[论文解读] Quantifying the computational security of multi-user systems
本文将猜解框架扩展至多用户系统,表明在已知 V 个用户中识别出 U 个用户的字符串时,所需猜解次数的渐近平均值按特定 Rényi 熵(阶数为 (V−U+1)/(V−U+2))所决定的速率呈指数增长。本文建立了猜解的大偏差原理,证明了香农熵是猜解增长的通用下界,并在渐近情形下刻画了最优策略类别。
The Guesswork problem was originally motivated by a desire to quantify computational security for single user systems. Leveraging recent results from its analysis, we extend the remit and utility of the framework to the quantification of the computational security for multi-user systems. In particular, assume that V users independently select strings stochastically from a finite, but potentially large, list. An inquisitor who does not know which strings have been selected wishes to identify U of them. The inquisitor knows the selection probabilities of each user and is equipped with a method that enables the testing of each (user, string) pair, one at a time, for whether that string had been selected by that user. Here we establish that, unless U = V, there is no general strategy that minimizes the distribution of the number of guesses, but in the asymptote as the strings become long we prove the following: by construction, there is an asymptotically optimal class of strategies; the number of guesses required in an asymptotically optimal strategy satisfies a large deviation principle with a rate function, which is not necessarily convex, that can be determined from the rate functions of optimally guessing individual users’ strings; if all user’s selection statistics are identical, the exponential growth rate of the average guesswork as the string-length increases is determined by the specific Rényi entropy of the string-source with parameter (V −U +1)/(V −U +2), generalizing the known V = U = 1 case; and that the Shannon entropy of the source is a lower bound on the average guesswork growth rate for all U and V, thus providing a bound on computational security for multi-user systems. Examples are presented to illustrate these results and their ramifications for systems design. I.
研究动机与目标
- 量化多用户系统中攻击者猜测用户所选字符串的计算安全性。
- 分析在已知选择概率时,识别出 V 个用户中 U 个用户的字符串所需猜解次数。
- 研究当字符串长度增加时,猜解增长的渐近行为。
- 利用香农熵建立猜解增长的下界,并刻画最优策略。
提出的方法
- 使用大偏差理论分析识别 U 个用户字符串所需猜解次数的分布。
- 为多用户场景构建渐近最优的猜解策略类别。
- 利用个体用户字符串猜解的速率函数,推导猜解的速率函数。
- 应用阶数为 (V−U+1)/(V−U+2) 的 Rényi 熵,刻画平均猜解指数增长速率。
- 证明香农熵对所有 U 和 V 均为猜解增长的通用下界。
- 采用渐近分析,证明当字符串长度趋于无穷时,策略收敛至最优。
实验结果
研究问题
- RQ1在多用户系统中,识别出 V 个用户中的 U 个用户字符串时,平均猜解次数的渐近增长速率是多少?
- RQ2选择概率的结构如何影响多用户场景下猜解的分布?
- RQ3能否对任意 U 和 V,利用香农熵推导出猜解增长的通用下界?
- RQ4Rényi 熵在刻画多用户系统最优猜解策略中起什么作用?
- RQ5是否存在一种通用策略,可使所有多用户配置下的猜解分布最小化?
主要发现
- 随着字符串长度增加,平均猜解的指数增长速率由源字符串的特定 Rényi 熵(阶数为 (V−U+1)/(V−U+2))决定。
- 源的香农熵是所有 U 和 V 取值下平均猜解增长速率的通用下界。
- 除非 U = V,否则不存在能最小化猜解分布的通用策略,但在长字符串极限下存在渐近最优策略类别。
- 渐近最优策略中的猜解次数满足大偏差原理,其速率函数不一定是凸的。
- 多用户猜解的速率函数可由各用户字符串猜解的速率函数构造而成。
- 当所有用户具有相同的选取统计特性时,猜解增长速率完全由阶数为 (V−U+1)/(V−U+2) 的 Rényi 熵刻画。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。