• Aucun résultat trouvé

On the Secret-Key Rate of Binary Random Variables

N/A
N/A
Protected

Academic year: 2022

Partager "On the Secret-Key Rate of Binary Random Variables"

Copied!
2
0
0

Texte intégral

(1)

Proceedings Chapter

Reference

On the Secret-Key Rate of Binary Random Variables

GANDER, Martin Jakob, MAURER, Ueli M.

Abstract

Consider a scenario in which two parties Alice and Bob as well as an opponent Eve receive the output of a binary symmetric source (e,g. installed in a satellite) over individual, not necessarily independent binary symmetric channels. Alice and Bob share no secret key initially and can only communicate over a public channel completely accessible to Eve. The authors derive a lower bound on the rate at which Alice and Bob can generate secret-key bits about which Eve has arbitrarily little information, This lower bound is strictly positive as long as Eve's binary symmetric channel is not perfect, even if Alice's and Bob's channels are by orders of magnitude less reliable than Eve's channel

GANDER, Martin Jakob, MAURER, Ueli M. On the Secret-Key Rate of Binary Random

Variables. In: IEEE International Symposium on Information Theory. IEEE, 1994. p. 351

DOI : 10.1109/ISIT.1994.394667

Available at:

http://archive-ouverte.unige.ch/unige:6555

Disclaimer: layout of this document may differ from the published version.

1 / 1

(2)

On the Secret-Key Rate of Binary Random Variables

MartinJ.Gander

Department of Computer Science Stanford University Stanford, CA 94305-2140, USA

UeliM.Maurer

Institute for Theoretical Computer Science ETH Zurich

CH-8092 Zurich, Switzerland

Abstract|

Consider a scenario in which two parties Alice and Bob as well as an opponent Eve receive the output of a binary symmetric source (e.g. installed in a satellite) over individual, not necessarily indepen- dent binary symmetric channels. Alice and Bob share no secret key initially and can only communicate over a public channel completely accessible to Eve. We de- rive a lower bound on the rate at which Alice and Bob can generate secret-key bits about which Eve has arbi- trarily little information. This lower bound is strictly positive as long as Eve's binary symmetric channel is not perfect, even if Alice's and Bob's channels are by orders of magnitude less reliable than Eve's channel.

I.Introduction

We assume in this paper that Alice, Bob and Eve know the sequences of binary random variablesXN= X1X2:::XN],

Y

N = Y1Y2:::YN] and ZN = Z1Z2:::ZN], respective- ly, where the triples (XiYiZi), for 1 i N, are gen- erated by a discrete memoryless source according to some probability distribution PXYZ, and PXYZ is of the form

PXY

Z =PRPXjRPYjRPZjRfor an unbiased binary ran- dom variableR(the bit broadcast by the satellite) and three independent binary symmetric channelsPXjR,PYjRandPZjR with bit error probabilities A, B and E, respectively. The case of dependent channels can easily be transformed into a corresponding scenario of independent channels.

II. Secret-Key Rate

The secret key rate ofPXYZ, denotedS(XYjjZ), was de- ned in 2] as the maximal rateM=N at which Alice and Bob can generate secret shared random key bitsS1:::SM by ex- changing messages over an insecure public channel accessible to Eve, such that the rate at which Eve obtains information about the key is arbitrarily small, i.e., such that

lim

N!1

1

N

I(S1:::SMZNCt) = 0

where Ct is the collection of messages exchanged between Alice and Bob over the public channel. Note that the bits

S

1 :::S

M can be used as the key in the one-time pad system for transmitting a message in perfect secrecy over the public channel.

The following upper and lower bounds onS(XYjjZ) were proved in 2]:

S(XYjjZ) minI(XY)I(XYjZ)]

and

S(XYjjZ)maxI(YX);I(ZX) I(XY);I(ZY)]:

This lower bound states the intuitive result that the secret key rate is positive if either Eve (knowingZ) has less information aboutY than Alice or, by symmetry, Eve has less information aboutX than Bob. Furthermore, it was demonstrated in 2]

by an example that, quite surprisingly, S(XYjjZ) can be positive even if neither of these conditions is satised, i.e., if the right hand side of (II) vanishes or is negative. The purpose of this paper is to prove a lower bound on the secret key rate of binary random variables for the case where both Alice's and Bob's channels are noisier than Eve's channel, i.e., A >E andB >E.

III.Results

Let

= (1;A)B+A(1;B) and

= L

L+ (1;)L: We have

S(XYjjZ) Rc(1;h();IE) where

IE= 1

L+ (1;)L

L

X

w =0 dw

L

w

1;h

d

w

d

w+dN;w and

Rc= 1

L K;1

Y

i=0

2

i

i + (1;i)2i:

This quantity is strictly positive whenE >0,A 6= 1=2 and

B 6= 1=2.

IV. Generalizations

Using techniques decribed in 3], the same bound can be proved for the much stronger denition of secret key rate which requires that the total amount of (rather than the rate at which Eve receives) information aboutS be negligible.

References

1] C.H. Bennett, G. Brassard, C. Crepeau and U.M. Maurer, Gen- eralized privacy amplication, these proceedings, (also submit- ted toIEEE Transactions on Information Theory).

2] U.M. Maurer, Secret key agreement by public discussion from common information,IEEE Transactions on Information The- ory, Vol. 39, No. 3, pp. 733-742, May 1993.

3] U.M. Maurer, The strong secret key rate of discrete random triples, to appear inProc. Symp. on Communications, Coding and Cryptography, R. Blahut et al. (eds.), Ascona, Switzerland, Feb. 10{13, 1994, Kluwer.

Références

Documents relatifs

For every p-pass Shellsort algorithm and every increment sequence, every subset of n!/2 n input permutations of n keys contains an input permutation that uses ⍀ ( pn 1⫹(1⫺⑀)/p

We propose a totally explicit lower bound for the N´eron-Tate height of algebraic points of infinite order of abelian varieties.. Let k be a number field of degree D = [k :

Ilias, Immersions minimales, premiere valeur propre du Lapla- cien et volume conforme, Mathematische Annalen, 275(1986), 257-267; Une ine- galit´e du type ”Reilly” pour

Indeed, it is shown in [Nag04] that this upper bound, computed using a type system, has a purely geometric interpretation (it is the spectral radius of a random walk on the tree

Similarly to the case where P is the Laplace operator (see [9]), we apply a scaling argument on this estimate to derive a linear Strichartz estimate on T L 2 on the time interval

Its main result is an asymptotically deterministic lower bound for the PE of the sum of a low compressibility approximation to the Stokes operator and a small scaled random

Next, we prove the uniqueness statements in Theorems 1.2 and 1.3. We start with some notation and definitions. d-ball) is a homology d-sphere (resp. d-ball) over any field.

Réversible automata form a natural class of automata with links to artificial intelligence [1], and to biprefix codes [4], Moreover réversible automata are used to study