Skip to main content
QUICK REVIEW

[论文解读] Security Notions for Information Theoretically Secure Encryptions

Mitsugu Iwamoto, Kazuo Ohta|arXiv (Cornell University)|Jun 9, 2011
Wireless Communication Security Techniques参考文献 4被引用 4
一句话总结

本文研究了基于变分距离定义的三种信息论完美保密(PS)变体,证明其中一种变体——PS_*M(ε)——严格强于其他两种。研究进一步表明,其余两种变体本质上等价于统计不可区分性(IND)和语义安全(SS),从而厘清了信息论密码学中核心安全概念之间的层次关系与相互联系。

ABSTRACT

This paper is concerned with several security notions for information theoretically secure encryptions defined by the variational (statistical) distance. To ensure the perfect secrecy (PS), the mutual information is often used to evaluate the statistical independence between a message and a cryptogram. On the other hand, in order to recognize the information theoretically secure encryptions and computationally secure ones comprehensively, it is necessary to reconsider the notion of PS in terms of the variational distance. However, based on the variational distance, three kinds of definitions for PS are naturally introduced, but their relations are not known. In this paper, we clarify that one of three definitions for PS with the variational distance, which is a straightforward extension of Shannon's perfect secrecy, is stronger than the others, and the weaker two definitions of PS are essentially equivalent to the statistical versions of indistinguishability and semantic security.

研究动机与目标

  • 厘清基于变分距离定义的三种信息论完美保密自然变体之间的关系。
  • 解决在变分距离下不同完美保密定义是否等价或相异的模糊性问题。
  • 通过将信息论安全与计算安全概念关联至统计IND与SS,统一理解两者之间的联系。
  • 证明一种PS定义严格强于其他定义,凸显安全保证中的关键差距。
  • 提供一个正式框架,利用变分距离度量比较信息论安全与计算安全概念。

提出的方法

  • 引入三种完美保密变体:PS_*M(ε)、PS_C*(ε)与PS_CM(ε),每种均基于涉及消息、密文与联合分布的变分距离约束。
  • 利用定理1证明,在对称密钥加密中,条件分布P_C|M由加密函数与密钥分布唯一确定。
  • 应用Pinsker不等式与变分距离的性质,将互信息与变分距离关联,使安全定义建立在信息论度量基础之上。
  • 构造一个病态示例(Σ_ex),其转移矩阵P_C|M为双随机矩阵,证明PS_*M(ε)严格强于其他两种定义。
  • 证明PS_C*(ε)与PS_CM(ε)分别等价于基于变分距离的统计不可区分性(IND)与语义安全(SS)。
  • 利用后验概率分布P_M|C分析敌手从密文中推断消息的能力,表明PS_*M(ε)要求所有密文下P_M|C的均匀性。

实验结果

研究问题

  • RQ1基于变分距离定义的三种完美保密变体——PS_*M(ε)、PS_C*(ε)与PS_CM(ε)——在ε > 0时是否等价?
  • RQ2基于变分距离的完美保密定义如何与统计不可区分性(IND)和语义安全(SS)相关联?
  • RQ3这三种PS变体之间是否存在严格层次关系?若有,哪一种最强?
  • RQ4是否存在一个密码系统在统计IND-安全下成立,却无法满足PS_*M(ε)(对小ε)?
  • RQ5在变分距离界方面,PS_*M(ε)与其他两种定义之间的定量差距为何?

主要发现

  • PS_*M(ε)严格强于PS_C*(ε)与PS_CM(ε),其病态示例表明,即使后两者成立,前者仍可能不成立。
  • 对任意ε > 0,存在一个对称密钥密码系统Σ_ex,其PS_C*(ε)与PS_CM(ε)-安全性的ε = 2/n,但当n较大时,PS_*M(ε′)-安全性的ε′ ≥ 1/2。
  • 该示例实现了统计IND(ε)-安全性,其中ε = 2/n,随着n增大可趋于任意小。
  • PS_C*(ε)与PS_CM(ε)在变分距离下本质上分别等价于统计不可区分性与语义安全。
  • 在该示例中,变分距离d(P_M|C(⋅|c), P_M(⋅))在非可忽略比例的密文(c = c₁或c₂)上超过ε,即使ε很小,仍违反PS_*M(ε)。
  • 该示例中转移矩阵P_C|M为双随机矩阵,确保满足所需性质的对称密钥密码系统存在。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。