Return
VOLE-PDRAA: An Efficient Privacy-Preserving Data Retrieval Protocol With Anonymous Authorization Based on Vector-OLE
Z
D
M
K
DOI:10.1109/tdsc.2026.3695233.png)
Abstract
En 中文
The General Data Protection Regulation (GDPR) aims to enable the free flow of personal data while enhancing individual control. Integrating privacy-preserving data retrieval methods can provide stronger protection for personal privacy. However, existing approaches lack compliance mechanisms aligned with the GDPR, making it difficult in practice to simultaneously satisfy the principles of lawfulness and data minimization, while also exhibiting clear limitations in both security and efficiency. To address these problems, we propose VOLE-PDRAA, an efficient <underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">p</u>rivacy-preserving <underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">d</u>ata <underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">r</u>etrieval protocol with <underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">a</u>nonymous <underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">a</u>uthorization based on the <underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">V</u>ector-<underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">O</u><underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">L</u><underline xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">E</u> (VOLE). Specifically, VOLE-PDRAA constructs a VOLE-blinded identifier by integrating pseudorandom linear encoding with VOLE-derived correlation vectors, enabling rigorous anonymity guarantees during authorization. Building on this, the protocol incorporates a non-interactive zero-knowledge proof (NIZK) to achieve anonymous authorization for the data subject and to generate verifiable informed consent proofs, thereby meeting the principle of lawfulness. Meanwhile, the data controller can verify whether each retrieval request falls within the scope authorized by the data subject without learning any identifiable information, thus maintaining adherence to the data-minimization principle in a post-quantum environment. Furthermore, VOLE-PDRAA utilizes labeled private set intersection (labeled-PSI) to safeguard the confidentiality of identifiers and their associated records under post-quantum security conditions, while enabling large-scale batch retrieval. Our protocol takes a comprehensive security analysis within the Universal Composability (UC) framework. Experimental evaluation validates its superiority through comparison with state-of-the-art work.
Keywords:
GDPR
VOLE
anonymous authorization
post-quantum
batch retrieval
UC-security
Journal
IF:
7.5
Papers:
2.4K
Citations:
9.6K
