Bounds and Characterizations of Authentication/Secrecy Schemes (original) (raw)
Related papers
Coding theorems for secret-key authentication systems
This paper provides Shannon theoretic coding theorems on the impersonation attack and the substitution attack against authentication systems constructed by secret key cryptography. Though several lower bounds on the success probability of the impersonation attack and the substitution attack have been developed, their upper bounds are rarely discussed. This paper treats an extended authentication system including blocklength K and permits the decoding error probability tending to zero as K→∞. It is shown that 2-KI(W:E) is the smallest attainable upper bound of the success probability of the impersonation attack, where I(W;E) denotes the mutual information between cryptogram W and key E. A relationship between the success probability of the substitution attack and H(E|W) is also characterized, where H(E|W) denotes the conditional entropy of E given W
PAPER Coding Theorems for Secret-Key Authentication Systems
SUMMARY This paper provides the Shannon theoretic cod- ing theorems on the success probabilities of the impersonation attack and the substitution attack against secret-key authentica- tion systems. Though there are many studies that develop lower bounds on the success probabilities, their tight upper bounds are rarely discussed. This paper characterizes the tight upper bounds in an extended secret-key authentication system that in- cludes blocklength K and permits the decoding error probability tending to zero as K →∞ . In the extended system an encoder encrypts K source outputs to K cryptograms under K keys and transmits K cryptograms to a decoder through a public chan- nel in the presence of an opponent. The decoder judges whether K cryptograms received from the public channel are legitimate or not under K keys shared with the encoder. It is shown that 2−KI(W ;E) is the minimal attainable upper bound of the success probability of the impersonation attack, where I(W ; E) denotes th...