A Strong Privacy Amplification Protocol by Unconditionally Secure Authentication

Liu Sheng · Chinese Journal of Computers · 2000

Communications over the public channel should be authenticated to make privacy amplification against active adversaries possible. A new method of constructing authentication codes from error correcting codes is proposed and analyzed, and an arbitrary q ary code( q is a prime power) can be transformed into an authentication code according to the method. When the two communicants share n bit partially secret string S , an authentication scheme can be constructed from a ( 2 m,k,2 m-k+1 ) extended Reed Solomon code, where m=[XXZS-ZSX*3Y0]n/k[XXYS-YSX*3Y0] and 2 mk . As long as the two parties share an authentication key of at least 3 m bit, there exists a strong protocol for privacy amplification which ensures that the probability that the adversary successfully implements active attacks is at most k/2 m , and a highly secret string can be distilled of length about the Renyi entropy of S when given Eve's complete knowledge U=u about S . As n is large enough, more than 3 m bits secret string can always be distilled, thus the protocol is practical.

Read the paper · More papers on PaperTik