[Paper Review] Secure Modulo Sum via Multiple Access Channel
This paper proposes a secure computation protocol for modular sum over a multiple access channel (MAC), enabling multiple parties to compute the sum of their private inputs modulo q without leaking individual information. By leveraging channel coding and secrecy analysis, the authors derive a lower bound on the secure modulo sum capacity, with explicit numerical results for Gaussian MAC, demonstrating practical feasibility in wireless communication systems.
We discuss secure computation of modular sum when multiple access channel from distinct players $A_1, \ldots, A_c$ to a third party (Receiver) is given. Then, we define the secure modulo sum capacity as the supremum of the transmission rate of modulo sum without information leakage of other information. We derive its useful lower bound, which is numerically calculated under a realistic model that can be realizable as a Gaussian multiple access channel (MAC).
Motivation & Objective
- To enable secure computation of modular sum among multiple parties using a multiple access channel (MAC) instead of traditional secure communication channels.
- To define and analyze the secure modulo sum capacity as the maximum rate of reliable and private transmission of the sum.
- To establish a lower bound on the secure modulo sum capacity under general MAC conditions, especially for realistic Gaussian MAC models.
- To demonstrate the feasibility of achieving secure computation in wireless networks without relying on cryptographic key distribution.
- To extend the protocol to support applications such as secure zero-sum randomness generation for multi-party computation and anonymous authentication.
Proposed method
- Formalizes the secure modulo sum capacity as the supremum of transmission rates where only the modulo sum is revealed to the receiver.
- Applies information-theoretic secrecy analysis using R\'enyi divergence and $s$-R\'enyi divergence to bound information leakage.
- Derives a lower bound on the secure modulo sum capacity using the $s$-R\'enyi divergence and channel degradation techniques.
- Utilizes affine code constructions and maximum likelihood decoding to ensure reliable recovery of the modulo sum at the receiver.
- Adapts the computation-and-forward framework to the secure setting by encoding messages with random linear codes to mask individual inputs.
- Analyzes the Gaussian MAC case by modeling the channel as a real-valued additive noise channel with discrete inputs, and computes achievable rates numerically.
Experimental results
Research questions
- RQ1What is the maximum rate at which multiple parties can securely compute the modular sum over a MAC without leaking individual inputs?
- RQ2How can secrecy be guaranteed in a MAC setting where the receiver observes a superposition of signals?
- RQ3What is the lower bound on the secure modulo sum capacity for a general MAC, and how does it behave under symmetric or semi-symmetric conditions?
- RQ4Can the proposed protocol be realized in practical wireless systems, such as Gaussian MAC, and what are the achievable rates?
- RQ5How does the use of random linear coding and channel degradation techniques ensure both reliability and secrecy in the computation?
Key findings
- The secure modulo sum capacity is bounded below by a function involving $s$-R\'enyi divergence, providing a computable lower bound for general MACs.
- For symmetric MACs, the secure modulo sum capacity equals the capacity of a single-user channel, simplifying analysis and design.
- In the Gaussian MAC model, the lower bound on secure modulo sum capacity is numerically computed, showing practical feasibility in wireless networks.
- The protocol achieves reliable decoding of the modulo sum using affine codes and maximum likelihood decoding, with error probability approaching zero under the rate condition (21).
- The use of uniformly distributed random keys in encoding ensures that individual messages remain hidden from the receiver, satisfying the secrecy condition.
- The framework enables the generation of secure zero-sum randomness among $k+1$ parties, which can be used as a cryptographic primitive for secure multi-party computation and anonymous authentication.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.