We refine and extend Ziv's model and results regarding perfectly secure encryption of individual sequences. According to this model, the encrypter and the legitimate decrypter share in common a secret key, not shared with the unauthorized eavesdropper, who is aware of the encryption scheme and has some prior knowledge concerning the individual plaintext source sequence. This prior knowledge, combined with the cryptogram, is harnessed by eavesdropper which implements a finite-state machine as a mechanism for accepting or rejecting attempted guesses of the source plaintext. The encryption is considered perfectly secure if the cryptogram does not provide any new information to the eavesdropper that may enhance its knowledge concerning the plaintext beyond his prior knowledge. Ziv has shown that the key rate needed for perfect secrecy is essentially lower bounded by the finite-state compressibility of the plaintext sequence, a bound which is clearly asymptotically attained by Lempel-Ziv compression followed by one-time pad encryption. In this work, we consider some more general classes of finite-state eavesdroppers and derive the respective lower bounds on the key rates needed for perfect secrecy. These bounds are tighter and more refined than Ziv's bound and they are attained by encryption schemes that are based on different universal lossless compression schemes. We also extend our findings to the case where side information is available to the eavesdropper and the legitimate decrypter, but may or may not be available to the encrypter as well.
翻译:我们改进了Ziv关于个体序列完美安全加密的模型与结果。在该模型中,加密方与合法解密方共享一个秘密密钥,该密钥不被未授权的窃听者所知;窃听者知晓加密方案,并对个体明文源序列具备某种先验知识。窃听者结合这种先验知识与密文,通过有限状态机机制接受或拒绝其所猜测的源明文。若密文未向窃听者提供任何可能增强其超出先验知识的明文认知的新信息,则该加密方案被视为完美安全。Ziv已证明:实现完美保密所需密钥率本质上受到明文序列的有限状态压缩率的下界约束,且该界由Lempel-Ziv压缩结合一次一密加密方案渐近可达。在本工作中,我们考虑更一般化的有限状态窃听者类别,并推导出实现完美保密所需密钥率的相应下界。这些下界比Ziv的界更紧致、更精细,且可通过基于不同通用无损压缩方案的加密方案实现。我们还将研究拓展至窃听者与合法解密方均拥有边信息,而加密方可能拥有也可能不拥有该边信息的情形。