Methods for key-dissemination
Network coding techniques enable terminal nodes to compute shared secret keys directly from received messages, overcoming the limitations of traditional methods by achieving higher key rates and security in key distribution networks.
Patent Information
- Application Number
- PCT/US2025/035812
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-27
- Filing Date
- 2025-06-27
- Publication Date
- 2026-01-02
AI Technical Summary
Traditional methods for key distribution in networks require terminal nodes to reconstruct source information before computing shared keys, imposing constraints on achievable key rates and network efficiency, and do not adequately address security against eavesdroppers.
Distribute shared secret keys using network coding techniques that allow intermediate nodes to perform coding operations, enabling terminal nodes to compute keys directly from received messages without reconstructing source bits, ensuring security and flexibility in key computation.
Achieves higher key rates, flexible key computation, and security against eavesdroppers, supporting multiple terminal sets with pairwise independent keys.
Smart Images

Figure US2025035812_02012026_PF_FP_ABST
Abstract
Description
Attorney Docket No.: 011520.01970 METHODS FOR KEY-DISSEMINATION Statement Regarding Federally Sponsored Research
[0001] This invention was made with government support under contract no. CCF-2245204 awarded by the National Science Foundation. The government has certain rights in the invention. Cross-Reference to Related Applications
[0002] The present application claims the benefit of U.S. Provisional Application No.62 / 665,168, filed June 27, 2024, now pending, the disclosure of which is hereby incorporated by reference in its entirety. Field of the Disclosure
[0003] The present disclosure relates to methods and systems for distributing sharedsecret keys in communication networks, and more particularly to methods using network coding techniques for secure key dissemination without requiring source reconstruction at terminal nodes. Background of the Disclosure
[0004] The resource of shared secret randomness, e.g., a shared secret key, plays afundamental role in the theory and practice of network communication systems. Applications include cryptographic encryption, randomized coding technologies in the presence of uncertain noise models, distributed computing, statistical inference, distributed learning, distributed authentication, identification, local differential-privacy, and more. A uniformly distributed key, shared among some network users and potentially hidden from others, appears as a central resource in a variety of communication tasks.
[0005] Traditional approaches to key distribution in networks typically require thatterminal nodes first reconstruct the source information bits before computing any shared keys. This reconstruction requirement imposes significant constraints on the achievable key rates and network efficiency.Attorney Docket No.: 011520.01970
[0006] Network coding allows intermediate nodes in a network to perform codingoperations on incoming data rather than simply forwarding packets. This enables more efficient use of network resources compared to traditional routing approaches. However, the application of network coding to secure key distribution, particularly without requiring source reconstruction, has not been fully explored.
[0007] Prior work on secure multicast network coding has focused primarily on scenarioswhere a single source generates both messages and randomness, with uniform security assumptions where eavesdroppers can access any collection of at most z unit-capacity network links. While capacity characterizations exist for these limited scenarios, more general settings remain open problems.
[0008] There exists a need for improved methods of key dissemination that can achievehigher rates while maintaining security against eavesdroppers, particularly methods that do not require terminal nodes to first reconstruct source information before computing shared keys Brief Summary of the Disclosure
[0009] The present disclosure provides methods for distributing one or more sharedsecret keys in a communication network using network coding techniques. The methods enable terminal nodes to compute shared secret keys directly from received network-coded messages without requiring reconstruction of the original source bits.
[0010] In some aspects, the disclosure provides a method including: generating aplurality of random bits at one or more source nodes in the network; transmitting messages derived from the random bits through the network, wherein intermediate nodes forward the messages by computing and forwarding functions of the received messages according to predetermined local encoding functions; and computing, at terminal nodes organized into one or more terminal sets, one or more shared secret keys based on the messages received from the intermediate nodes, wherein each shared secret key is a function of the random bits and is computed without requiring the terminal nodes to reconstruct each random bit from the source nodes.
[0011] Embodiments of the disclosure achieve several advantages over prior art methods:Attorney Docket No.: 011520.01970
[0012] - Higher achievable key rates compared to methods requiring sourcereconstruction
[0013] - Flexible key computation allowing terminals to decode shared randomnesswithout recovering individual source bits
[0014] - Security against eavesdroppers controlling individual network nodes
[0015] - Support for multiple terminal sets with pairwise independent keys
[0016] Additional features and advantages will be apparent from the following detaileddescription, taken in conjunction with the accompanying drawings. Description of the Drawings
[0017] For a fuller understanding of the nature and objects of the disclosure, referenceshould be made to the following detailed description taken in conjunction with the accompanying drawings.
[0018] Figure 1: A number of examples corresponding to Question 1, highlighting themajor ideas used in our combinatorial characterization of networks that allow positive-rate secure multicast.
[0019] Figure 2: Fig. 2(a) illustrates the sets (^^0, ^^1, ^^2) from Definition III.2 and thesubsets ^^^^, ^^^^, ^^^^for cut-vertex ^^ with the refined subsets ^^^^,1and ^^^^,2from Definition III.3. Vertex ^^ is connected by an alternating path from ^^ (see Definition III.4). Fig.2(b) illustratesProtocol III.1 for ^^ in the case where ℓ = 3 and ^^ = ^^ = 0. The red node ^^^^ is in ^^^^,1 ∩ ^^^^,1,the blue node ^^1 is in ^^^^,1 ∩ ^^^^,2, the blue node ^^2 is in ^^^^,2 ∩ ^^^^,3, and the green node ^^^^ isin ^^^^,3 ∩ ^^^^,3. After receiving ^^ + ^^^^, node ^^ does not learn anything about ^^ and can output^^ + ^^^^. Fig. 2(c) illustrates an example for the achievability of Theorem III.1 in which ^^ = 1.
[0020] Figure 3: An example of the instance ℐ used in Theorem 4 to show that ^^(ℐ) ≥^^^^SR(ℐ) for ^^ = 2 (presented here in a simplified form in which nodes ^^^^ are omitted).
[0021] Figure 4: An example instance for Theorem 6.
[0022] Figure 5: A tight example for Theorem 7.Attorney Docket No.: 011520.01970
[0023] Figure 6: A chart depicting a method according to an embodiment of the presentdisclosure. Detailed Description of the Disclosure
[0024] With reference to Figure 6, the present disclosure may be embodied as amethod 100 for distributing one or more shared secret keys in a communication network using network coding. The method 100 includes generating 103 a plurality of random bits at one or more source nodes in the network. The method includes transmitting 106 messages derived from the random bits through the network. Intermediate nodes forward the messages by computing and forwarding functions of the received messages (for example, according to predetermined local encoding functions).
[0025] At terminal nodes, one or more shared secret keys are computed 109 based on themessages received from the intermediate nodes. Each shared secret key is a function of the random bits. Each shared secret key may be computed 109 without requiring the terminal nodes to reconstruct each random bit of the plurality of random bits from the one or more source nodes. The terminal nodes may be organized into one or more terminal sets. In some embodiments, each terminal set may decode its respective shared secret key independently based on messages received from at least two vertex-disjoint paths.
[0026] In some embodiments, the network includes a plurality of source nodes. Eachshared secret key may be computed as a linear combination of the random bits from the plurality of source nodes.
[0027] In some embodiments, the network includes a single source node and a pluralityof terminal sets. Each terminal set may compute a distinct shared secret key. The shared secret keys may be pairwise independent, such that mutual information between any two distinct keys is zero.
[0028] The method may further include assigning a label (e.g., color) to the edges orvertices of the network. In this way, the method may include ensuring that each terminal set can decode its respective shared secret key independently based on messages received from distinct paths based on the assigned labels. For example, each vertex may be assigned a label identical to its predecessors if all predecessors share the same label, or a unique label otherwise.Attorney Docket No.: 011520.01970
[0029] In some embodiments, the method may include ensuring that each shared secretkey is independent of the information available at any single non-terminal node in the network to maintain secrecy from eavesdroppers.
[0030] In some embodiments, the method may include ensuring that each shared secretkey is independent of information on a specified subset of edges in the network to maintain secrecy from eavesdroppers accessing those edges.
[0031] In some embodiments, the network includes a plurality of source nodes, eachgenerating a set of random bits. Each shared secret key may be computed as a function of the random bits from the plurality of source nodes. The method may include ensuring each shared secret key is secure against eavesdroppers at any single non-terminal node.
[0032] In some embodiments, the method may include using random bits generated at theone or more source nodes to mask messages passing through intermediate nodes, including cut vertices, thereby ensuring the security of the one or more shared secret keys against eavesdroppers accessing information at those nodes.
[0033] Illustrative embodiments of the present disclosure are further described below inthe non-limiting examples (Example 1 and Example 2).
[0034] EXAMPLE 1:
[0035] I. INTRODUCTION
[0036] The resource of shared secret randomness, i.e., a shared secret key, plays afundamental role in the theory and practice of network communication systems; applications include cryptographic encryption, randomized coding technologies, distributed computing, statistical inference, distributed learning, distributed authentication, identification, local differential-privacy, and more. Motivated by the central role of shared randomness in such a wide range of distributed applications, the work at hand addresses the problem of disseminating common randomness over noiseless networks, i.e., in the context of Network Coding; we call this the key-cast problem. In key-cast, network nodes hold independent random bits, and one seeks a communication scheme that allows all terminal nodes to share a secret key ^^.Attorney Docket No.: 011520.01970
[0037] In this work, we focus on the cryptographically-motivated setting of key-cast inwhich one is only required to disseminate a positive-rate key, which, once shared among a collection of terminals, can be used to generate long sequences of common pseudo-random bits; the pseudo-random bits, in turn, can be used in applications like those mentioned above. Our interest lies in secret key dissemination under a natural secrecy condition in which the shared key ^^ is independent of the information available at any non-terminal network node. As a result, in our setting, no network node, not even the nodes where random bits originate, other than the terminal nodes themselves that share the secret key ^^ learns any information about the secret key ^^ as they participate in communicating ^^ to the terminal nodes.
[0038] This work characterizes the combinatorial requirements that allow the design of acertain key-cast scheme based on the notion of secure-multicast. In secure-multicast one seeks to securely communicate source information to a collection of terminals in the presence of an eavesdropper with predefined eavesdropping capabilities. The model of secure multicast network coding includes source nodes, which have access to message information, and additional nodes that generate independent randomness used to enable secure communication. Most prior works on secure multicast consider a single source setting in which the source ^^ generates both source messages and independent randomness, while no other network nodes can generate randomness. They further apply a uniform security assumption in which the eavesdropper can access any collection of at most ^^ unit-capacity network links for a given security parameter ^^. A major result in this context includes a characterization of the secure multicast capacity and a demonstration that the capacity can be efficiently obtained using linear codes. A more general model of secure-multicast, where several network nodes can generate messages and / or independent randomness and eavesdroppers have access to edge sets with varying capacities (e.g., the setting of eavesdropping on nodes) is studied in previous work; in this general setting, the capacity is not fully characterized. In fact, determining its value is known, in certain cases, to be NP-hard or as hard as determining the capacity of the k-unicast problem (a well-known open problem in the study of network codes).
[0039] Our study focuses on the design of positive-rate key-cast schemes that areresilient against non-uniform eavesdroppers that can access the information available at any single node. Our scheme builds on a corresponding positive-rate secure-multicast scheme in the setting in which any network node can generate randomness or messages and under the security requirement that no single internal network node can gain information about the transmittedAttorney Docket No.: 011520.01970 message(s). Towards that end, in this work we ask and solve the following question (stated roughly below, and with greater rigor in Section II).
[0040] Question 1 (Positive-rate secure-multicast). Given a communication network G inwhich any network node can generate independent randomness, and given a set of terminal nodes D, is it possible to securely multicast a message m from a source s to nodes in D such that no non-terminal network node (except s) can gain information about m?
[0041] Figure 1 depicts a number of examples corresponding to Question 1. In theexamples, any node can generate independent uniformly distributed random bits. In what follows, we review the examples in Figure 1, highlighting the major ideas used in our answer to Questions 1.
[0042] • Secure multicast. The networks depicted in Figure 1 allow the securecommunication of message ^^ from source ^^ to terminal set ^^, where ^^ = {^^} in Figure 1(a),Figure 1(b) and ^^ = {^^1,^^2} in Figure 1(c). In Figure 1(a), the vertex ^^ is a cut-vertex thatseparates ^^ and ^^. So, naively, one may conclude that ^^ has the capabilities to gain information about any message transmitted between ^^ and ^^. However, as noticed in prior works on secure network coding, the information traversing the cut-vertex ^^ can at times be protected using (a collection of) one-time pads. We refer to such vertices ^^ as protected cut-vertices. Cut-vertices (and protected cut-vertices) play a major role in our analysis; see, Definitions III.2 and III.3. Indeed, in Figure 1(a) the blue node can generate a uniformly distributed bit ^^ that is independent of ^^. As this node is connected to both ^^ and ^^, a one time pad is established and ^^ does not gain information about ^^, implying secure communication.
[0043] The padding protocols protecting the information traversing ^^ may be moreadvanced than that of Figures1(a). Additional examples are given in Figures 1(b) and 1(c). The nodes colored in blue, red, and green, generate various uniformly distributed and independent bits ^^^^, ^^^^, {^^^^}, and through certain connectivity requirements (related to the notion of alternating paths, see Definition III.4) allow the protection of source information ^^ traversing ^^. We formally define these requirements and the corresponding “padding” protocol in Definitions III.3 and Protocol III.1, respectively. The combinatorial characterization of networks for which the answer to Question 1 is positive is given in Theorem III.1.Attorney Docket No.: 011520.01970
[0044] • Secure key-cast. The examples depicted in Figures 1(a)-1(c) also allow securekey-cast. Recall that for secure key-cast no network node (including the sources) gain any information on the shared key ^^. In the case of a single terminal ^^, this is trivial, since ^^ cantrivially generate its own key ^^. But even in the case of Figure 1(c) in which ^^ = {^^1,^^2} onecan establish a shared key ^^ by sending an additional uniformly distributed and independent bit ^^′ from ^^ to ^^1and ^^2. This allows the terminals access to ^^ and ^^′, and accordingly to thekey ^^ = ^^ + ^^′ which is independent of the information available at any non-terminal networknode. We note that while it is not always the case that networks allowing secure multicast (when|^^| > 1) also allow secure key-cast, not much is needed (with respect to the network topology)to convert a secure multicast scheme to a secure key-cast one. We elaborate on such extended schemes in Theorem IV.1.
[0045] The remainder of our presentation is structured as follows. In Section II, wepresent our detailed model and formalize Question 1. The combinatorial characterization of networks that allow positive-rate secure multicast (i.e., for which the answer to Question 1 is “yes”) is given in Section III. Section IV designs positive-rate secure key-cast schemes using positiverate secure-multicast. We conclude with a brief discussion on recent work on secure key- cast in Section V.
[0046] II. MODEL
[0047] We follow the notation of previous work, modified here to address the positive-rate setting. For any ℓ > 0, [ℓ] ≜ {1,2, … , ⌈ℓ⌉.
[0048] • Key-cast Instance: An instance ℐ = (^^,^^,^^, ℬ) of the key-cast problemincludes an acyclic directed network ^^ = (^^,^^), a collection of source nodes ^^ ⊆ ^^, a collectionof terminal nodes ^^ ⊆ ^^, and a collection ℬ = {^^1, … ,^^|ℬ|} of subsets of edges specifying thesecrecy requirements. Each source node ^^^^ ∈ ^^ holds an unlimited collection ^^^^ = {^^^^^^}^^ofindependent, uniformly distributed bits. Let ^^ =∪^^^^∈^^ ^^^^ denote all randomat thesource nodes. Following a conventionof acyclic network coding, weassume that the terminals ^^ ∈ ^^ have no outgoing edges.
[0049] • Key-Codes: A network code (ℱ,^^) = ({^^^^}, {^^^^}), here called a key-code, is anassignment of an alphabet ^^^^ and a (local) encoding function ^^^^ for each edge ^^ ∈ ^^ and aAttorney Docket No.: 011520.01970decoding function ^^^^ for each terminal ^^^^ ∈ ^^. For every edge ^^ = (^^, ^^), the edge message^^^^ ∈ ^^^^ from ^^ to ^^ equals the evaluation of encoding function ^^^^ on inputs ^^In(^^); here, for ageneric node ^^0, In-edges(^^0) is the collection (^^: ^^ = (^^,^^0) ∈ ^^) of edges incoming to ^^0,^^In(^^0) = ((^^^^: ^^ ∈ In-edges(^^0)), ({^^^^^^}^^:^^0 = ^^^^)) captures all information available to node^^0during the communication process, and, similarly, In-nodes(^^0) is the collection of nodes ^^such that (^^,^^0) ∈ ^^. In order to ensure that ^^In(^^) is available to node ^^ before it encodes,communication proceeds according to a predetermined topological order on ^^.
[0050] A key-code with target rate ^^ > 0 is considered successful if, for every terminal^^^^ ∈ ^^, the evaluation of decoding functions ^^^^ on the vector of random variables ^^In(^^^^) equalsthe reproduction of a uniform random variable ^^ over alphabet ^^ = [2^^] such that the followingcriteria are satisfied. First, key ^^ meets secrecy constraints ℬ, which specifies that for every ^^ ∈ℬ, ^^(^^; (^^^^: ^^ ∈ ^^)) = 0. Second, each terminal ^^^^ decodes key ^^. Notice that the alphabets ^^^^chosen in code design may be set to be arbitrarily large. We thus refer to the setting at hand as “positive-rate” since the rate per time step resulting from choosing a large alphabet size ^^^^may be very small but still greater than zero.
[0051] Definition II.1 (Secure key-cast feasibility). Instance ℐ is said to have positivekey-cast rate ^^key > 0 if there exists a keycode (ℱ, ^^) such that
[0052] • Key Rate: ^^ is a uniform random variable over [2^^key].
[0053] • Decoding: For all ^^^^ ∈ ^^, ^^(^^|^^In(^^^^)) = 0.
[0054] • Secrecy:^^ ∈ ℬ.
[0055] • Secure-multicast: In the secure-multicast setting, one distinguishes betweensource nodes ^^^^that hold message information and source nodes ^^^^that hold independent randomness used for masking. The two subsets may intersect. As before, we assume that everynode ^^^^ in ^^^^ ∪ ^^^^ holds an unlimited collection of independent bits {^^^^^^}^^.
[0056] Definition II.2 (Secure-multicast feasibility). = (^^, (^^^^, ^^^^),^^, ℬ) issaid to have positive secure-multicast rate ^^sec > 0 if there exists a network code (ℱ,^^) suchthatAttorney Docket No.: 011520.01970
[0057] • Message Rate: ^^ is a uniform random variable over [2^^sec] such that ^^ =^^′ ⊂ {^^^^^^}^^∈^^^^,^^, where ^^′ is a subset of the source-bits generated by sources in ^^^^.
[0060] Notice that in both Definition II.1 and Definition II.2, the random variable ^^ isshared between the terminals in ^^. In the key-cast setting (II.1), ^^ denotes the secret key, which may be a (uniformly distributed) function of source bits; the source bits themselves are not necessarily decoded at terminals in ^^. In the secure multicast setting (II.2), ^^ denotes the secret message generated at sources in ^^^^and decoded at each terminal in ^^. It is thus evident that the task of key-cast is more flexible than that of secure multicast: roughly speaking, instance ℐ haspositive key-cast rate ^^key > 0 according to Definition II.1 if ℐ has positive secure-multicast rate^^sec > 0 according to Definition II.2, but ^^key > 0 in Definition II.1 does not ensure ^^sec > 0 inDefinition II.2 since ^^key > 0 does not ensure decodability of even a single bit from ^^^^.
[0061] The work at hand addresses instances in which each network node can generateuniformly distributed independent random bits, i.e., the setting that ^^ = ^^ in Definition II.1 and^^^^ = ^^ in Definition II.2. Moreover, we consider eavesdroppers that have access to anyindividual network node (except terminal nodes). Namely, for ^^ ∈ ^^, in Definition II.1 weconsider ℬ = {^^^^|^^ ∈ ^^\^^, ^^^^ = In-edges(^^)}. (The security requirement expressed by ℬimplies that ^^(^^; (^^^^: ^^ ∈(^^))) = 0. Notice, by the definition of ^^In(^^), that thisimplies ^^(^^; ^^In(^^)) = ^^(^^; (^^^^: ^^ ∈ In-edges(^^)), ^^^^) = 0 as well for the independent bits ^^^^of all information available to ^^.) Similarly, in Definition II.2 we require the message to be kept secret from any non-terminal node excluding message-generating sources.
[0062] In Section III, below, we seek to combinatorially characterize instances ℐ withpositive secure-multicast rate. We note that if there exists a secure-multicast scheme over ℐ =(^^, (^^^^, ^^^^),^^, ℬ) communicating positive rate ^^ with |^^^^| > 1, then there exists a positive-ratesingle message-source secure-multicast scheme over ℐ = (^^, ({^^}, ^^^^),^^, ℬ) for each ^^ ∈ ^^^^ thatgenerates message-bits in ^^. We can construct the latter code from the former by replacing allAttorney Docket No.: 011520.01970 random message bits in ^^ generated by nodes in ^^^^\ {^^} by constants. We thus, without loss ofgenerality, consider instances in which ^^^^ = {^^}.We seek to answer the following question,which formalizes Question 1 from the Introduction.
[0063] Question 1 (Positive-rate secure multicast). For which instances ℐ =(^^, ({^^},^^),^^, ℬ) with ℬ = {^^^^ | ^^ ∈ ^^ \ (^^ ∪ {^^}), ^^^^ = In-edges(^^)} can we achieve ^^sec >0?
[0064] III. ANSWERING QUESTION 1
[0065] In this section we consider secure multicast instances ℐ = (^^, (^^^^ = {^^}, ^^^^ =^^),^^, ℬ) in which ℬ = {^^^^ | ^^ ∈ ^^ \ (^^ ∪ {^^}), ^^^^ = In-edges(^^)}. That is, in ℐ, we require theinformation multicast from ^^ to ^^ of the information available at any networknode except the source s and consider the case where |^^| = 1, i.e., ^^ ={^^}, and analyze secure communication from ^^ to ^^. We then address general ^^. We start with a number of definitions followed by a subroutine to be used in our analysis. The definitions and subroutine are illustrated by Figure 2.
[0066] A. Preliminary notation and definitions (^^ = {^^})
[0067] Definition III.1. A vertex ^^ ∈ ^^ is called a cut-vertex for the source-terminalpair (^^,^^) if the removal of ^^ separates ^^ from ^^ in ^^. Equivalently, all paths from ^^ to ^^ go through ^^.
[0068] Let ^^ = {^^}. We define a partition of ^^ that describes each node’s connectivityto ^^ and from ^^.
[0069] Definition III.2 (Partition (^^0, ^^1, ^^2)). In the partition (^^0, ^^1, ^^2) of ^^, ^^0 isthe set of vertices ^^ ∈ ^^ that are not reachable from ^^ but from which ^^ is reachable, ^^1 is theset of vertices ^^ ∈ ^^ that are reachable from ^^ and from which ^^ is reachable, and ^^2 is the setof vertices ^^ ∈ ^^ from which ^^ is not reachable.
[0070] We next define the notion of “^^0-protected cut-vertices.” Roughly speaking, acut-vertex ^^ ∈ ^^1 is ^^0-protected if random variables generated at nodes in ^^0 can be used tomask the message transmitted by ^^, thereby preventing ^^ from learning anything about the message from ^^. Figure 2 depicts this definition.Attorney Docket No.: 011520.01970
[0071] Definition III.3 (^^0-protected vertices). Let (^^0, ^^1, ^^2) be the partition ofDefinition III.2. For any cut-vertex ^^ ∈ ^^1, consider the subsets ^^^^, ^^^^, and ^^^^ of ^^0, where
[0072] • ^^ ∈ ^^^^ if there exists a path ^^^^(^^,^^) from ^^ to ^^ in which all vertices except ^^are in ^^0,
[0073] • ^^ ∈ ^^^^ if there exist a path ^^^^(^^, ^^) from ^^ to some ^^ ∈ In-nodes(^^) ∩ ^^1, and
[0074] • ^^ ∈ ^^^^ if there exists a path ^^^^(^^,^^) from ^^ to ^^ such that the first (intopological order) vertex ^^ in ^^^^(^^,^^) ∩ ^^1 has topological order greater than ^^;sets ^^^^, ^^^^, and ^^^^ can intersect. Let {^^1, ^^2, … , ^^^^} = In-node(^^) ∩ ^^0. For ^^ ∈ [^^], let (^^^^,^^,^^^^,^^, ^^^^,^^) be the vertices in (^^^^, ^^^^, ^^^^), respectively, that are connected by a path to ^^^^. Notethat ^^^^,^^ and ^^^^,^^ are included in ^^^^,^^. Now, ^^ is said to be ^^0-protected if ^^^^ ∩ ^^^^ ≠ ^^, or if forℓ ≥ 2, there exists ^^1, ^^2, … , ^^ℓ ∈ [^^] such that ^^^^,^^1 ≠ ^^, ^^^^,^^ℓ ≠ ^^, and ^^^^,^^^^ ∩ ^^^^,^^^^+1 ≠ ^^ for^^
[0075] The above definitions are closely related to the notion of alternating paths. SeeFigure 2.
[0076] Definition III.4 (Alternating path). Given a directed graph ^^ with vertex set ^^and edge set ^^, its undirected variant, denoted by ^^, has vertex set ^^ and undirected edge set^^ = {(^^, ^^) | (^^,^^) ∈ ^^}. Nodes ^^1 and ^^2 are connected by an alternating path in ^^, if ^^1 and
[0077] Claim III.1. If a cut-vertex ^^, with respect to (^^,^^), is ^^0-protected then thereexists an alternating path ^^alt(^^,^^) connecting ^^ and ^^ that does not include ^^.
[0078] We are now ready to state the main theorem for this section.
[0079] Theorem III.1. Let ℐ = (G, (Sm = {s}, ^^^^ = V), D = {d}, ℬ) with ℬ = {βv | v ∈V \ (D ∪ {s}), βv = In-edges(v)}. Then ℐ has secure-multicast rate ^^sec > 0 according toDefinition II.2 if and only if every cut-vertex ^^ is ^^0-protected.
[0080] B. The “padding” protocolAttorney Docket No.: 011520.01970
[0081] Before addressing the proof of Theorem III.1 we preset our padding protocol(depicted in Figure 2), specifying how information can be transmitted from vertices in ^^0to a ^^0-protected cut-vertex ^^ ∈ ^^1 (and additional vertices in ^^1) to assist in masking the messageinformation transmitted by the source node ^^. The secure-multicast scheme suggested shortly to answer Question 1 uses the padding protocol repeatedly.
[0082] Protocol III.1 (Padding protocol for ^^0-protected ^^). Let ^^ be a cut-vertex in ^^1that is ^^0-protected according to Definition III.3. In this case, either ^^^^ ∩ ^^^^ ≠ ^^ or, for someℓ ≥ 2, there exists {^^1, ^^2, … , ^^ℓ} ⊂ [^^] such that ^^^^,^^1 ≠ ^^, ^^^^,^^ℓ ≠ ^^, and, for ^^ ∈ [ℓ − 1], itholds that ^^^^,^^^^ ∩ ^^^^,^^^^+1 ≠ ^^.to−^^ in ^^^^(^^^^,^^) ∩ ^^1 has topological order greater than u. Let ^^^^ be a uniformly distributed bitgenerated at ^^^^. Finally let ^^,^^, ^^ ∈ {0,1} be random variables such that the variables in thecollection {^^,^^, ^^,^^^^,^^1, … , ^^ℓ−1,^^^^} are mutually independent. The protocol described below
[0084] • node ^^ has access to ^^ + ^^ + ^^ (additions are mod 2),
[0085] • node ^^ has access to ^^, and
[0086] • node ^^ may or may-not have access to ^^,
[0087] and guarantees that
[0088] • node ^^ is able to compute ^^ + ^^ + ^^^^.
[0089] • node ^^ does not gain any information about ^^.
[0090] The protocol proceeds as follows.Attorney Docket No.: 011520.01970
[0091] • Node ^^^^ sends ^^^^ to ^^ through ^^^^(^^^^, ^^) and to ^^^^1 through ^^^^(^^^^, ^^^^1). Node^^, with access to ^^ + ^^ + ^^ and ^^^^, sends ^^ + ^^ + ^^ + ^^^^ to ^^.
[0092] • For ^^ ∈ [ℓ − 1], node ^^^^ sends ^^^^ to ^^^^^^ through ^^^^ (^^^^, ^^^^^^) and to ^^^^^^+1^^^^(^^^^,^^ℓ).
[0094] • The incoming nodes of ^^ in ^^0 now compute the following functions to beforwarded to ^^. Node ^^^^1 computes and forwards ^^^^ + ^^1. For ^^ ∈ {2, … , ℓ − 1}, node ^^^^^^computes and forwards ^^^^−1 + ^^^^ . Node ^^^^ℓ computes and forwards ^^ℓ−1 + ^^^^.addition to theprecise information content of ^^, ^^, and ^^, are presented later when the padding protocol is used in our secure-multicast scheme given in Theorem III.1.
[0096] Under the given definitions, each of the nodes ^^^^,^^1, … ,^^ℓ−1, and ^^^^ is thesource of a one-time pad (here denoted by ^^^^,^^1, … , ^^ℓ−1, ^^^^) independent of all other randomvariables in the network. These one-time pads areadded and then removed from ^^ (representing the source message) to ensure that ^^ remains protected. Protection at the bottleneck ^^ is achieved by transmitting to the bottleneck not the protection bits themselves but sums of consecutive pairs of those bits. Namely,
[0097] Claim III.2. After running Protocol III.1, it holds that (i) node u is able tocompute ^^ + ^^ + ^^^^, and (ii) node ^^ does not gain any information about ^^.
[0098] Proof: For (i), the proof follows from the fact that node ^^, knowing ^^ and usingincoming information from ^^, ^^^^1 , … , ^^^^ℓ can compute ^^ + (^^ + ^^ + ^^ + ^^^^) + (^^^^ + ^^1) +(^^1 + ^^2) +· · · +(^^ℓ−2 + ^^ℓ−1) + (^^ℓ−1 + ^^^^) = ^^ + ^^ + ^^^^. For (ii), note that the incominginformation to u is independent of α; namely, ^^(^^,^^ + ^^ + ^^ + ^^^^,^^, ^^^^ + ^^1,^^1 +^^2, … , ^^ℓ−2 + ^^ℓ−1,^^ℓ−1 + ^^^^;^^) = 0.
[0099] C. Proof of Theorem III.1Attorney Docket No.: 011520.01970
[0100] Proof: We start by proving achievability. The proof is depicted in Figure 2(c). Ifthere are no cut vertices in ^^, then ^^ and ^^ are 2-vertex connected, meaning that there exist twovertex-disjoint paths, ^^1(^^,^^) and ^^2(^^,^^), in ^^ between ^^ and ^^. Then ^^SR > 0 since, givenindependent uniformly distributed bits ^^ and ^^, the source can send ^^ + ^^ on ^^1 and ^^ on ^^2.The resulting scheme is secure.
[0101] Otherwise, let ^^1, … ,^^^^ be the collection of cut-vertices ordered topologically.We here present a proof sketch for the case ^^ = 1, i.e., when there is a single cut-vertex ^^1separating ^^ and ^^. As ^^1 is ^^0-protected, there exist a path ^^^^(^^^^, ^^) for ^^^^ ∈ ^^^^1 and ^^ ∈In-nodes(^^1) ∩ ^^1, and a path ^^^^(^^^^,^^) through ^^ for ^^^^ ∈ ^^^^1 and ^^ ∈ ^^1 of topological ordergreater than that of ^^1; here ^^^^1and ^^^^1are the subsets of ^^0corresponding to ^^1in DefinitionIII.3. By Protocol III.1 and Claim III.2, assuming that ^^1 receives information ^^ + ^^ + ^^ + ^^^^and ^^ for ^^^^ at ^^^^, vertex ^^1 can compute ^^ + ^^ + ^^^^ in a way that keeps allincoming information to ^^1collectively independent of ^^.
[0102] Let ^^1,1, ^^1,2 be a partition of ^^1 implied by ^^1 in which ^^1,1 includes all verticesof ^^1 of topological order at most that of ^^1. From ^^ = 1, it follows that either ^^ and ^^1 areconnected by two vertex-disjoint paths ^^1(^^,^^1) and ^^2(^^,^^1) or that (^^,^^1) ∈ ^^. Similarly, for^^1,2, ^^1 and ^^ are either connected by two vertex-disjoint paths or (^^1,^^) ∈ ^^.We here assumethe former, more general, case for both pairs (^^,^^1) and (^^1,^^). We also assume that ^^1(^^,^^1) passes through vertex ^^ defined above.
[0103] We are now ready to suggest a secure communication scheme in which the source^^ securely sends a uniform bit ^^ to ^^. Source ^^ sends ^^ + ^^1 on path ^^1(^^,^^1) until vertex ^^,and send ^^1 on path ^^2(^^, ^^1), where ^^1 is an independent uniformly distributed bit. Let ^^ = ^^,let ^^ ≡ 0 be constant, and let ^^ = ^^1. It holds that ^^ has access to ^^ + ^^ + ^^ = ^^ + ^^1 and ^^1has access to ^^ = ^^1. Applying Protocol III.1 on ^^1 now guarantees by Claim III.2 that ^^1 cancompute ^^ + ^^ + ^^^^ = ^^ + ^^^^ without gaining information about ^^ = ^^; in addition, ^^^^ isforwarded on ^^^^(^^^^,^^) to ^^. Notice that all other nodes in ^^1,1do not gain information about^^ = ^^ either. Vertex ^^1 prepares to send ^^ + ^^^^ in the next step of communication.
[0104] In ^^1,2, ^^1 sends ^^ + ^^2 + ^^^^ for a uniform and independent bit ^^2 on one of thetwo vertex disjoint paths connecting ^^1and ^^, and sends ^^2on the other. It follows that eachAttorney Docket No.: 011520.01970 node in ^^1,2{^^} gains no information about ^^ (even under the assumption that it knows ^^^^). As ^^ has access to ^^^^it can decode ^^. This concludes the achievability proof. We omit the converse proof due to space limitations.
[0105] D. Multiple terminals
[0106] When D includes more than a single terminal node, we can perform the schemedescribed in Theorem III.1 for each terminal node di in parallel with independent randomness; this yields a legitimate code since our positive-rate model allows arbitrary edge alphabets. We conclude the following corollary.
[0107] Corollary III.1. Let I = (G, (^^^^ = {s}, ^^^^ = V),D, B) with B = {βv | v ∈ V \ (D ∪{s}), βv = In-edges(v)}. Then ℐ has secure-multicast rate ^^sec > 0 if and only if, for every d ∈ D,every cut-vertex u with respect to (s, d) is ^^_0-protected.
[0108] IV. SECURE KEY-CAST THROUGH SECURE MULTICAST
[0109] We here present a sufficient condition for secure key-cast in the setting in whichwe require the key ^^ delivered to the terminals in D to be independent of the information available at any network node (except the terminals in D themselves). The ability to achieve security at all nodes, including source nodes that generate information, is a unique property of keycast that distinguishes key-cast from secure multicast.
[0110] Theorem IV.1. Let I = (G, V,D, B) in which B = {βv | v ∈ V \ D, βv = In-edges(v)}. Then I has key-cast rate ^^key > 0 if (i) there exists a node s for which for every d ∈ Devery cutvertex u separating s and d is ^^0-protected, and, in addition, (ii) there exists a node ^^’ such that for all d ∈ D there is a path from ^^’ to d that does not pass through s.
[0111] V. CONCLUSIONS
[0112] In this Example 1, we characterize positive-rate secure-multicast instances underthe notion of node-security. We show that instances ℐ with positive secure-multicast rate ^^sec>0 imply (under additional connectivity conditions) positive key-cast rate ^^key > 0 under thesecurity requirement that information available at any single network node (excluding the terminals in ^^, but including the source nodes) is independent of the shared key ^^. The oppositeassertion, that ^^key > 0 implies ^^sec > 0, does not hold.Attorney Docket No.: 011520.01970
[0113] EXAMPLE 2
[0114] SECTION I. Introduction
[0115] The resource of shared randomness plays a fundamental role in the theory andpractice of network communication systems. A uniformly distributed key, shared among some network users and potentially hidden from others, appears as a central resource in a variety of communication tasks. For example, a shared key can be used to secure transmitted information through cryptographic encryption or an information-theoretically secure one-time-pad; shared keys allow the use of randomized coding techniques in the presence of uncertain noise models, such as the Gaussian arbitrary varying channel model, yielding increased rates when compared to deterministic coding techniques that do not rely on common randomness; shared keys are regularly assumed in the context of distributed computing, statistical inference, and distributed learning, through the availability of public coins, to coordinate between network users in constrained systems such as the Internet of Things (IoT) or federated learning; and the sharing of common random keys lies at the heart of methods for distributed authentication, identification, and local differential-privacy through shared forms of sampling and hashing.
[0116] While shared randomness plays a central role in a wide range of distributedapplications critical to modern technology, in some cases the dissemination of such randomness comes at a high price due to the large amount of randomness needed and the network resources required for distribution. For example, in network coding applications, the rate of secure communication is impacted by the rate of the available keys. Similarly, in private forms of distributed learning, the requirement to disseminate shared keys over increasingly ambitious network topologies occupies critical bandwidth and computational resources. In the task of strong coordination over networks, the required rate of shared randomness reduces that of communication, limiting the network capacity. As an alternative to full-rate key-cast, cryptographic solutions distribute only short uniform seeds among network components, enabling all devices to independently generate long sequences of common pseudo-random bits. The potential downside for such strategies is that they rely on computational limitations of malicious network components. Further, they may be too computationally expensive to implement in resource-limited devices such as those used in the IoT. Due to the critical nature of technologies that rely on shared randomness, it is important to study the task of keyAttorney Docket No.: 011520.01970 dissemination not only in the cryptographic setting but also from an information theoretic perspective, guaranteeing performance regardless of computational capabilities.
[0117] This work asks how to disseminate keys through a given network, efficiently andat high rate, in the presence of potential eavesdroppers, thereby enabling tasks like the ones mentioned above that require shared user common randomness.
[0118] Work on key dissemination (also called secret key-agreement) in memorylessnetwork structures typically includes a collection of users and an eavesdropper, all of whom receive correlated information over a noisy memoryless channel or network and have access to a public communication channel. This eavesdropper’s correlated information is typically assumed to be a noisy version of that obtained by other users. The system objective is to deliver a shared key to the users while keeping it hidden from the eavesdropper. An example of channels studied in the field of multi-terminal information theory under this framework is a broadcast channel enhanced with a public noiseless-channel. The shared key includes information generated at the source node and additional randomness extracted from the (at times) correlated noise applied to different users. Remarkably, including a public channel increases the achievable key rate even though the public channel is completely exposed to eavesdropping.
[0119] This work initiates the study of key dissemination, here called key-cast, in thecontext of noiseless networks, i.e., in the context of Network Coding. In this context, traditional studies of communication, which address the transfer of messages from their source of generation to their intended destination, may be used to (securely) establish shared keys. An important observation that motivates this work is that the strategies optimized for delivering messages are suboptimal for delivering shared random keys. This is possible since distributing keys requires only the distribution of shared randomness, not the reconstruction of source information. Removing the requirement of source reconstruction grants a flexibility to the communication process that gives rise to the potential for increased key-rates when compared to traditional forms of communication that require source reconstruction.
[0120] A. Background
[0121] In the context of multi-source multi-terminal network-coding, the problem of keydissemination is closely related to the task of secure (“wiretap”) communication, in which the goal is to securely communicate source information to a collection of terminals in the presenceAttorney Docket No.: 011520.01970 of an eavesdropper with predefined eavesdropping capabilities. Secure network coding and secret key-cast are similar in the sense that the information eventually shared between terminals is kept secret from the network eavesdropper. They differ in that in the former source nodes hold message information that must be recovered at terminal nodes while in the latter the key(s) may be a function of the independent randomness held by the source nodes. The flexibility in the requirements for key dissemination opens the possibility of key-rates that exceed those that can be obtained in the secure network coding setting.
[0122] Most works on secure network coding address the multicast setting in which allterminals require the reconstruction of all source information. In full generality, the model of secure multicast network coding includes source nodes, which have access to message information, and key nodes that generate independent randomness used to enable secure communication. In many studies of single-source multicast, a single node generates both source messages and independent keys; no other network nodes can generate randomness. The eavesdropper can access any collection of at most z network links for a given security parameter z. A major result in this context includes a characterization of the secure multicast capacity and a demonstration that the capacity can be efficiently obtained using linear codes. The model in full generality, where several network nodes can generate messages and / or independent randomness, is studied in; in this case, the capacity is not fully characterized. On the contrary, some previous work shows that determining the secure-multicast capacity in instances with a single message- generating source, a single terminal, and certain eavesdropping capabilities is NP-hard. Moreover, other previous work shows that for single-source, single-terminal settings in which all edges have unit capacity and any node can generate random keys, if the eavesdropper can accessany single edge in the network (^^ = 1), then determining the secure-rate is as hard as theproblem of determining whether the all 1’s (symmetric) rate vector (1,1,…,1) is in the (non- secure) capacity region of the k-unicast problem in the context of network coding; determining the capacity of the k-unicast problem is a well-known open problem in the study of network codes.
[0123] The problem of key dissemination is also related to other network coding tasksbeyond secure network coding. Examples include network coding scenarios in which the communicated information is something other than pure source bits. For example, network coding function-communication, considers scenarios in which a predetermined function of the source information, such as a sum of source values, is to be shared between all terminal nodes.Attorney Docket No.: 011520.01970 Sum-function network codes might lend themselves to key dissemination, as a key set to be the sum of all source information is independent of each partial sum (including each individual source) communicated over network edges. Similar to the secure multicast problem in its general form, determining the capacity of sum networks is as hard as determining the capacity of multiple-unicast network coding; this is shown through a reduction implying, rather counter intuitively, that linear codes do not suffice to achieve capacity in sum-networks.
[0124] In both secure-multicast and functional-communication, the informationtransmitted is required to be a certain predetermined function of the source information. Pliable index coding considers a communication scenario in which the information decoded at terminals is of a flexible nature loosely reminiscent of the flexibility of the key in the key-dissemination problem. Index coding is a representative form of multiple-unicast network coding in which a server holding all source messages wishes to communicate through a capacity-limited noiseless broadcast channel with multiple terminals, each holding potentially distinct message side- information and requiring potentially distinct messages. Pliable index coding is a variant of index coding in which terminals are required to decode not a specific source message, but any message they do not already have as side information; this flexibility confers significant rate advantages when compared to traditional index coding. Various forms of security in the context of pliable index-coding (and index-coding) have been studied. While both introduce flexibility to the communication process, pliable index-coding and key dissemination differ significantly in that pliable index-coding decoders are not required to decode shared / common information.
[0125] The problem of secret-key generation in the context of wireless networks usingthe methodology of network coding (i.e., that of performing coding operations at internal network nodes) appear, for example, in the context of sensor networks, dynamic wireless systems, and multiresolutional streaming. The models, questions, and results of these latter works differ significantly from those studied here.
[0126] B. Brief Overview of Study
[0127] In this work, we study key dissemination, i.e., key-cast and multiple key-cast, in avariety of different network settings. In the settings at hand, we compare the task of key dissemination to traditional forms of communication in which terminal nodes first reconstruct source information and perhaps later post-process this information to create a shared key.Attorney Docket No.: 011520.01970 Moreover, we present combinatorial conditions for key-cast and multiple key-cast through the design of corresponding communication schemes.
[0128] We start with the task of key-cast, in which there is one terminal set and allterminals in the set want to share a single key K. In this context, we study both single-source networks and multiple-source networks, addressing the secure setting, in which the shared key is not revealed to an eavesdropper with predefined eavesdropping capabilities, as well as the non- secure setting, in which the key need not be hidden. For key-cast, we study the similarities and differences between the dissemination process with and without the requirement of source reconstruction, and ask how hard the task of determining the key-capacity is. We then move to the study of multiple terminal sets, each requiring a distinct key, i.e., multiple key-cast. Here, also, we study the secure and non-secure setting, and present combinatorial conditions for key dissemination and design corresponding multiple key-cast schemes. In addition, as before, we compare the multiple key-cast rate with and without the restriction of source reconstruction, required in traditional forms of communication; both for the single terminal-set setting and for the multiple terminal-set condition, key-cast achieves a strict advantage in rate when the source reconstruction requirement is relaxed. Before stating and presenting our results formally, we give a detailed model in Section II.
[0129] SECTION II. Model
[0130] The following notation is useful to the definitions that follow. For any integer ℓlet [ℓ] = {1,2, … , ℓ}. Our model captures the multiple key-cast setting, including ℓ terminal sets.
[0131] Acyclic Multiple Key-cast Instance: An instance ℐ = (^^,^^, {^^^^} ℓ^^=1 , {ℬ^^}ℓ^^=1) ofthe multiple key-cast problem includes an acyclic directed network ^^ = (^^,^^) in which eachedge ^^ ∈ ^^ has unit capacity (we allow multiple parallel edges to capture connectivity of higherinteger capacity), a collection of source nodes ^^ ⊆ ^^, a collection of disjoint terminal sets ^^^^ ⊆^^ for ^^ ∈ [ℓ], each including a collection of terminal nodes, and, for ^^ ∈ [ℓ], a collection ofsubsets of edges ℬ^^ = {^^^^,1, … ,^^^^,|^^^^|} specifying the secrecy requirements. Each source node^^^^ ∈ ^^ holds anof independent, uniformly distributed bits ^^^^ = {^^^^^^}^^. Let^^ =∪^^^^∈^^ ^^^^ denote all random bits available at the source nodes.that iscommon in the study of acyclic network coding, we assume that source nodes ^^ ∈ ^^ have noAttorney Docket No.: 011520.01970 incoming edges and that the terminals ^^ ∈∪^^∈[ℓ] ^^^^ have no outgoing edges. (We note that someresults may be generalized to cyclic network.)
[0132] Key-Codes: For blocklegth n, network code, also referred throughout as key-code, (ℱ,^^) = ({^^^^}, {^^^^,^^}) is an assignment of a (local) encoding function ^^^^ for each edge ^^ ∈^^ and a function ^^^^,^^ for each terminal ^^^^,^^ ∈ ^^^^, for ^^ ∈ [ℓ]. For every edge ^^ = (^^, ^^),^^ ^^ = [2^^] from u to v the evaluation of encoding function ^^^^ onI^^^inputs ^^n^(^^); here, for a generic node ^^0, ^^In(^^0) = ∶ ^^′ = (^^,^^0) ∈ ^^), ({^^^^^^}^^:^^0 = ^^^^))captures all information available to ure that ^^^ens^(^^)is available to node u a predetermined topological order on E. A key-code with target rate R is considered successful if for each ^^ ∈ [ℓ] and every terminal ^^^^,^^ ∈ ^^^^ the evaluation of decoding functions ^^^^,^^ on thevector of random variables ^^I^n^(di,j)() equals the reproduction of a uniform random variable ^^^^over alphabet [2^^^^] such that the following criteria are satisfied. First, key ^^^^meets secrecy constraints ℬ , whic ^^^^ h specifies that for every ^^ ∈ ℬ^^ , ^^(^^^^; (^^^^ : ^^ ∈ ^^)) = 0. Second, eachterminal-set ^^^^ decodes a distinct key ^^^^ such that for ^^ ≠ ^^′ key ^^^^ is independent of key ^^^^ ′,i.e., random variables{^^ℓ^^}are pair-wise independent (PWI)giving ^^(^^ ;^^^^′) = 0 for all ^^ ≠^^′. (In the multiple key-cast setting, we consider the distribution ofkeys, implying, e.g., that a key from one terminal set does not reveal information about another terminal set’s key. Pairwise independent keys lend themselves naturally to the security requirement that any key remains hidden from every network node (except terminal nodes requesting that key). One may consider other forms, either weaker or stronger, of independence between keys corresponding to different terminal sets. The dissemination of mutually independent keys has strong connections to, and can be shown to be as hard as, multiple-unicast network coding. The study of additional forms of key-independence is beyond the scope of this work and is touched on only briefly in Section V.)
[0133] Definition 1 (Multiple Key-Cast Feasibility):
[0134] Instance ℐ is said to be (^^,^^)-feasible if there exists a key-code (ℱ,^^) withblocklength n such that
[0135] Decoding: For all ^^ ∈ [ℓ] and all ^^ ^^^^,^^ ∈ ^^^^, ^^ (^^^^|^^In(^^^^,^^) ) = 0.Attorney Docket No.: 011520.01970
[0136] PWI key rate: For all ^^ ∈ [ℓ], ^^^^ is a uniform random variable with ^^(^^^^) = ^^^^.For ^^ ≠ ^^′ ∈ [ℓ], ^^(^^^^;^^^^′) = 0.
[0137] Secrecy: For all ^^ ∈ [ℓ], ^^(^^ ; ( ^^^^ ^^^^ ∶ ^^ ∈ ^^)) = 0 for any subset ^^ ∈ ℬ^^.
[0138] In this study, we also compare key dissemination with more traditional forms ofcommunication in which source information is first reconstructed at the terminals and only then (perhaps) post-processed to derive a shared key ^^^^; we call that approach source-reconstructed (SR) key-cast.
[0139] Definition 2 (SR Multiple Key-Cast Feasibility):
[0140] Instance ℐ is said to be (^^,^^)SR-feasible if there exists a key-code (ℱ,^^) withblocklength n such that
[0141] Source reconstruction: For all ^^ ∈ [ℓ] and all ^^^^,^^ ∈ ^^^^, there exists a collectionof source information bits ^^ ^^^^,^^ ⊆ ^^, such that ^^(^^^^,^^|^^In(^^^^,^^) ) = 0, i.e., message bits in ^^^^,j aredecoded at terminal ^^ .note that in Definition 2 onehave required, without lossgenerality, that all terminals ^^^^,^^ ∈ ^^^^ decode the same set of source information bits ^^^^,^^ ⊆ ^^,i.e., that ^^^^,^^ = ^^^^,^^′ for distinct ^^^^,^^ and ^^^^,^^′ in ^^^^. This follows from our requirement that key^^^^ be a ^^^^; j for any terminal ^^^^,^^ ∈ ^^^^.)
[0142] PWI key construction and rate (post-processing): For all ^^ ∈ [ℓ], there exists auniform random variable ^^^^ with H(^^^^)=Rn such that for all ^^^^,^^ ∈ ^^^^, H(^^^^|^^^^,j)=0. For ^^ ≠ ^^′ ∈[ℓ], I(^^^^;^^^^′)=0.
[0143] Secrecy: For all ^^ ∈ [ℓ], I(^^ ^^^^;(^^^^:^^ ∈β))=0 for any subset β∈\scriptB_i.
[0144] Definition 3 (Multiple Key-Cast Capacity):
[0145] The (symmetric) multiple key-cast capacity of I, denoted by ^^(ℐ), is themaximum R for which for all Δ>0 there exist infinitely many blocklengths n such that I is (R−Δ,n)-feasible. Restricting all encoding and decoding operations to be linear, we define the linear key-cast capacity ^^^^(ℐ) analogously. The capacity obtainable by first reconstructing source information and then post-processing to a shared key is denoted by ^^SR(ℐ), and the linear variant is denoted by ^^S^^R (ℐ). The definitions are similar to those for ^^(ℐ) and ^^^^(ℐ).Attorney Docket No.: 011520.01970
[0146] In key-cast, where there is a single terminal set D, and thus a single collection ofsubsets B, we denote a problem instance as ℐ = (^^, ^^,^^, ℬ). Similarly, when the network has asingle source s, we use I=(G,s,{^^^^}ℓ^^ = 1,{ℬ^^}ℓ^^ = 1) for the multiple key-case setting and ℐ =(^^, ^^,^^, ℬ) for the key-cast setting. Finally, the non-secure case is obtained by taking B (or theelements in {ℬ^^}ℓ^^ = 1) to be empty.
[0147] SECTION III. Formal Statement of Results
[0148] A. Key-Cast
[0149] We first make a couple of observations regarding the key-cast setting. We startwith single-source key-cast, i.e. key dissemination with a single terminal-set. For single-source key-cast we show that there is no difference between the traditional (secure) multicast-capacity and the key-capacity. Specifically, in this setting, there is no benefit in relaxing the requirement of source reconstruction in the context of key dissemination.
[0150] Theorem 1 (Single Source Key-Cast):
[0151] Let ℐ = (^^, ^^,^^, ℬ) be an instance of the single-source key-cast problem then^^(ℐ)=^^SR(ℐ).
[0152] We then show that the same holds for multiple-source key-cast in the special caseof linear codes when we do not have any security requirements.
[0153] Theorem 2 (Multiple-Source, Non-Secure, Linear Key-Cast):
[0154] Let ℐ = (^^, ^^,^^, ℬ) be a non-secure instance of the key-cast problem, i.e., with^^ = ^^, then ^^^^(ℐ)=^^S^^R (ℐ).
[0155] The proofs of Theorems 1 and 2 appear in Section IV. Both theorems can beshown to hold for general edge capacities and for cyclic graphs using the same proofs applied to an appropriate model. We here roughly outline the proof ideas. In the single source case of Theorem 1, any uniform key K obtained through key-cast can be replaced by a collection of message bits, using an appropriate pre-encoding function at the single source. In the non-secure case of Theorem 2, any uniform key K obtained through (linear) key-cast can be replaced by a collection of message bits across different sources. The process first reduces the support of K byAttorney Docket No.: 011520.01970 identifying source information bits ^^^^^^that can be deterministically set to zero without impacting the key rate; the argument then employs appropriate decoding at the terminal nodes.
[0156] Remark 1:
[0157] The question of whether Theorem 2 holds for general (not necessarily linear)codes remains open. In other words, whether relaxing the requirement of source reconstruction improves key-rate in the non-secure key-cast setting is unknown. An affirmative answer would imply that ^^(ℐ)>^^^^SR(ℐ) and thus, since ^^SR(ℐ)=^^SR (ℐ)=^^^^(ℐ) when ^^ = ^^, that ^^(ℐ)>^^^^(ℐ);this would prove an advantage to non-linear codes in (multi-source) key-cast when ^^ = ^^.
[0158] To study how hard the task of key-cast is, we present a reduction from the secure-multicast network coding problem. As stated previously, previous work shows that when the eavesdropper has control of a single unit-capacity network edge, determining the capacity of secure-multicast instances with a single source node that generates messages, multiple network nodes that generate independent randomness, and a single terminal node, is as hard as resolving the capacity of multiple-unicast network coding instances. More specifically, it is shown in previous work that one can reduce the question of whether the all-1s rate vector falls in the capacity of a multiple-unicast network coding instance to the problem of determining the secure- multicast capacity of the instances described above. Theorem 3, below, follows from reducing the latter problem to the problem of key-cast.
[0159] Theorem 3 (Key-Cast Is Hard):
[0160] Determining the capacity of key-cast is at least as difficult as determining whetherthe all-1s rate vector is in the capacity region of a multiple-unicast network coding problem.
[0161] Using our model from Section II, the significance of Theorem 3 relies on thehardness of determining whether the all-1s rate vector is in the capacity region of a multiple- unicast network coding instance in which all edges are of unit capacity. In a modified model for key-cast that allows general edge-capacities, one can obtain an enhanced hardness result by using Theorem 3 to reduce multiple-unicast network coding instances with general edge capacities to key-cast instances with general edge capacities.
[0162] Finally, we show that relaxing the requirement of source reconstruction in thecontext of key-cast may have significant rate benefits.Attorney Docket No.: 011520.01970
[0163] Theorem 4 (Key-Cast With Source Reconstruction):
[0164] For any integer ^^ > 1, there exist instances ℐ = (^^, ^^,^^, ℬ) of the key-castproblem such that ^^(^^) ≥ ^^^^^^^^(^^).
[0165] We note that the key-code corresponding to ^^(ℐ) presented in the proof ofTheorem 4 satisfies a natural secrecy condition: the key K shared by the nodes in terminal set D is independent of the information obtained by any network node, including the information held by any source node. As a result, no network node, other than each node d in terminal set D, learns any information about K.
[0166] B. Multiple Key-Cast
[0167] In the multiple key-cast setting, we focus our studies on single-source instances.Recall that, in multiple key-cast, one is required to distribute a key to all members of a given terminal set, with distinct keys simultaneously going to distinct terminal sets. The distributed keys should have the property that the key held by any terminal node does not reveal any information about any key shared by terminals from a different terminal set. That is, we require the keys to be pair-wise independent. The simultaneous dissemination of distinct keys to distinct terminal sets over networks is useful, e.g., as a prelude to future communication tasks within each terminal set and for multiparty applications that require unique identification, authentication, and private communications obtained through key dissemination. For a single terminal set, key-cast over single-source instances is equivalent to traditional forms of communication via Theorem 1; notably, this is not the case for multiple key-cast.
[0168] We start our analysis with the non-secure setting. Our non-secure multiple key-cast results are partially inspired by the analysis appearing in previous work, which address coding solutions and upper bounds for 2-unicast network coding with integral edge capacities. Roughly speaking, we here show, for single-source, non-secure instances with multiple terminalsets ℐ = (^^, ^^, {^^^^} ℓ^^=1 , {ℬ^^ = ^^}ℓ^^=1), that unit-rate, multiple key-cast is possible if and only if foreveryset ^^^^ , and for every ^^ ≠ ^^, there exists a unit-capacity path from thesource s to di that does not pass through a cut-set ^^^^ corresponding to terminals ^^^^ ∈ ^^^^ . For each^^ ∈ [ℓ], we specify the cut-set ^^^^ using the following definition from previous work.
[0169] Definition 4 (The Cut Set ^^^^):Attorney Docket No.: 011520.01970
[0170] An edge e is referred to as an (^^,^^)-separating edge if its removal from Gseparates terminal d from source s. For every ^^ ∈ [ℓ] and ^^ ∈ ^^^^, let ^^^^ be the (^^,^^)-separatingedge of minimum topological order in G (if such an edge exists); otherwise, let ^^^^ = ^^. Forevery ^^ ∈ [ℓ], let ^^^^ = {^^^^|^^ ∈ ^^^^ , ^^^^≠ϕ}.
[0171] For multiple key-cast we prove
[0172] Theorem 5 (Multiple Key-Cast):
[0173] Consider an instance ℐ = (^^, ^^, {^^^^} ℓ^^=1 , {ℬ^^ = ^^}ℓ^^=1) of the multiple key-castproblem with ℬ^^ = ^^ for ^^ ∈ [ℓ] (i.e., . Then ^^(ℐ)≥1 if and only iffor every ^^, ^^ ∈ [ℓ] such that ^^ ≠ ^^ andexists a unit-capacity pathconnecting s to d that does not use edges in ^^^^.
[0174] Theorem 6, below, compares the achievable key rate ^^(ℐ) of our scheme with themaximum key-rate ^^SR(ℐ) obtainable through source reconstruction. The comparison shows a significant gap.
[0175] Theorem 6 (Multiple Key-Cast With Source Reconstruction):
[0176] Fix ^^ > 0. There exist instances ℐ of the non-secure, multiple key-cast problemthat satisfy the sufficient conditions of Theorem 5 for which ^^SR(ℐ) ≤ 3 / 4 + ^^.
[0177] We finally turn to secure instances of the key-cast problem. We consider (single-source) multiple key-cast in which one distributes a collection of keys ^^ = {^^1, … ,^^ℓ} to theterminals in disjoint terminal sets {^^1, … ,^^ℓ} under the security requirement that for each ^^ ∈[ℓ], the only network nodes ^^ ∈ ^^ ∖ {^^} that individually hold any information regarding key ^^^^are the terminal nodes in ^^^^. We study the key capacity in this setting through the lens of secret sharing.
[0178] In the secret sharing paradigm, a dealer holds a uniformly distributed secretmessage, from which it must distribute one share to each user in a collection of users. Each share is a random variable computed by the dealer using the secret message and additional randomness. An access structure (^^access,^^no-access) is a predetermined collection of subsets of users, such that each subset of users in ^^accesscan jointly decode the secret and each subset ofAttorney Docket No.: 011520.01970 users in ^^no-accessfails to learn anything about the secret through its combined observations. Forexample, threshold access structures require that any collection of ^^ + 1 users can jointlyrecover the secret messsage, while any subset of k users cannot learn anything about the secret.
[0179] We present combinatorial conditions allowing single-source, multiple key-castunder the security requirements specified above.
[0180] Theorem 7 (Secure Multiple Key-Cast):
[0181] Consider an instance ℐ = (^^, ^^, {^^^^} ℓ^^=1 , {ℬ^^ = ^^}ℓ^^=1) of the multiple key-castproblem such that for ^^ ∈ [ℓ], ℬ^^ = {In(^^) ∣ ^^ ∈ ^^ ∖ (^^^^ ∪ {^^})}. Then ^^(ℐ) ≥ 1 if
[0182] • for every terminal ^^ ∈∪^^ ^^^^, there exist two vertex-disjoint paths from s to d,and,
[0183] • for every non-terminal node ^^ ∈ ^^ ∖ (∪^^ ^^^^), there exist two edge-disjoint pathsfrom s to v.
[0184] Moreover, the combinatorial conditions are tight in the sense that there existinstances ^^ = (^^, ^^, {^^ } ℓ , { } ℓ^^ ^^=1 ℬ^^ ^^=1 ) satisfying the conditions for which ^^(ℐ) = 1.
[0185] Wethe current proof paradigms of Theorem 5 and 7 may rely heavily onthe acyclic nature of G and on the fact that all edges in G have integer capacities. Extending beyond this setting is left to future studies. Theorem 8, below, bounds the comparable maximum key-rate obtainable through source reconstruction, which demonstrates a significant gap.
[0186] Theorem 8 (Secure Multiple Key-Cast With SR):
[0187] Let ^^ > 0. There exists an instance ℐ of the secure multiple key-cast problem thatsatisfies the combinatorial conditions of Theorem 7 for which ^^SR(ℐ) ≤ 3 / 4 + ^^.
[0188] SECTION IV. Proof of Theorems
[0189] A. Proof of Theorem 1
[0190] We wish to show that if ℐ = (^^, ^^,^^, ℬ) is a single-source instance of the key-castproblem, then ^^(ℐ)=^^SR(ℐ). The fact that ^^(ℐ) ≥ ^^SR(ℐ) follows from our definitions. To proveAttorney Docket No.: 011520.01970 that ^^(ℐ) ≤ ^^SR(ℐ), consider a network code (ℱ,^^) = ({^^^^}, {^^^^}) for ℐ that is (^^, ^^)-feasible.Let ^^ = ^^(^^) where ^^ is the global-encoding function for K and ^^ = (^^1, … , ^^|^^|) is the vectorof random bits used by the (single) source s communication over ℐ. If |^^| = ^^^^, then, byour definitions, it follows that f must be a permutation function; thus, slightly modifying the decoding functions in ℐ. to output M, we obtain an (^^,^^)SR-feasible code for ℐ. (where the key K is exactly M).
[0191] Let |^^| = ^^ > ^^^^. Since K is uniform, for each instance k of K the pre-image^^−1(^^) has size exactly 2^^−^^^^. Thus, there exists a pre-encoding permutation π over {0,1}^^for which, for all k, ^^−1(^^−1(^^)) is of size exactly 2^^−^^^^and the mapping ^^(^^(^^)) depends only on ^^′ = (^^1, … , that the code that first uses the pre-encoding ^^ on M and thenproceeds usingSR-feasible. Specifically, the key obtained is exactly ^^′. For security, let ^^ ∈ ℬ, and let ℎ^^(^^) represent the global encoding function of the original code(ℱ,^^) for ℐ corresponding to (^^^^ ∶ ^^ ∈ ^^). In the original code, we have, for any ^^ ∈ ℬ, that^^(^^; (^^^^ ∶ ^^ ∈ ^^)) = ^^(^^(^^); ℎ^^(^^)) = 0. In the new code for ℐ, the edges ^^ ∈ ^^ transmit^^^^and M is uniform, it now follows in the new codethat ^^(^^; ℎ^^(^^(^^)) = ^^(^^(^^(^^)); ℎ^^(^^(^^))) = ^^(^^(^^); ℎ^^(^^)) = 0 for any subset ^^ ∈ ℬby
[0192] B. Proof of Theorem 2
[0193] We wish to show that if ℐ = (^^, ^^,^^, ℬ) is a non-secure (^^ = ^^) instance of thelinear multi-source key-cast problem, then ^^^^(ℐ) = ^^ ^^SR (ℐ). The fact that ^^^^(ℐ) ≥ ^^S^^R (ℐ) follows from our definitions. To show that ^^^^(ℐ) ≤ ^^S^^R (ℐ), consider a linear network code (ℱ,^^)=({^^^^}, {^^^^}) for ℐ that is (^^,^^)-feasible. Let ^^ = ^^^^ where for ^^ = (^^^^ ∶ ^^ ∈ |^^|), ^^^^ ={^^^^^^}^^∈[^^^^]are the independent random bits usedand∶ ^^^^ ∈ ^^, ^^ ∈ [^^^^]) is the vector of random bits used by all sources duringcommunication, ^^ = ∑^^^^∈^^ ^^^^ is the size of ^^, and ^^ is the ^^^^ × ^^ global-encoding matrix of K.As ^^(^^) = ^^^^ it^^ is of rank ^^^^. Similar to the proof of Theorem 1, if |^^| = ^^ =it follows from our definitions that ^^ must be invertible; thus, slightly modifying the decoding functions in (ℱ,^^) to output ^^, we obtain an (^^,^^)_SR-feasible code for ℐ.Attorney Docket No.: 011520.01970
[0194] If instead |M|>Rn, let A′ be an Rn×L matrix derived from A which preserves Rnindependent columns from A and replaces all other columns with the all-zeros column. It holdsthat ^^(^^′^^) = ^^^^. This implies that a new key K′=A′M of the same rate can be communicatedusing the same linear network code (ℱ,^^) in which bit ^^^^^^corresponding to a zeroed out column in by the corresponding source ^^^^by a constant value of 0, or, equivalently, source ^^^^omits random bit ^^^^^^from the linear combinations transmitted on its outgoing links. The latter, in turn, implies that, in the modified code, exactly Rn bits from M are used to determine the uniform rate-R keyby the terminals. This now implies, as discussed in the case that|M|=Rn, that ℐ is (^^,^^)SR-feasible. Notice that it is crucial that we are studying the case of ^^ =^^; the reduction above does not necessarily preserve independence between the resulting key and other forms of information transmitted on network links.
[0195] C. Proof of Theorem 3
[0196] We wish to prove that determining the capacity of key-cast is at least as difficultas determining whether the all-1s rate vector (1,1, … ,1) is in the capacity region of a multiple-unicast network coding problem. To prove the theorem, it suffices to reduce the hard instance, ℐSM, of the secure-multicast (SM) problem from previous work (see discussion in Section III) to the key-cast problem. In the SM setting, one distinguishes between the subset of source nodes ^^^^that hold message information and the subset ^^^^of nodes that hold independent randomness used for masking. The two subsets may intersect. As in the model for key-cast, every node ^^^^in^^^^ ∪ ^^^^ holds an unlimited collection of independent bits {^^^^^^}^^. Instance ℐSM=(^^SM,(^^^^,^^^^),^^SM,ℬSM) is said to be (^^,^^)SM-feasible if there exists a network code (ℱ,^^) with blocklength n such that
[0197] Message Rate: K equals a collection of message bits of size Rn from (^^^^^^:^^^^∈^^^^),i.e., K equals a collection of bits generated by sources in ^^^^.
[0198] Decoding: For all ^^ ^^^^ ∈ ^^SM, ^^(^^|^^In(^^^^) ) = 0.[01 Secrecy: ^^(^^; ^^ ∶ = ^^ ∈ ℬSM.
[0200] The hard instance ℐSM of previous work includes a single message-generatingsource node s, i.e., ^^^^={s}, a single terminal node d, a network ^^SM=(^^SM,^^SM), and a collectionAttorney Docket No.: 011520.01970ℬSM = {{^^} | ^^ ∈ ^^SM } representing the security requirement that the message communicatedfrom s to d must be independent of the information transmitted on any individual edge ^^ ∈ ^^SM.The set ^^^^ equals ^^SM. Let R be any integer. Instance ℐ = (^^, ^^,^^, ℬ) of the key-cast problem isobtained from ℐSM and R by adding a new terminal ^^′ to the vertex set, giving ^^ = ^^SM ∪ {^^′},and setting ^^ = (^^,^^) for ^^ = ^^SM ∪ {(^^,^^′)} where edge (^^,^^′) has capacity R. We set sourceset ^^ = {^^} ∪ ^^^^, terminal set ^^ = {^^,^^′}, and security requirement ℬ = ℬSM.
[0201] We show for every ^^′ ≤ ^^ that there exists an (^^′,^^)SM-feasible code for ℐSM ifand only if there exists an (^^′,^^)-feasible code for ℐ. Combining this with the result of previous work that shows that determining whether there exists an (^^′,^^)SM-feasible code for ℐSMis as hard as determining whether the all-1s rate vector is in the capacity region of a given k-unicast network coding instance concludes our assertion. First, assume that there exists an (^^′,^^)SM- feasible code for ℐSM. Let K be the rate ^^′ message that is securely communicated from source s to terminal d. Using the exact same code on ℐ and communicating K directly on the new edge (^^,^^′), one can communicate K to all terminals in D. As the original code is secure in ℐSMfor theedge sets in ℬSM = ℬ, the code is (^^′,^^)-feasible for ℐ.
[0202] Now assume that there exists an (^^′,^^)-feasible code for ℐ. As only informationgenerated at s can be shared between the new terminal ^^′ and the other terminal ^^ ∈ ^^, it holdsthat the shared uniform key K is a function of the random bits generated at s. Moreover, as ℬ =ℬ , for ever ^^SM y ^^ ∈ ℬ the code on ℐ satisfies ^^(^^, (^^^^ ∶ ^^ ∈ ^^)) = 0. Notice that K may be a(global) function of the random bits {^^^^} held by s, and, in the context of secure multicast, onerequires that K equals a collection of bits included in ({^^^^^^}j :^^^^ ∈ ^^^^). Using ideas analogous tothose presented in the proof of Theorem 1, one can modify the code at hand by adding a pre- processing function π at s to guarantee that the newly decoded key K is equal to a collection of bits held by s. Thus, the new network code, when restricted to ^^SM, is an (^^′,^^)SM-feasible code for ℐSM. This concludes the proof of our assertion.
[0203] D. Proof of Theorem 4
[0204] We wish to prove, for any integer α>1, that there exist instances ℐ = (^^, ^^,^^, ℬ)of the key-cast problem such that ^^(ℐ) ≥α^^SR(ℐ). Let α>1. Roughly speaking, the instance ℐ =(^^, ^^,^^, ℬ) we present is reminiscent of combination networks, used often to design examples inthe context of network coding. The network ℐ, depicted in a simplified form for the special caseAttorney Docket No.: 011520.01970 of α=2 in Figure 3, has the following structure. Network G is acyclic and has three layers ofnodes. The first layer comprises the source nodes ^^ = {^^1, … , ^^^^}. Here, we set r to be equal toα+1. The second layer comprises two sets of intermediate nodes U={u1,…,ur} and^̅^={^̅^1,…,^̅^r}. The final layer comprises terminal nodes ^^ = {^^^^}^^ ∈ [^^]. The edge set of Gcomprises the following edges, an edge (^^^^,^^^^) for every ^^ ∈ [^^], an edge (^^^^,^̅^^^) for every j≠i in[^^]2, an edge (^^^^,di) and (^̅^^^,^^^^) for every ^^ ∈ [^^]. Each edge has capacity 1. (In Figure 3, nodes^^^^ are omitted to simplifyeach node ^^ ∈ ^^ ∪ ^̅^, the set ℬ contains a subset^^^^ = (^^ ∶ ^^ ∈ In(^^)) comprising all incoming edges to v. Thus, ℬ = {^^^^ ∶ ^^ ∈ ^^ ∪ ^̅^}.
[0205] We first show that ^^(ℐ) ≤1. Consider any network code for ℐ that is (^^,^^)-feasible. Let K be the key shared by all terminal nodes. For nodes ^^ ∈ ^^ ∪ ^̅^, let ^^(^^) be the(single) edge leaving v and let ^^^^^^(^^) be the information transmitted on e(v). Since ^^^^ ∈ ℬ, itmust hold that ^^(^^;^^^^^^(^^) ) ≤ ^^ (^^ ^^^^ ∶ ^^ ∈ ^^^^)) = 0. We now show that this implies that^^(^^) ≤ ^^, ^^ ^^ terminal ^^^^. The structure of ℐ implies that^^(^^) = ^^(^^;^^^^^^(^^^^),^^^^^^(^̅^^^)) =^^(^^; ^^ ^^^^(^^^^)) + ^^(^^;^^^^^^(^̅^^^)|^^^^^^(^^^^))) =^^(^^; ^^^^^^(^̅^^^)|^^^^^^(^^^^))) ≤ ^^(^^ ^^^^(^̅^^^)) ≤ ^^.To show that ^^(ℐ) = 1, we(i.e., of rate R=1). Roughly speaking, our code communicates the sum of all sources to each terminal di.Formally, for n= 1, source node ^^^^ sends the same bit ^^^^ on all of its outgoing edges, and nodes^^^^and ^̅^^^send the binary sum of their incoming information on their single outgoing edge. these sums, every terminal obtains the (same) sum ∑^^ ^^=1 ^^^^ ≜ ^^. Due to the nature of K,for any ^^^^ ∈ ℬ it holds that ^^(^^; (^^ ^^^^ ∶ ^^ ∈ ^^^^)) = 0. We conclude that ℐ is (^^,^^)-feasible forR= 1.
[0206] We now show that ^^SR(ℐ) ≤1 ^^−1. Consider any network code for ℐ that is (^^,^^)SN-feasible. Denote theinformation at terminal di by ^^(^^); here, ^^(^^)⊆M is a subset of source bits. Recall that for each terminal di it holds that H(K|^^(^^))=0.Let ^^(^^) △ ^^(^^′) ⊂ ^^ be the symmetric difference between ^^(^^) and M(i′). Then, for anyterminals ^^^^ and ^^^^′ for which ^^(^^) ≠ ^^(^^′), ^^(^^; ^^(^^) △ ^^(^^′)) = 0. Thus, for ^̅^ =∩ ^^^^ ∈^^^^(^^) it holds that ^^(^^|^̅^) = 0. Let ^̅^^^ be the bits in ^̅^ generated at source ^^^^ ∈ ^^, i.e.,Attorney Docket No.: 011520.01970 ^̅^^^=^̅^∩^^^^⊆^^^^, and let ^^^^=|^̅^^^ | / n. For any ^^ ∈ [^^], removing a single edge from ℐ separatesterminal ^^^^from sources (^^^^:j≠i). Therefore, using standard cut-set bounds with respect tothat ∑^^≠^^ ^^^^ ≤ 1. Summing over i, we conclude that ∑^^ ∑^^≠^^ ^^^^ ≤ ^^ , whichin turn implies that ∑^^^^^^ ≤^^ ^^−1. Moreover, as ^^^^ ∈ ^^ lies on the only path from ^^^^ to terminal ^^^^,^^(^̅^^^^^|^^In(^^^^)) = of ℬ, we have for all i∈ [^^] that ^^ ^^In (^^^^)) = 0, whichnow that ^^for all ^^ ∈ [^^]. Similarly, by our definition of ℬ, it holds that^^)) = 0 for all ^^ ∈ [^^] since ^̅^^^ ∈ ^̅^ lies on the only path from {^^^^}j≠i to ^^^^. Thus,for every ^^ ∈ [^^],^^(^^) = ^^(^^; ^̅^)= ^^ (^^; (^̅^^^ ∶ ^^ ≠ ^^)) + ^^ (^^; ^̅^^^|(^̅^^^ ∶ ^^ ≠ ^^))Summing over all ^^ ∈ [^^],^^ ⋅^^ ^^−1, implying that ^^^^ = ^^(^^) ≤^^ ^^−1. We finally conclude that 1 = ^^(ℐ) ≥ (^^ − 1)^^SR(ℐ) = ^^^^SR(ℐ).of Theorem 5
[0208] Given an instance ℐ = (^^, ^^, {^^^^}ℓ^^ = 1, {ℬ^^}ℓ^^ = 1) of the non-secure multiplekey-cast problem with ℬ^^ = ^^ for ^^that ^^(ℐ) ≥1 if and only if for every^^, ^^ ∈ [ℓ] such that j≠i and for every terminal ^^ ∈ ^^^^ there exists a unit-capacity path connectings to d that does not use edges in the cut set ^^^^(see Definition 4). The proof is inspired by prior work, which addressed coding solutions and converses for 2-unicast network coding instances with integral edge capacities. We start with the converse. Consider any key dissemination protocol of rate ^^ ≥ 1. We here omit the blocklength n to simplify notation. For any edge e, let^^^^ be the information transmitted on e. For any edge set A, let ^^^^ = (^^^^ ∶ ^^ ∈ ^^) be theinformation transmitted on edges ^^ ∈A. For any vertex v, let ^^In(v) be the incoming informationto v during the protocol. We first note that for any edge e in ^^^^ it must hold that ^^(^^^^|^^^^) =^^(^^^^|^^^^) = 0; this follows since ^^ = ^^^^ for some terminal ^^ ∈ ^^^^ that requires key ^^^^ of rate^^ ≥ 1, and e has unit capacity. It follows that H(^^^^ |^^^^^^)= ^^(^^^^^^|^^^^) = 0. Assume now, incontradiction, that there exist ^^, ^^ ∈ [ℓ], ^^ ≠ ^^, and a terminal ^^ ∈ ^^^^ such that ^^^^ separates s fromd. This implies, by our decoding requirements, that H(^^^^|^^^^^^) = 0. However, as H(^^^^^^ |^^^^)=0, weAttorney Docket No.: 011520.01970 conclude that H(^^^^|^^^^)=0. Hence, by the pairwise independence requirements, R=H(^^^^)=H(^^^^|^^^^)=0, which contradicts our assumption that R≥1.
[0209] For achievability, we design an encoding scheme in two stages; both stages aredeterministic. First, we design a 2-multicast coding solution using a certain edge-coloring of G. Then, the coloring and coding scheme are modified to match our key dissemination requirements.
[0210] Let the source s hold 2 messages, a and b. In our edge-colorings, an edge ecolored by the color α represents the transmission of the linear combination ^^ + ^^^^ on e, wherea, b, and α are all elements of a sufficiently large field F of size 2n for blocklength n, with all operations done over F. Our coloring is governed by the predetermined topological order of edges in G. We assume, without loss of generality, that every node in G is connected from s. Otherwise, one can remove such nodes from G without impacting the communication protocol.
[0211] The first coloring stage: Consider the edge e of least topological order. We colore with the color α= 1 corresponding to the message ^^ + ^^^^ = ^^ + ^^. Next, we continue coloringby induction over the topological order of edges e in G. For each subsequent edge e, assume, by induction, that all incoming edges of e have been colored. If e is an outgoing edge from the source s, here called a source edge, then assign a new color to e that is greater (by one) than the largest color previously assigned. If e has two incoming edges with distinct colors, then, again, assign a new color to e greater (by one) than the largest color previously assigned; such an edge e is called newly colored. Otherwise, e takes the color of its incoming neighbors; such an edge iscalled color preserving. An edge ^^ = (^^, ^^) is said to be 2 edge-connected from s if ^^ ≠ ^^ andthere exist at least 2 edge-disjoint paths from s to u. In Claim 1, given at the end of this proof, we show that e is newly colored if and only if e is 2 edge-connected from s.
[0212] Validity of the encoding corresponding to the first coloring stage: We nowshow that an edge e with color α can compute its outgoing message ^^ + ^^^^ from its incominginformation. If e is a source edge, then the outgoing information on e can be computed from s since s holds both a and b. If e is newly colored, then e has two incoming edges that are colored by different colors; the different incoming edge colors imply that the incoming edges carry independent information from which e can recover any linear combination of source informationAttorney Docket No.: 011520.01970 a and b. Finally, if e is color preserving, then all its incoming edges have the same color as e, and thus e can forward the information from its incoming edges.
[0213] The second coloring stage: In our second coloring / coding stage, we focus on thecut sets ^^^^ from Definition 4. For each ^^ ∈ [ℓ], we start by assigning a new color ^^^^ (distinctfrom all other colors) to all edges e in ^^^^. We then continue in topological order and change the color of edge e to ^^^^if all incoming edges to e are colored ^^^^. The color of all other edges remains unchanged.
[0214] Note that, from our assumptions on G, it holds that ^^^^∩^^^^′=ϕ for any ^^, ^^′ ∈ [ℓ].To see why this is true, note that otherwise there exists ^^ ∈ ^^^^∩^^^^′ and a corresponding ^^ ∈ ^^^^such that ^^ = ^^^^ (see Definition 4), and thus d is disconnected from s by the removal of e. Thiscontradicts the assumption on G that any terminal d has a path from s that does not pass through^^^^′ . Moreover, after the completion of the second coloring stage, for any ^^ ∈ [ℓ], all edges ^^ ∈ ^^^^are (still) colored ^^^^; that is, in the process of the second coloring stage, there is no j′≠j for which the incoming edges of e all equal ^^^^′. If this were not true, then any path from s to e would have to include an edge colored ^^^^′ with minimum topological order, and that edge would have to befrom ^^^^′ . This would imply, as above, that the terminal ^^ ∈ ^^^^ corresponding to ^^ = ^^^^ ∈ ^^^^would be disconnected from s by the removal of e, which, in turn, would be disconnected from sby the removal of ^^^^′ . This, again, would contradict the assumption on G that any terminal ^^ ∈^^^^has a path from s that does not pass through ^^^^′. Finally, it holds, after the second stage ofcoloring, that edge ^^ ∈ ^^^^ is colored ^^^^ if and only if e is disconnected from s by the removal of^^^^. Namely, similar to the proof of Claim 1, if e is disconnected from s by the removal of ^^^^, one can study the edge-set partition (^^^^,^^^^) of E implied by the removal of ^^^^and prove by induction that edges in ^^^^, and in particular all incoming edges to e, are colored ^^^^. For the other direction, if e is not disconnected from s by the removal of ^^^^, then there exists a path P from s to e that does not pass through ^^^^. No edge on path P can have color ^^^^, as otherwise the edge with minimum topological order on path P that has color ^^^^must be from ^^^^; the latter contradicts the definition of P. This now implies that e has anedge that does not have color ^^^^.
[0215] Validity of the encoding corresponding to the second coloring stage: We nextprove that our modified assignment of colors after the second coloring stage does not impact theAttorney Docket No.: 011520.01970 network coding feasibility; that is, we prove that any edge e can compute its outgoing information from its incoming information. We consider the following cases. (i) For each source edge e, network coding feasibility follows trivially. (ii) For each edge e with color ^^^^and at least one incoming edge of color ^^^^, e can forward the information from that incoming edge. (iii) Foreach edge e with color ^^^^ and no incoming edge of color ^^^^, it must be the case that ^^ ∈ ^^^^. Bythe topological-minimality condition in Definition 4, ^^ ∈ ^^^^ is 2 edge-connected from s and thus,by Claim 1, e is labeled newly colored in the first coloring stage. This implies that the incoming edges of e do not all have the same color in the first coloring phase. As we show above that theredoes not exist ^^′ ≠ ^^ such that the incoming edges of e are all colored ^^^^′ , we conclude that, afterthe second stage of coloring, e has at least two incoming edges with distinct colors. Such edges hold independent linear combinations of a and b and thus imply network coding feasibility at e. (iv) The remaining edges did not change color in the second stage of coloring. If any such e has two incoming edges with distinct colors, then their incoming information is independent, and e can compute its outgoing information from its incoming information. Otherwise, all incoming edges of e have the same color ^^. As e did not change color in the second phase of coloring, ^^cannot equal ^^^^ for ^^ ∈ [ℓ]. Thus, e and all incoming edges of e did not change color in thesecond stage of coloring, implying that e is color preserving and thus can forward its incoming information.
[0216] The decoding of ^^^^=a+^^^^b at terminals ^^ ∈ ^^^^ : To finish our proof, we need toshow that for any ^^ ∈ [ℓ], any terminal ^^ ∈ ^^^^ is able to decode key ^^^^=a+^^^^b (of rate 1). Noticethat the keys {^^^^}^^∈[ℓ]are pair-wise independent. We here assume, without loss of generality,that each terminald in G has only one incoming edge. Otherwise, for any terminal ^^ ∈ ^^^^one can construct a new instance by adding to G a new node ^^′, adding a new edge (^^,^^′), and modifying ^^^^by removing d and adding ^^′. The new instance is solvable at rate 1 if and only if the original instance is solvable at rate 1. With this assumption, the single incoming edge e to^^ ∈ ^^^^ is either in ^^^^ or is separated from s by the removal of ^^^^. This follows from theobservation that d is separated from s by the removal of its single incoming edge, and thus thereexists an edge ^^^^ ∈ ^^^^ of minimum topological order disconnecting d from s. As edges in ^^^^ andthose separated from s by the removal of ^^^^ are colored by ^^^^, terminal ^^ ∈ ^^^^ receives^^^^=a+^^^^b from its incoming edge. This concludes our achievability proof.Attorney Docket No.: 011520.01970
[0217] Claim 1:
[0218] Edge e is newly colored (in the first phase of coloring) if and only if e is 2 edge-connected from s.
[0219] Proof:
[0220] First assume that e is not newly colored. If e is a source edge, then, by ourdefinitions, e is not 2 edge-connected from s. Otherwise e is color preserving and all incoming edges of e share the color α with e. Let ^^∗be the edge with color α of minimum topological order. We now claim that removing ^^∗disconnects e from s, implying that e is not 2 edge- connected from s. Towards this end, assume in contradiction that there is a path P from s to e that does not include edge ^^∗. Let e′ be the color-α edge on path P of minimum topological order. It holds that e′≠^^∗as P∩{^^∗}=ϕ. As ^^∗precedes e′ in topological order and they are both colored α, it holds that e′ is not colored nor a source edge. Therefore, e′ is colorpreserving, i.e., all incoming e′ are also colored α, including the incoming edge of e′ on P. This contradicts the minimality assumption on the topological order of e′ on P.
[0221] For the reverse direction, assume e is not 2 edge-connected from s. If e is a sourceedge, then we conclude that it is not newly colored. Otherwise, there is a single edge ^^∗in G whose removal will disconnect s from e. Consider the edge set partition (^^^^,^^^^) of E implied bythe removal of ^^∗, where outgoing edges of s are in ^^^^ and ^^ ∈ ^^^^. It now follows, by inductionon the topological order of G, that all edges in ^^^^(including e) are color preserving with color ^^.
[0222] F. Proof of Theorem 6
[0223] Let ^^ > 0. We wish to prove that there exist instances ℐ of the non-secure,multiple key-cast problem that satisfy the sufficient conditions of Theorem 5 for which ^^SR(ℐ) ≤3 / 4 + ^^. Before embarking on that proof, we prove the following technical lemma, which isimplied by the Plotkin bound. The proof is given for completeness. Define the support of abinary codeword ^^ = (^^1, … , ^^^^) as {^^ ∈ [^^] ∣ ^^^^ = 1}.
[0224] Attorney Docket No.: 011520.01970
[0225] Any size-M, blocklength-n binary code in which codewords are limited toHamming weight at most wn contains a pair of codewords ^^ = (^^ ′1, … , ^^^^) and ^^′ = (^^1 , … , ^^^′^)such that the union of the support of ^^ and ^^′ has size at most ^^^^(2 − ^^) ⋅ (1 +1 ^^−1).
[0226] Proof:
[0227] (of Lemma 1) For any two codewords x and x′, let ℓ^^,^^′ =∣ {^^ ∈ [^^] ∣ ^^^^ = 1} ∪{^^ ∈ [^^] ∣ ^^ ′^^ = 1} ∣. Let ℓ = m^^≠i^n^′ℓ^^,^^′. We would like to show that for codes of size M, it holdsthat ℓ ≤ ^^^^(2 − ^^) ⋅ (1 +1^^ = ^^ − ℓ ′ =′^^−1). Let ℓ^^,^^′^^,^^ ∣ {^^ ∈ [^^] ∣ ^^^^ = 0} ∩ {^^ ∈ [^^] ∣ ^^^^=0} ∣ be the number of entries i in which both ^^ ′ ^^^^ and ^^^^ equal 0; and let ℓ = ^^ − ℓ. On one hand,∑ ℓ^^′ ≤^^ℓ^^.^^,^^ (2)′On the other hand, if ^^ is thewhich ^^^^ = 0, then,codeword pairs for both ^^^^and ^^′equal 0 and summing over i, we have^^^^ ∑ℓ^^′ = ∑(^^^^) .
[0228] Given the weightnotice that ∑^^ ^^^^ ≥ ^^(1 − ^^)^^.Moreover, under this constraint, the expression ∑ (^^^^) is minimized for each i, ^^ 2^^^^(1 − ^^). We thus conclude that^^ ^^^^ ≥^^=^^^^ ≥ ^^ ^^(1 − ^^)).Thus, ℓ^^ ≥ ^^(1 − ^^) −^^−1 , or, equivalently, ^1 − ^^ + ^^^^( )ℓ ≤ ^^ − ^ ( )2 1 − ^^^^ − 1 ≤ ^^^^(2 − ^^) ⋅ (1 +1 ^^ − 1). This concludes the proof of our assertion.Attorney Docket No.: 011520.01970
[0229] We use the following corollary of Lemma 1 obtained by setting ^^ − 1 =1 ^^ ≥ ^^(2−^^) ^^ .
[0230] Corollary 1:
[0231] Let ^^ > 0. Any blocklength-n binary code of size ^^ = 1 +1 ^^ in which codewordsare limited to Hamming weight at most wn contains a pair of codewords ^^ = (^^1, … , ^^^^) and^^′ = (^^ ′1 , … , ^^^ ′^ ) such that the union of the support of x and x′ (i.e., the set {^^ ∈ [^^] ∣ ^^^^ = 1} ∪{^^ ∈ [^^] ∣ ^^ ′ = 1}) is of s 2^^ ize at most ^^(2^^ − ^^ ) + ^^^^.
[0232] We are now ready to prove Theorem 6. We consider the 3-layered instancedepicted in Figure 4. The network includes a source s connected by 2 unit-capacity edges to an intermediate node x. The source s and node x represent the first two layers of the network. Thethird layer includes terminal nodes ^^1, … , ^^ℓ for ℓ= 1+1 / ^, each connected with a unit-capacityedge from x, and each belonging to a distinct terminal set ^^^^ = {^^^^}. Note that this instancesatisfies the conditions of Theorem 5. To bound ^^SR(ℐ), consider any blocklength-n key-codeusing source reconstruction. Each terminal decodes a subset of the source information bits ^^ ={^^1,^^2, … }; subset ^^(^^) is decoded at terminal ^^^^ for ^^ ∈ [ℓ]. Let ^^^^ be the subset of source bitsthat are decodable at node x. We first notice that |^^^^| ≤ 2^^, and thus we assume, without loss ofgenerality, that ^^^^ ⊆ {^^1, … , ^^2^^}. Given the graph topology, we also observe, for each ^^ ∈ [ℓ],that ^^(^^) is awith |^^(^^)| ≤ ^^. Considering the characteristic binary vector ^^^^ of^^(^^) as a subset of ^^^^, we obtain a codebook ^^1, … , ^^ℓ of codewords each of blocklength (atmost) 2n and of weight at most n. Appending zeros to codewords if needed, we obtain acodebook c1,…,cℓ of blocklength 2n and of weight at most n. Applying Corollary 1 with w= 1 / 2and blocklength 2n, we conclude that there exist indices i≠j such that the total support of ^^^^and^^^^ is at most (2^^ − ^^2 + ^^)2^^ = (3 + 4^^)^^ / 2; the corresponding observation holds for ^^(^^)and ^^(^^). Since ^^^^is a function of ^^(^^), ^^^^is a function of M(j), and ^^^^is independent of ^^^^,we conclude(^^^^) + ^^(^^^^) ≤ (3 + 4^^)^^ / 2, which in turn implies that ^^SR(ℐ) ≤ (3 +4^^) / 4 = 3 / 4 + ^^.
[0233] Remark 2:Attorney Docket No.: 011520.01970
[0234] Given the connectivity conditions of Theorem 5, one can show, using randomlinear network coding over blocklength n, that every terminal node can decode two (uniformly distributed) messages, each of entropy n / 2. Thus, each terminal, using a potentially different linear combination of the decoded messages, can obtain a key of rate 1 / 2 that is independent of any key decoded by a terminal in a different decoding set. This simple scheme implies that^^SR(ℐ) ≥1 / 2. Thus, the gap presented in Theorem 6 between key dissemination schemes withand without source reconstruction, while not necessarily optimal, is of the correct order.
[0235] G. Proof of Theorem 7
[0236] Given an instance ℐ = (^^, ^^, {^^^^} ℓ^^=1 , {ℬ^^}ℓ^^=1) of the multiple key-cast problemsuch that for ^^ ∈ [ℓ], ℬ^^ = {In(^^) ∣ ^^ ^^ {^^})}, we wish to show that ^^(ℐ) ≥1 if, (a) forevery terminal ^^ ∈∪^^ ^^^^, there exist paths from s to d, and, (b) for every non-terminal node ^^ ∈ ^^ ∖ (∪^^ ^^^^), there exist two edge-disjoint paths from s to v. Moreover, wewish to show that the combinatorial conditions are tight in the sense that there exist instances ^^ =(^^, ^^, {^^^^} ℓ^^=1 , {ℬ^^} ℓ^^=1 ) satisfying these conditions for which ^^(ℐ) = 1. The proof is inspired bythe distributed secret sharing scheme presented in previous work for the threshold k= 1. Thesuggested dissemination scheme uses a special vertex coloring of the vertices in the acyclic graph G. The vertex coloring we use is similar in nature to the edge coloring used in Theorem 5 and has similar properties, albeit with respect to vertex connectivity and not edge connectivity.
[0237] We start by defining the graph coloring, which assigns an integer color ^^^^ to eachvertex ^^ ∈ ^^. Our coloring proceeds in the predefined topological order. Here and below, weassume that colors are assigned in increasing linear order, i.e., each time a distinct color is assigned, its value is one larger than the previously assigned color. The source s receives color^^^^ = 1. Each neighbor u of s that only has incoming edges from s is assigned a unique color.Such vertices are called source connected vertices. For each subsequent vertex u, assume, by induction, that all vertices v of topological order preceding that of u have been colored. If u hastwo incoming edges, (^^,^^) and (^^′,^^), such that ^^^^ ≠ ^^^^′, then assign a color to u that is distinctfrom all colors previously assigned. Such vertices are called (as in the proof of Theorem 5) newlycolored. Otherwise, cu takes the color of its incoming neighbors, i.e., ^^^^ = ^^^^ for (any) incomingedge (^^,^^). Such vertices are called color preserving. A vertex u in G is 2-vertex connected from s if there exist two vertex disjoint paths, P1 and P2, from s to u, i.e., no vertices except s and u appear in both paths, and, in addition, if u is a neighbor of s, then ^^1and ^^2do not shareAttorney Docket No.: 011520.01970 any edges. Similar to Claim 1, in Claim 2, stated later, we show that a vertex u in G is 2-vertex connected from s if and only if it is newly colored or source connected.
[0238] Claim 2 implies that every terminal node is either newly colored or sourceconnected. As shown below, the color of each terminal determines its key, and keys of different colors are pairwise independent. To allow terminals in the same terminal set to decode the same key, we slightly modify the coloring scheme. Specifically, we pick, for each terminal set ^^^^, arepresentative terminal ^^^^ ∈ ^^^^, and we assign all terminals in ^^^^ the color ^^^^^^. Thus, the colorrepresenting terminal set ^^^^is ^^^^^^. As we assume in this work that terminal nodes do have any outgoing edges, the suggested modified coloring does not change the color of nodes incoming to any network node u.
[0239] We now present the blocklength-n key distribution scheme. Assume the graph Gis colored by (a subset of) colors {1,2,3,…,c}. We take n to be sufficiently large such that 2^^> ^^. Consider the finite field F of size 2^^. The source s picks three independent values s, a, b uniformly at random from F. For each neighbor u of s that only has incoming edges from s, i.e.,for each source-connected node u, the source transmits ^^ + ^^^^^^ and ^^ + ^^^^^^ to u (all operationsare done over F). This is possible since any node in G is 2-edge connected from the source (i.e., in this case, there are two edges connecting s to u). We proceed in topological order and show byinduction that every vertex u receives what it needs to compute ^^ + ^^^^^^ and ^^ + ^^^^^^. Consider anetwork node u (that may also be a terminal node). If u is newly colored, then it has at least 2incoming edges (v,u) and (v′,u) with ^^^^ ≠ ^^^^′ . In this case, v transmits (^^ + ^^^^^^) + ^^^^(^^ + ^^^^^^)on (v,u) and v′ transmits (^^ + ^^^^′^^) + ^^^^(^^ + ^^^^′^^) on (^^′,^^). Rearranging the terms in thelinear equations above, we conclude that u receives (^^ + ^^^^^^) + ^^^^(^^ + ^^^^^^) and (^^ + ^^^^^^) +^^^^′(^^ + ^^^^^^), which (since ^^^^ ≠ ^^^^′) allows it to decode ^^ + ^^^^^^ and ^^ + ^^^^^^. If u is neithernewly-colored nor source-connected, then u is a color preserving node. Recall that any node, including node u, must have at least two incoming edges (otherwise it would not be two edge or vertex connected from s). Let (v,u) and (v′,u) be two incoming edges for u. Here v may equal v′,and since u is color preserving, ^^^^ = ^^^^ = ^^^^′. Thus v can forward ^^ + ^^^^^^ on (v,u), and v′ canforward ^^ + ^^^^^^ on (v′,u).
[0240] At the end of this process, every vertex u in the graph G has received exactly twodistinct messages, ^^ + ^^^^^^ and ^^ + ^^^^^^ (or two independent linear combinations thereof). ForAttorney Docket No.: 011520.01970each ^^ ∈ [ℓ], define the key for terminal set ^^^^ to be ^^^^ = ^^ + ^^^^^^^^. We conclude that everyterminal d in ^^^^can recover ^^^^after the protocol is complete.
[0241] To prove secrecy, we now use the fact that every terminal node is either newlycolored or source connected; that is, for ^^ ∈ ^^^^ , the color cdi differs from ^^^^ for any vertex ^^ ∈^^^^. As any such v (that is not the source) only receives (^^ + ^^^^^^) and (^^ + ^^^^^^) (or linearcombinations thereof) during the protocol, it holds that the mutual information between v’smessages and ^^^^ is zero. Formally, for any ^^ ∈ [ℓ], if ^^ ∈ ^^^^ ∪ {^^}, then ^^^^^^ ≠ ^^^^ and thus^^(^^In(^^);^^^^) = ^^((^^ + ^^^^^^), (^^ + ^^^^^^); ^^ + = here omit the blocklength n from ournotation for simplicity.
[0242] To show that the bound ^^(ℐ) ≥1 is tight under the combinatorial conditionsassumed in Theorem 7, we now present an example instance ℐ (depicted in Figure 5) thatsatisfies the conditions for which ^^(ℐ) = 1. In our example, the single source s must disseminatetwo keys ^^1 and ^^2 to terminal sets ^^1 = {^^11,^^12} (in red) and ^^2 = {^^21,^^22} (in purple),respectively, such that (i) for each node ^^ ^^, ^^} and for any i∈{1,2}, I(^^^^;^^In(v))=0, and (ii)for each ^^, ^^ ∈ {1,2}, ^^ ≠ ^^, and any terminal node ^^ ∈ ^^^^ , ^^(^^^^;^^In(d)) = 0. In Figure 5, all edgeshave capacity 1. Note that each terminal has two vertex-disjoint paths from s, and all nodes are two edge-connected from s. We show that the maximum achievable key rate in this case is 1.
[0243] Consider any secret key dissemination protocol. For any vertex v, let ^^In(v) be theincoming information to v during the protocol, and for any edge (u,v) let ^^^^^^be the information transmitted on (u,v). Here, as the network is acyclic, we consider communication according to topological order on G. We next present a number of information inequalities that we use to prove our assertion.
[0244] First, consider edges (x,z) and (y,z), and note that ^^(^^In(^^)) ≤ ^^(^^^^^^) + ^^(^^^^^^).Without loss of generality, let ^^(^^^^^^) ≥ ^^(^^^^^^). Then ^^(^^^^^^) ≥ 0.5 ^^(^^In(^^)) and^^(^^^^^^|^^^^^^) ≤ 0.5 ^^(^^In(^^)).
[0245] Moreover, we now have that^^(^^In(^^),^^In(^^)) = ^^(^^In(^^)) + ^^(^^In(^^)|^^In(^^))Attorney Docket No.: 011520.01970 ≤2 + ^^(^^^^^^,^^^^^^|^^^^^^)= 2 + ^^Given our security requirements andthat ^^^^,^^11is independent of ^^1, that ^^^^,^^11is independent of ^^1, and that ^^1is a function of ^^^^,^^11and ^^^^,^^11. These observations imply that^^(^^1) = ^^(^^1|^^^^,^^11)^^Similarly, ^^(^^1) ≤ ^^+^^(^^^^,^^11|^^^^,^^11) ≥ 2^^(^^1). Combining the above observations with the fact that ^^2 is aand with our security assumption that the incoming information to ^^11isindependent of ^^2, we find that ^^(^^In(^^),^^In(^^)) ≥ ^^(^^^^,^^11^^^^,^^11 ,^^2)
[0246] Denote the key rate ^^(^^1) = ^^(^^2) by R. Finally, using the fact that ^^In(z) isindependent of ^^1we have ^^(^^In(^^),^^In(^^)) = ^^(^^In(^^),^^In(^^),^^1)^^.
[0247] We now• ^^(^^In(^^),^^In(^^)) ≥ 3^^Attorney Docket No.: 011520.01970 •^^(^^In(^^),^^In(^^)) ≥ ^^ + ^^(^^In(^^))Theimply that 2^^(^^In(^^),^^In(^^)) ≤ 4 + ^^(^^In(^^)) ≤ 4 + ^^(^^In(^^),^^In(^^)) − ^^,implying thatgives3^^ ≤ ^^(^^In(^^),^^In(^^)) ≤ 4 − ^^,which proves our assertionof Theorem 7.
[0248] Claim 2:
[0249] A vertex u in G is 2-vertex-connected from s if and only if it is newly colored orsource connected.
[0250] Proof:
[0251] For the forward direction, assume u is not newly colored nor source connected,i.e., u is color preserving. Then all incoming edges (v,u) have ^^^^ = ^^0 for a common color ^^0.Let ^^∗ be the vertex in G with least topological order such that ^^^^∗ = ^^0. Notice, by our coloringprocedure, that for every vertex ^^′ ≠ ^^∗ in the graph G, if ^^^^′ = ^^^^∗ = ^^0 then it must be the casethat all incoming edges (^^, ^^′) to ^^′ satisfy ^^^^ = ^^0. We now claim that removing ^^∗disconnects u from s, implying that u is not 2-vertex-connected from s. Assume, in contradiction, that there is a path P from s to u that does not pass through ^^∗. Let v′ be the vertex on P withminimum topological order for which ^^^^′ = ^^0. As all incoming edges (v,u) to u satisfy ^^^^ = ^^0,the vertex ^^′ is well defined. The vertex ^^′ cannot be ^^∗by our assumption that P does not pass through ^^∗. The vertex ^^′ cannot be s since no other vertex except s has color 1. Thus, theincoming edge (^^, ^^′) to ^^′ along the path P must satisfy ^^^^ = ^^0; this contradicts theminimality assumption on the topological order of ^^′.
[0252] For the reverse direction, assume u is not 2-vertex-connected. Given ourassumption on G that all vertices, including neighbors of s, are two edge-connected from s, it holds that u is not source connected. We conclude that there is a single vertex v in G whose removal will disconnect s from u. Consider the cut partition (^^^^,^^^^) of V implied by the removalAttorney Docket No.: 011520.01970 of v, where ^^ ∈ ^^^^ and ^^ ∈ ^^^^. It now follows by induction on the topological order of G that allvertices in ^^^^(including u) are color preserving with color ^^^^.
[0253] H. Proof of Theorem 8
[0254] Let ^^ > 0. We wish to prove that there exists an instance ℐ of the secure multiplekey-cast problem that satisfies the combinatorial conditions of Theorem 7 for which ^^SR(ℐ) ≤3 / 4+^. We start by defining the instance ℐ, which is a modified version of that given inFigure 5. Let the number of terminal sets ^^9 9 ^^ be ℓ =^^(1 +^^) instead of ℓ = 2 as in Figure 5. Thegraph G of ℐ includes nodes s, x, y, zterminal nodes ^^^^1 and ^^^^2 for ^^ ∈ [ℓ]. Node s isconnected to x by two unit-capacity edges; similarly, s is connected to y by two unit-capacity edges. Node x is connected to z by a single edge, and, similarly, y is connected to z by a single edge. Finally, for each ^^ ∈ [ℓ], node x is connected by a single edge to ^^^^1, node y is connectedby a single edge to ^^^^2, and z is connected to both ^^^^1 and ^^^^2. In ℐ, for ^^ ∈ [ℓ], the single sources must disseminate key ^^^^ to terminal set ^^^^ ={^^^^1, ^^^^2} such that (i) for each node ^^ ∈ {^^,^^, ^^}and for any ^^ ∈ [ℓ], ^^(^^^^;^^In(^^)) = 0, and (ii) for any terminal node d, In(^^) does not reveal anyinformation about a key that is not required at d. Note that each terminal in G has 2 vertex- disjoint paths from s, and all nodes are two-edge connected from s. Below, we show that ^^SR(ℐ) ≤3 / 4+^.
[0255] For each ^^ ∈ [ℓ], let ^^(^^) be the source message bits reconstructed at terminalnode ^^^^1. Let ^^ =∪^^ ^^(^^). For each ^^(^^), we have ^^(^^(^^)|^^In(^^),^^In(^^)) = 0. Thus, it alsoholds that ^^(^^|^^In(^^),^^In(^^)) = 0. We conclude that, ^^(^^) ≤ ^^(^^In(x),^^In(z)) ≤ ^^(^^In(x)) +^^(^^In(z)|^^In(x)) ≤ 3.
[0256] Considering the characteristic binary vector ^^^^ of ^^(^^) as a subset of B, we obtaina codebook ^^1, … , ^^ℓ of codewords, each of blocklength |^^| ≤ 3^^ and weight at most 2n.Appending zeros to codewords if needed, we obtain a codebook ^^1, … , ^^ℓ of blocklength 3n andof weight at most 2n. By the pigeonhole principle, there exists a weight w such that at least 1 +9 ^^ of the terminals {^^^^1}^^ decode ^^(^^) which has size in the range [3^^^^, 3(^^ + ^^ / 9)^^]. ApplyingCorollary 1 with such w and blocklength 3n, we conclude that there exist distinct indices i and i′ such that the total support of ^^^^ and ^^^^′ , and that of ^^(^^) and ^^(^^′), are at most (2^^ − ^^2)3^^ +Attorney Docket No.: 011520.01970 ^^^^. As ^^^^is a function of ^^(^^), ^^^^′ is a function of ^^(^^′), and ^^^^is independent of ^^(^^′), we conclude that ^^(^^^^) ≤ |^^(^^) ∖ ^^(^^′)| = |^^(^^) ∪ ^^(^^′)| − |^^(^^′)|≤ (2^^ − ^^2 − ^^)3^^ + ^^^^
[0257] This
[0258] Remark 3:
[0259] Given the connectivity conditions of Theorem 7, one can show that ^^SR(ℐ) ≥1 / 2. Thus, the gap presented in Theorem 8 between key dissemination schemes with and without source reconstruction, while not necessarily optimal, is of the correct order. A rough sketch of the key-code and analysis follows. For each edge that is not incoming to a terminal node, one performs the communication scheme presented in Theorem 7 over several independent “generations”, i.e., one repeats the scheme from Theorem 7 in parallel m times, for sufficiently large m, where in generation j∈[m], the source uses independent uniform variables ^^^^, ^^^^, and ^^^^. The blocklength of the m-generation scheme is mn. With each terminal set ^^^^, we associate a subset ^^^^ of [m] of size m / 2 such that for all ^^ ≠ ^^′ ∈ [ℓ] it holds that |^^^^ ∩ ^^^^′| ≤ ^^ / 4. Such aof subsets exists for mas a function of ℓ. Tothe encoding on incoming edges to ^^ ∈ ^^^^, recall that d has at least two incoming edges (u,d) and (v,d) with ^^^^ ≠^^^^. For every index ^^ ∈ ^^^^, vertex v transmits ^^^^ + ^^^^^^^^ and ^^^^ + ^^^^^^^^ to d, and u transmits ^^^^ +^^^^^^^^ and ^^^^ + ^^^^^^^^ to d. In this process, v transmits on the edge (^^,^^) 2|^^^^| = ^^ linearcombinations over the field F of size 2^^, which can be done over blocklength mn. Similarly, for u. For every ^^ ∈ ^^^^, terminal ^^ ∈ ^^^^ receives enough information to decode ^^^^ , ^^^^, ^^^^. The key ^^^^of rate 1 / 2 is set to be ^^ / 2 uniform random linear combinations of the variables{^^^^}^^ ∈ ^^^^ ∪{^^^^}^^ ∈ ^^^^ ∪ {^^^^}^^ ∈ ^^^^. It now follows for sufficiently large n that, with highforis independent of ^^In(v) for any node ^^ ∈ {^^} ∪ ^^^^ in G.
[0260] SECTION V. Concluding RemarksAttorney Docket No.: 011520.01970
[0261] This work initiates the study of key dissemination in the context of networkcoding. We address both the (single) key-cast setting in which all terminals wish to share a key K and the multiple key-cast setting in which there are multiple terminal sets, each sharing a different key. Our study spans the secure and non-secure settings and compares the key-rates obtainable with and without the requirement of source reconstruction; the latter corresponds to traditional methods of network coding.
[0262] Although the present disclosure has been described with respect to one or moreparticular embodiments, it will be understood that other embodiments of the present disclosure may be made without departing from the spirit and scope of the present disclosure.
Claims
Attorney Docket No.: 011520.01970 What is claimed is:
1. A method for distributing one or more shared secret keys in a communication network using network coding, the method comprising: generating a plurality of random bits at one or more source nodes in the network; transmitting messages derived from the random bits through the network, wherein intermediate nodes forward the messages by computing and forwarding functions of the received messages; computing, at terminal nodes organized into one or more terminal sets, one or more shared secret keys based on the messages received from the intermediate nodes, wherein each shared secret key is a function of the random bits and is computed without requiring the terminal nodes to reconstruct each random bit of the plurality of random bits from the one or more source nodes.
2. The method of claim 1, wherein the network comprises a plurality of source nodes, and each shared secret key is computed as a linear combination of the random bits from the plurality of source nodes.
3. The method of claim 1, wherein the network comprises a single source node and a plurality of terminal sets, each terminal set computing a distinct shared secret key, and wherein the shared secret keys are pairwise independent, such that mutual information between any two distinct keys is zero.
4. The method of claim 3, further comprising assigning a label to the edges or vertices of the network, and further comprising ensuring that each terminal set can decode its respective shared secret key independently based on messages received from distinct paths based on the assigned labels.
5. The method of claim 4, wherein each vertex is assigned a label identical to its predecessors if all predecessors share the same label, or a unique label otherwise.
6. The method of claim 1, further comprising ensuring that each shared secret key is independent of the information available at any single non-terminal node in the network to maintain secrecy from eavesdroppers.Attorney Docket No.: 011520.01970 7. The method of claim 6, further comprising ensuring that each shared secret key is independent of information on a specified subset of edges in the network to maintain secrecy from eavesdroppers accessing those edges.
8. The method of claim 1, wherein the network comprises a plurality of source nodes, each generating a set of random bits, and each shared secret key is computed as a function of the random bits from the plurality of source nodes, and further comprising ensuring each shared secret key is secure against eavesdroppers at any single non-terminal node.
9. The method of claim 1, further comprising using random bits generated at the one or more source nodes to mask messages passing through intermediate nodes, including cut vertices, thereby ensuring the security of the one or more shared secret keys against eavesdroppers accessing information at those nodes.
10. The method of claim 1, wherein each terminal set decodes its respective shared secret key independently based on messages received from at least two vertex-disjoint paths.