4 ms·
In this PIR model the server has to read the whole database, otherwise it would be easy on the server to see, that these rows were not accessed and therefore th
by karulont 2y ago
In this PIR model the server has to read the whole database, otherwise it would be easy on the server to see, that these rows were not accessed and therefore they are not the one the client queried.
In this PIR model the server runtime is O(n) where n is the number of rows.
To keep it practical, we do support sharding the database. Client leaks a few bits of hashed query to pick the right shard, where we process the entire shard. There is a inherent privacy-performance tradeoff: less shards = less leakage vs more shards = better performance & less privacy.
- lsh123 2y agoThanks for explanation. I will read the code to see how sharing works.
- karulont 2y agohttps://github.com/apple/swift-homomorphic-encryption/blob/356b9d19ef1842d31ffc16e29956ebfd9bb43e96/Sources/PrivateInformationRetrieval/KeywordDatabase.swift#L55 https://github.com/apple/swift-homomorphic-encryption/blob/3... Run SHA256 on the keyword, truncate the hash and take the modulus with number of shards.