On security properties of all-or-nothing transforms
From MaRDI portal
Abstract: All-or-nothing transforms have been defined as bijective mappings on all s-tuples over a specified finite alphabet. These mappings are required to satisfy certain "perfect security" conditions specified using entropies of the probability distribution defined on the input s-tuples. Alternatively, purely combinatorial definitions of AONTs have been given, which involve certain kinds of "unbiased arrays". However, the combinatorial definition makes no reference to probability definitions. In this paper, we examine the security provided by AONTs that satisfy the combinatorial definition. The security of the AONT can depend on the underlying probability distribution of the s-tuples. We show that perfect security is obtained from an AONT if and only if the input s-tuples are equiprobable. However, in the case where the input s-tuples are not equiprobable, we still achieve a weaker security guarantee. We also consider the use of randomized AONTs to provide perfect security for a smaller number of inputs, even when those inputs are not equiprobable.
Recommendations
Cites work
- All or nothing at all
- All-or-nothing encryption and the package transform
- Computational results on invertible matrices with the maximum number of invertible \(2\times 2\) submatrices
- Exposure-resilient functions and all-or-nothing transforms
- scientific article; zbMATH DE number 3577144 (Why is no real title available?)
- scientific article; zbMATH DE number 1759790 (Why is no real title available?)
- scientific article; zbMATH DE number 1418314 (Why is no real title available?)
- Invertible binary matrices with maximum number of 2-by-2 invertible submatrices
- Linear \((2, p, p)\)-AONTs exist for all primes \(p\)
- Some results on the existence of t-all-or-nothing transforms over arbitrary alphabets
- Something about all or nothing (transforms)
Cited in
(9)- \textsf{Transform} without \textsf{encode} is not sufficient for SIFA and FTA security: a case study
- Linear \((2, p, p)\)-AONTs exist for all primes \(p\)
- Exposure-resilient functions and all-or-nothing transforms
- scientific article; zbMATH DE number 1759790 (Why is no real title available?)
- Applied Cryptography and Network Security
- scientific article; zbMATH DE number 1418314 (Why is no real title available?)
- Something about all or nothing (transforms)
- Rectangular, range, and restricted AONTs: three generalizations of all-or-nothing transforms
- All or nothing at all
This page was built for publication: On security properties of all-or-nothing transforms
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q2243897)