Secure Summation: Capacity Region, Groupwise Key, and Feasibility
Abstract
The secure summation problem is considered, where users, each holds an input, wish to compute the sum of their inputs at a server securely, i.e., without revealing any information beyond the sum even if the server may collude with any set of up to users. First, we prove a folklore result for secure summation - to compute bit of the sum securely, each user needs to send at least bit to the server, each user needs to hold a key of at least bit, and all users need to hold collectively some key variables of at least bits. Next, we focus on the symmetric groupwise key setting, where every group of users share an independent key. We show that for symmetric groupwise keys with group size , when , the secure summation problem is not feasible; when , to compute bit of the sum securely, each user needs to send at least bit to the server and the size of each groupwise key is at least bits. Finally, we relax the symmetry assumption on the groupwise keys and the colluding user sets; we allow any arbitrary group of users to share an independent key and any arbitrary group of users to collude with the server. For such a general groupwise key and colluding user setting, we show that secure summation is feasible if and only if the hypergraph, where each node is a user and each edge is a group of users sharing the same key, is connected after removing the nodes corresponding to any colluding set of users and their incident edges.
Cite
@article{arxiv.2205.08458,
title = {Secure Summation: Capacity Region, Groupwise Key, and Feasibility},
author = {Yizhou Zhao and Hua Sun},
journal= {arXiv preprint arXiv:2205.08458},
year = {2022}
}