Source-linked AI summary

The Wiretap Channel with Feedback: Encryption over the Channel

Lifeng Lai, Hesham El Gamal, H. Vincent Poor

arXiv:0704.2259v1cs.ITcs.CR

TL;DR

The paper asks whether noisy feedback can improve secrecy in wiretap channels without a separate noiseless public channel. It analyzes modulo-additive channels with full- and half-duplex destinations, showing that destination-only private-key feedback reaches strong secrecy benchmarks and remains positive in the half-duplex case.

  • Problem

    The paper addresses secrecy enhancement when feed-forward and feedback signals share a noisy channel instead of using a separate noiseless public feedback channel.

  • Method

    The paper uses modulo-additive channel structure so destination feedback acts as a private key and encryption occurs over the channel.

  • Results

    Full-duplex modulo-additive channels achieve the source-destination capacity without the wiretapper, while a modified scheme achieves a positive half-duplex secrecy rate.

  • Takeaways & Limitations

    The results establish a destination-only-key encryption paradigm that significantly outperforms the classical public-discussion paradigm.

Abstract

from arXiv · show

In this work, the critical role of noisy feedback in enhancing the secrecy capacity of the wiretap channel is established. Unlike previous works, where a noiseless public discussion channel is used for feedback, the feed-forward and feedback signals share the same noisy channel in the present model. Quite interestingly, this noisy feedback model is shown to be more advantageous in the current setting. More specifically, the discrete memoryless modulo-additive channel with a full-duplex destination node is considered first, and it is shown that the judicious use of feedback increases the perfect secrecy capacity to the capacity of the source-destination channel in the absence of the wiretapper. In the achievability scheme, the feedback signal corresponds to a private key, known only to the destination. In the half-duplex scheme, a novel feedback technique that always achieves a positive perfect secrecy rate (even when the source-wiretapper channel is less noisy than the source-destination channel) is proposed. These results hinge on the modulo-additive property of the channel, which is exploited by the destination to perform encryption over the channel without revealing its key to the source. Finally, this scheme is extended to the continuous real valued modulo-$Λ$ channel where it is shown that the perfect secrecy capacity with feedback is also equal to the capacity in the absence of the wiretapper.

I. INTRODUCTION

The paper studies wiretap channels with feedback carried over the same noisy channel as feed-forward transmission. It shows that modulo-additive structure enables destination-only-key encryption and strong secrecy results in full- and half-duplex settings.

  • Prior foundations: Shannon-style perfect secrecy requires a shared key whose entropy is at least the message entropy.The paper contrasts this key-distribution burden with wiretap-channel approaches that use channel noise for secrecy.
  • Prior foundations: Wyner showed that a degraded source-wiretapper channel can support perfectly secure messages without private keys.The construction uses stochastic encoding to hide information in additional noise observed by the wiretapper.
  • Prior feedback work: Perfect secrecy capacity can be zero when the source-wiretapper channel is less noisy than the main channel.Earlier noiseless-feedback work established that feedback can restore a positive secrecy rate in such unfavorable cases, but its general capacity remains unknown.
  • Noisy-feedback model: The proposed model removes the separate noiseless feedback channel by sending destination feedback over the same noisy channel as feed-forward transmission.The wiretapper observes a mixture of source and feedback signals, while the source can causally adapt its transmission.
  • Main results: For full-duplex modulo-additive DMCs, noisy feedback raises perfect secrecy capacity to the main-channel capacity without the wiretapper.A simple scheme uses randomly generated destination feedback as a private key and performs encryption through modulo addition.
  • Main results: A half-duplex feedback scheme achieves a positive perfect secrecy rate for any non-trivial channel distribution.The feedback balances destination erasures against wiretapper errors, and the approach extends to continuous modulo-Λ lattice channels, achieving main-channel capacity.
  • Contribution: The paper presents an encryption paradigm that uses a private key known only to the destination and exploits modulo-additive structure.The authors report that this approach significantly outperforms the classical public-discussion paradigm.

II. THE MODULO-ADDITIVE DISCRETE MEMORYLESS CHANNEL

The paper defines a modulo-additive discrete memoryless wiretap channel with causal noisy feedback shared across the transmission setting. It formalizes stochastic source encoding, feedback encoding, decoding, reliability, equivocation, and perfect-secrecy capacity.

  • Channel model: The channel uses finite alphabets with modulo-additive outputs formed by adding source symbols and noise samples.The destination and wiretapper receive y(i) = [x(i) + n1(i)] mod |Y| and z(i) = [x(i) + n2(i)] mod |Z|.
  • Feedback model: At time i, the destination sends causal feedback over the same noisy channel used for feed-forward transmission.The feedback symbol may depend on previously received destination outputs through X1(i) = Ψ(Y i−1).
  • Feedback model: The destination may choose the feedback alphabet, whose signal is observed noisily by the source, wiretapper, and destination-side channel components.The feedback noise may be correlated with the forward noises, and all additions use the corresponding alphabet sizes.
  • Coding formulation: An (M, n) code combines a causal stochastic source encoder, a stochastic feedback encoder, and a destination decoder.The source maps the message to channel inputs, while the destination maps past received signals to feedback symbols and an n-symbol output to a decoded message.
  • Performance criteria: A secrecy rate is achievable when a sequence of codes supports reliable transmission and the required equivocation condition for every sufficiently large blocklength.The noisy-feedback secrecy capacity is the maximum achievable rate under perfect secrecy.
  • Adversary model: The wiretapper has unlimited computational resources and knows both the source coding scheme and the destination feedback function.The model therefore evaluates secrecy against an informed wiretapper rather than relying on obscurity of the protocol.

A. Known Results

Earlier public-discussion approaches generate a secret key but may require one-time-pad encryption, reducing the effective source-destination rate. For degraded wiretap channels, public discussion does not increase secrecy capacity.

  • Public discussion: The public-discussion model adds an infinite-capacity noiseless channel through which the source and destination exchange information to generate a key hidden from the wiretapper.
  • Public discussion: Public-discussion schemes can generate an identical secret key at the source and destination, but transmitting messages may then require one-time-pad encryption.The resulting effective secrecy rate may be lower than the reported comparison results.
  • Model: The wiretap channel is a channel-type model in which nodes observe correlated variables, with public discussion providing an additional noiseless communication channel.
  • Known capacity results: For degraded wiretap channels, public discussion does not increase secrecy capacity.This conclusion is stated for both cases where the wiretapper channel is degraded relative to the main channel and where the main channel is degraded relative to the wiretapper channel.

B. The Main Result

The main scheme uses noisy feedback in a modulo-additive channel as a destination-only private key, encrypting through the channel while the source uses ordinary channel coding. It achieves reliable transmission up to the main-channel capacity with perfect secrecy.

  • Main result: The discrete memoryless modulo-additive wiretap channel’s secrecy capacity is characterized under noisy feedback.The scheme requires no complicated feedback function; a random number generator suffices.
  • Achievability scheme: Reliable transmission is achievable for any rate Rf < C, where C is the main-channel capacity without the wiretapper.
  • Achievability scheme: The destination generates a uniformly distributed feedback signal and subtracts it modulo the output alphabet before decoding.This restores an effective channel equivalent to the main channel without feedback.
  • Secrecy: The wiretapper’s observation is independent of the transmitted codeword, yielding perfect secrecy with I(W; Z) = 0.The result is perfect secrecy in Shannon’s strong sense.
  • Encryption over the channel: The feedback signal acts as a private key known only to the destination, and the modulo-additive channel performs the encryption.The source ignores the feedback signal and uses the ordinary channel code.
  • Secrecy: Only the destination needs the encryption key, eliminating the burden of secret-key distribution.
  • Main result: Noisy-feedback secrecy capacity exceeds the secret-key capacity of public-discussion schemes in this setting.The contrast arises because the noiseless feedback signal is also available to the wiretapper, whereas the proposed noisy feedback is not perfectly known to the source or wiretapper.

C. The Binary Symmetric Channel Example

The BSC examples show how noisy feedback can transform the wiretap channel and substantially improve secrecy, including when the wiretapper channel is degraded or otherwise unfavorable.

  • Encryption over the channel: Feedback can convert the original BSC into an equivalent channel whose secrecy performance is characterized through modified crossover parameters.The destination uses its transmitted signal to alter the effective channel seen by the source and wiretapper.
  • Special case: When both main and wiretap channels are noiseless, destination-generated feedback creates a virtual noisy channel while its private value remains known to the destination.The destination randomly transmits a binary feedback symbol, enabling encryption over the channel.
  • Channel cases: The BSC wiretap channel is analyzed under multiple degradedness and noise-correlation cases.The cases distinguish whether the main channel or source-wiretapper channel is degraded, and whether the noise variables are independent or correlated.
  • Results: The feedback scheme achieves a secrecy capacity at least as large as the public-discussion benchmark for BSC wiretap channels.The paper reports that the gain over public discussion is significant in many relevant special cases.

IV. EVEN HALF-DUPLEX FEEDBACK IS SUFFICIENT

The half-duplex scheme uses randomized feedback timing to confuse the wiretapper while preserving opportunities for reception. It guarantees a positive secrecy rate across broad BSC conditions.

  • Design challenge: Half-duplex feedback must balance confusing the wiretapper against erasing source symbols at the destination.Always transmitting prevents the destination from receiving, whereas never transmitting provides no feedback advantage.
  • Randomized timing: The destination transmits randomly with probability t and otherwise listens, while the source and wiretapper know t but not the exact feedback times.This hidden timing preserves uncertainty about whether feedback occurred.
  • Equivalent channels: The equivalent wiretapper channel remains a BSC with crossover probability ˆδ = δ + t − 2δt, while the main channel includes erasures with probability t.The destination receives only during the remaining 1 − t fraction of channel uses.
  • Achievable rate: Rf = (1 − H(ǫ))/2 with µ = t = 1/2, yielding a nonzero secrecy rate whenever ǫ ≠ 1/2.This rate is achieved irrespective of the wiretapper channel conditions.
  • Modulo-additive extension: For general discrete modulo-additive channels, uniform feedback makes the wiretapper output independent of the source input while the destination still listens 1/|Z| of the time.The paper notes that finding the optimal feedback distribution is tedious.

V. THE MODULO-Λ CHANNEL

The modulo-Λ model extends the encryption-over-the-channel idea to continuous-valued inputs represented within a lattice fundamental region. Noisy feedback raises secrecy capacity to the no-wiretapper main-channel capacity.

  • Motivation: The continuous model is motivated by preserving the modulo structure used in the discrete proof and by its role in approaching AWGN capacity.The paper describes modulo-Λ channels as compatible with lattice coding and decoding for AWGN channels.
  • Main result: Noisy feedback increases the modulo-Λ wiretap secrecy capacity to the main-channel capacity without a wiretapper.The paper states this result as the continuous analogue of the discrete-channel conclusion.
  • Channel model: The modulo-Λ channel represents inputs in a lattice fundamental region and reduces the received value modulo Λ after adding Gaussian noise.The output is the unique element of the fundamental region congruent to the noisy sum.
  • Feedback model: With feedback, the destination and wiretapper receive modulo-Λ sums containing the source, feedback, and their respective Gaussian noises.The source also receives a modulo-Λ sum involving the feedback signal and a separate noise variable.

1. Here ⌊x⌋denotes the largest integer that is smaller

The modulo-Λ achievability proof uses uniformly distributed source codewords and feedback to hide the source from the wiretapper while preserving the main-channel rate. The result reaches perfect secrecy at the no-wiretapper capacity.

  • Achievability: Uniform feedback over the fundamental region makes the wiretapper’s received sequence independent of the source codeword.This is the crypto-lemma step underlying perfect secrecy.
  • Scope boundary: The modulo-Λ structure is essential because removing the wiretapper’s modulo restriction can reveal additional information about the source message.The paper attributes this concealment mechanism to the group structure required by the crypto lemma.
  • Limitation: The secrecy capacity of the unrestricted wiretap AWGN channel remains unresolved, with only achievable rates currently available in the discussed setting.The paper contrasts this open problem with the solved modulo-Λ model.

VI. CONCLUSION

The paper characterizes secrecy capacity or achievable rates for several noisy-feedback wiretap settings and introduces encryption using a private destination-only key over modulo-additive channels. Full-duplex secrecy capacity reaches the wiretapper-free source-destination capacity, while modified feedback yields a positive half-duplex secrecy rate.

  • The paper obtains secrecy capacity or achievable rates for several instances of the wiretap channel with noisy feedback.
  • Full-duplex channel: Full-duplex modulo-additive channels achieve secrecy capacity equal to the source-destination capacity without a wiretapper.
  • Full-duplex channel: A simple scheme achieves this capacity by having the destination randomly choose its feedback signal from a specified alphabet.
  • Half-duplex channel: A modified feedback scheme achieves a positive secrecy rate for the half-duplex channel.
  • Encryption paradigm: The proposed encryption paradigm uses a private key known only to the destination and significantly outperforms the public discussion approach for sharing private keys.
  • Open problems: Characterizing arbitrary DMCs and the AWGN channel with feedback, exploiting other channel structures, and extending the work to multi-user channels remain future research directions.
Loading 0704.2259v1…