2021-SACM-PRIVATELY-PUNCTURABLE-PSEUDORANDOM-SETS":{"group":"construction","label":"Privately puncturable PR sets","lane_rationale":"Constructs a reusable puncture-and-refresh mechanism maintaining client hints without extra per-client server storage.","lenses":["preprocessing","adaptivity_state"],"selection_rationale":"Reusable refresh mechanism behind SACM21 and the starting object modified by later near-optimal constructions.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR":{"anchor_roles":["first_feasibility","capability_boundary"],"group":"efficiency","label":"Adaptive single-server amortization","lane_rationale":"Advances the amortized server-time/client-storage profile for adaptive single-server queries using persistent client state and refresh; preprocessing costs remain explicit.","lenses":["server_work","preprocessing","adaptivity_state"],"primary":true,"selection_rationale":"Changes the semantic contract to adaptive multi-query single-server PIR while keeping both amortized server time and extra storage sublinear.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2022-CHK-ADAPTIVE-STORAGE-TIME-LOWER-BOUND":{"anchor_roles":["lower_bound_or_barrier"],"group":"foundation","label":"Adaptive storage–time bound","lane_rationale":"Proves the adaptive multi-query client-storage times amortized server-time lower bound for an unmodified database.","lenses":["server_work","preprocessing","adaptivity_state"],"selection_rationale":"Explains the square-root target later matched by Piano and prevents sublinear online work from being read without its client-storage cost.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION":{"group":"construction","label":"Homomorphic single-server compiler","lane_rationale":"Provides the reusable homomorphic compiler from a two-server offline interaction to single-server multi-query PIR.","lenses":["preprocessing","adaptivity_state"],"selection_rationale":"Exposes the compilation mechanism used and modified by later near-optimal single-server work.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND":{"anchor_roles":["lower_bound_or_barrier","capability_boundary"],"group":"foundation","label":"Public-hint storage–time bound","lane_rationale":"Proves a public-hint storage–time lower bound in a stated computational cell-probe range rather than an upper-bound efficiency advance.","lenses":["server_work","preprocessing"],"primary":true,"selection_rationale":"Separates public/server preprocessing from private client preprocessing by proving a stronger storage–time lower bound in the public-hint cell-probe model.","thread":"public_preprocessing_depir","visibility":"backbone"},"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION":{"anchor_roles":["reusable_mechanism","practice_transition"],"group":"construction","label":"Regev→GSW translation","lane_rationale":"Introduces ciphertext translation as a reusable mechanism separating the query's communication representation from server evaluation.","lenses":["deployment_performance"],"primary":true,"selection_rationale":"Introduces the ciphertext-translation mechanism that creates Spiral's distinct high-rate practical family.","thread":"he_query_compression","visibility":"backbone"},"PIR-RESULT-2022-SPIRAL-SPIRALSTREAM-HIGH-RATE-THROUGHPUT":{"group":"efficiency","label":"SpiralStream throughput","lane_rationale":"A streaming specialization reports a named throughput/response-rate improvement in a specified large-record setting; the raw run remains separate.","lenses":["server_work","deployment_performance"],"selection_rationale":"Source-bound streaming result illustrates the mechanism's concrete regime without turning one benchmark into a universal ranking.","thread":"he_query_compression","visibility":"reviewed_related"},"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE":{"anchor_roles":["first_feasibility","capability_boundary"],"group":"construction","label":"Unkeyed DEPIR","lane_rationale":"Realizes unkeyed DEPIR with deterministic public preprocessing from Ring-LWE; public preprocessing and unkeyed security qualify this concrete construction.","lenses":["preprocessing"],"primary":true,"selection_rationale":"Establishes standard-assumption single-server unkeyed DEPIR with public preprocessing and polylogarithmic online costs.","thread":"public_preprocessing_depir","visibility":"backbone"},"PIR-RESULT-2023-LMW-DEPIR-POLYLOG-ONLINE-TIME-AND-COMMUNICATION":{"group":"efficiency","label":"Polylog online cost","lane_rationale":"Records the polylogarithmic query-time/communication frontier with O(N^(1+epsilon)) preprocessing and O(N^epsilon) updates, not cost-free preprocessing.","lenses":["communication","server_work","preprocessing"],"selection_rationale":"Quantifies the LMW23 online frontier while the unkeyed-DEPIR capability node carries the paper's default transition.","thread":"public_preprocessing_depir","visibility":"reviewed_related"},"PIR-RESULT-2023-LP-NEAR-OPTIMAL-ADAPTABLE-PSEUDORANDOM-SETS":{"group":"construction","label":"Adaptable PR sets","lane_rationale":"Defines and constructs the adaptable-set update mechanism with its paper-specific intermediate-key security contract.","lenses":["preprocessing","adaptivity_state"],"selection_rationale":"Distinct add/remove mechanism explaining how LP23 differs technically from the parallel ZLTS23 result.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2023-LP-NEAR-OPTIMAL-SINGLE-SERVER-PREPROCESSING-FRONTIER":{"group":"efficiency","label":"Independent near-optimal PIR","lane_rationale":"Independently attains near-square-root amortized server/client-state costs with polylogarithmic bandwidth; independent progress does not imply inheritance from ZLTS.","lenses":["communication","server_work","preprocessing","adaptivity_state"],"primary":true,"selection_rationale":"Preserves independent attribution for the same near-optimal frontier without duplicating the default transition.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2023-SIMPLEPIR-DOUBLEPIR-COMPRESSED-HINT":{"group":"efficiency","label":"DoublePIR compressed hint","lane_rationale":"Reduces client hint size in a matched setting while increasing per-query communication and reducing throughput; this is an explicit resource trade-off.","lenses":["client_hint","deployment_performance"],"selection_rationale":"Exposes the hint-size trade-off inside the SimplePIR family without creating a separate default architecture.","thread":"hint_matrix","visibility":"reviewed_related"},"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC":{"anchor_roles":["practice_transition"],"group":"efficiency","label":"Memory-bound LWE matvec","lane_rationale":"Reorganizes online computation into a memory-bandwidth-oriented matrix-vector product and reports its throughput with a large reusable client hint.","lenses":["server_work","deployment_performance"],"primary":true,"selection_rationale":"Changes the practical objective from asymptotically sublinear work to a linear pass approaching memory bandwidth with a reusable public hint.","thread":"hint_matrix","visibility":"backbone"},"PIR-RESULT-2023-TREEPIR-DDH-BASED-SUBLINEAR-TIME-POLYLOG-BANDWIDTH-PIR":{"group":"construction","label":"TreePIR from DDH","lane_rationale":"Realizes the two-server preprocessing cost target with weak privately puncturable PRFs from DDH; the changed assumption is a qualified property, not its own lane.","lenses":["communication","server_work","preprocessing","adaptivity_state"],"primary":true,"selection_rationale":"Shows that the SACM-style two-server cost program can be reached from the weaker DDH assumption with a different puncturing mechanism; it is an assumption branch rather than a new default frontier.","thread":"multi_server_dpf","threads":["preprocessing_theory"],"visibility":"reviewed_related"},"PIR-RESULT-2023-YEO-OMV-BARRIER-FOR-GENERAL-PIR-LOWER-BOUNDS":{"group":"foundation","label":"OMV lower-bound barrier","lane_rationale":"Relates stronger lower bounds in a broader computational model to the OMV conjecture, delimiting lower-bound techniques rather than excluding PIR.","lenses":["server_work","preprocessing"],"selection_rationale":"Explains why the tight theorem is model-scoped and why substantially more general lower bounds are difficult.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2023-YEO-TIGHT-PRIVATE-PREPROCESSING-STORAGE-TIME-LOWER-BOUND":{"anchor_roles":["lower_bound_or_barrier"],"group":"foundation","label":"Tight hint–probe bound","lane_rationale":"Sharpens the hint-size/probe lower bound and scoped batch-query extension in the replication model.","lenses":["server_work","preprocessing","adaptivity_state"],"primary":true,"selection_rationale":"Closes the private-preprocessing storage/probe gap in the stated model and supplies the matching lower-bound anchor for the construction chain.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR":{"anchor_roles":["capability_boundary","current_frontier"],"group":"efficiency","label":"Near-optimal single-server bandwidth","lane_rationale":"Advances single-server preprocessing bandwidth to polylogarithmic while retaining near-square-root amortized work and client storage under LWE.","lenses":["communication","server_work","preprocessing","adaptivity_state"],"primary":true,"selection_rationale":"Reaches the near-optimal single-server square-root computation and polylogarithmic bandwidth point for unbounded adaptive queries.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2023-ZLTS-PRIVATELY-PROGRAMMABLE-PSEUDORANDOM-SETS":{"group":"construction","label":"Programmable PR sets","lane_rationale":"Constructs programmable pseudorandom sets to batch and homomorphically realize refresh operations; it is a component rather than a complete PIR scheme.","lenses":["preprocessing","adaptivity_state"],"selection_rationale":"Named mechanism that batches refresh operations in the ZLTS23 single-server compiler.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2024-PIANO-PRACTICAL-SINGLE-SERVER-SUBLINEAR-TIME-PIR":{"anchor_roles":["practice_transition"],"group":"efficiency","label":"Practical sublinear single-server PIR","lane_rationale":"Provides a contextual practical-scaling finding for sublinear online work on databases up to 100 GB, rather than merely announcing the Go artifact.","lenses":["server_work","preprocessing","deployment_performance","adaptivity_state"],"primary":true,"selection_rationale":"Demonstrates that single-server sublinear online work can be implemented concretely using PRFs rather than only heavy theoretical machinery.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2024-PIANO-PRF-ONLY-OPTIMAL-CLIENT-PREPROCESSING":{"group":"construction","label":"PRF-only Piano construction","lane_rationale":"The selected primary contribution is a self-contained PRF-only PIR construction avoiding heavier cryptographic machinery; its bound match is separately qualified on the edge.","lenses":["server_work","preprocessing","adaptivity_state"],"selection_rationale":"Construction-level mechanism behind Piano's practical transition; kept related so one paper does not occupy two default nodes for one transition.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2024-SINGLEPASS-CONSTANT-TIME-DATABASE-UPDATES":{"group":"efficiency","label":"Constant-time updates","lane_rationale":"Reduces hint-update work to worst-case constant edits and amortized constant appends without the earlier logarithmic query-bandwidth overhead.","lenses":["preprocessing","updates"],"selection_rationale":"Separates the dynamic-database capability from the paper's preprocessing-speed contribution.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING":{"anchor_roles":["practice_transition","capability_boundary"],"group":"efficiency","label":"One-pass client preprocessing","lane_rationale":"Reduces enrollment preprocessing to exactly one database pass and reports scoped preprocessing/query improvements.","lenses":["preprocessing","deployment_performance","adaptivity_state","updates"],"primary":true,"selection_rationale":"Changes practical enrollment to one database pass and anchors the dynamic client-preprocessing branch.","thread":"preprocessing_theory","visibility":"backbone"},"PIR-RESULT-2024-THORPIR-CONSTANT-DEPTH-HOMOMORPHIC-THORP-PREPROCESSING":{"group":"efficiency","label":"Homomorphic Thorp preprocessing","lane_rationale":"Reduces homomorphic hint-generation depth to a constant with linear circuit size and sublinear offline communication; accelerator estimates remain distinct from measured deployment.","lenses":["preprocessing","deployment_performance"],"primary":true,"selection_rationale":"Important FHE preprocessing-circuit refinement, but its accelerator assumptions do not replace the default PRF practice transition.","thread":"preprocessing_theory","visibility":"reviewed_related"},"PIR-RESULT-2024-YPIR-HIGH-THROUGHPUT-LWE-TO-RLWE-TRANSLATION":{"group":"construction","label":"LWE→RLWE throughput","lane_rationale":"The atomic mechanism packs the DoublePIR response into an RLWE representation while preserving the matrix-vector online path; its measured point remains conditional.","lenses":["server_work","deployment_performance"],"selection_rationale":"Captures the translation optimization and its measured regime without duplicating YPIR's silent-preprocessing transition.","thread":"silent_conversion","visibility":"reviewed_related"},"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD":{"anchor_roles":["capability_boundary","practice_transition"],"group":"efficiency","label":"Silent preprocessing","lane_rationale":"Eliminates downloaded client hints by moving preprocessing state to the server, at the price of larger online queries rather than an unconditional improvement.","lenses":["client_hint","preprocessing","deployment_performance"],"primary":true,"selection_rationale":"Removes the large offline client download from the high-throughput hint family, changing preprocessing ownership rather than merely improving a number.","thread":"silent_conversion","visibility":"backbone"},"PIR-RESULT-2025-DISTRIBUTIONAL-CLASSIC-PIR-BLACK-BOX-COMPILER":{"group":"construction","label":"Classic→distributional compiler","lane_rationale":"Provides a black-box transform from classic batch PIR to popularity-partitioned distributional PIR with relaxed correctness.","lenses":["server_work","deployment_performance","correctness_contract"],"selection_rationale":"Shows how the new correctness model composes with classic PIR rather than constituting a new backend family.","thread":"distributional_correctness","visibility":"reviewed_related"},"PIR-RESULT-2025-DISTRIBUTIONAL-DISTRIBUTIONAL-PIR-WITH-RELAXED-CORRECTNESS":{"group":"foundation","label":"Distributional correctness","lane_rationale":"Defines distribution-dependent correctness while retaining classic query indistinguishability, introducing a new model rather than merely improving classic PIR.","lenses":["server_work","deployment_performance","correctness_contract"],"primary":true,"selection_rationale":"Changes the correctness contract while preserving query privacy, so it must be visible but not merged into the classic-PIR efficiency backbone.","thread":"distributional_correctness","visibility":"reviewed_related"},"PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR":{"anchor_roles":["capability_boundary","current_frontier"],"group":"construction","label":"Information-theoretic multi-server DEPIR","lane_rationale":"Realizes information-theoretic DEPIR with multiple non-colluding servers and subpolynomial online costs; it changes the server/security setting rather than dominating one-server DEPIR.","lenses":["server_work","preprocessing"],"primary":true,"selection_rationale":"Removes computational assumptions from DEPIR by changing to the multi-server non-collusion model while retaining near-linear preprocessing and subpolynomial queries.","thread":"public_preprocessing_depir","visibility":"backbone"},"PIR-RESULT-2025-LMW-BLACKBOX-BLACK-BOX-PRIMITIVES-COLLAPSE-TO-ONE-WAY-FUNCTIONS-FOR-SK-DEPIR":{"anchor_roles":["lower_bound_or_barrier","current_frontier"],"group":"foundation","label":"Black-box collapse","lane_rationale":"Proves a black-box construction-power collapse in a specified SK-DEPIR oracle framework, not a generic impossibility for structured DEPIR.","lenses":["preprocessing"],"primary":true,"selection_rationale":"Narrows which generic black-box ingredients can plausibly yield secret-key DEPIR and anchors the current barrier branch.","thread":"public_preprocessing_depir","visibility":"backbone"},"PIR-RESULT-2025-LMW-BLACKBOX-TWO-ROUND-PASSIVE-SERVER-BLACK-BOX-BARRIER":{"group":"foundation","label":"Two-round black-box barrier","lane_rationale":"Proves a scoped two-round passive-server black-box barrier with locality/correctness restrictions; other rounds and non-black-box methods are not excluded.","lenses":["preprocessing","server_work"],"selection_rationale":"Retains the strongest scoped impossibility statement while avoiding presentation as a general DEPIR impossibility.","thread":"public_preprocessing_depir","visibility":"reviewed_related"},"PIR-RESULT-2026-ZIPPIR-HIGH-THROUGHPUT-WITHOUT-CLIENT-HINT-STORAGE":{"group":"efficiency","label":"Hintless high throughput","lane_rationale":"The contextual efficiency result trades client hints for small refreshable per-client server state and almost-silent offline work; reported throughput is setting specific.","lenses":["client_hint","deployment_performance"],"selection_rationale":"Separates the claimed capability from the compression mechanism while proceedings and artifact review remain incomplete.","thread":"silent_conversion","visibility":"reviewed_related"},"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION":{"anchor_roles":["reusable_mechanism","current_frontier"],"group":"construction","label":"LWE→Paillier compression","lane_rationale":"Provides a reusable lattice-to-additive-ciphertext compression mechanism by homomorphically evaluating the linear decryption phase.","lenses":["client_hint","deployment_performance"],"primary":true,"selection_rationale":"Candidate mechanism for removing large client hints while preserving high throughput; kept with explicit prepublication maturity.","thread":"silent_conversion","visibility":"backbone"}},"overview_reading_path":["PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR","PIR-RESULT-1997-KO-FIRST-NONTRIVIAL-SINGLE-SERVER-CPIR","PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION","PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL","PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","PIR-RESULT-2014-GI-DPF-INTRODUCED-DISTRIBUTED-POINT-FUNCTIONS","PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR","PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","PIR-RESULT-2024-PIANO-PRACTICAL-SINGLE-SERVER-SUBLINEAR-TIME-PIR","PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING","PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR","PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION"],"problems":[{"id":"communication","label":"Communication","question":"How small can PIR queries and answers be under each server and preprocessing model?","reading_path":["PIR-RESULT-1998-CGKS-TWO-SERVER-N-ONE-THIRD-COMMUNICATION","PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION","PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL","PIR-RESULT-2014-GI-DPF-COMPACT-TWO-SERVER-PIR-QUERIES","PIR-RESULT-2023-LMW-DEPIR-POLYLOG-ONLINE-TIME-AND-COMMUNICATION"]},{"id":"server_work","label":"Server work","question":"Can PIR reduce online server work below a full database scan without hiding costs elsewhere?","reading_path":["PIR-RESULT-2000-BIM-LINEAR-WORK-BARRIER-WITHOUT-PREPROCESSING","PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","PIR-RESULT-2023-YEO-TIGHT-PRIVATE-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","PIR-RESULT-2024-PIANO-PRACTICAL-SINGLE-SERVER-SUBLINEAR-TIME-PIR","PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","PIR-RESULT-2024-YPIR-HIGH-THROUGHPUT-LWE-TO-RLWE-TRANSLATION"]},{"id":"client_hint","label":"Client storage and hints","question":"Which designs remove or compress client hints without sacrificing throughput?","reading_path":["PIR-RESULT-2023-SIMPLEPIR-DOUBLEPIR-COMPRESSED-HINT","PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","PIR-RESULT-2026-ZIPPIR-HIGH-THROUGHPUT-WITHOUT-CLIENT-HINT-STORAGE"]},{"id":"preprocessing","label":"Preprocessing","question":"What is gained, assumed, or ruled out when work moves offline?","reading_path":["PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF","PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR","PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND","PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR","PIR-RESULT-2025-LMW-BLACKBOX-TWO-ROUND-PASSIVE-SERVER-BLACK-BOX-BARRIER"]},{"id":"deployment_performance","label":"Deployment performance","question":"Which mechanisms survive implementation and contextual measurement on large databases?","reading_path":["PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","PIR-RESULT-2022-SPIRAL-SPIRALSTREAM-HIGH-RATE-THROUGHPUT","PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","PIR-RESULT-2024-YPIR-HIGH-THROUGHPUT-LWE-TO-RLWE-TRANSLATION","PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION"]},{"id":"adaptivity_state","label":"Adaptivity and state","question":"Which schemes support adaptive queries, and where do mutable hints or per-client state live?","reading_path":["PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR","PIR-RESULT-2024-PIANO-PRACTICAL-SINGLE-SERVER-SUBLINEAR-TIME-PIR","PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING"]},{"id":"updates","label":"Database updates","question":"How does a database change invalidate, refresh, or incrementally update preprocessing state?","reading_path":["PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES","PIR-RESULT-2024-SINGLEPASS-CONSTANT-TIME-DATABASE-UPDATES","PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE"]},{"id":"correctness_contract","label":"Correctness contract","question":"Which results change success or failure semantics while retaining query privacy?","reading_path":["PIR-RESULT-2025-DISTRIBUTIONAL-DISTRIBUTIONAL-PIR-WITH-RELAXED-CORRECTNESS"]}],"relations":[{"change_dimensions":["model","security","assumption"],"evidence_locator":"KO abstract and introduction","evidence_url":"https://doi.org/10.1109/SFCS.1997.646125","id":"lineage-a528bb3c85e12ffd","map_relation":"reference","predecessor":"PIR-RESULT-1998-CGKS-DEFINED-INFORMATION-THEORETIC-PIR","relation_basis":"model_relation","relation_type":"CHANGES_SECURITY_MODEL","review_status":"abstract_checked","statement":"KO retains the CGKS index-privacy objective but replaces replicated non-colluding servers with one server and computational privacy under quadratic residuosity.","successor":"PIR-RESULT-1997-KO-FIRST-NONTRIVIAL-SINGLE-SERVER-CPIR"},{"change_dimensions":["efficiency","assumption"],"evidence_locator":"CMS99 Introduction and Main Theorem, PDF pp. 2-3","evidence_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/pirpolylog.pdf","id":"lineage-da8c9527875e2ab4","map_relation":"lineage","predecessor":"PIR-RESULT-1997-KO-QUADRATIC-RESIDUOSITY-N-EPSILON-COMMUNICATION","relation_basis":"result_progression","relation_type":"CHANGES_ASSUMPTION","review_status":"fulltext_checked","statement":"CMS99 explicitly takes KO97's single-server n^epsilon communication result as its starting boundary and obtains polylogarithmic communication under the new Phi assumptions.","successor":"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION"},{"change_dimensions":["model","efficiency"],"evidence_locator":"CK20 abstract and introduction","evidence_url":"https://eprint.iacr.org/2019/1075.pdf","id":"lineage-ce6257af2de352e8","map_relation":"lineage","predecessor":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","relation_basis":"model_relation","relation_type":"CHANGES_PREPROCESSING","review_status":"primary_source_checked","statement":"CK20 develops the offline/online PIR program using query-independent private client state rather than BIM-style auxiliary server storage, enabling sublinear online lookups without increasing server storage; its lower bound is scoped to the unencoded/no-extra-server-state model.","successor":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE"},{"change_dimensions":["model","assumption","efficiency"],"evidence_locator":"LMW23 abstract and introduction","evidence_url":"https://eprint.iacr.org/2022/1703.pdf","id":"lineage-8d61fea9dc9e2a13","map_relation":"lineage","predecessor":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","relation_basis":"model_relation","relation_type":"CHANGES_PREPROCESSING","review_status":"primary_source_checked","statement":"LMW23 develops public server preprocessing into unkeyed single-server DEPIR with deterministic client-independent preprocessing and polylogarithmic online time and communication under Ring-LWE. Its preprocessing and update costs remain part of the model.","successor":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE"},{"change_dimensions":["model","efficiency"],"evidence_locator":"SACM21 Introduction and Theorem 1.1, PDF pp. 1-4","evidence_url":"https://eprint.iacr.org/2020/1592.pdf","id":"lineage-5cc9b6ec997e9111","map_relation":"lineage","predecessor":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","relation_basis":"model_relation","relation_type":"CHANGES_PREPROCESSING","review_status":"fulltext_checked","statement":"SACM21 develops the PIR preprocessing program through two-server private client preprocessing, attaining unbounded queries with near-square-root online work/client storage and polylogarithmic bandwidth. This differs from BIM's auxiliary-server-storage setting.","successor":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR"},{"change_dimensions":["efficiency","functionality"],"evidence_locator":"SACM21 Introduction, discussion of CK20, and Theorem 1.1","evidence_url":"https://eprint.iacr.org/2020/1592.pdf","id":"lineage-fae37e1521f63497","map_relation":"lineage","predecessor":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"fulltext_checked","statement":"SACM21 starts from the CK20 two-server client-preprocessing line and preserves its near-square-root online computation while reducing online bandwidth to polylogarithmic for unbounded queries.","successor":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR"},{"change_dimensions":["mechanism","efficiency","implementation"],"evidence_locator":"Checklist Sections 2.2-3, USENIX PDF pp. 878-881","evidence_url":"https://www.usenix.org/system/files/sec21-kogan.pdf","id":"lineage-1949d26f80cdbd08","map_relation":"lineage","predecessor":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"fulltext_checked","statement":"Checklist adapts the CK20 offline/online PIR approach into a concrete two-server blocklist system and evaluates sublinear server-side lookups.","successor":"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS"},{"change_dimensions":["mechanism","model","functionality","efficiency"],"evidence_locator":"CHK22 Introduction, Sections 1.1 and 3-5","evidence_url":"https://eprint.iacr.org/2022/081.pdf","id":"lineage-8f9ecff8b4fc1591","map_relation":"lineage","predecessor":"PIR-RESULT-2020-CK-SUBLINEAR-ONLINE-LOOKUPS-WITHOUT-EXTRA-SERVER-STORAGE","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"fulltext_checked","statement":"CHK22 extends the offline/online line from isolated lookups to a single-server, adaptive multi-query scheme with sublinear amortized time and storage.","successor":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Spiral abstract and Introduction, comparison with ACLS18","evidence_url":"https://eprint.iacr.org/2022/368.pdf","id":"lineage-6848733ce6b86f42","map_relation":"lineage","predecessor":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"Spiral introduces Regev-to-GSW ciphertext translation and reports query-size, response-rate and throughput improvements relative to prior lattice PIR systems including SealPIR in the paper's evaluated settings; the comparison is not an unconditional ranking across workloads.","successor":"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION"},{"change_dimensions":["mechanism","model","assumption","security"],"evidence_locator":"ZLTS23 Sections 2.1-2.2, PDF pp. 5-10","evidence_url":"https://eprint.iacr.org/2022/609.pdf","id":"lineage-60334d2780b84842","map_relation":"lineage","predecessor":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","relation_basis":"technical_dependency","relation_type":"CHANGES_SECURITY_MODEL","review_status":"fulltext_checked","statement":"ZLTS23 explicitly takes the SACM21 optimal two-server scheme as its starting point and homomorphically compiles its offline and refresh interactions into one server.","successor":"PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR"},{"change_dimensions":["efficiency"],"evidence_locator":"ZLTS23 Abstract, Table 1, and Theorem 1.1","evidence_url":"https://eprint.iacr.org/2022/609.pdf","id":"lineage-e3940f790a9028c7","map_relation":"lineage","predecessor":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"fulltext_checked","statement":"ZLTS23 keeps CHK22's near-square-root single-server computation and storage profile while reducing amortized bandwidth from near-square-root to polylogarithmic.","successor":"PIR-RESULT-2023-ZLTS-OPTIMAL-SINGLE-SERVER-PREPROCESSING-PIR"},{"change_dimensions":["mechanism"],"evidence_locator":"ZLTS23 Section 2.2, PDF pp. 8-10","evidence_url":"https://eprint.iacr.org/2022/609.pdf","id":"lineage-75e4231e3f3b72c5","map_relation":"lineage","predecessor":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"fulltext_checked","statement":"ZLTS23 says its batched-refresh idea is inspired by CHK22 and strengthens the compilation with privately programmable pseudorandom sets.","successor":"PIR-RESULT-2023-ZLTS-PRIVATELY-PROGRAMMABLE-PSEUDORANDOM-SETS"},{"change_dimensions":["efficiency"],"evidence_locator":"LP23 Abstract and Introduction, PDF pp. 1-4","evidence_url":"https://eprint.iacr.org/2022/830.pdf","id":"lineage-358457a620db1c37","map_relation":"lineage","predecessor":"PIR-RESULT-2022-CHK-ADAPTIVE-SINGLE-SERVER-SUBLINEAR-AMORTIZED-PIR","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"fulltext_checked","statement":"LP23 identifies CHK22's near-square-root single-server time but near-square-root bandwidth as the remaining gap and independently reaches polylogarithmic amortized bandwidth.","successor":"PIR-RESULT-2023-LP-NEAR-OPTIMAL-SINGLE-SERVER-PREPROCESSING-FRONTIER"},{"change_dimensions":["bounds","model"],"evidence_locator":"Yeo23 Sections 1.1 and 3, Theorems 2, 5, and 6","evidence_url":"https://eprint.iacr.org/2022/828.pdf","id":"lineage-8e473fc5ce1b74db","map_relation":"lineage","predecessor":"PIR-RESULT-2020-CK-OPTIMAL-OFFLINE-ONLINE-TRADEOFF","relation_basis":"analysis","relation_type":"SHARPENS_BOUND","review_status":"fulltext_checked","statement":"Yeo23 closes the multiplicative logarithmic gap in CK20's single-query private-preprocessing storage-time lower bound and generalizes the trade-off to batch queries.","successor":"PIR-RESULT-2023-YEO-TIGHT-PRIVATE-PREPROCESSING-STORAGE-TIME-LOWER-BOUND"},{"change_dimensions":["bounds","efficiency","assumption"],"evidence_locator":"Piano Section 1.1, PDF p. 3","evidence_url":"https://eprint.iacr.org/2023/452.pdf","id":"lineage-4c438d67cacf1ffe","map_relation":"lineage","predecessor":"PIR-RESULT-2022-CHK-ADAPTIVE-STORAGE-TIME-LOWER-BOUND","relation_basis":"analysis","relation_type":"MATCHES_BOUND","review_status":"fulltext_checked","statement":"Piano explicitly states that its PRF-only construction matches the CHK22 adaptive client-storage times server-time lower bound up to polylogarithmic factors.","successor":"PIR-RESULT-2024-PIANO-PRF-ONLY-OPTIMAL-CLIENT-PREPROCESSING"},{"change_dimensions":["efficiency"],"evidence_locator":"SinglePass Abstract, Introduction, and Section 4","evidence_url":"https://eprint.iacr.org/2024/303.pdf","id":"lineage-d9a2f33811b0f2ec","map_relation":"lineage","predecessor":"PIR-RESULT-2021-CHECKLIST-PRACTICAL-SUBLINEAR-TWO-SERVER-LOOKUPS","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"fulltext_checked","statement":"SinglePass directly compares against Checklist and reduces client preprocessing to one database pass while improving the reported preprocessing and query costs.","successor":"PIR-RESULT-2024-SINGLEPASS-SINGLE-PASS-CLIENT-PREPROCESSING"},{"change_dimensions":["efficiency"],"evidence_locator":"SinglePass Abstract and Section 5","evidence_url":"https://eprint.iacr.org/2024/303.pdf","id":"lineage-4aa7a390680b0c1f","map_relation":"lineage","predecessor":"PIR-RESULT-2021-CHECKLIST-LOGARITHMIC-AMORTIZED-UPDATES","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"fulltext_checked","statement":"SinglePass replaces the Checklist-style logarithmic update overhead with worst-case constant-time edits and amortized constant-time append additions to its client hint, while ordinary queries avoid Checklist's logarithmic bandwidth overhead; deletion semantics are not generalized.","successor":"PIR-RESULT-2024-SINGLEPASS-CONSTANT-TIME-DATABASE-UPDATES"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"ThorPIR Introduction and construction overview, PDF pp. 1-4","evidence_url":"https://eprint.iacr.org/2024/482.pdf","id":"lineage-f4d2b27274f4b812","map_relation":"lineage","predecessor":"PIR-RESULT-2022-CHK-TWO-SERVER-TO-SINGLE-SERVER-COMPILATION","relation_basis":"technical_dependency","relation_type":"OPTIMIZES","review_status":"fulltext_checked","statement":"ThorPIR targets the deep homomorphic hint-generation bottleneck in prior single-server client-preprocessing compilations and replaces it with a constant-depth Thorp-shuffle circuit.","successor":"PIR-RESULT-2024-THORPIR-CONSTANT-DEPTH-HOMOMORPHIC-THORP-PREPROCESSING"},{"change_dimensions":["mechanism","model","efficiency"],"evidence_locator":"Distributional PIR Sections 3, 6, and 7","evidence_url":"https://www.usenix.org/system/files/usenixsecurity25-lehmkuhl.pdf","id":"lineage-097a715f92830237","map_relation":"lineage","predecessor":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"fulltext_checked","statement":"The Distributional PIR system instantiates its black-box compiler with SimplePIR and separately optimizes SimplePIR's encryption and preprocessing path.","successor":"PIR-RESULT-2025-DISTRIBUTIONAL-CLASSIC-PIR-BLACK-BOX-COMPILER"},{"change_dimensions":["model","security","assumption","efficiency"],"evidence_locator":"Multi-server DEPIR Abstract and Introduction","evidence_url":"https://eprint.iacr.org/2024/829.pdf","id":"lineage-05e2d6ecd4b113cc","map_relation":"lineage","predecessor":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","relation_basis":"result_progression","relation_type":"CHANGES_SECURITY_MODEL","review_status":"fulltext_checked","statement":"The 2025 work responds to LMW23's standard-assumption single-server DEPIR boundary with information-theoretic DEPIR using roughly logarithmically many non-colluding servers, near-linear preprocessing and subpolynomial online time/communication. It changes the server model rather than strengthening the single-server construction.","successor":"PIR-RESULT-2025-LLFMP-MULTISERVER-DEPIR-INFORMATION-THEORETIC-MULTI-SERVER-DEPIR"},{"change_dimensions":["assumption","bounds"],"evidence_locator":"Black-box DEPIR abstract and theorem overview","evidence_url":"https://eprint.iacr.org/2025/552.pdf","id":"lineage-a213e2ae9070ffd5","map_relation":"related_work","predecessor":"PIR-RESULT-2023-LMW-DEPIR-FIRST-UNKEYED-DEPIR-FROM-RING-LWE","relation_basis":"analysis","relation_type":"EXPOSES_LIMITATION","review_status":"primary_source_checked","statement":"LMW25 establishes a construction-power collapse for black-box primitives in its stated SK-DEPIR oracle framework. This provides context for structured DEPIR assumptions but does not rule out LMW23's Ring-LWE construction.","successor":"PIR-RESULT-2025-LMW-BLACKBOX-BLACK-BOX-PRIMITIVES-COLLAPSE-TO-ONE-WAY-FUNCTIONS-FOR-SK-DEPIR"},{"change_dimensions":["model","mechanism","efficiency"],"evidence_locator":"YPIR abstract and Introduction","evidence_url":"https://www.usenix.org/system/files/usenixsecurity24-menon.pdf","id":"lineage-1c6e3f42e2355ca6","map_relation":"lineage","predecessor":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","relation_basis":"result_progression","relation_type":"CHANGES_PREPROCESSING","review_status":"primary_source_checked","statement":"YPIR removes the downloaded client hint present in the SimplePIR line by applying LWE-to-RLWE packing to DoublePIR's response, keeping database-dependent preprocessing at the server and accepting larger online queries. This is a preprocessing-cost progression relative to SimplePIR, not an identification of SimplePIR with DoublePIR.","successor":"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD"},{"change_dimensions":["model","mechanism","efficiency"],"evidence_locator":"USENIX Security 2026 accepted-paper abstract","evidence_url":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","id":"lineage-38390e2c928e889e","map_relation":"reference","predecessor":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","relation_basis":"result_progression","relation_type":"CHANGES_PREPROCESSING","review_status":"abstract_checked","statement":"ZipPIR's accepted abstract targets the client-storage and update burden of large hint-based protocols such as SimplePIR through LWE-to-Paillier compression and almost silent offline work.","successor":"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION"},{"change_dimensions":["implementation"],"evidence_locator":"Paper artifact reference and repository README","evidence_url":"https://github.com/microsoft/SealPIR","id":"lineage-6ed849b834381e7c","map_relation":"reference","predecessor":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"primary_source_checked","statement":"The public SealPIR repository implements the paper's compressed RLWE query expansion pipeline.","successor":"PIR-IMPL-2018-SEALPIR"},{"change_dimensions":["implementation"],"evidence_locator":"Paper artifact reference and repository","evidence_url":"https://github.com/menonsamir/spiral","id":"lineage-860c241dc4cfaa36","map_relation":"reference","predecessor":"PIR-RESULT-2022-SPIRAL-REGEV-GSW-CIPHERTEXT-TRANSLATION","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"primary_source_checked","statement":"The Spiral repository implements the Regev-to-GSW translation and streaming variants evaluated by the paper.","successor":"PIR-IMPL-2022-SPIRAL"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"Spiral abstract","evidence_url":"https://eprint.iacr.org/2022/368.pdf","id":"lineage-b1fb550aacf9a51a","map_relation":"reference","predecessor":"PIR-IMPL-2022-SPIRAL","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"primary_source_checked","statement":"The contextual observation records the implementation's source-reported 1.9 GB/s and 0.81 response-rate streaming setting.","successor":"PIR-BENCH-2022-SPIRAL-STREAM"},{"change_dimensions":["implementation"],"evidence_locator":"USENIX paper artifact reference","evidence_url":"https://github.com/ahenzinger/simplepir","id":"lineage-953376b8fc4c66bc","map_relation":"reference","predecessor":"PIR-RESULT-2023-SIMPLEPIR-SIMPLEPIR-MEMORY-BANDWIDTH-LWE-MATVEC","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"primary_source_checked","statement":"The SimplePIR Go artifact implements the paper's memory-bandwidth-oriented LWE matrix-vector protocol.","successor":"PIR-IMPL-2023-SIMPLEPIR"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"USENIX abstract and Table 10","evidence_url":"https://www.usenix.org/system/files/usenixsecurity23-henzinger.pdf","id":"lineage-4d7c07a412da155c","map_relation":"reference","predecessor":"PIR-IMPL-2023-SIMPLEPIR","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"primary_source_checked","statement":"The observation binds the SimplePIR artifact to the paper's 1 GB database, 121 MB hint, 242 KB online communication, and roughly 10 GB/s/core setting.","successor":"PIR-BENCH-2023-SIMPLEPIR-1GB"},{"change_dimensions":["implementation"],"evidence_locator":"USENIX artifact appendix A.2-A.4","evidence_url":"https://www.usenix.org/system/files/usenixsecurity24-appendix-menon.pdf","id":"lineage-b925e6aa9be196fe","map_relation":"reference","predecessor":"PIR-RESULT-2024-YPIR-SILENT-PREPROCESSING-REMOVES-HINT-DOWNLOAD","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"primary_source_checked","statement":"The archived b980152 artifact implements YPIR and fixes the Rust, compiler, Docker, and recommended AVX-512 environment used by the evaluation.","successor":"PIR-IMPL-2024-YPIR"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"YPIR abstract and artifact appendix","evidence_url":"https://www.usenix.org/system/files/usenixsecurity24-menon.pdf","id":"lineage-ff79c7fb85f54f8f","map_relation":"reference","predecessor":"PIR-IMPL-2024-YPIR","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"primary_source_checked","statement":"The contextual observation records the artifact's 32 GB small-record setting with 12.1 GB/s/core and 2.5 MB total communication.","successor":"PIR-BENCH-2024-YPIR-32GB"},{"change_dimensions":["implementation"],"evidence_locator":"USENIX Security 2026 accepted-paper abstract","evidence_url":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","id":"lineage-f991dbf186853665","map_relation":"reference","predecessor":"PIR-RESULT-2026-ZIPPIR-LWE-TO-PAILLIER-CIPHERTEXT-COMPRESSION","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"abstract_checked","statement":"A separate prototype object records the paper-described LWE-to-Paillier system while artifact availability remains unresolved at the cutoff.","successor":"PIR-IMPL-2026-ZIPPIR"},{"change_dimensions":["implementation","efficiency"],"evidence_locator":"USENIX Security 2026 accepted-paper abstract","evidence_url":"https://www.usenix.org/conference/usenixsecurity26/presentation/mahdavi","id":"lineage-53256ccd4dbda9d2","map_relation":"reference","predecessor":"PIR-IMPL-2026-ZIPPIR","relation_basis":"analysis","relation_type":"BENCHMARKS","review_status":"abstract_checked","statement":"The candidate observation binds the accepted abstract's throughput and server-storage claims to its 1 GB database setting without filling missing hardware or parameter fields.","successor":"PIR-BENCH-2026-ZIPPIR-1GB"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Gentry–Ramzan Introduction, Our Results, PDF pp. 2-3","evidence_url":"https://www.cs.umd.edu/~gasarch/TOPICS/pir/logn.pdf","id":"lineage-b5467c61c610549a","map_relation":"lineage","predecessor":"PIR-RESULT-1999-CMS-POLYLOGARITHMIC-SINGLE-SERVER-COMMUNICATION","relation_basis":"technical_dependency","relation_type":"CHANGES_MECHANISM","review_status":"fulltext_checked","statement":"Gentry–Ramzan explicitly starts from the CMS Phi-hiding technique and changes the encoding so one short response recovers a block, obtaining O(k+d) communication and constant rate for large blocks.","successor":"PIR-RESULT-2005-GR-CONSTANT-RATE-SINGLE-DATABASE-BLOCK-RETRIEVAL"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Ali et al. USENIX abstract and Sections 3 and 7","evidence_url":"https://www.usenix.org/system/files/sec21-ali.pdf","id":"lineage-be4bb15ef34c98d7","map_relation":"lineage","predecessor":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","relation_basis":"technical_dependency","relation_type":"OPTIMIZES","review_status":"fulltext_checked","statement":"FastPIR explicitly improves SealPIR with compression and a new oblivious expansion, reducing communication while preserving essentially the same computation cost in the paper's evaluation.","successor":"PIR-RESULT-2021-ALI-TRADEOFFS-FASTPIR-COMPRESSED-SEALPIR-TRADEOFF"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Ali et al. USENIX abstract and Sections 4 and 7","evidence_url":"https://www.usenix.org/system/files/sec21-ali.pdf","id":"lineage-4962860f1a2e2ee6","map_relation":"lineage","predecessor":"PIR-RESULT-2018-SEALPIR-SEALPIR-COMPRESSED-RLWE-QUERIES","relation_basis":"technical_dependency","relation_type":"CHANGES_MECHANISM","review_status":"fulltext_checked","statement":"MulPIR changes the recursive response mechanism by using multiplicative homomorphism, exposing an explicit communication-versus-server-computation trade-off.","successor":"PIR-RESULT-2021-ALI-TRADEOFFS-MULPIR-MULTIPLICATIVE-RECURSION-TRADEOFF"},{"change_dimensions":["assumption","mechanism","efficiency"],"evidence_locator":"TreePIR Abstract and Introduction","evidence_url":"https://eprint.iacr.org/2023/204.pdf","id":"lineage-3cbef749a31ac450","map_relation":"lineage","predecessor":"PIR-RESULT-2021-SACM-NEAR-OPTIMAL-TWO-SERVER-PREPROCESSING-PIR","relation_basis":"result_progression","relation_type":"CHANGES_ASSUMPTION","review_status":"fulltext_checked","statement":"TreePIR explicitly targets SACM's two-server sublinear-time, polylog-bandwidth point and realizes it from DDH using weak privately puncturable PRFs instead of the heavier privately puncturable-set machinery.","successor":"PIR-RESULT-2023-TREEPIR-DDH-BASED-SUBLINEAR-TIME-POLYLOG-BANDWIDTH-PIR"},{"change_dimensions":["model","bounds"],"evidence_locator":"Persiano–Yeo Abstract and Theorems 1-2, PDF pp. 1-2 and 8","evidence_url":"https://eprint.iacr.org/2022/235.pdf","id":"lineage-7c685ce592a6635d","map_relation":"lineage","predecessor":"PIR-RESULT-2000-BIM-FORMALIZED-PIR-WITH-PREPROCESSING","relation_basis":"analysis","relation_type":"ANALYZES","review_status":"fulltext_checked","statement":"Persiano–Yeo analyzes the public-preprocessing PIR model in the BIM line and proves tr = Omega(n log n) for its stated computational cell-probe hint range. The edge connects a model contribution to its lower-bound analysis, not to a separately mapped BIM bound.","successor":"PIR-RESULT-2022-PY-LIMITS-PUBLIC-PREPROCESSING-STORAGE-TIME-LOWER-BOUND"}],"rubric_version":1,"schema_version":1,"selection_policy":"semantic_contract_anchors","threads":[{"color":"#667784","description":"Privacy definitions, information-theoretic origins, and the single-server transition.","id":"roots_privacy","label":"PIR foundations"},{"color":"#73549a","description":"Multi-server communication savings and distributed point functions.","id":"multi_server_dpf","label":"Multi-server and DPF"},{"color":"#9a6c2d","description":"Client-specific hints, adaptive queries, storage-time tradeoffs, and practical enrollment.","id":"preprocessing_theory","label":"Client preprocessing"},{"color":"#8a7442","description":"Client-independent server preprocessing, doubly efficient PIR, and its barriers.","id":"public_preprocessing_depir","label":"Public preprocessing and DEPIR"},{"color":"#2f718e","description":"Homomorphic query expansion and compressed encrypted queries.","id":"he_query_compression","label":"HE query compression"},{"color":"#4f7b60","description":"Matrix-vector protocols and compressed client hints.","id":"hint_matrix","label":"Client-hint protocols"},{"color":"#b65358","description":"Ciphertext conversion and hintless high-throughput PIR.","id":"silent_conversion","label":"Silent conversion"},{"color":"#7a647a","description":"PIR variants that preserve query privacy while changing the correctness contract.","id":"distributional_correctness","label":"Distributional correctness"}]},"stats":{"constructions":25,"countsByType":{"assumption":20,"barrier":3,"benchmark_run":4,"construction":25,"implementation":5,"milestone":6,"open_problem":2,"paper":28,"parameter_set":4,"result":54,"route":2,"workload":4},"entities":157,"lineageRelationships":25,"propertyAssertions":350,"relationships":249,"unresolvedReferences":0},"unresolved":[],"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}