Semantic Security for the Wiretap Channel

Semantic Security for the Wiretap Channel
复制标题

DOI:
10.1007/978-3-642-32009-5_18
复制
发表时间:
2012-08
期刊:
--
影响因子:
--
通讯作者:
M. Bellare;Stefano Tessaro;A. Vardy
M. Bellare;Stefano Tessaro;A. Vardy
中科院分区:
其他
文献类型:
--
作者:
M. Bellare;Stefano Tessaro;A. Vardy

文献摘要

被引文献

相似文献

窃听通道是这样一种设置,在该设置中,人们的目标是仅基于从发送者到对手的通道比从发送者到接收者的通道“更嘈杂”的假设来提供通信数据的信息论隐私。在过去的30年里,它在信息和编码(I&C)社区中发展起来,基本上脱离了现代密码学的并行发展。本文旨在通过涉及两个方面的进展的密码处理来弥合这一差距,即定义和方案。在第一个方面(定义),我们解释了目前使用的mis-r定义是薄弱的,并提出了两种选择:基于互信息的mis和基于经典的语义安全概念的ss。我们证明了它们的等价性,从而将定义隐私的两种根本不同的方式联系在一起,并为建设提供了一个新的、强大的和有充分依据的目标。在第二方面(方案),我们提供了第一个显式方案,它具有以下所有特征:它被证明同时实现了安全性(SS和MIS,而不仅仅是MIS-R)和可译码;它具有最优速率;并且加密和解密算法都被证明是多项式时间的。
The wiretap channel is a setting where one aims to provide information-theoretic privacy of communicated data based solely on the assumption that the channel from sender to adversary is “noisier” than the channel from sender to receiver. It has developed in the Information and Coding (I&C) community over the last 30 years largely divorced from the parallel development of modern cryptography. This paper aims to bridge the gap with a cryptographic treatment involving advances on two fronts, namely definitions and schemes. On the first front (definitions), we explain that the mis-r definition in current use is weak and propose two alternatives: mis (based on mutual information) and ss (based on the classical notion of semantic security). We prove them equivalent, thereby connecting two fundamentally different ways of defining privacy and providing a new, strong and well-founded target for constructions. On the second front (schemes), we provide the first explicit scheme with all the following characteristics: it is proven to achieve both security (ss and mis, not just mis-r) and decodability; it has optimal rate; and both the encryption and decryption algorithms are proven to be polynomial-time.