English

On the Information-theoretic Security of Combinatorial All-or-nothing Transforms

Information Theory 2022-02-22 v1 Cryptography and Security Combinatorics math.IT

Abstract

All-or-nothing transforms (AONT) were proposed by Rivest as a message preprocessing technique for encrypting data to protect against brute-force attacks, and have numerous applications in cryptography and information security. Later the unconditionally secure AONT and their combinatorial characterization were introduced by Stinson. Informally, a combinatorial AONT is an array with the unbiased requirements and its security properties in general depend on the prior probability distribution on the inputs ss-tuples. Recently, it was shown by Esfahani and Stinson that a combinatorial AONT has perfect security provided that all the inputs ss-tuples are equiprobable, and has weak security provided that all the inputs ss-tuples are with non-zero probability. This paper aims to explore on the gap between perfect security and weak security for combinatorial (t,s,v)(t,s,v)-AONTs. Concretely, we consider the typical scenario that all the ss inputs take values independently (but not necessarily identically) and quantify the amount of information H(XY)H(\mathcal{X}|\mathcal{Y}) about any tt inputs X\mathcal{X} that is not revealed by any sts-t outputs Y\mathcal{Y}. In particular, we establish the general lower and upper bounds on H(XY)H(\mathcal{X}|\mathcal{Y}) for combinatorial AONTs using information-theoretic techniques, and also show that the derived bounds can be attained in certain cases. Furthermore, the discussions are extended for the security properties of combinatorial asymmetric AONTs.

Keywords

Cite

@article{arxiv.2202.10280,
  title  = {On the Information-theoretic Security of Combinatorial All-or-nothing Transforms},
  author = {Yujie Gu and Sonata Akao and Navid Nasr Esfahani and Ying Miao and Kouichi Sakurai},
  journal= {arXiv preprint arXiv:2202.10280},
  year   = {2022}
}

Comments

16 pages

R2 v1 2026-06-24T09:47:56.717Z