SECRET KEY AGREEMENT BY PUBLIC DISCUSSION FROM COMMON INFORMATION
SECRET KEY AGREEMENT BY PUBLIC DISCUSSION FROM COMMON INFORMATION
复制标题
DOI:
10.1109/18.256484
复制
发表时间:
1993-05-01
影响因子:
2.5
通讯作者:
MAURER, UM
中科院分区:
文献类型:
--
作者:
MAURER, UM
The problem of generating a shared secret key S by two parties knowing dependent random variables X and Y, respectively, hut not sharing a secret key initially, is considered. An enemy who knows the random variable Z, jointly distributed with X and Y according to some probability distribution P(XYZ), can also receive all messages exchanged by the two parties over a public channel. The goal of a protocol is that the enemy obtains at most a negligible amount of information about S. Upper bounds on H(S) as a function of P(XYZ) are presented. Lower bounds on the rate H(S)/N (as N --> infinity) are derived for the case where X = [X1,..., X(N)], Y = [Y1,...,Y(N)] and Z = [Z1,..., Z(N)] result from N independent executions of a random experiment generating X(i), Y(i) and Z(i) for i = 1,..., N. In particular, it is shown that such secret key agreement is possible for a scenario where all three parties receive the output of a binary symmetric source over independent binary symmetric channels, even when the enemy's channel is superior to the other two channels. The results suggest how to build cryptographic systems that are provably secure against enemies with unlimited computing power under realistic assumptions about the partial independence of the noise on the involved communication channels.