[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-81961-en":3,"doc-seo-81961-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},81961,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Lower Bounds for PIR with Preprocessing from Blackbox Cryptography","The document investigates limits of single-server private information retrieval (PIR) when the client performs preprocessing, focusing on blackbox cryptography usage. For a client preprocessing storing s bits about an n-bit database, it proves an online amortized computation lower bound of Ω(n/s) across k=Ω(s) queries, implying either Ω(n/s) amortized online communication or Ω(n/s) cryptographic server operations. The bounds are shown optimal by matching constructions, rule out doubly efficient PIR, and extend to symmetric PIR in the random oracle model with matching constructions using only one-way functions during queries.","arXiv :2607 .0645 1v2 [ cs .CR] 8 Jul 2026  \nLower Bounds for PIR with Preprocessing from Blackbox Cryptography  \nAlexander Hoover * Giuseppe Persiano † Kevin Yeo ‡  \nAbstract  \nWe study the limits of single-server private information retrieval (PIR) with preprocessing. Prior work has shown that single-server PIR with sublinear communication requires alinear number of (public-key) server operations per query [DMO00, DH24] . Recent breakthrough works, including [CHK22, ZPZS24, LMW23], circumvent these lower bounds by critically leveraging preprocessing to construct single-server PIR with sublinear query computation.  \nOur work presents computation lower bounds for any single-server PIR with preprocessing that makes blackbox usage of any cryptography (such as random oracles and virtual blackbox obfuscation) . For any client preprocessing scheme where the client stores s bits about an n-bit database, we prove the online amortized computation must be Ω (n /s) across k = Ω (s) queries (even if performed in a single batch query) . In more detail, we prove that they must have either Ω (n /s) amortized online communication or the server must perform Ω (n /s) cryptographic operations. Our lower bounds are optimal as there exist PIRs with client preprocessing matching exactly one of the above requirements while outperforming the other. Furthermore, our lower bounds also rule out the existence of doubly efficient PIR from blackbox cryptography with sublinear query computation (current constructions use ring LWE) . We note our lower bounds are widely applicable to any single-server PIR scheme that makes blackbox usage of cryptography including those with weaker privacy guarantees. In contrast, prior works only proved computation lower bounds for restricted classes of single-server PIR constructions (e.g., non-encoding servers or single-roundtrip queries) .  \nOur proof framework also supports Ω(n /s) communication lower bounds for the following three classes of single-server PIR: schemes where the server performs o(n /s) cryptographic operations, schemes where the server’s cryptographic operations depend only on query communication and schemes with perfect privacy in the idealized model. Our results hold unconditionally whereas prior communication lower bounds required additional complexity assumptions.  \nWe also prove lower bounds for symmetric private information retrieval (SPIR) with client preprocessing in the random oracle model and present a matching SPIR construction with client preprocessing using only OWFs during queries.  \n* Stevens Institute of Technology, [ahoover@stevens.edu](ahoover@stevens.edu)[ ](ahoover@stevens.edu)†Universit di Salerno, [giuper@gmail.com](giuper@gmail.com)  \n‡Google, [kwlyeo@google.com](kwlyeo@google.com)  \nContents  \n1 Introduction 1  \n1.1 Our Contributions ...................................... 2  \n1.2 Our Techniques ........................................ 5  \n1.2.1 Computation Lower Bounds ............................ 5  \n1.2.2 Communication Lower Bounds ........................... 10  \n1.2.3 Symmetric PIR without Online Public-Key Cryptography ........... 11  \n2 Related works 11  \n3 Preliminaries 13  \n3.1 Crypto Oracles ........................................ 15  \n3.2 PIR with Preprocessing .................................... 17  \n3.3 Subkey prediction ....................................... 18  \n3.4 Blackbox constructions .................................... 19  \n4 Computation Lower Bounds 20  \n4.1 Dual Private Information Retrieval ............................. 21  \n4.2 Constructing a Dual PIR ................................... 22  \n4.3 Correctness Analysis of Dual PIR Construction ...................... 26  \n4.4 Impossibility of Dual PIR .................................. 31  \n4.5 Impossibility of (Public-Key) Doubly Efficient PIR .................... 35  \n4.6 Impossibility of Weak PIR (with Preprocessing) ...................... 37  \n5 Communication Lower Bounds 38  \n5.1 PIR with Sublinear Serv","cbCaijD1V1AMhedR","https://ap.wps.com/l/cbCaijD1V1AMhedR","pdf",465066,4,1,65,"English","en",105,"# Introduction\n## Our Contributions\n## Our Techniques\n# Related works\n# Preliminaries\n## Crypto Oracles\n## PIR with Preprocessing\n## Subkey prediction\n## Blackbox constructions\n# Computation Lower Bounds\n## Dual Private Information Retrieval\n## Constructing a Dual PIR\n## Correctness Analysis of Dual PIR Construction\n## Impossibility of Dual PIR\n## Impossibility of (Public-Key) Doubly Efficient PIR\n## Impossibility of Weak PIR (with Preprocessing)\n# Communication Lower Bounds\n## PIR with Sublinear Server Cryptographic Operations\n## PIR with Communication-Determined Server Cryptographic Operations\n## PIR with Perfect Privacy\n# Symmetric PIR without Online Public-Key Cryptography\n## Formal model\n## Limitations of SPIR without Public-Key Cryptography\n## Toy Constructions\n## SPIR with Sublinear Online Computation\n## Detailed Construction","[{\"question\":\"What problem does the paper study in single-server PIR with preprocessing?\",\"answer\":\"It studies computation and communication limits for single-server PIR schemes where the client can preprocess and the scheme uses blackbox cryptography.\"},{\"question\":\"What lower bound is proved for online amortized computation?\",\"answer\":\"For client preprocessing that stores s bits about an n-bit database, the paper proves online amortized computation must be Ω(n/s) across k=Ω(s) queries.\"},{\"question\":\"How do the results apply to doubly efficient PIR and symmetric PIR?\",\"answer\":\"The bounds rule out doubly efficient PIR from blackbox cryptography with sublinear query computation, and they also provide lower bounds for symmetric PIR in the random oracle model with a matching construction using only one-way functions during queries.\"}]","Lower Bounds for PIR with Preprocessing from Blackbox Cryptography | PDF",1784177305,164,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"lower-bounds-for-pir-with-preprocessing-from-blackbox-cryptography","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":20},"https://docshare.wps.com/document/lower-bounds-for-pir-with-preprocessing-from-blackbox-cryptography/81961/",{"url":53,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-01","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the paper study in single-server PIR with preprocessing?","Question",{"text":76,"@type":77},"It studies computation and communication limits for single-server PIR schemes where the client can preprocess and the scheme uses blackbox cryptography.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What lower bound is proved for online amortized computation?",{"text":81,"@type":77},"For client preprocessing that stores s bits about an n-bit database, the paper proves online amortized computation must be Ω(n/s) across k=Ω(s) queries.",{"name":83,"@type":74,"acceptedAnswer":84},"How do the results apply to doubly efficient PIR and symmetric PIR?",{"text":85,"@type":77},"The bounds rule out doubly efficient PIR from blackbox cryptography with sublinear query computation, and they also provide lower bounds for symmetric PIR in the random oracle model with a matching construction using only one-way functions during queries.","https://schema.org",{"og:url":53,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]