Pith. sign in

REVIEW 3 major objections 5 minor 81 references

Coding-Based Hybrid Post-Quantum Cryptosystem for Non-Uniform Information

T0 review · 3 major / 5 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read The paper claims that NU-HUNCC achieves individual information-theoretic secrecy against a wiretapper on any $w<\ell$ links and ISS-CCA1 post-quantum security against an all-observing eavesdropper, at rates approaching $1/H(V)$ for…

desk verdict Genuine extension of HUNCC to non-uniform sources with a solid IT-Eve analysis, but the ISS-CCA1 proof is missing a parameter condition and should be fixed before the PQ claim is accepted. read the letter →

arxiv 2503.05873 v1 pith:QC3DL6CB submitted 2025-01-26 cs.IT math.IT

classification cs.ITmath.IT MSC 94A6094A1794B05
keywords post-quantumcryptographyhybridcryptosystemindividualsecrecynon-uniformmessagespolarcodesvariationaldistanceISS-CCA1securenetworkcoding
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper asks whether non-uniform messages can be protected against both a computationally unbounded eavesdropper and a quantum-capable eavesdropper without encrypting everything. It claims yes: compress each non-uniform message into nearly uniform form with a polar-code source encoder using a tiny shared seed, mix the compressed messages through an individual-secrecy linear code, and encrypt only a small fraction of the mixed links. The resulting scheme, NU-HUNCC, is claimed to leak at most $2\sqrt{2\ell\tilde{n}2^{-n\beta}}$ to an eavesdropper who observes any $w<\ell$ links, and to satisfy a new notion, ISS-CCA1, against an all-observing post-quantum adversary. If correct, this yields post-quantum security at rates approaching $1/H(V)$, far above an encrypt-everything baseline, with a sub-linear seed overhead.

What carries the argument

The load-bearing object is the almost-uniform source encoder: it one-time pads the unpolarized bits $J_V$ of the polar transform with a uniform seed of size $d_J = |J_V| = n^{0.72\text{--}0.73}$, producing compressed messages whose joint distribution sits within $\sqrt{2\ell\tilde{n}2^{-n\beta}}$ of uniform in non-normalized variational distance. That uniformity turns on the IS channel code: for a uniform message matrix, the linear coset code has zero mutual information per column, so the triangle inequality bounds the true leakage by twice the source encoder's gap. On the cryptographic side, the new ISS-CCA1 definition bounds the adversary's advantage on any individual message by the ratio $(p_{\max}-p_{\min})/(p_{\max}+p_{\min})$ plus the underlying cryptosystem's SS-CCA1 advantage, and the near-uniform compressed messages drive that ratio to a negligible value.

What would settle it

Compute, for a binary memoryless source with $H(V)=0.9$, $n=2^{19}$, $\beta=0.4$, $\ell=8$, and seed length $d_J \approx n^{0.73}$, the empirical variational distance $V(p_{M_L},p_U)$ between the compressed message matrix and the uniform distribution over many source and seed realizations; if it exceeds $\sqrt{2\ell\tilde{n}2^{-n\beta}}$ by a non-negligible margin, Eq. (19) and the leakage bound of Theorem 1 fail at this finite blocklength.

Watch

Extended reading notes

Core claim

NU-HUNCC is a three-stage construction: a polar-code source encoder with a sub-linear shared uniform seed maps each non-uniform source vector to an almost-uniform compressed word; an individual-secrecy (IS) linear coset code over $\mathbb{F}_{2^\mu}$ premixes the compressed words across $\ell$ links; and a semantically secure public-key cryptosystem encrypts only $c<\ell$ of the links plus the seed. The paper's central claim is that this combination is $k_s$-individually secure against an IT-Eve observing any $w<\ell$ links, with leakage at most $2\sqrt{2\ell\tilde{n}2^{-n\beta}}$, and ISS-CCA1 secure against an all-observing Crypto-Eve. The reason the proof works is that uniformity is required in non-normalized variational distance, not normalized divergence: standard lossless compressors only guarantee the latter, which is insufficient for the hybrid secrecy argument. The paper also proves a converse stating that at most $\ell-w$ messages can be individually secured when Eve sees $w$ links, making the tradeoff tight.

Load-bearing premise

The scheme inherits from the cited polar-code source encoder the guarantee that compressed messages are within $\sqrt{2\ell\tilde{n}2^{-n\beta}}$ of uniform in non-normalized variational distance when a truly uniform sub-linear seed is used; if that imported uniformity guarantee fails, the individual-secrecy claim against an unbounded wiretapper collapses.

Editorial extensions

If this is right

  • Non-uniform sources can be secured against both IT-Eve and Crypto-Eve at data rates approaching $1/H(V)$ in the finite blocklength regime, with seed overhead $d_J/n\to 0$.
  • The number of individually secured messages is exactly capped at $\ell-w$: the converse shows that securing one additional message forces the eavesdropper's observed-link count down by one.
  • Encrypting $c<\ell$ links and the seed with any SS-CCA1 post-quantum cryptosystem is enough for ISS-CCA1 security; in the paper's example with $\ell=10$ and $n=128$ KB the rate lands within 7% of the scheme's upper bound.
  • The hybrid template is universal: any SS-CCA1-secure post-quantum public-key scheme can replace the demonstration cryptosystem, so the rate and complexity tradeoffs track the chosen primitive.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Beyond the paper: the leakage bound predicts a concrete scaling law — doubling the blocklength $n$ cuts the variational leakage by roughly $2^{-n\beta/2}$, while adding links only grows it as $\sqrt{\ell}$ — which can be checked directly by simulation for moderate $n$.
  • Beyond the paper: because the security proof only uses the source encoder's non-normalized variational uniformity, any fixed-length lossless compressor with a sub-linear seed satisfying the same bound could replace the polar-code encoder, potentially improving the seed exponent below $n^{0.72}$.
  • Beyond the paper: the ISS-CCA1 guarantee in practice requires instantiating the encryption with a randomized or CCA1-secure PQ variant; the paper's rate example uses the original McEliece (not itself SS-CCA1), so a deployment would trade some rate for the proven security level.
  • Beyond the paper: the converse implies a simple network-design rule — for a known wiretap budget $w$, the maximum number of individually protected files is $\ell-w$ regardless of the source code, so adding physical links is the only way to protect more messages.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper introduces NU-HUNCC, a hybrid post-quantum cryptosystem for non-uniform messages in the finite blocklength regime. The scheme combines a polar-code-based source encoder with a sub-linear uniform seed, a linear or non-linear individual-secrecy (IS) channel code, and partial encryption of a small number of links with an SS-CCA1-secure public-key cryptosystem. Against an information-theoretic eavesdropper (IT-Eve) observing any w < ℓ links, the paper proves ks-individual security (Theorem 1) with leakage bounded by 2√(2ℓñ2^{−nβ}) and provides a converse (Theorem 3). Against a computationally bounded eavesdropper (Crypto-Eve) observing all links, it defines a new security notion ISS-CCA1 (Definition 4) and claims NU-HUNCC satisfies it (Theorems 5 and 6). Rate theorems (Theorems 4 and 7) and numerical comparisons are also provided.

Significance. If the results were fully established, the paper would make a useful contribution: it extends the hybrid HUNCC approach to non-uniform sources, gives explicit finite-blocklength leakage bounds, and introduces a per-message variant of CCA1 security. The IT-Eve analysis with the uniform-in-variational-distance source coder is a natural and potentially valuable extension, and the converse is of independent interest. The paper also gives concrete rate and complexity comparisons. However, the central Crypto-Eve security claim currently rests on a proof that does not deliver the stated definition, and the IT-Eve proof has an unresolved modeling gap concerning the seed's secrecy. These need to be fixed before the main claims can be accepted.

major comments (3)
  1. [Sec. X, Eqs. (35)–(36), and Definition 4] The proof of Theorem 5 does not establish that NU-HUNCC is ISS-CCA1 as defined. In Definition 4, the advantage must be negligible in the security parameter c. Equation (36) bounds the source-induced term by 2^{3/2}·2^{-nβ/2}·μkw, which is independent of c. The subsequent sentence claims that 'for every d′ Crypto-Eve's advantage can be made smaller than 1/(μc)^{d′} by choosing an appropriate d,' but choosing d only controls the 1/(μc)^d term from the underlying SS-CCA1 scheme; it cannot reduce the source-induced term. For fixed n, that term is a constant, not negligible in c. The theorem must state and use a condition linking n (or kw) to c—for example n superpolynomial in c—or the security definition must be modified so that negligibility is required jointly in n and c. As written, the central ISS-CCA1 claim is not proven.
  2. [Sec. V (Algorithm 1) and Sec. VIII-B, Eq. (19)] The proof of Theorem 1 assumes that the source-coder output M_L is almost uniform in non-normalized variational distance, via the bound V(p_{M_L}, p_U) ≤ √(2ℓñ2^{−nβ}). This uniformity is achieved by one-time-padding the JV bits with a uniform seed U_dJ. In the scheme as described in Algorithm 1, the seed is encrypted with the public-key cryptosystem and transmitted over the network. An IT-Eve is computationally unbounded, so she can decrypt the seed and condition on it; the distribution p_{M_L|U} is then not close to uniform, and the leakage bound (19) does not apply to the actual conditional distribution. The paper must either explicitly assume that the seed is shared over a channel inaccessible to IT-Eve (e.g., a pre-shared secret or a separate wiretap code) and include the cost of that sharing in the rate analysis, or modify the scheme so that knowledge of the seed by IT-Eve does not invalidate the uniformity argument. As it stands, the proof of Theorem 1 does not cover the scheme as presented.
  3. [Sec. VII-B and Theorem 5] The numerical rate and complexity evaluations use the original McEliece cryptosystem with [1024, 524]-Goppa codes, while Theorem 5 and Definition 4 require Crypt†1 to be SS-CCA1. The original McEliece is not SS-CCA1, as the footnote admits. Consequently, the numbers in Figs. 4–7 and Table I describe a scheme whose security is not proven by the paper's theorems. The evaluation should be redone using an SS-CCA1-secure randomized McEliece variant (with its corresponding r and key sizes), or the results should be explicitly qualified as illustrative of the overhead structure rather than as the achieved rate of the ISS-CCA1-secure scheme.
minor comments (5)
  1. [Sec. X, last paragraph] The claim that ISS-CCA1 for columns j ∈ JV 'follows directly from the SS-CCA1 of Crypt 1' is too terse; the argument that encrypting the seed prevents any non-negligible advantage on the padded bits should be written out.
  2. [Sec. X, Eq. (36)] The inequality labeled (a) in the derivation of Eq. (36), namely that the ratio is less than 2ζμkw, is asserted without proof ("which can be easily proved"); please provide a brief derivation or a reference.
  3. [Sec. III-B, Definition 4] The definition states that the adversary's advantage is measured by the winning probability p_{σ−max} + ϵ(c); in standard terminology the advantage is the excess over p_{σ−max}. Please clarify the intended quantity, since the proof then subtracts 1/2 as if the advantage were over a uniform guess.
  4. [Throughout] There are several typos and misspellings: "McEliecce" should be "McEliece", "ineligibility" should be "negligibility", and "divination" in Sec. X should be "deviation". A careful proofread is needed.
  5. [Fig. 1c and Theorem 4] The description of the NU-IS example stores the uniform seed on server 1 without protection while an IT-Eve observes two of three servers; this appears inconsistent with the seed-secrecy requirement needed for the variational-distance uniformity argument. The rate expression in Theorem 4 also counts the seed as transmitted data, but if the seed must be delivered over a separate secure channel, the cost of that channel should be accounted for.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the polar source coder and uniform-input IS-code results are external or parameter-free, and the non-uniform and ISS-CCA1 analyses are genuine extensions.

full rationale

The proof of Theorem 1 is a standard hybrid argument. The leakage V(p_Z|V_Ks, p_Z) is bounded by the triangle inequality into three terms. Terms (16) and (18) reduce to the source encoder uniformity bound from Chou et al. [43, Proposition 4]; term (17) is the zero-leakage property of the linear IS code from Cohen et al. [12, Sec. VI] for uniform inputs. Those are external or parameter-free results that do not include the paper's non-uniform target; using them as building blocks is legitimate independent support, not circularity. Theorem 5 likewise reduces ISS-CCA1 to the SS-CCA1 guarantee of the underlying public-key scheme and separately bounds the non-uniformity-induced term (pmax - pmin)/(pmax + pmin); the proof exhibits a concrete reduction instead of assuming the conclusion. The skeptic's concern that the n-dependent term is not shown negligible in the security parameter c is a correctness or parameter-tying issue, not a definitional reduction. The rate and converse proofs are bit-counting and information-inequality arguments. No fitted parameter is renamed as a prediction, and no ansatz or uniqueness is smuggled in via self-citation. The circularity burden is therefore low.

Assumptions & free parameters 0 free parameters · 5 assumptions · 0 invented entities

The central claim rests on five external building blocks: a polar source coder with seed, an IS linear code, an SS-CCA1 encryption scheme, the DMS independence assumption, and the IND-SS equivalence. No free parameters are fitted to data; the seed size dJ is taken from the polarization bound. No new physical or mathematical entities are postulated.

assumptions (5)
  • domain assumption The polar-codes-based source encoder from [43] achieves almost uniform output in non-normalized variational distance with a sub-linear uniform seed (V(p_{M_L}, p_U) <= sqrt(2*l*ntilde*2^{-n*beta})).
    Invoked in Sec. IV-A and used in the proof of Theorem 1 (Eq. 19); not proved in this paper.
  • domain assumption The linear IS channel code from [12, Sec. VI] achieves zero mutual information I(M_Ks; Z_W) = 0 for uniform messages over F_{2^mu} with mu >= l.
    Used in Sec. VIII-B to bound expression (17) via Eq. (20); load-bearing for IT-Eve security.
  • domain assumption The underlying public-key cryptosystem Crypt_dagger_1 is SS-CCA1 secured (and hence its probabilistic extension is post-quantum secure).
    Assumed in Theorems 5-6 and used in the reduction in Sec. X; the paper notes the original McEliece is not SS-CCA1 and recommends probabilistic variants.
  • domain assumption Messages are independent and drawn from a DMS (V, p_V); the paper notes dependence can be handled by joint source coding.
    Stated in Sec. II and used throughout the proofs.
  • standard math IND-CCA1 security implies SS-CCA1 for public-key encryption, and this extends to the individual-message non-uniform setting.
    Cited from [1] in Sec. X without a dedicated proof for the ISS-CCA1 setting.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Coding-Based Hybrid Post-Quantum Cryptosystem for Non-Uniform Information." pith.science (2026). https://pith.science/paper/QC3DL6CB

@misc{pith2026250305873,
  author       = {Pith},
  title        = {Pith review of: Coding-Based Hybrid Post-Quantum Cryptosystem for Non-Uniform Information},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/QC3DL6CB}},
  note         = {Machine review of arXiv:2503.05873}
}
read the original abstract

We introduce for non-uniform messages a novel hybrid universal network coding cryptosystem (NU-HUNCC) in the finite blocklength regime that provides Post-Quantum (PQ) security at high communication rates. Recently, hybrid cryptosystems offered PQ security by premixing the data using secure linear coding schemes and encrypting only a small portion of it. The data is assumed to be uniformly distributed, an assumption that is often challenging to enforce. Standard fixed-length lossless source coding and compression schemes guarantee a uniform output in normalized divergence. Yet, this is not sufficient to guarantee security. We consider an efficient compression scheme uniform in non-normalized variational distance for the proposed hybrid cryptosystem, that by utilizing a uniform sub-linear shared seed, guarantees PQ security. Specifically, for the proposed PQ cryptosystem, first, we provide an end-to-end practical coding scheme, NU-HUNCC, for non-uniform messages. Second, we show that NU-HUNCC is information-theoretic individually secured (IS) against an eavesdropper with access to any subset of the links and provide a converse proof against such an eavesdropper. Third, we introduce a modified security definition, individual semantic security under a chosen ciphertext attack (ISS-CCA1), and show that against an all-observing eavesdropper, NU-HUNCC satisfies its conditions. Finally, we provide an analysis of NU-HUNCC's high data rate, low computational complexity, and the negligibility of the shared seed size.

Figures

Figures reproduced from arXiv: 2503.05873 by the authors.

Figure 1
Figure 1. Secured storage solution of three files {Vi} 3 i=1 on three servers against all observing Crypto-Eve and IT-Eve which has access to two servers. (a) optimal compression of the source and encryption using the original McEliecce cryptosystem with a [1024, 524]-Goppa codes [27], [31] against Crypto-Eve, (b) optimal compression of the source and encoding using Network Coding Wiretap Type II [34] against IT-Eve, (c) Prop… view at source ↗
Figure 2
Figure 2. NU-HUNCC cryptosystem with ℓ noiseless communication links and two types of Eve’s: IT-Eve with access to w < ℓ links, and Crypto-Eve with access to all the links. The lossless almost uniform compression is done by the polar codes-based encoder from [43]. c of the links are encrypted by a PQ public-key SS-CCA1 cryptosystem. The mixing of the messages is done by either the linear or non-linear IS network code scheme f… view at source ↗
Figure 3
Figure 3. Numerical simulation of the seed size for a source [PITH_FULL_IMAGE:figures/full_fig_p012_3.png] view at source ↗
Figures from the paper (3 more)
Figure 6
Figure 6. Figure 6: Numerical simulation of the communication rate as a [PITH_FULL_IMAGE:figures/full_fig_p013_6.png]
Figure 5
Figure 5. Figure 5: Numerical simulation of the communication rate as a [PITH_FULL_IMAGE:figures/full_fig_p013_5.png]
Figure 7
Figure 7. Figure 7: Numerical simulation of the complexity as a function [PITH_FULL_IMAGE:figures/full_fig_p014_7.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

81 extracted references · 71 canonical work pages

  1. [1]

    Probabilistic encryption & how to play mental poker keeping secret all partial information,

    S. Goldwasser and S. Micali, “Probabilistic encryption & how to play mental poker keeping secret all partial information,” in Providing sound foundations for cryptography: on the work of Shafi Goldwasser and Silvio Micali, 2019, pp. 173–201

  2. [2]

    B. A. Forouzan and D. Mukhopadhyay, Cryptography and network security. Mc Graw Hill Education (India) Private Limited New York, NY , USA:, 2015, vol. 12

  3. [3]

    Bloch and J

    M. Bloch and J. Barros, Physical-layer security: from information theory to security engineering . Cambridge University Press, 2011

  4. [4]

    Post-quantum cryptography,

    D. J. Bernstein and T. Lange, “Post-quantum cryptography,” Nature, vol. 549, no. 7671, pp. 188–194, 2017

  5. [5]

    Communication theory of secrecy systems,

    C. E. Shannon, “Communication theory of secrecy systems,” The Bell System Technical Journal, vol. 28, no. 4, pp. 656–715, 1949

  6. [6]

    The wire-tap channel,

    A. D. Wyner, “The wire-tap channel,” The Bell System Technical Journal, vol. 54, no. 8, pp. 1355–1387, 1975

  7. [7]

    Physical layer security in broadcast networks,

    Y . Liang, H. V . Poor, and S. Shamai, “Physical layer security in broadcast networks,” Sec. and Comm. Net. , vol. 2, no. 3, pp. 227–238, 2009

  8. [8]

    Information theoretic security,

    ——, “Information theoretic security,” Foundations and Trends® in Comm and Inf. Theory , vol. 5, no. 4–5, pp. 355–580, 2009

Show all 81 references
  1. [9]

    X. Zhou, L. Song, and Y . Zhang, Physical layer security in wireless communications. Crc Press, 2013

  2. [10]

    Wiretap channel with causal state information and secure rate-limited feedback,

    A. Cohen and A. Cohen, “Wiretap channel with causal state information and secure rate-limited feedback,” IEEE Transactions on Communica- tions, vol. 64, no. 3, pp. 1192–1203, 2016

  3. [11]

    A note on wyner’s wiretap channel (corresp.),

    A. Carleial and M. Hellman, “A note on wyner’s wiretap channel (corresp.),” IEEE Transactions on Information Theory , vol. 23, no. 3, pp. 387–390, 1977

  4. [12]

    Secure multi-source multicast,

    A. Cohen, A. Cohen, M. Médard, and O. Gurewitz, “Secure multi-source multicast,” IEEE Transactions on Communications , vol. 67, no. 1, pp. 708–723, 2019

  5. [13]

    Joint and individual secrecy in broadcast channels with receiver side information,

    A. S. Mansour, R. F. Schaefer, and H. Boche, “Joint and individual secrecy in broadcast channels with receiver side information,” in 2014 IEEE 15th International Workshop on Signal Processing Advances in Wireless Communications (SPAWC), 2014, pp. 369–373

  6. [14]

    The individual secrecy capacity of degraded multi-receiver wiretap broadcast channels,

    ——, “The individual secrecy capacity of degraded multi-receiver wiretap broadcast channels,” in 2015 IEEE International Conference on Communications (ICC) , 2015, pp. 4181–4186

  7. [15]

    Individual secrecy for the broadcast channel,

    Y . Chen, O. O. Koyluoglu, and A. Sezgin, “Individual secrecy for the broadcast channel,” IEEE Transactions on Information Theory , vol. 63, no. 9, pp. 5981–5999, 2017

  8. [16]

    Can marton coding alone ensure individual secrecy?

    J. Y . Tan, L. Ong, and B. Asadi, “Can marton coding alone ensure individual secrecy?” in 2019 IEEE Information Theory Workshop (ITW). IEEE, 2019, pp. 1–5

  9. [17]

    Absolute security in terahertz wireless links,

    A. Cohen, R. G. D’Oliveira, C.-Y . Yeh, H. Guerboukha, R. Shrestha, Z. Fang, E. Knightly, M. Médard, and D. M. Mittleman, “Absolute security in terahertz wireless links,” IEEE Journal of Selected Topics in Signal Processing , 2023

  10. [18]

    Securing angularly dispersive terahertz links with coding,

    C.-Y . Yeh, A. Cohen, R. G. D’Oliveira, M. Médard, D. M. Mittleman, and E. W. Knightly, “Securing angularly dispersive terahertz links with coding,” IEEE Trans. on Inf. Forensics and Security , 2023

  11. [19]

    Introduction to modern cryptography: principles and protocols,

    J. Kaltz and Y . Lindell, “Introduction to modern cryptography: principles and protocols,” Chapman and Hall , 2008

  12. [20]

    Twenty years of attacks on the RSA cryptosystem,

    D. Boneh et al. , “Twenty years of attacks on the RSA cryptosystem,” Notices of the AMS , vol. 46, no. 2, pp. 203–213, 1999

  13. [21]

    Algorithms for quantum computation: discrete logarithms and factoring,

    P. Shor, “Algorithms for quantum computation: discrete logarithms and factoring,” in Proceedings 35th Annual Symposium on Foundations of Computer Science, 1994, pp. 124–134

  14. [22]

    On insecurity of cryptosystems based on generalized reed-solomon codes,

    V . M. Sidelnikov and S. O. Shestakov, “On insecurity of cryptosystems based on generalized reed-solomon codes,” 1992

  15. [23]

    On the concatenated structure of a linear code,

    N. Sendrier, “On the concatenated structure of a linear code,” Applicable Algebra in Engineering, Communication and Computing , vol. 9, no. 3, pp. 221–242, 1998

  16. [24]

    Cryptanalysis of the sidelnikov cryp- tosystem,

    L. Minder and A. Shokrollahi, “Cryptanalysis of the sidelnikov cryp- tosystem,” in Advances in Cryptology-EUROCRYPT 2007: 26th Annual International Conference on the Theory and Applications of Crypto- graphic Techniques, Barcelona, Spain, May 20-24, 2007. Proceedings

  17. [25]

    Using low density parity check codes in the mceliece cryptosystem,

    C. Monico, J. Rosenthal, and A. Shokrollahi, “Using low density parity check codes in the mceliece cryptosystem,” in 2000 IEEE International Symposium on Information Theory (Cat. No. 00CH37060). IEEE, 2000, p. 215

  18. [26]

    Springer, 2007, pp. 347–360

  19. [27]

    An efficient attack of a mceliece cryptosys- tem variant based on convolutional codes,

    G. Landais and J.-P. Tillich, “An efficient attack of a mceliece cryptosys- tem variant based on convolutional codes,” in Post-Quantum Cryptog- raphy: 5th International Workshop, PQCrypto 2013, Limoges, France, June 4-7, 2013. Proceedings 5 . Springer, 2013, pp. 102–117

  20. [28]

    A public-key cryptosystem based on algebraic,

    R. J. McEliece, “A public-key cryptosystem based on algebraic,” Coding Thv, vol. 4244, pp. 114–116, 1978

  21. [29]

    Semantic security for the McEliece cryptosystem without random oracles,

    R. Nojima, H. Imai, K. Kobara, and K. Morozov, “Semantic security for the McEliece cryptosystem without random oracles,” Designs, Codes and Cryptography, vol. 49, pp. 289–305, 2008

  22. [30]

    A CCA2 secure variant of the McEliece cryptosystem,

    N. Dottling, R. Dowsley, J. Muller-Quade, and A. C. Nascimento, “A CCA2 secure variant of the McEliece cryptosystem,” IEEE Trans. on Inf. Theory, vol. 58, no. 10, pp. 6672–6680, 2012

  23. [31]

    On IND-CCA1 Security of Ran- domized McEliece Encryption in the Standard Model,

    F. Aguirre Farro and K. Morozov, “On IND-CCA1 Security of Ran- domized McEliece Encryption in the Standard Model,” in Code-Based Cryptography: 7th International Workshop, CBC 2019, Darmstadt, Germany, May 18–19, 2019, Revised Selected Papers 7 . Springer, 2019, pp. 137–148

  24. [32]

    Goppa codes,

    E. Berlekamp, “Goppa codes,” IEEE Transactions on Information The- ory, vol. 19, no. 5, pp. 590–592, 1973

  25. [33]

    The algebraic decoding of goppa codes,

    N. Patterson, “The algebraic decoding of goppa codes,” IEEE Transac- tions on Information Theory , vol. 21, no. 2, pp. 203–207, 1975

  26. [34]

    A distinguisher for high-rate McEliece cryptosystems,

    J.-C. Faugere, V . Gauthier-Umana, A. Otmani, L. Perret, and J.-P. Tillich, “A distinguisher for high-rate McEliece cryptosystems,” IEEE Trans. on Inf. Theory, vol. 59, no. 10, pp. 6830–6844, 2013

  27. [35]

    On wiretap networks ii,

    S. Y . El Rouayheb and E. Soljanin, “On wiretap networks ii,” in 2007 IEEE International Symposium on Information Theory . IEEE, 2007, pp. 551–555

  28. [36]

    Network coding-based post-quantum cryptography,

    A. Cohen, R. G. L. D’Oliveira, S. Salamatian, and M. Médard, “Network coding-based post-quantum cryptography,” IEEE Journal on Selected Areas in Information Theory , vol. 2, no. 1, pp. 49–64, 2021

  29. [37]

    Post-quantum security for ultra-reliable low-latency heterogeneous networks,

    R. G. D’Oliveira, A. Cohen, J. Robinson, T. Stahlbuhk, and M. Médard, “Post-quantum security for ultra-reliable low-latency heterogeneous networks,” in MILCOM 2021-2021 IEEE Military Communications Conference (MILCOM). IEEE, 2021, pp. 933–938. 20

  30. [38]

    Partial encryption after encoding for security and reliability in data systems,

    A. Cohen, R. G. D’Oliveira, K. R. Duffy, and M. Médard, “Partial encryption after encoding for security and reliability in data systems,” in 2022 IEEE International Symposium on Information Theory (ISIT) . IEEE, 2022, pp. 1779–1784

  31. [39]

    CERMET: Coding for energy reduction with multiple encryption techniques – it’s easy being green,

    J. Woo, V . A. Vasudevan, B. Kim, A. Cohen, R. G. D’Oliveira, T. Stahlbuhk, and M. Médard, “CERMET: Coding for energy reduction with multiple encryption techniques – it’s easy being green,” arXiv preprint arXiv:2308.05063, 2023

  32. [40]

    Crypto-mine: Cryptanalysis via mu- tual information neural estimation,

    B. D. Kim, V . A. Vasudevan, J. Woo, A. Cohen, R. G. D’Oliveira, T. Stahlbuhk, and M. Médard, “Crypto-mine: Cryptanalysis via mu- tual information neural estimation,” in ICASSP 2024-2024 IEEE In- ternational Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE,...

  33. [41]

    Folklore in source coding: Information-spectrum approach,

    T. S. Han, “Folklore in source coding: Information-spectrum approach,” IEEE Transactions on Information Theory , vol. 51, no. 2, pp. 747–753, 2005

  34. [42]

    Data compression with nearly uniform output,

    R. A. Chou and M. R. Bloch, “Data compression with nearly uniform output,” in 2013 IEEE International Symposium on Information Theory . IEEE, 2013, pp. 1979–1983

  35. [43]

    Polar coding for secret-key generation,

    R. A. Chou, M. R. Bloch, and E. Abbe, “Polar coding for secret-key generation,” IEEE Transactions on Information Theory , vol. 61, no. 11, pp. 6213–6237, 2015

  36. [44]

    Coding schemes for achieving strong secrecy at negligible cost,

    R. A. Chou, B. N. Vellambi, M. R. Bloch, and J. Kliewer, “Coding schemes for achieving strong secrecy at negligible cost,” IEEE Trans- actions on Information Theory , vol. 63, no. 3, pp. 1858–1873, 2017

  37. [45]

    Universal weakly secure network coding,

    D. Silva and F. R. Kschischang, “Universal weakly secure network coding,” in 2009 IEEE Information Theory Workshop on Networking and Information Theory . IEEE, 2009, pp. 281–285

  38. [46]

    Universal secure network coding via rank-metric codes,

    ——, “Universal secure network coding via rank-metric codes,” IEEE Transactions on Information Theory , vol. 57, no. 2, pp. 1124–1135, 2011

  39. [47]

    The google file system,

    S. Ghemawat, H. Gobioff, and S.-T. Leung, “The google file system,” in Proceedings of the nineteenth ACM symposium on Operating systems principles, 2003, pp. 29–43

  40. [48]

    Dynamo: Amazon’s highly available key-value store,

    G. DeCandia, D. Hastorun, M. Jampani, G. Kakulapati, A. Lakshman, A. Pilchin, S. Sivasubramanian, P. V osshall, and W. V ogels, “Dynamo: Amazon’s highly available key-value store,” ACM SIGOPS operating systems review, vol. 41, no. 6, pp. 205–220, 2007

  41. [49]

    Bigtable: A distributed storage system for structured data,

    F. Chang, J. Dean, S. Ghemawat, W. C. Hsieh, D. A. Wallach, M. Bur- rows, T. Chandra, A. Fikes, and R. E. Gruber, “Bigtable: A distributed storage system for structured data,” ACM Transactions on Computer Systems (TOCS), vol. 26, no. 2, pp. 1–26, 2008

  42. [50]

    Apache hadoop goes realtime at facebook,

    D. Borthakur, J. Gray, J. S. Sarma, K. Muthukkaruppan, N. Spiegelberg, H. Kuang, K. Ranganathan, D. Molkov, A. Menon, S. Rash et al. , “Apache hadoop goes realtime at facebook,” in Proceedings of the 2011 ACM SIGMOD International Conference on Management of data, 2011, pp. 1071–1080

  43. [51]

    Windows azure storage: a highly available cloud storage service with strong consistency,

    B. Calder, J. Wang, A. Ogus, N. Nilakantan, A. Skjolsvold, S. McKelvie, Y . Xu, S. Srivastav, J. Wu, H. Simitci et al. , “Windows azure storage: a highly available cloud storage service with strong consistency,” in Proceedings of the Twenty-Third ACM Symposium on Operating Sys...

  44. [52]

    A mathematical theory of communication,

    C. E. Shannon, “A mathematical theory of communication,” The Bell system technical journal , vol. 27, no. 3, pp. 379–423, 1948

  45. [53]

    Compression of individual sequences via variable-rate coding,

    J. Ziv and A. Lempel, “Compression of individual sequences via variable-rate coding,” IEEE transactions on Information Theory, vol. 24, no. 5, pp. 530–536, 1978

  46. [54]

    Lossless source coding with polar codes,

    H. S. Cronie and S. B. Korada, “Lossless source coding with polar codes,” in 2010 IEEE International Symposium on Information Theory . IEEE, 2010, pp. 904–908

  47. [55]

    Noiseless coding of correlated information sources,

    D. Slepian and J. Wolf, “Noiseless coding of correlated information sources,” IEEE Trans. on Inf. Theory, vol. 19, no. 4, pp. 471–480, 1973

  48. [56]

    Secure multiplex coding attaining channel capacity in wiretap channels,

    D. Kobayashi, H. Yamamoto, and T. Ogawa, “Secure multiplex coding attaining channel capacity in wiretap channels,” IEEE Transactions on Information Theory, vol. 59, no. 12, pp. 8131–8143, 2013

  49. [57]

    Weakly secure network coding,

    K. Bhattad, K. R. Narayanan et al. , “Weakly secure network coding,” NetCod, Apr, vol. 104, pp. 8–20, 2005

  50. [58]

    Relations among notions of security for public-key encryption schemes,

    M. Bellare, A. Desai, D. Pointcheval, and P. Rogaway, “Relations among notions of security for public-key encryption schemes,” in Advances in Cryptology—CRYPTO’98: 18th Annual International Cryptology Con- ference Santa Barbara, California, USA August 23–27, 1998 Proceed- ings...

  51. [59]

    A CCA2 secure public key encryption scheme based on the McEliece assumptions in the standard model,

    R. Dowsley, J. Müller-Quade, and A. C. Nascimento, “A CCA2 secure public key encryption scheme based on the McEliece assumptions in the standard model,” in Cryptographers’ Track at the RSA Conference . Springer, 2009, pp. 240–251

  52. [60]

    Broadcast channels with confidential mes- sages,

    I. Csiszár and J. Korner, “Broadcast channels with confidential mes- sages,” IEEE transactions on information theory , vol. 24, no. 3, pp. 339–348, 1978

  53. [61]

    Channel polarization: A method for constructing capacity- achieving codes for symmetric binary-input memoryless channels,

    E. Arikan, “Channel polarization: A method for constructing capacity- achieving codes for symmetric binary-input memoryless channels,”IEEE Transactions on Information Theory , vol. 55, no. 7, pp. 3051–3073, 2009

  54. [62]

    The one-time pad revisited,

    C. Matt and U. Maurer, “The one-time pad revisited,” in 2013 IEEE International Symposium on Information Theory . IEEE, 2013, pp. 2706–2710

  55. [63]

    Theory of codes with maximum rank distance,

    E. M. Gabidulin, “Theory of codes with maximum rank distance,” Problemy peredachi informatsii, vol. 21, no. 1, pp. 3–16, 1985

  56. [64]

    Maximum-rank array codes and their application to crisscross error correction,

    R. M. Roth, “Maximum-rank array codes and their application to crisscross error correction,” IEEE transactions on Information Theory , vol. 37, no. 2, pp. 328–336, 1991

  57. [65]

    Knapsack-type cryptosystems and algebraic coding theory,

    H. Niederreiter, “Knapsack-type cryptosystems and algebraic coding theory,” Prob. Contr. Inform. Theory, vol. 15, no. 2, pp. 157–166, 1986

  58. [66]

    A public-key cryptosystem based on binary reed- muller codes,

    V . M. Sidelnikov, “A public-key cryptosystem based on binary reed- muller codes,” 1994

  59. [67]

    A new version of mceliece pkc based on convolutional codes,

    C. Löndahl and T. Johansson, “A new version of mceliece pkc based on convolutional codes,” in Information and Communications Security: 14th International Conference, ICICS 2012, Hong Kong, China, October 29-31, 2012. Proceedings 14 . Springer, 2012, pp. 461–470

  60. [68]

    On the scaling of polar codes: Ii. the behavior of un-polarized channels,

    S. H. Hassani, K. Alishahi, and R. Urbanke, “On the scaling of polar codes: Ii. the behavior of un-polarized channels,” in 2010 IEEE International Symposium on Information Theory. IEEE, 2010, pp. 879– 883

  61. [69]

    Sub-4.7 scaling exponent of polar codes,

    H.-P. Wang, T.-C. Lin, A. Vardy, and R. Gabrys, “Sub-4.7 scaling exponent of polar codes,” IEEE Transactions on Information Theory , 2023

  62. [70]

    Complexity and second moment of the mathematical theory of communication,

    H.-P. Wang, “Complexity and second moment of the mathematical theory of communication,” arXiv preprint arXiv:2107.06420 , 2021

  63. [71]

    Polar codes are optimal for lossy source coding,

    S. B. Korada and R. L. Urbanke, “Polar codes are optimal for lossy source coding,” IEEE Transactions on Information Theory, vol. 56, no. 4, pp. 1751–1768, 2010

  64. [72]

    On the rate of channel polarization,

    E. Arikan and E. Telatar, “On the rate of channel polarization,” in 2009 IEEE Int. Sym. on Inf. Theory . IEEE, 2009, pp. 1493–1495

  65. [73]

    A lower bound for discrimination information in terms of variation (corresp.),

    S. Kullback, “A lower bound for discrimination information in terms of variation (corresp.),” IEEE Trans. on Inf. Theory , vol. 13, no. 1, pp. 126–127, 1967

  66. [74]

    The optimal use of rate-limited random- ness in broadcast channels with confidential messages,

    S. Watanabe and Y . Oohama, “The optimal use of rate-limited random- ness in broadcast channels with confidential messages,” IEEE Transac- tions on Information Theory , vol. 61, no. 2, pp. 983–995, 2014

  67. [75]

    Bounds for entropy and divergence for distributions over a two-element set,

    F. Topsøe, “Bounds for entropy and divergence for distributions over a two-element set,” J. Ineq. Pure Appl. Math , vol. 2, no. 2, 2001

  68. [76]

    Resilient network coding in the presence of byzantine adversaries,

    S. Jaggi, M. Langberg, S. Katti, T. Ho, D. Katabi, and M. Médard, “Resilient network coding in the presence of byzantine adversaries,” in IEEE INFOCOM 2007-26th . IEEE, 2007, pp. 616–624

  69. [77]

    On coding for reliable communication over packet networks,

    D. S. Lun, M. Médard, R. Koetter, and M. Effros, “On coding for reliable communication over packet networks,” Physical Communication, vol. 1, no. 1, pp. 3–20, 2008

  70. [78]

    Coding for errors and erasures in random network coding,

    R. Koetter and F. R. Kschischang, “Coding for errors and erasures in random network coding,” IEEE Trans. on Inf. Theory , vol. 54, no. 8, pp. 3579–3591, 2008

  71. [79]

    A rank-metric approach to error control in random network coding,

    D. Silva, F. R. Kschischang, and R. Koetter, “A rank-metric approach to error control in random network coding,” IEEE Trans. on Inf. Theory , vol. 54, no. 9, pp. 3951–3967, 2008

  72. [80]

    Random walks on finite groups and rapidly mixing markov chains,

    D. Aldous, “Random walks on finite groups and rapidly mixing markov chains,” in Séminaire de Probabilités XVII 1981/82: Proceedings . Springer, 1983, pp. 243–297. APPENDIX A SECURE INDIVIDUAL NON-L INEAR CODE AGAINST IT-E VE (PROOF OF THEOREM 2) We give here the full secrecy a...

  73. [81]

    We start by bounding the maximum and minimum possible probabilities of the codewords in B1 and B2

    The number of possible codewords remaining in bin 1 is as high as possible where the number of possible codewords remaining in bin 2 is as low as possible, |B1| ≥ |B2|, 2) the induced probability of the codewords from bin 1 is as high as possible while the induced probability ...

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.