English

Low-bandwidth recovery of linear functions of Reed-Solomon-encoded data

Information Theory 2022-01-27 v3 math.IT

Abstract

We study the problem of efficiently computing on encoded data. More specifically, we study the question of low-bandwidth computation of functions F:FkFF:\mathbb{F}^k \to \mathbb{F} of some data xFkx \in \mathbb{F}^k, given access to an encoding cFnc \in \mathbb{F}^n of xx under an error correcting code. In our model -- relevant in distributed storage, distributed computation and secret sharing -- each symbol of cc is held by a different party, and we aim to minimize the total amount of information downloaded from each party in order to compute F(x)F(x). Special cases of this problem have arisen in several domains, and we believe that it is fruitful to study this problem in generality. Our main result is a low-bandwidth scheme to compute linear functions for Reed-Solomon codes, even in the presence of erasures. More precisely, let ϵ>0\epsilon > 0 and let C:FkFn\mathcal{C}: \mathbb{F}^k \to \mathbb{F}^n be a full-length Reed-Solomon code of rate 1ϵ1 - \epsilon over a field F\mathbb{F} with constant characteristic. For any γ[0,ϵ)\gamma \in [0, \epsilon), our scheme can compute any linear function F(x)F(x) given access to any (1γ)(1 - \gamma)-fraction of the symbols of C(x)\mathcal{C}(x), with download bandwidth O(n/(ϵγ))O(n/(\epsilon - \gamma)) bits. In contrast, the naive scheme that involves reconstructing the data xx and then computing F(x)F(x) uses Θ(nlogn)\Theta(n \log n) bits. Our scheme has applications in distributed storage, coded computation, and homomorphic secret sharing.

Keywords

Cite

@article{arxiv.2107.11847,
  title  = {Low-bandwidth recovery of linear functions of Reed-Solomon-encoded data},
  author = {Noah Shutty and Mary Wootters},
  journal= {arXiv preprint arXiv:2107.11847},
  year   = {2022}
}

Comments

31 pages, 0 figures