English

Secure Summation: Capacity Region, Groupwise Key, and Feasibility

Information Theory 2022-05-18 v1 math.IT

Abstract

The secure summation problem is considered, where KK users, each holds an input, wish to compute the sum of their inputs at a server securely, i.e., without revealing any information beyond the sum even if the server may collude with any set of up to TT users. First, we prove a folklore result for secure summation - to compute 11 bit of the sum securely, each user needs to send at least 11 bit to the server, each user needs to hold a key of at least 11 bit, and all users need to hold collectively some key variables of at least K1K-1 bits. Next, we focus on the symmetric groupwise key setting, where every group of GG users share an independent key. We show that for symmetric groupwise keys with group size GG, when G>KTG > K-T, the secure summation problem is not feasible; when GKTG \leq K-T, to compute 11 bit of the sum securely, each user needs to send at least 11 bit to the server and the size of each groupwise key is at least (KT1)/(KTG)(K-T-1)/\binom{K-T}{G} bits. Finally, we relax the symmetry assumption on the groupwise keys and the colluding user sets; we allow any arbitrary group of users to share an independent key and any arbitrary group of users to collude with the server. For such a general groupwise key and colluding user setting, we show that secure summation is feasible if and only if the hypergraph, where each node is a user and each edge is a group of users sharing the same key, is connected after removing the nodes corresponding to any colluding set of users and their incident edges.

Keywords

Cite

@article{arxiv.2205.08458,
  title  = {Secure Summation: Capacity Region, Groupwise Key, and Feasibility},
  author = {Yizhou Zhao and Hua Sun},
  journal= {arXiv preprint arXiv:2205.08458},
  year   = {2022}
}
R2 v1 2026-06-24T11:20:08.785Z