Cheaper joint permutation mechanism

Develop a joint-permutation procedure for the retained data-acquisition positions that is cheaper than the storage-model string commitment used in Step~\ref{QSPIR:shuffle}, while preserving the uniformity and security properties required by the single-server QSPIR protocol.

Background

The protocol uses a storage-model string commitment to generate a joint random permutation of the retained positions. This prevents either party from aligning conclusive positions across blocks, but the paper estimates that the auxiliary commitment transmission costs more than an order of magnitude above the data transmission.

The conclusion explicitly leaves open the construction of a less expensive alternative that preserves the required statistical sampling and adversarial robustness.

References

Three questions remain open: a certificate of the client's measurement that tolerates channel noise, a cheaper joint permutation than the storage-model commitment of Step~\ref{QSPIR:shuffle}, and index privacy against a server who departs from assumption (P).

— One-Way Quantum Symmetric Private Information Retrieval Protocol From A Single Database Server Using NISQ Devices  (2610.02093 - Zou et al., 1 Oct 2026) in Conclusion, final paragraph; Step~\ref{QSPIR:shuffle} and Appendix \ref{app:storage_commitment}