Method and unit for operating a storage device, storage device, and data processing system

By applying the randomized encoding process and PUF signature on the storage device, and using discrete memoryless multi-sources to generate common randomness and keys, the problems of low data storage and identification efficiency and insufficient confidentiality in the prior art are solved, and efficient and secure data storage and identification are achieved.

CN112292684BActive Publication Date: 2025-06-13TECHNISCHE UNIVERSITAT MUNCHEN
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201980041255.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-06-21
Filing Date
2019-06-19
Publication Date
2025-06-13
Estimated Expiration
2039-06-19

AI Technical Summary

Technical Problem

Existing storage devices and operating methods are difficult to ensure efficient storage and identification of data when processing large amounts of data, and at the same time, there is a lack of effective confidentiality measures, especially in the identification process.

Method used

By applying a randomized encoding process on the storage device, the data to be stored is randomly encoded, and common randomness and keys are generated using PUF signatures and discrete memory-free multi-sources to ensure the confidentiality and security of the data during storage and identification.

Benefits of technology

It realizes efficient storage and identification of data on the storage device while ensuring the confidentiality and security of data, and preventing eavesdroppers from eavesdropping and identification of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112292684B_ABST
    Figure CN112292684B_ABST
Patent Text Reader

Abstract

The present invention relates to a method (S) for operating a storage device (10), wherein, in order to write and store a storage item (d) into the storage device (10), the storage item (d) to be written and stored is provided (S1), in particular by using recognized concepts and theories (S1), an encoding process (S2) carried out in a randomized manner is applied to the storage item (d) in order to generate and provide a randomized encoded storage item (Uk), and the randomized encoded storage item (Uk) is written and stored (S3) into the storage device (10). At least a first randomization process (S4) is the basis of the encoding process (S2). The first randomization process (S4) is a randomization process dedicated to and assigned to the storage device (10). The present invention also relates to a unit for operating a storage device (10), a storage device (10) and a system (1) for processing data. By having two randomization processes (S4, S5) as the basis of the encoding process (S2), a distinction can be made between a confidentiality-guaranteed and a non-confidentiality-guaranteed randomization process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to a method and a unit for operating a storage device, such a storage device, and a system for data processing. Background Art

[0002] Known storage devices and methods for operating such storage devices are described in the so-called Shannon model for message transmission and channel storage, in which, for the block lengths involved, messages and storage items can be reliably transmitted and written in an exponentially growing manner. However, in a large variety of applications, the increasing amount of data to be controlled and the huge and rapid development require more effective data storage and identification strategies, while also paying attention to increasing confidentiality matters, especially for the identification process, which is understood as a process of detecting and / or confirming the existence of a storage item in the storage device, i.e., the theory introduced by Ahlswede and Dueck in 1989 [2]. Summary of the Invention

[0003] An object of the present invention is to provide a method and a unit for operating a storage device, such a storage device, and a system for data processing, which are configured to store and identify data on the storage device more effectively and securely.

[0004] The object of the present invention is achieved by a method for operating a storage device according to the claimed subject matter, a unit for operating or controlling a storage device according to the claimed subject matter, a storage device according to the claimed subject matter, and a system for data processing according to the claimed subject matter.

[0005] According to a first aspect of the present invention, there is provided a method for operating a storage device or a method for operating such a storage device, wherein, in order to write and store a storage item to the storage device: (A) provide the storage item to be written and stored, (B) an encoding process performed in a randomized manner is applied to the storage item so as to generate and provide a randomly encoded storage item, and (C) write and store the randomly encoded storage item to the storage device. At least a first randomization process is the basis of the encoding process. The first randomization process is a randomization process dedicated to and assigned to the storage device.

[0006] The process of providing the storage item to be written or stored may also be referred to as a process of obtaining, receiving, generating, acquiring, etc. from a device, a sensor, a processor, or another storage device, for example.

[0007] According to a preferred embodiment of the method according to the present invention, at least one second randomization process is the basis of the encoding process.

[0008] A distinction can be made between a confidentiality-guaranteed and a confidentiality-non-guaranteed randomization process by means of two randomization processes that underlie the encoding process.

[0009] In this regard, the second randomization process can be a randomization process dedicated to a specific hardware item.

[0010] In particular, the second randomization process can be based on the PUF signature of the underlying hardware item to ensure a high degree of confidentiality. According to a preferred embodiment of the invention, storing storage items by means of the PUF signature can be made secure and eavesdropping by eavesdroppers can be prevented. Thus, the PUF signature can be designed to have a rather small length when compared to the block length of the underlying storage unit and / or when assigned to the storage item to be written and / or stored in the storage device. Additionally, the key derived from the PUF signature can also advantageously have a negligible length.

[0011] The first randomization process can be a common randomization process.

[0012] According to an alternative and preferred embodiment of the invention, the respective randomization processes are obtained from a discrete memoryless multi-source and / or based on a discrete memoryless multi-source with respect to one or more underlying probability distributions and alphabets.

[0013] According to a specific implementation of the method for operating a storage device according to the invention, the encoding process and its underlying encoder can be configured to generate an encoded storage item from the obtained storage item, in particular based on source items obtained from a discrete memoryless source, as a juxtaposition with:

[0014] (i) auxiliary data derived by the encoder and in particular its dedicated unit,

[0015] (ii) an auxiliary message also derived by the encoder and in particular its dedicated unit,

[0016] (iii) the image of the common randomness under a mapping that is characteristic of the underlying identification protocol and corresponds to the storage item encrypted using a key (in particular by group composition).

[0017] The common randomness and / or the key can be generated and derived by the encoder and in particular by its dedicated unit, and / or from the storage item and the source item, the storage item and the source item being obtained from a common source, a PUF source, and / or a general and underlying discrete memoryless multi-source over the underlying alphabet.

[0018] According to another embodiment of the method for operating a storage device and for identifying the presence or absence of a storage item within the storage device,

[0019] - Provide information regarding the presence or absence of a storage item to be identified in the storage device.

[0020] - A decoding process for identification by randomization can be applied to storage items to generate and provide randomly encoded storage items.

[0021] - The randomly encoded storage items are attempted to be identified or are identified within the storage device, and

[0022] - An identification message indicating the presence or absence of randomly encoded storage items in the storage device is generated and output.

[0023] Preferably, for the encoding process and its underlying encoder and / or the decoding process and its underlying decoder, it is configured such that: by considering the auxiliary data and the auxiliary message transmitted together with the encoded storage items written to the storage device,

[0024] (a) Together with source items obtained from a basic random source, the decoder can reconstruct the common randomness and the key, respectively, as attempts or approximations of the common randomness and the key at the encoder position, and with a high probability of making them equal, and

[0025] (b) The decoder can reconstruct an image of the common randomness from the encrypted image of the common randomness by using the inverse of the key and thus in a decrypted form.

[0026] For the identification process and / or the output process related to the identification message, the decoding process and its underlying decoder can be advantageously configured such that

[0027] - Based on a mapping that is a characteristic of the basic identification protocol, compare the reconstruction of the basic key for the storage item of interest with the reconstruction of the basic key for any storage item stored in the storage device, and in particular,

[0028] - For at least one storage item stored in the storage device, in the case of consistent reconstruction, output an acknowledgment message, and for each storage item stored in the storage device, in the case of inconsistent reconstruction, output a non-acknowledgment message.

[0029] When summarizing all the cases given above, the present invention can be alternatively or additionally described by the following description:

[0030] When a storage process or system receives an item as the message to be stored then, the encoder is used for the encoding process S2, which can have the following configuration:

[0031] .

[0032] Thus, through the encoder , the encoded storage item as the common message Constructed based on the source project is written to storage device 10 in S3 and is a juxtaposition of the following:

[0033] (i) Auxiliary data derived by the encoder and its specific unit such that the decoder can reconstruct the common randomness together with that from random sources 30, 40 ,

[0034] (ii) An auxiliary message also derived by the encoder and its another specific unit such that the decoder can reconstruct the key together with that from random sources 30, 40 ,

[0035] (iii) The image of the common randomness under the mapping that is a feature of the identification protocol and corresponds to the message where the message is encrypted using the key , especially by group composition

[0036] wherein the common randomness and the key are also generated and derived by the encoder and its specific unit, and especially based on the message obtained from the common source 30 and / or PUF source 40 and the underlying discrete memoryless multi-source usually on the alphabet and the source project is generated and derived.

[0037] Such an identification mapping is part of the identification protocol and can be explicitly constructed as described in Verdu and Wei

[15] .

[0038] For the identification of the message , a decoder defined according to the following formula is used

[0039]

[0040] Based on and , the decoder generates the common randomness and a key which are respectively generated as a common randomness at the encoder and a key attempt or approximation, in particular by constructing a protocol to make them equal with a high probability, i.e., satisfying and .

[0041] The decoder reconstructs from and by using the key in a reverse and thus decrypted form to reconstruct .

[0042] Then, in the case where the decoder is interested in the message the decoder compares and for reconstruction.

[0043] Furthermore, the present invention also provides a unit for operating a storage device, which is configured to initiate, execute, and / or control a method for operating a storage device, and the method is configured according to the present invention.

[0044] The present invention also proposes to provide a storage device, which is configured to store storage items and is executed, used, operated, and / or controlled by a method according to the present invention, and particularly includes a unit for operating a storage device configured according to the present invention and / or a connection to the unit.

[0045] Finally, a system for data processing according to the present invention is configured to be used with and / or controlled by a method according to the present invention, and the system particularly includes a storage device designed according to the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] These and other details, advantages, and features of the present invention will be described based on embodiments of the present invention and with reference to the drawings.

[0047] Figure 1 is a schematic block diagram of a first embodiment of a storage system and a method for operating a storage device according to the present invention, which particularly focuses on the process of encoding and writing the provided storage items.

[0048] Figure 2 is a schematic block diagram of another embodiment of a storage system and a method for operating a storage device according to the present invention, which particularly focuses on the process of identifying the provided storage items with respect to the presence or absence of the provided storage items in the storage device.

[0049] Figure 3 and Figure 4 is a schematic block diagram of other embodiments of a storage system and a method of operating a storage device according to the present invention, which particularly focuses on a single PUF source and PUF sources combined with a common source, where all sources are formed as discrete memoryless multi-sources. Detailed implementation manners

[0050] In the following embodiments and the technical background of the present invention, by referring to the attached Figures 1 to 4 are introduced in detail. The same or equivalent elements and elements with the same or equivalent functions are denoted by the same reference numerals. The detailed descriptions of the elements and components are not repeated in every case.

[0051] Without departing from the gist of the present invention, the depicted and described features and other characteristics of the embodiments of the present invention can be arbitrarily separated and recombined.

[0052] The present invention relates to a method S of operating a storage device 10, wherein, in order to write and store a storage item into the storage device 10, a storage item S1 to be written and stored is provided , in particular, the storage item to be written and stored is provided by using the recognized concepts and theories, and an encoding process S2 performed in a randomized manner is applied to the storage item so as to generate and provide a randomly encoded storage item , and the randomly encoded storage item is written and stored S3 into the storage device 10. At least the randomization process S4 is the basis of the encoding process S2. The first randomization process S4 is a randomization process dedicated to and assigned to the storage device 10. The present invention also relates to a unit for operating the storage device 10, a storage device 10, and a system 1 for processing data. By having two randomization processes S4, S5 based on the encoding process S2, a distinction can be made between a confidentiality-guaranteed and a non-confidentiality-guaranteed randomization process.

[0053] Figure 1 is a schematic block diagram of a first embodiment of a data processing system 1 and a method S for operating a storage device 10 according to the present invention, which particularly focuses on the encoding process S2 and the process S3 of writing the provided message or storage item.

[0054] In Figure 1 , a message or a storage item selected from a set of messages or a storage item is provided according to the process S1, and it is applied to the storage item based on a combination of the randomization processes S4 and S5 , and The process S2 of encoding, the randomization processes S4 and S5 are based on the common source 30 and the PUF source 40. The common source 30 is dedicated to the storage device 10, while the PUF source 40 is secret and is only provided to authorized users or groups of authorized users.

[0055] The process S2 of encoding a stored item or a message is implemented by an encoder as defined above and further elucidated below, and it produces an encoded stored item or a message. The encoded stored item or the message is written by the process S3 and thus stored in the storage device 10, for example, implemented through a common database.

[0056] Therefore, the process S2 of encoding a stored item implemented by the encoder depends on the underlying message or stored item to be written or stored , and depends on the source inputs provided by the first randomization process S4 and the second randomization process S5 and their underlying sources 30 and 40 respectively , and ultimately depends on the further specific nature and characteristics of the encoder .

[0057] Figure 2 is a schematic block diagram of another embodiment of the data processing system 1 according to the present invention and the method S for operating the storage device 10, with particular emphasis on the process S7 of identifying whether the provided stored item exists or does not exist in the storage device 10.

[0058] Figure 2 The identification process S8 for the message or stored item to be checked is described in more detail. First, the step of checking whether the stored item to be checked exists in the storage device 10 provides S1 to the process S6 of decoding the stored item . The decoding process S6 is also based on one or more randomization processes S4 and S5 and the corresponding underlying sources 30 and 40 respectively, and in particular on the source input , and it is implemented by a decoder as described above and will be further elucidated in detail below.

[0059] The result of the decoding process S6 is provided to the identification process S7, which controls the subsequent process S8 of outputting the identification message through the process S7'.

[0060] The identification message provided by the output process S8 produces a confirmation result, and for example, in an investigation message “Yes” when there are instances or representations stored in storage device 10. The process S8 of outputting an identification message produces a confirmation of the non - existence of an investigation message as a result. For example, if storage device 10 does not contain any instances or representations of the investigation message, it is “No”.

[0061] Figure 3 and Figure 4 are schematic block diagrams of further embodiments of data processing system 1 and method S of operating storage device 10 according to the present invention, namely, with a particular emphasis on providing a single PUF source 40 and providing a PUF source 40 in combination with a common source 30, respectively. All sources 30, 40 are preferably formed as discrete memoryless multi - sources.

[0062] Figure 3 and Figure 4 elucidate in more detail the presence of one or two discrete memoryless multi - sources 30 and 40, namely, the presence of a single PUF source 40 in Figure 3 and dedicated to a certain external hardware on the one hand, and on the other hand the presence of a common source 30 together with the PUF source 40 in Figure 4 as well.

[0063] In addition, the attacks of eavesdropper 20 are elucidated in Figure 3 and Figure 4 . The eavesdropper can access the common database 10, but cannot access the PUF source 40 and its corresponding data for reconstructing the underlying key as already elucidated above and will be further explained below. Thus, the eavesdropper 20 cannot identify any stored items or messages for which the detection and / or confirmation of the presence or absence may have been written and stored in storage device 10 using the data of PUF source 40.

[0064] More details about the embodiments shown in Figure 3 and Figure 4 are provided in the following sections.

[0065] Therefore, these and other aspects of the present invention will also be described in detail below:

[0066] General technical formula

[0067] In connection with the present invention, secure storage on a public database is considered, such that the stored messages can be identified. It is assumed that legitimate users have access to the output of the source. The source is configured and used to generate common randomness for identification. A protocol for secure storage for identification is defined such that the number of messages that can be identified grows exponentially with the number of symbols read from the source. Additionally, the privacy leakage of the protocol for identification is considered.

[0068] In the following, some aspects of the identification based on the present invention will first be improved through the concept of point-to-point transmission, and then its use and application will be considered in order to improve the storage of the identification model to which the present invention belongs:

[0069] One of the most fundamental models in information theory is the discrete memoryless channel or DMC for point-to-point transmission. This concept has been introduced in C. E. Shannon's "A Mathematical Theory of Communication" (Bell System Technical Journal, Vol. 27, No. 3, pp. 379 - 423, 1948, [1]). For such a model, the Shannon capacity is defined as the supremum of all achievable transmission rates.

[0070] Informally speaking, if a message can be transmitted at this rate, then a rate can be achieved, and the transmitted message can be reconstructed from the channel output with high probability. For this notion of achievability, the number of messages that can be reliably transmitted grows exponentially with the block length. In addition to the Shannon capacity, the identification capacity can also be introduced according to the content in R. Ahlswede and G. Dueck's "Identification via channels" (IEEE Transactions on Information Theory, Vol. 35, No. 1, pp. 15 - 29, 1989, [2]).

[0071] Here, point-to-point transmission over a discrete memoryless channel is again considered, but the definition of achievability is different.

[0072] The decoder now does not attempt to find the message that has been sent from the channel output, but the decoder is interested in different messages or a single message and attempts to find whether this message already exists, that is, the decoder attempts to identify the message. Of course, the sender does not know the message that the receiver is interested in.

[0073] In this case, the probability that the receiver correctly identifies the message should be close to 1. For this notion of achievability, the number of messages that can be reliably identified grows exponentially with the block length.

[0074] The corresponding strong converse result was found in "New results in the theory of identification via channels" by T. S. Han and S. Verdú, IEEE Transactions on Information Theory, Vol. 38, No. 1, pp. 14 - 25, [3].

[0075] The further development of the identification concept for identifying storage models and applied to identifying storage models can be further promoted by looking at the possible use cases in the various possible applications that can be envisioned in the context of the present invention.

[0076] - Storing a user's private information in a public data cloud by a service provider.

[0077] - Storing data in an industrial application (e.g., industrial data (production data, operation data, etc.) when operating complex equipment) in a database, followed by the identification of errors or abnormal situations.

[0078] - Storing a large amount of data in a public space (e.g., video surveillance) for the subsequent identification of people or dangerous situations, where on the one hand certain people / events should be identified and on the other hand the privacy of other people should be protected.

[0079] In addition, there are also various implementation examples, one of which is given by the following scenario:

[0080] - The data is stored in a database by an authorized agency.

[0081] - When identifying people and events, the police can access the database.

[0082] - The police attempt to identify a specific person .

[0083] - The judge can permit this task.

[0084] - Then, the police must use a decoder to identify the person .

[0085] - The police will only get a yes or no answer.

[0086] - In addition, the decoder cannot be used to identify another person because the decoder always gives the wrong answer for another person.

[0087] In this case, two different models are considered:

[0088] 1. Secure storage for identification on a public database:Particularly relates to a Physical Unclonable Function (PUF) source. The PUF source is substantially equivalent to a biological source. We assume that the output of the biological source uniquely characterizes a person, while the output of the PUF source uniquely characterizes a device. This allows us to use the output of the PUF source for secure storage.

[0089] Considering Figure 4 the secure storage process for identification described in

[0090] In the first stage, the system obtains the message to be stored in the database , where the database consists of k storage units, and each storage unit can store values from the alphabet . The system reads from the PUF source. Then, the system uses an encoder to generate from (i.e., the item to be stored for message ) and stores in the public database.

[0091] In the second stage, the system reads from the database and reads from the PUF source. Then, the system uses a decoder based on the message of interest to determine and whether is the message stored in the underlying database.

[0092] 2. Storage of an identification model with two sources : Considered Figure 4 the secure storage process for identification described in

[0093] In the first stage, the system obtains the message to be stored in the database , where the database consists of storage units, and each storage unit can store values from the alphabet . We use for time sharing between the PUF source and the common source. The system reads from the common source and reads from the PUF source. Then, the system uses an encoder to generate from ( ) and stores in the public database.

[0094] In the second stage, the system reads from the database and reads from the common source and reading from the PUF source . Then, the system uses a decoder according to the message of interest in order to utilize ( ) and to determine whether it is the message stored in the database.

[0095] Additional technical background

[0096] In the following, in order to better understand the gist of the present invention and its differences when compared with the general strategies for transmitting, writing, and / or storing storage items or messages, other technical backgrounds are summarized:

[0097] Traditionally, storage is only performed in the Shannon image. Here, all messages are stored such that many messages can be stored exponentially. When reading the memory content, the question of which message is stored is answered.

[0098] "Common randomness in information theory and cryptography ii. CR capacity" by R. Ahlswede and I. Csiszar, see IEEE Transactions on Information Theory, Vol. 44, No. 1, pp. 225 - 240, 1998, [4], defines the so-called source model for generating common randomness.

[0099] Common randomness plays an important role in identification. In addition to R. Ahlswede and I. Csiszar [4], R. Ahlswede and V.B. Balakirsky also described "Identification under random processes" [5] in Citeseer, 1995, and introduced how to reliably identify messages by sending an auxiliary message over the channel using the common randomness generated from the source. Here, the number of messages that can be reliably identified grows exponentially with the number of symbols read from the source.

[0100] Security is a key requirement for modern communication and storage systems. A promising approach to achieving security is physical layer security based on information - theoretic security.

[0101] The basic model considered in information - theoretic security is the wiretap channel, as discussed by A.D. Wyner in "The wire - tap channel", Bell System Technical Journal, Vol. 54, No. 8, pp. 1355 - 1387, 1975, [6], and by I. Csiszar and J. Korner in "Broadcast channels with confidential messages", IEEE Transactions on Information Theory, Vol. 24, No. 3, pp. 339 - 348, 1978, [7].

[0102] In this context, and in contrast to point-to-point transmission, in the context of the present invention, it is preferably assumed that an attacker or eavesdropper can access the messages sent through an additional discrete memoryless channel. In particular, the present invention relates to a protocol that allows reliable communication between legitimate users while making it difficult for an attacker to decode the messages from the channel output to which the attacker has access. In this case, the number of messages that can be transmitted reliably and securely grows exponentially with the block length.

[0103] According to "New Directions in the Theory of Identification via Channels" by R. Ahlswede and Z. Zhang, IEEE Transactions on Information Theory, Vol. 41, No. 4, pp. 1040 - 1050, [8], identification for the wiretap channel is considered. It can be seen that in this case, the number of messages that can be reliably identified as described above grows exponentially with the block length. The secure identification capacity is even equal to the Shannon capacity of the main channel. This result can be generalized according to: "Secure Identification for the Wiretap Channel; Robustness, Superadditivity, and Continuity" by H. Boche and C. Deppe, IEEE Transactions on Information Forensics and Security, 2018, [9] and "Secure Identification under Jamming Attacks", 2017 IEEE Symposium on Information Forensics and Security (WIFS), IEEE, 2017, pp. 1 - 6,

[10] , which consider robust identification for the wiretap channel.

[0104] For the source model, there is also a point to consider the generation of keys, as described in "Common Randomness in Information Theory and Cryptography - Part I: Secret Sharing" by R. Ahlswede and I. Csiszar, IEEE Transactions on Information Theory, Vol. 39, No. 4, 1993,

[11] .

[0105] "Biosecurity from an Information - Theoretic Perspective" by T. Ignatenko and F. M. Willems, Now, 2012,

[12] , and "Privacy - Security Trade - offs in Biometric Security Systems" by L. Lai, S.-W. Ho, and H. V. Poor, 46th Annual Allerton Conference on Communication, Control, and Computing, 2008, pp. 268 - 273,

[13] , explain the discrete memoryless source from the source model as a biological source, and they consider the privacy leakage of the protocols for key generation.

[0106] Some results on common randomness and key generation from discrete memoryless multi - sources are essential for the present invention. Hereinafter, common randomness is also referred to as CR, keys are also referred to as SK, and discrete memoryless multi - sources are also referred to as DMMS.

[0107] In the following, specific information - theoretic entities and requirements for defining the present invention will be promoted, introduced, and defined:

[0108] First, in the context of the present invention, the following information - theoretic models are considered in particular:

[0109] Definition 1 . Set as a natural number. The source model consists of a discrete memoryless multi - source (DMMS) , an (optionally randomized) encoder and an (optionally randomized) decoder . Set and as the outputs of the DMMS. The random variable or is generated from by using , and the random variable is generated from ( ) by using . We call ( ) the common randomness / key or CR / SK generation protocol.

[0110] In addition, the generation of common randomness or CR as described above is considered.

[0111] Definition 2. . Set . The item is called the achievable common randomness or CR generation rate with a forward communication rate constraint for the source model if for every there exists such that for all there is a common randomness / key or CR / SK generation protocol such that for , the following relation is satisfied:

[0112]

[0113] The corresponding CR / SK generation protocol is called the common randomness or CR generation protocol with a rate constraint. The supremum of all achievable CR generation rates with a forward communication rate constraint is denoted by the CR capacity .

[0114] Remark 1 . The last achievability requirement (2) is required to avoid protocols in which CR is deterministically generated while is arbitrarily large. The requirement as well as the bounds on can be facilitated by a claim, which shows and The distance between them is arbitrarily small, so it is required that .

[0115] Remark 2 . It can be seen that for each CR generation protocol with rate constraints, a CR generation protocol with rate constraints can be found such that for , the following formula is valid.

[0116]

[0117] This is why this protocol can always be considered in the following, where the distribution of the common randomness CR is close to the uniform distribution in this sense.

[0118] In the discussion of Ahlswede and Csiszar in 1998, was further characterized.

[0119] The privacy leakage of the source model was also considered. This consideration is meaningful when assuming that a part of the source model, the DMMS, is a PUF source.

[0120] Definition 3 . The triple is called the triple of the achievable CR generation rate, the forward communication rate, and the privacy leakage rate for the source model if each has , so that for all there is a CR / SK generation protocol, so that for , the following relationship is satisfied:

[0121]

[0122] The corresponding CR / SK generation protocol is called a private CR generation protocol. The set of all rate triples achievable using a private CR generation protocol is called the CR capacity region .

[0123] In the context of the present invention, what is of interest is . In the first approach, a private CR generation protocol with deterministic encoders and decoders is considered. The corresponding CR capacity region is denoted by .

[0124] In the discussion of Ahlswede and Csiszar in 1998, a deterministic CR generation protocol with rate constraints was considered, and the corresponding capacity has been described, which is called .

[0125] The following properties of them are valid:

[0126] Theorem 1 : It is considered that

[0127]

[0128] Among them, maximizing runs over all random variables so that the attribute and the attribute are satisfied. In addition, only the random variables need to be considered, which follow .

[0129] On the one hand, key generation with perfect secrecy is also considered.

[0130] Definition 4 . A project is called the achievable SK generation rate for the source model if for each it has such that for all it has a CR / SK generation protocol, and the following relationship is satisfied:

[0131]

[0132] The corresponding CR / SK generation protocol is represented by a perfect SK generation protocol. The supremum of all achievable SK generation rates is called the SK capacity .

[0133] It can be proved in the following results:

[0134] Theorem 2 . It is considered that .

[0135] Remark 3 . In the proof of achievability, deterministic encoders and decoders can be used. This implies the relationship.

[0136] Limitations of the current state of the art

[0137] In the description of the part of the prior art, the storage of the exponential data volume of the Shannon image currently in use has been described. In the storage of the Shannon image, big data is actually a huge problem. The gap between the data rate generated by big data and the data rate provided by Moore's law for the development of storage media is still constantly expanding. For the storage for later identification, there is no such problem.

[0138] A source model for generating common randomness is considered. However, contrary to the discussion by Ahlswede and Csiszar in 1998, when the source is interpreted as a biological source, the privacy leakage of the corresponding protocol can also be considered. Then the common randomness can be used for identification.

[0139] Therefore, in the following, the contribution of the present invention is especially twofold.

[0140] While considering privacy leakage, the capacity for common randomness generation is characterized by a discrete memoryless source. A protocol for identification using a discrete memoryless source is constructed. Contrary to the discussion by Ahlswede and Csiszar in 1998 and the discussion by Ahlswede and Balakirsky in 1995, in the context of the present invention, it is assumed that the auxiliary messages are stored in a public database.

[0141] The protocols for identification are constructed such that they provide confidentiality. Therefore, these protocols allow for secure storage for identification. The present invention can also consider the privacy leakage of these protocols.

[0142] Some aspects of the present invention

[0143] The present invention is especially based on the representation of a model for identification and secure storage of the corresponding protocol.

[0144] In the following, an information - theoretic model for the storage process for identification based on the present invention is defined.

[0145] Definition 5 . Settings . The storage for the identification model consists of a discrete memoryless multi - source (DMMS) over an alphabet , an alphabet , a set of (possibly randomized) encoders, and a set of (possibly randomized) decoders, all . Settings . Let and be random variables (RVs) generated from . We call the storage for the identification protocol.

[0146] Assume that for each storage unit, we read symbols from the PUF source. Now discuss the properties of an intuitively good storage for the identification protocol.

[0147] When the decoder is interested in the message , it is reasonable to require that at When stored in a database, the decoder makes a correct decision with high probability. The corresponding error is called a type-I error. Thus, the decoder should have a low probability of making a type-I error.

[0148] When the message stored in the database is not , the decoder should also make a correct decision with high probability. We call the corresponding error a type-II error. Thus, the decoder should have a low probability of making a type-II error.

[0149] Interested in the maximum possible recognition rate, in this case, considering the number of storage units as the source. Usually for recognition, the second-order rate is considered.

[0150] Consider eavesdropper 20 who reads from the common database 10. Assume that eavesdropper 20 wants to identify a specific message. Eavesdropper 20 knows the protocol used and can even assume that eavesdropper 20 knows the message that the decoder wants to identify. Appropriately, the sum of the probability that the eavesdropper makes a type-I error and the probability that the eavesdropper makes a type-II error is close to 1.

[0151] The output of the PUF source uniquely characterizes the device, so one might want to reuse a part of the output of the PUF source. This is why it is desirable that the attacker does not have much information about the output of the PUF source .

[0152] This gives the motivation for the following definition of the achievability of storage for the recognition model.

[0153] Definition 6 . Set . The tuple is called an achievable rate pair for the storage of the recognition model if for every it has such that for all and , there exists a storage for the recognition protocol, then for all , for all decoding strategies of eavesdropper 20, the following relationship is satisfied:

[0154]

[0155] The first item describes the decoder error of the first type, the second item describes the decoder error of the second type, the third item describes the property of the model for eavesdropper 20, the fourth item describes the growth in which the controllable storage item in the model increases or improves exponentially by a factor of two, and the fifth item describes the privacy leakage property of the model.

[0156] The corresponding storage for identifying the protocol is called the secure storage protocol. We call the set of all achievable rate pairs for this storage for identifying the protocol the capacity region .

[0157] Remark 4. Requirement (3) - the third item given in Definition 6 above - ensures that the protocol is optimal when considering security in the following sense. There is a decoding strategy for the eavesdropper such that the sum of the probability of the eavesdropper making a type I error and the probability of the eavesdropper making a type II error is 1, while the eavesdropper does not use any observations from its public database

[0158] Remark 5 . The secret model selected from the 2012 treatise of Ignatenko and Willems can be interpreted as a model for secure storage using biological sources. But here, the decoder reconstructs the message stored in the database rather than identifying it. Accordingly, the set of messages that can be stored in the database grows exponentially with the block length rather than growing exponentially multiplicatively

[0159] The following observations can be made regarding the capacity region : Let

[0160] Lemma 1 : Set . is a closed set

[0161] To describe , Theorem 1 obtained from the 1998 treatise of Ahlswede and Csiszar can be used

[0162] Theorem 3 : Assume

[0163]

[0164] and only consider the random variable satisfying .

[0165] Now, consider CR generation with a random private CR generation protocol

[0166] Theorem 4 : Assume

[0167]

[0168] and only consider the random variable satisfying .

[0169] Now describe Therefore, while considering privacy leakage, use the results generated by CR and SK. First, consider the deterministic secure storage for the identification protocol Let represent the corresponding capacity region, and obtain the following achievability results.

[0170] Theorem 5 : Assume that

[0171]

[0172] where the union is taken over all random variables V that satisfy and .

[0173] Now consider the random secure storage for the identification protocol.

[0174] Theorem 6 : Assume that

[0175]

[0176] where the union is taken over all random variables such that and .

[0177] In the following, an information - theoretic model of the storage process for identification using two sources 30, 40 is defined.

[0178] Definition 7 : Set as a finite set, and . The two - source storage for the identification model consists of the alphabet , two discrete memory - less multi - sources (DMMS) and over the alphabets and , respectively, the set of (possibly randomized) encoders for all , and the set of (possibly randomized) decoders for all . Set and as random variables (RVs) generated from , and set and as multiple random variables generated from . Define and . This entity is called the two - source storage for the identification protocol.

[0179] Now, the properties that stores for identifying protocols should have so that they are intuitively considered to be good stores for identifying protocols will be discussed below.

[0180] Reasonably: Required when using the decoder To a message or stored item Find a message or stored item When the message is stored in the database 10, the probability of the first type of error is small. It is also desirable to have a small probability of the second type of error. Consider an eavesdropper 20 who reads from the public database 10 and wants to find out whether the message Is it stored on the database 10. The eavesdropper 20 also has access to the public source 30. It is desirable that the sum of the probability that the eavesdropper 20 makes a type I error and the probability that the eavesdropper 20 makes a type II error is close to 1.

[0181] We are interested in the maximum possible recognition rate, in which case the number of memory cells is considered a resource. Consider a fixed ratio of the number of symbols read from the two sources to the number of memory cells in the database 10 .

[0182] The output of the PUF source uniquely characterizes the device, so you may want to reuse part of the output of the PUF source. This is why it is hoped that the attacker 20 does not have much information about the PUF source output. information.

[0183] This gives motivation for the following definition of realizability of storage for identification models.

[0184] Definition 8 :set up We will tuple is called the achievable rate pair for storage of the recognition model, if each All have , so that all and have storage for identifying protocols, then for all , for all decoder strategies of eavesdropper 20 All satisfy the following relationship:

[0185]

[0186] The set of all rate pairs achievable using this storage for identifying the protocol is called the capacity region .

[0187] The considerations regarding CR generation can be extended by adding a second source.

[0188] Definition 9 : set up and settings . The two-source model consists of two discrete memoryless multi-sources (DMMSs) respectively over alphabets and , (possibly random) encoders and , and (possibly random) decoders . Settings and are random variables (RVs) generated from and , and setting is an RV generated from and . Define and . RV is generated using from , and RV is generated using from . The can be called a two-source CR generation protocol.

[0189] Inspired by the discussion on the achievability of the source model and the storage for identifying the model, the achievability for the two-source model can be defined.

[0190] Definition 10 : The triple is called an achievable CR generation rate versus forward communication rate versus privacy leakage rate pair for the two-source model if for every there exists such that for all there is a CR generation protocol, and for the following relationship holds:

[0191]

[0192] The set of all rate triples achievable using this CR generation protocol is called the CR capacity region .

[0193] In addition to the foregoing description of the present invention, for additional disclosure, express reference is made to the Figures 1 to 4 graphical representation.

[0194] List of references

[0195] [1] C. E. Shannon, "A Mathematical Theory of Communication", Bell System Technical Journal, Vol. 27, No. 3, pp. 379 - 423, 1948

[0196] [2] R. Ahlswede and G. Dueck, "Identifying via channels", IEEE Transactions on Information Theory, Vol. 35, No. 1, pp. 15 - 29, 1989

[0197] [3] T. S. Han and S. Verdu, "New results in the theory of identifying via channels", IEEE Transactions on Information Theory, Vol. 38, No. 1, pp. 14 - 25, 1992

[0198] [4] R. Ahlswede and I. Csiszar [4], described by R. Ahlswede and V. B. Balakirsky, "Identification under random processes", Citeseer, 1995

[0199] [5] R. Ahlswede and V. B. Balakirsky, "Identification under random processes", Citeseer, 1995

[0200] [6] A. D. Wyner, "The wire - tap channel", Bell System Technical Journal, Vol. 54, No. 8, pp. 1355 - 1387, 1975

[0201] [7] I. Csiszar and J. Korner, "Broadcast channels with confidential messages", IEEE Transactions on Information Theory, Vol. 24, No. 3, pp. 339 - 348, 1978

[0202] [8] R. Ahlswede and Z. Zhang, "New directions in the theory of identifying via channels", IEEE Transactions on Information Theory, Vol. 41, No. 4, pp. 1040 - 1050, 1995

[0203] [9] H. Boche and C. Deppe, "Secure identification for the wire - tap channel; robustness, super - additivity and continuity", IEEE Transactions on Information Forensics and Security, 2018

[0204]

[10] H. Boche and C. Deppe, "Secure identification under jamming attacks", in Information Forensics and Security (WIFS), 2017 IEEE Symposium, IEEE, 2017, pp. 1 - 68

[0205]

[11] R. Ahlswede and I. Csiszar, "Common randomness in information theory and cryptography - Part I: Secret sharing", IEEE Transactions on Information Theory, Vol. 39, No. 4, 1993

[0206]

[12] T. Ignatenko and F. M. Willems, "Biometric Security from an Information Theoretic Perspective", Now, 2012

[0207]

[13] L. Lai, S.-W. Ho and H. V. Poor, "Privacy-Security Tradeoffs in Biometric Security Systems", Proceedings of the 46th Annual Allerton Conference on Communication, Control, and Computing, 2008, pp. 268 - 273

[0208]

[14] I. Csiszar and J. Körner, "Information Theory: Coding Theorems for Discrete Memoryless Systems", Cambridge University Press, 2011

[0209]

[15] S. Verdu and V. K. Wei, "Explicit Construction of the Optimal Constant-Weight Codes for Identification via Channels", IEEE Transactions on Information Theory, Vol. 39, No. 1, 1993

[0210] List of Reference Signs and Abbreviations

[0211] 1 System, Storage System

[0212] 10 Storage Device, Common Database

[0213] 20 Eavesdropper

[0214] 30 Common Resource

[0215] 40 PUF Source

[0216] B (Input) Storage Item, Bit Order

[0217] B’ (Randomly Encoded) Storage Item

[0218] CR Common Randomness

[0219] Message Set

[0220] Message, Storage Item Written / Stored in Storage Device 10 (from Message Set )

[0221] Message, Storage Item to be Identified (from Message Set )

[0222] DMC Discrete Memoryless Channel

[0223] DMMS Discrete Memoryless Multi-Source

[0224] Common randomness

[0225] Secret key

[0226] Auxiliary data

[0227] Auxiliary message

[0228] PUF Physical Unclonable Function

[0229] Discrete memoryless multi-source

[0230] Discrete memoryless multi-source

[0231] Discrete memoryless multi-source

[0232] S Operating method

[0233] S1 Provide storage item

[0234] S2 Encode the storage item (based on a randomization process)

[0235] S3 Write the encoded storage item

[0236] S4 First randomization process (encoder site)

[0237] S4’ First randomization process (decoder site)

[0238] S5 Second randomization process (encoder site)

[0239] S5’ Second randomization process (decoder site)

[0240] S6 Decode the storage item for identification (based on a randomization process)

[0241] S7 Identification process

[0242] S7’ Control process (applied to the process of outputting the identification message S8)

[0243] S8 Output identification message

[0244] SK Secret key

[0245] Mapping for the characteristics of the identification protocol

[0246] Encoded storage item / message (specifically written / stored in the storage device 10)

[0247] Alphabet

[0248] Source item, random variable

[0249] Source item, random variable

[0250] Source item, random variable

[0251] Alphabet

[0252] Alphabet

[0253] Alphabet

[0254] Alphabet

[0255] Source item, random variable

[0256] Source item, random variable

[0257] Source item, random variable

[0258] Alphabet

[0259] Encoder

[0260] Decoder

Claims

1. A method (S) for operating a storage device (10), wherein: - To store an item Write and store it in the storage device (10) - Process S1: Provide the storage item to be written and stored , - The encoding process S2 performed in a randomized manner is applied to the storage item , so as to generate and provide a randomly encoded storage item , and - Process S3: Write the randomly encoded storage item to and store it in the storage device (10). - At least one first randomization process S4 is the basis of the encoding process S2, - The first randomization process S4 is a randomization process dedicated to and assigned to the storage device (10), - The encoding process S2 and its encoder are configured to generate the randomly encoded stored item based on a source item obtained from a discrete memoryless source and a stored item obtained , associated with: (i) The auxiliary data derived from the encoder and its first unit , (ii) the auxiliary message derived from the encoder and its second unit , (iii) the common randomness under the mapping which is a feature of the identification protocol and corresponds to the stored item and the stored item is encrypted using a secret key and ​ - The common randomness and the secret key are generated and derived by the encoder based on the storage item and the source item The source item is obtained from a common source (30), a physical unclonable function PUF source (40), and / or a general and fundamental discrete memoryless multi-source with respect to an alphabet and is obtained 2. The method (S) according to claim 1, wherein, At least one second randomization process S5 is the basis of the encoding process S2.

3. The method (S) according to claim 2, wherein, The second randomization process S5 is a randomization process dedicated to a specific hardware item.

4. The method (S) according to claim 3, wherein, The second randomization process S5 is based on the PUF signature of the underlying hardware item.

5. The method (S) according to any one of the preceding claims, wherein, The first randomization process S4 is a common randomization process.

6. The method (S) according to any one of the preceding claims, wherein, The corresponding randomization process is obtained from a discrete memoryless multi-source of an alphabet with respect to one or more probability distributions.

7. A method (S) for operating a storage device (10), wherein, In order to identify the presence or absence of a stored item within the storage device (10) by means of the identification process S7 , - Provide information about the storage item to be identified that is present or absent in the storage device (10) , - The decoding process S6 for identification by randomization is applied to the storage item , providing a randomly encoded storage item , - Recognition process S7: Check the stored item of the random code to be recognized within the storage device (10) - Generating and / or outputting an identification message indicating the presence or absence of the randomly encoded storage item in the storage device (10) through the output process S8 and - The decoding process S6 and its underlying decoder are configured such that: by considering the auxiliary data transmitted together with the encoded storage items written to the storage device (10) , (a) Together with source items obtained from discrete memoryless multiple sources, the decoder is able to reconstruct common randomness and a key as attempts or approximations of the common randomness and the key located at the position of the encoder respectively, and make them equal with high probability; and (b) the decoder is able to obtain from the encrypted image of the common randomness and by using the inverse of the said key and thus in a decrypted form reconstruct the image of the common randomness .

8. The method (S) according to claim 7, wherein, For the recognition process S7 and / or the output process S8 related to the recognition message, the decoding process S6 and its decoder are configured to: - At the decoder When interested in the stored item the decoder compares and the reconstruction of, and - For at least one stored item stored in the storage device (10) , an acknowledgement message is output in the case of successful reconstruction, and for each stored item stored in the storage device (10) , a non-acknowledgement message is output in the case of unsuccessful reconstruction.

Citation Information

Patent Citations

  • Asymmetric error correction and flash-memory rewriting using polar codes

    CN107077886A

  • Remote verification of file protections for cloud data storage

    US8346742B1