Source-linked AI summary

Effective Secrecy: Reliability, Confusion and Stealth

Jie Hou, Gerhard Kramer

arXiv:1311.1411v3cs.ITcs.CR

TL;DR

The paper asks how to secure confidential communication while also hiding the presence of meaningful transmission. It defines effective secrecy using informational divergence and resolvability, relates stealth to binary hypothesis testing, and shows that the resulting capacities match weak and strong secrecy capacities for the studied channels.

  • Problem

    Existing secrecy measures do not by themselves require that an eavesdropper be unable to detect whether meaningful communication is occurring.

  • Method

    The paper defines effective secrecy through informational divergence and uses resolvability and binary hypothesis testing to analyze stealth for wire-tap and broadcast channels.

  • Results

    Effective secrecy capacity for the wire-tap channel and capacity region for broadcast channels with confidential messages are the same as their weak and strong secrecy counterparts.

  • Takeaways & Limitations

    A single security criterion can jointly capture reliability, message confusion, and stealth without changing the established capacities for these channels.

Abstract

from arXiv · show

A security measure called effective security is defined that includes strong secrecy and stealth communication. Effective secrecy ensures that a message cannot be deciphered and that the presence of meaningful communication is hidden. To measure stealth we use resolvability and relate this to binary hypothesis testing. Results are developed for wire-tap channels and broadcast channels with confidential messages.

I. INTRODUCTION

The paper introduces effective secrecy, a security measure combining message secrecy with stealth against an eavesdropper. It uses informational divergence and resolvability to connect this measure to reliability and binary hypothesis testing.

  • I. INTRODUCTION: Weak secrecy permits the eavesdropper to decipher a growing number of message bits, motivating the use of unnormalized mutual information for strong secrecy.Weak secrecy normalizes leakage by blocklength, whereas strong secrecy requires unnormalized mutual information to vanish.
  • I. INTRODUCTION: Effective secrecy strengthens security by requiring both confidentiality of the message and concealment of meaningful communication.The condition makes the message difficult to learn while hiding whether useful transmission is occurring.
  • I. INTRODUCTION: The proposed measure uses informational divergence D(P_MZ^n||P_MQ_Z^n), comparing communication with the eavesdropper’s expected output when useful messages are absent.The joint distribution captures message secrecy, while the reference output distribution captures stealth.
  • I. INTRODUCTION: The paper develops the measure for wire-tap and broadcast channels, then relates stealth to binary hypothesis testing.The paper is organized around problem formulation, a main theorem, hypothesis testing, and related work.

A. Notation

This section establishes notation for random variables, sequences, distributions, sets, and letter-typical sequences used throughout the paper.

  • A. Notation: Uppercase letters denote random variables, lowercase letters their realizations, superscripts finite sequences, and subscripts positions within sequences.For example, X^n denotes a length-n sequence and X_i its i-th symbol.
  • A. Notation: Probability distributions use subscripts such as P_X, while subscripts may be omitted when lower-case arguments identify the distribution.The notation also uses Q_X^n for independent, identically distributed sequences.
  • A. Notation: Calligraphic letters denote sets, with |S| giving set size and S^c denoting the complement.The notation also defines support and probabilities of sets.
  • A. Notation: The paper defines letter-typical sequences through empirical symbol counts N(a|x^n) relative to a distribution and tolerance parameter.This notation supports the typical-sequence arguments used in information-theoretic proofs.

B. Wire-Tap Channel

The wire-tap model sends a confidential message to Chandler while Ross observes a separate channel output. Effective secrecy requires reliable decoding together with low message leakage and indistinguishable communication presence.

  • B. Wire-Tap Channel: The encoder maps a uniformly distributed message into a length-n sequence, while an independent randomizer W confuses Ross.The randomizer has rate R_1 and is introduced specifically to reduce Ross’s information about M.
  • B. Wire-Tap Channel: Chandler observes Y^n and estimates M, whereas Ross observes Z^n and attempts to infer the message.The joint distribution P_MZ^n describes the message and eavesdropper output.
  • B. Wire-Tap Channel: Stealth compares Ross’s output distribution P_Z^n under useful communication with Q_Z^n, the output expected when no useful message is sent.When these distributions differ, Ross may detect communication presence.
  • B. Wire-Tap Channel: A rate R is achievable when Chandler decodes reliably and Ross both learns little about the message and cannot recognize meaningful transmission.The model evaluates reliability, message secrecy, and stealth jointly.
  • B. Wire-Tap Channel: The effective secrecy capacity C_S is the supremum of achievable rates satisfying the reliability and security requirements.The section formulates the capacity problem for the wire-tap channel.

III. MAIN RESULT AND PROOF

Theorem 1 states that effective secrecy does not reduce the wire-tap channel capacity: it equals the weak and strong secrecy capacity and has the usual auxiliary-variable characterization.

  • III. MAIN RESULT AND PROOF: The effective secrecy capacity equals the weak and strong secrecy capacity of the wire-tap channel.Thus, adding stealth to the security requirement preserves the established capacity expression.
  • III. MAIN RESULT AND PROOF: The capacity maximization ranges over joint distributions Q_VX satisfying the specified Markov chain.The auxiliary variable V is part of the standard single-letter characterization.
  • III. MAIN RESULT AND PROOF: The auxiliary variable can be restricted to cardinality |V| ≤ |X|.This gives a finite bound on the size of the optimizing auxiliary alphabet.

A. Achievability

Random coding establishes reliable, confidential, and stealthy communication under rate constraints involving the legitimate and eavesdropper channels. The resulting achievable secrecy rate is optimized using an auxiliary variable.

  • A. Achievability: The proof uses a random codebook with L·L1 codewords and uniform randomization over the auxiliary index for each message.The encoder selects w uniformly and transmits x^n(m,w), while the legitimate receiver uses a typicality check.
  • A. Achievability: Reliable decoding and effective secrecy follow when R + R1 < I(X;Y) and R1 > I(X;Z).The first condition controls decoding, while the second supports secrecy and stealth through randomization.
  • A. Achievability: 0 ≤ R < max_QV X [I(V;Y) − I(V;Z)] is achievable under the stated Markov constraint.Choosing V = X recovers the simpler bound, while optimizing over V can increase the achievable rate.
  • A. Achievability: The average divergence decomposes into message leakage and output-distribution divergence, linking secrecy of M with stealth of the transmission.When the divergence tends to zero, M and the eavesdropper output become nearly independent, while the output also approaches the reference distribution.

B. Converse

The converse bounds any effective-secrecy rate by the same auxiliary-variable expression used for achievability. Cardinality bounds complete the characterization.

  • B. Converse: The converse derives the upper bound max_QV X [I(V;Y) − I(V;Z)] over distributions satisfying the required Markov chain.A time-sharing variable and the telescoping identity reduce the blocklength expression to a single-letter bound.
  • B. Converse: The converse combines reliability and secrecy through a bound involving I(M;Y^n) − I(M;Z^n), Fano’s inequality, and the secrecy constraints.The resulting inequality controls the message rate up to vanishing error and secrecy terms.
  • B. Converse: The auxiliary variable can be chosen from a maximizing conditional distribution, so time sharing does not enlarge the single-letter maximum.This identifies a single distribution achieving the relevant maximum in the converse expression.
  • B. Converse: A cardinality bound on the auxiliary alphabet completes the converse proof.The bound is cited from the established result in [13, Theorem 22.1].

C. Broadcast Channels with Confidential Messages

For broadcast channels with confidential messages, the effective secrecy capacity region includes a common-message rate and a confidential-message rate. This region equals the weak and strong secrecy capacity region.

  • C. Broadcast Channels with Confidential Messages: The model adds a common message M0 for both receivers alongside a confidential message M intended for Chandler.Chandler estimates both messages, while Ross estimates only the common message.
  • C. Broadcast Channels with Confidential Messages: The effective secrecy region is defined as the closure of the achievable rate-pair set.Achievability requires the corresponding reliability and secrecy conditions for the two receivers.
  • C. Broadcast Channels with Confidential Messages: CBCC is the same as the weak and strong secrecy capacity region.The theorem extends the effective-secrecy characterization from wire-tap channels to broadcast channels with confidential messages.
  • C. Broadcast Channels with Confidential Messages: 0 ≤ R0 ≤ min{I(U;Y), I(U;Z)} and 0 ≤ R ≤ I(V;Y|U) − I(V;Z|U).The region is formed by taking the union over distributions satisfying the specified Markov chain.
  • C. Broadcast Channels with Confidential Messages: The proof of the broadcast-channel theorem is omitted because it is similar to the proof of Theorem 1.The result also permits restrictions on alphabet sizes.

D. Choice of Security Measures

Effective secrecy combines secrecy of the message with stealth of the communication itself. The paper gives examples showing that either property alone can fail to ensure the other.

  • D. Choice of Security Measures: Secrecy and stealth are distinct requirements: small message leakage does not by itself guarantee that communication remains undetectable.The paper considers examples where secrecy holds without stealth and stealth holds without secrecy.
  • D. Choice of Security Measures: Choosing an incorrect codebook distribution can leave D(P_Z^n||Q_Z^n) bounded away from zero despite satisfying the coding-rate condition.The example uses an alternative input distribution while retaining the relevant rate inequality.
  • D. Choice of Security Measures: Ross can recognize useful transmission even when he cannot decode the message if the output distribution is distinguishable from the reference distribution.This illustrates secrecy without stealth.
  • D. Choice of Security Measures: If R + R1 > I(X;Z) while the resolvability condition is violated, the eavesdropper output may appear stealthy even though secrecy fails.Thus small output divergence alone is insufficient to ensure that the message remains protected.

IV. HYPOTHESIS TESTING

The section frames stealth as binary hypothesis testing over whether meaningful communication is present. Under the stealth condition, the optimal tradeoff satisfies β = 1 − α, so Ross is effectively reduced to guessing.

  • IV. HYPOTHESIS TESTING: Under the stealth condition, Ross’s best detection strategy is guessing, yielding the tradeoff βopt = 1 − α.The same outcome can be achieved without observing the channel output or performing an optimal test.
  • IV. HYPOTHESIS TESTING: When the relevant divergence condition is not satisfied, Ross can detect Joey’s meaningful transmission rather than merely guess.The section contrasts the guessing regime with a regime in which Joey’s action is detectable.
  • IV. HYPOTHESIS TESTING: The hypotheses distinguish non-meaningful transmission from useful messaging, with α measuring false alarms and β measuring mis-detection.Ross accepts H0 for non-meaningful transmission and H1 for meaningful communication.
  • IV. HYPOTHESIS TESTING: For any fixed false-alarm tolerance α, Ross minimizes mis-detection probability with the Neyman–Pearson ratio test.The test chooses between H0 and H1 using a threshold F and minimizes β for a given α.
  • IV. HYPOTHESIS TESTING: As n →∞ and ξ2 →0, the tradeoff approaches the line α + β = 1, with endpoints (0,1) and (1,0).Thus, eliminating false alarms forces mis-detection, while eliminating mis-detection incurs a false-alarm probability of one.

V. DISCUSSION

The discussion emphasizes an unnormalized-divergence resolvability proof that is simpler and stronger than prior variational-distance results in the stated product-distribution, memoryless-channel setting. It distinguishes this work from earlier strong-secrecy analyses that did not address stealth.

  • V. DISCUSSION: The resolvability proof uses unnormalized informational divergence instead of variational distance and is simpler than the prior proof.The comparison is made for product distributions and memoryless channels.
  • V. DISCUSSION: In the stated product-distribution, memoryless-channel setting, the result is stronger because small D(PMZn||PMQn) implies small I(M;Zn), whereas small variational distance implies only small I(M;Zn).The discussion explicitly contrasts the implications of the two secrecy measures.
  • V. DISCUSSION: Hayashi derived asymptotic extensions from an unnormalized-divergence resolvability result for strong secrecy but did not consider stealth.His work focused on strong secrecy despite noting a formal connection to effective secrecy.
Loading 1311.1411v3…