Source-linked AI summary
Secure Transmission with Multiple Antennas II: The MIMOME Wiretap Channel
Ashish Khisti, Gregory Wornell
TL;DR
The paper asks how to characterize secrecy capacity for Gaussian MIMOME wiretap channels when direct optimization is difficult. It uses a minimax formulation with Gaussian wiretap coding and derives high-SNR and antenna-scaling conclusions, including limits of masked transmission.
Problem
Computing secrecy capacity directly from the Csiszár–Körner expression is difficult for the nondegraded MIMOME broadcast channel.
Method
The paper uses a convex-concave minimax problem with a saddle point and establishes Gaussian wiretap coding with an optimized covariance.
Results
The paper establishes a computable secrecy-capacity expression and shows that Gaussian inputs with the optimized covariance achieve capacity.
Takeaways & Limitations
At high SNR, generalized singular values characterize capacity, while masked MIMO transmission can be arbitrarily far from optimal; preventing secure communication requires 3T eavesdropper antennas with a 2:1 sender-to-receiver division.
Abstract
from arXiv · showhide
The capacity of the Gaussian wiretap channel model is analyzed when there are multiple antennas at the sender, intended receiver and eavesdropper. The associated channel matrices are fixed and known to all the terminals. A computable characterization of the secrecy capacity is established as the saddle point solution to a minimax problem. The converse is based on a Sato-type argument used in other broadcast settings, and the coding theorem is based on Gaussian wiretap codebooks. At high signal-to-noise ratio (SNR), the secrecy capacity is shown to be attained by simultaneously diagonalizing the channel matrices via the generalized singular value decomposition, and independently coding across the resulting parallel channels. The associated capacity is expressed in terms of the corresponding generalized singular values. It is shown that a semi-blind "masked" multi-input multi-output (MIMO) transmission strategy that sends information along directions in which there is gain to the intended receiver, and synthetic noise along directions in which there is not, can be arbitrarily far from capacity in this regime. Necessary and sufficient conditions for the secrecy capacity to be zero are provided, which simplify in the limit of many antennas when the entries of the channel matrices are independent and identically distributed. The resulting scaling laws establish that to prevent secure communication, the eavesdropper needs 3 times as many antennas as the sender and intended receiver have jointly, and that the optimimum division of antennas between sender and intended receiver is in the ratio of 2:1.
I. INTRODUCTION
The paper studies physical-layer security in MIMOME channels with fixed, publicly known channel matrices, where direct capacity computation is difficult. It develops a computable minimax characterization and identifies Gaussian signaling and covariance structure as central solutions.
- Channel model: MIMOME channels have multiple antennas at the sender, intended receiver, and eavesdropper, with fixed channel matrices known to all terminals.The formulation acknowledges that public knowledge of the eavesdropper’s channel is a strong assumption.
- Prior work: Independent Gaussian wiretap codebooks achieve capacity for special diagonal parallel subchannels, motivating Gaussian methods for the general MIMOME problem.
- Problem: Directly computing secrecy capacity from the Csiszár–Körner expression is difficult because MIMOME is a nondegraded broadcast channel.
- Contributions: The paper establishes a computable minimax characterization of MIMOME secrecy capacity using a Sato-type upper-bounding approach.Prior work identifies this approach as yielding a minimax expression and later establishing tightness for MIMOME.
- Contributions: It also establishes Gaussian input optimality and an optimum input covariance structure for the secrecy-capacity expression.The paper attributes the covariance result to hidden convexity in the optimization problem.
A. MIMOME Secrecy Capacity
The paper characterizes MIMOME secrecy capacity through a convex-concave minimax problem with a saddle point, yielding an optimal Gaussian wiretap coding scheme. The saddle-point structure also reveals degraded effective channels and a capacity-preserving condition on the optimal signal design.
- Capacity characterization: Theorem 1 characterizes MIMOME secrecy capacity through a minimax problem with a convex-concave structure and saddle point solution.The solution provides a convex reformulation of the covariance optimization rather than merely local KKT conditions.
- Capacity-achieving scheme: The capacity-achieving scheme uses u ∼CN(0, KP) with KP = ¯KP and x = u.This is a Gaussian wiretap coding scheme corresponding to the optimal covariance.
- Saddle-point structure: The optimal cross-covariance satisfies ¯Φ†Hr¯S = He¯S for every full-column-rank ¯S with ¯S¯S† = ¯KP, provided secrecy capacity is nonzero.This property is used to show that the effective eavesdropper channel is degraded relative to the intended receiver.
- Saddle-point structure: The optimal signal design transmits no information along directions where the eavesdropper has stronger gain than the legitimate receiver.In this case, providing the eavesdropper output to the legitimate receiver does not increase capacity, despite generally supplying an upper bound.
- Zero-capacity condition: When secrecy capacity is zero, the effective intended-receiver channel is degraded relative to the eavesdropper channel.The eavesdropper can simulate the intended receiver by adding independent noise under the stated condition.
B. Secrecy Capacity in the High-SNR Regime
At high SNR, GSVD converts the MIMOME channel into parallel subchannels, yielding a capacity-achieving wiretap coding strategy based on favorable generalized singular values. The section also shows that masked MIMO can be arbitrarily suboptimal and derives zero-capacity and antenna-scaling thresholds.
- High-SNR capacity: At high SNR, GSVD simultaneously diagonalizes the legitimate and eavesdropper channels, and transmission uses only subchannels stronger at the intended receiver.Independent Gaussian wiretap coding across these subchannels approaches capacity.
- Masked MIMO: The masked MIMO scheme can have an arbitrarily large asymptotic gap to capacity when generalized singular values are small.The scheme transmits in Null(Hr)⊥ and injects synthetic noise in Null(Hr), without requiring transmitter knowledge of He to construct those subspaces.
- Zero-capacity condition: The secrecy capacity is zero if and only if the channel’s largest generalized singular value satisfies the stated zero-capacity condition.The condition is expressed using σmax(Hr, He).
- Scaling laws: In the many-antenna i.i.d. regime, the zero-capacity threshold becomes independent of the particular channel realization and defines a deterministic scaling law.The limiting cases include zero capacity when the eavesdropper has at least twice the sender’s antennas or more antennas than the intended receiver.
- Scaling laws: 3T eavesdropper antennas are required when the transmitter-to-receiver allocation satisfies nr/nt = 1/2, the allocation that best thwarts the eavesdropper.Equal transmitter and receiver allocations remain near this optimum, requiring approximately 2.9142T eavesdropper antennas.
V. MIMOME SECRECY CAPACITY ANALYSIS
The section proves a minimax upper bound for MIMOME secrecy capacity and establishes that it is attained at a finite saddle point.
- The proof uses a Sato-type upper-bound argument and reduces tightness to matching the saddle value with the achievable lower bound R−(KP).
- The secrecy capacity is upper bounded by min KΦ∈KΦ max KP∈KP R+(KP, KΦ), with Gaussian input covariance KP and admissible noise cross-covariance KΦ.
- The minimax objective is convex-concave and has a finite saddle point (K̄P, K̄Φ), by convexity properties and Sion’s minimax theorem.
- Gaussian inputs maximize the relevant conditional mutual-information expression among distributions with a fixed covariance, with equality for px = CN(0, KP).
- The nonsingular-noise analysis is simpler; singular KΦ requires modified equivalent observations and is deferred to appendices.
B. Property of the Saddle Point
This section derives structural properties of the saddle-point input and noise covariances that support evaluation of the minimax saddle value.
- A saddle point satisfies matrix conditions characterized through the optimal covariance K̄P, cross-covariance K̄Φ, and an effective channel.
- The saddle-point properties imply full column-rank of the effective-channel product under the stated condition Hr ≠ Θ̄He.
- Proofs are presented first for positive-definite K̄Φ, with singular cases handled separately in appendices.
- The optimal input covariance is confined to the nonzero singular subspace of the effective channel, whose rank determines the relevant signal dimensions.
- The effective-channel representation interprets K̄P as an optimal input covariance for a MIMO channel with unit-variance white Gaussian noise.
C. Evaluation of the Saddle Value: Proof of Theorem 1
The saddle-value evaluation shows when the minimax upper bound equals the achievable lower bound, thereby proving the secrecy-capacity characterization.
- The saddle value R+(K̄P, K̄Φ) is expressed using the lower-bound rate R−(K̄P).
- If R+(K̄P, K̄Φ) = 0, secrecy capacity is zero; otherwise the saddle value equals the achievable rate R−(K̄P).
- The lower bound is achievable by selecting pu = px = CN(0, K̄P) in the Gaussian wiretap coding argument.
- The proof handles the positive-definite K̄Φ case directly and treats singular K̄Φ in an appendix.
VI. CAPACITY ANALYSIS IN THE HIGH-SNR REGIME
At high SNR, GSVD simultaneously diagonalizes the intended-receiver and eavesdropper channels, yielding parallel subchannels for secrecy-capacity analysis.
- GSVD properties: The GSVD produces an equivalent parallel channel model and characterizes the null space of He.
- Full-column-rank case: When He has full column-rank, the generalized singular values equal the ordinary singular values of HrHe†.
- High-SNR capacity: The high-SNR capacity expression is written in terms of the generalized singular values, and its asymptotic gap to capacity is obtained by comparing the resulting expression with the finite-SNR form.
B. Case I: rank(He) = nt
For rank(He)=nt, the GSVD yields parallel subchannels, and Gaussian wiretap coding uses only those shared subchannels where the intended receiver has the stronger gain. The converse matches this achievable secrecy rate.
- GSVD decomposition: The GSVD decomposes the channel into s shared subchannels, with no receiver-only or null subchannels in this case.The shared subchannels correspond to Sr,e; Se has dimension nt−s, while Sr and Sn are zero-dimensional.
- Achievability: Communication uses only shared subchannels whose intended-receiver gains exceed the eavesdropper gains.The selected channels are indexed by the smallest ν satisfying σj > 1.
- Achievability: Gaussian wiretap codebooks are applied independently across the selected parallel subchannels.The transmitted nonzero symbols are independent complex Gaussian variables under a power normalization that keeps total power at most P.
- Achievability: The resulting construction achieves the secrecy rate given by the paper’s rate expression.The rate follows by substituting the GSVD-based transmission into the secrecy-rate formula.
- Converse: The converse simplifies the minimax upper bound for this GSVD case and establishes the same result.The proof uses the pseudo-inverse and auxiliary matrices, with the maximization over KP eliminated when the relevant entropy term is zero.
D. Analysis of the Masked MIMO Transmission Scheme
The masked MIMO scheme is analyzed through the secrecy-rate expression and high-SNR limits. The analysis compares its determinant terms after channel transformations and asymptotic simplification.
- Rate analysis: The analysis evaluates the masked scheme by expanding the two terms in the secrecy-rate expression.The derivation substitutes the channel transformations and uses determinant identities and unitary invariance.
- High-SNR analysis: High-SNR behavior is obtained by taking Pt → ∞ in the derived rate expression.The limiting calculations use continuity of log det and the expansion (εI+M)^−1 = M^−1 + O(ε).
- High-SNR analysis: The resulting expressions retain separate determinant contributions involving the intended and eavesdropper channel matrices.These terms arise from the transformed rate formula and its high-SNR limit.
VII. MIMOME CHANNEL SCALING LAWS
This section characterizes when secure communication is impossible and derives large-antenna scaling laws. The conclusions also identify open questions about semi-blind schemes and the finite-antenna relevance of asymptotic rules.
- Scaling laws: For i.i.d. Gaussian channel matrices, the zero-capacity condition simplifies in the many-antenna limit with fixed antenna ratios.The asymptotic analysis takes nr, ne, and nt to infinity while holding nr/ne = γ and nt/ne = β fixed.
- Zero-capacity condition: σmax(Hr, He) ≤ 1 is necessary and sufficient for zero secrecy capacity in the stated full-column-rank high-SNR setting.When σmax > 1, a direction exists where the intended receiver has strictly greater gain, yielding positive rate for every P > 0.
- Implications: The GSVD supports both high-SNR capacity calculation and code design for the MIMOME channel.This connects the channel decomposition used in the achievability arguments with practical coding construction.
- Implications: Semi-blind masked MIMO schemes can be arbitrarily far from capacity in the general MIMOME setting.The paper contrasts this with the MISOME case, where prior work reports masked beamforming rates close to capacity at high SNR.
- Open questions: Whether better generalizations of masked beamforming exist, and when asymptotic antenna rules become predictive, remains open.The paper also notes unresolved secrecy rates under partial eavesdropper-channel knowledge.
- Scaling laws: The paper provides convenient antenna-allocation rules for preventing secure communication as the number of antennas grows.These rules become independent of the channel matrices in the asymptotic regime.
APPENDIX I PROOF OF CLAIM 2
The appendix proves Gaussian optimality for the conditional mutual-information optimization, including singular covariance cases. It uses channel reduction, contradiction arguments, and KKT conditions to connect the transformed and original problems.
- Gaussian optimality: The proof handles singular KΦ by showing that Gaussian inputs maximize I(x; yr|ye) under the covariance constraint.When the conditional mutual information can be infinite, a Gaussian input satisfying the relevant condition also attains infinity.
- Channel reduction: The original channel can be replaced by an equivalent combined channel whose mutual information has a log-det form.Claim 3 supplies the reduction, yielding I(x; yr, ye) = I(x; ỹ) and the corresponding determinant expression.
- Singular case: A contradiction argument rules out directions in Null(W) that would make the transformed mutual information infinite.The resulting infinite-rate contradiction establishes the required column-space relationship between H and W.
- KKT conditions: KKT conditions characterize solutions to the covariance optimization through nonnegative dual variables and positive semidefinite slack matrices.The trace and complementary-slackness conditions accompany the stationarity equations.
- MMSE connection: The proof identifies the MMSE error covariance with the matrix appearing in the KKT comparison.Γ(K̄P, K̄P) equals cov(yr|ye), which is also Λ̄ by definition.
APPENDIX V PROOF OF LEMMA 4 FOR SINGULAR ¯KΦ
The appendix handles singular noise cross-covariance by transforming the channel to equivalent observations whose associated covariance matrices are nonsingular. It then applies the nonsingular proofs of Lemmas 4 and 5, including separate treatment of the equality case.
- Equivalent channel model: The equivalent channel model has noise cross-covariance matrices with all singular values strictly below one, making the associated covariance matrices nonsingular.This property is established for both transformed observation models used in the proof.
- Proof of Lemma 4: The proof replaces the original observations and MMSE-estimation coefficients with their equivalent-model counterparts, then reuses the nonsingular-case argument of Lemma 4.The transformed variables include ˜yr and the coefficients associated with estimating it from ye.
- Proof of Lemma 4: The nonsingular argument implies that (Hr − ΘHe)S has full column rank.This conclusion follows after applying the transformed-model proof steps in the case Hr ≠ Θ̄He.
- Equality case: When Hr = Θ̄He, the appendix again invokes the equivalent observations ˜yr after noting that the relevant preceding condition implies Claim 2's condition.This handles the equality case separately from the Hr ≠ Θ̄He case.
- Proof of Lemma 5: For the second transformed model, the proof similarly substitutes equivalent observations, backward error covariance, and the equivalent-channel form of the covariance relation before applying Lemma 5.The substitutions are made for all full-column-rank S̄ satisfying S̄S̄† = K̄P.