Skip to main content

Guesswork subject to a total entropy budget

Publication ,  Conference
Rezaee, A; Beirami, A; Makhdoumi, A; Medard, M; Duffy, K
Published in: 55th Annual Allerton Conference on Communication Control and Computing Allerton 2017
July 1, 2017

We consider an abstraction of computational security in password protected systems where a user draws a secret string of given length with i.i.d. characters from a finite alphabet, and an adversary would like to identify the secret string by querying, or guessing, the identity of the string. The concept of a 'total entropy budget' on the chosen word by the user is natural, otherwise the chosen password would have arbitrary length and complexity. One intuitively expects that a password chosen from the uniform distribution is more secure. This is not the case, however, if we are considering only the average guesswork of the adversary when the user is subject to a total entropy budget. The optimality of the uniform distribution for the user's secret string holds when we have also a budget on the guessing adversary. We suppose that the user is subject to a 'total entropy budget' for choosing the secret string, whereas the computational capability of the adversary is determined by his 'total guesswork budget.' We study the regime where the adversary's chances are exponentially small in guessing the secret string chosen subject to a total entropy budget. We introduce a certain notion of uniformity and show that a more uniform source will provide better protection against the adversary in terms of his chances of success in guessing the secret string. In contrast, the average number of queries that it takes the adversary to identify the secret string is smaller for the more uniform secret string subject to the same total entropy budget.

Duke Scholars

Published In

55th Annual Allerton Conference on Communication Control and Computing Allerton 2017

DOI

Publication Date

July 1, 2017

Volume

2018-January

Start / End Page

1008 / 1015
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Rezaee, A., Beirami, A., Makhdoumi, A., Medard, M., & Duffy, K. (2017). Guesswork subject to a total entropy budget. In 55th Annual Allerton Conference on Communication Control and Computing Allerton 2017 (Vol. 2018-January, pp. 1008–1015). https://doi.org/10.1109/ALLERTON.2017.8262848
Rezaee, A., A. Beirami, A. Makhdoumi, M. Medard, and K. Duffy. “Guesswork subject to a total entropy budget.” In 55th Annual Allerton Conference on Communication Control and Computing Allerton 2017, 2018-January:1008–15, 2017. https://doi.org/10.1109/ALLERTON.2017.8262848.
Rezaee A, Beirami A, Makhdoumi A, Medard M, Duffy K. Guesswork subject to a total entropy budget. In: 55th Annual Allerton Conference on Communication Control and Computing Allerton 2017. 2017. p. 1008–15.
Rezaee, A., et al. “Guesswork subject to a total entropy budget.” 55th Annual Allerton Conference on Communication Control and Computing Allerton 2017, vol. 2018-January, 2017, pp. 1008–15. Scopus, doi:10.1109/ALLERTON.2017.8262848.
Rezaee A, Beirami A, Makhdoumi A, Medard M, Duffy K. Guesswork subject to a total entropy budget. 55th Annual Allerton Conference on Communication Control and Computing Allerton 2017. 2017. p. 1008–1015.

Published In

55th Annual Allerton Conference on Communication Control and Computing Allerton 2017

DOI

Publication Date

July 1, 2017

Volume

2018-January

Start / End Page

1008 / 1015