Private Information Retrieval (PIR) allows clients to retrieve database entries without leaking retrieval indices, yet malicious servers seriously compromise retrieval correctness. Existing Authenticated PIR (APIR) schemes resist selective-failure attacks but rely on computational hardness assumptions. In contrast, information-theoretic PIR with Result Verification (itPIR-RV) achieves integrity without computational assumptions, yet only provides relaxed query privacy with no defense against selective-failure attacks. This paper focuses on unconditionally secure information-theoretic APIR (itAPIR) constructions. We propose the rigorous information-theoretic security definition for itAPIR with statistical privacy against selective-failure attacks and integrity as core properties, formalize the hierarchical relation between itAPIR and itPIR-RV as a relaxed variant with identical integrity but basic query privacy, and prove a conversion theorem that valid itPIR-RV schemes can be directly upgraded to secure itAPIR with no extra overhead. Our work bridges the theoretical gap, simplifies itAPIR design, and enables quantum-resistant PIR in malicious server environments.
翻译:私有信息检索(PIR)允许客户端在不泄露检索索引的情况下获取数据库条目,但恶意服务器会严重破坏检索的正确性。现有的认证PIR(APIR)方案能够抵抗选择性失败攻击,但依赖于计算复杂性假设。相比之下,带有结果验证的信息论PIR(itPIR-RV)无需计算假设即可实现完整性,但仅提供宽松的查询隐私,且无法防御选择性失败攻击。本文聚焦于无条件安全的信息论APIR(itAPIR)构造。我们提出了itAPIR的严格信息论安全定义,其中针对选择性失败攻击的统计隐私和完整性为核心特性,将itAPIR与itPIR-RV之间的层级关系形式化为一种松弛变体(具有相同的完整性但仅具备基础查询隐私),并证明了一个转换定理:有效的itPIR-RV方案可直接升级为安全的itAPIR,且无需额外开销。我们的工作填补了理论空白,简化了itAPIR设计,并在恶意服务器环境中支持抗量子PIR。