arXiv is now an independent nonprofit! Learn more
License: arXiv.org perpetual non-exclusive license
arXiv:1809.03988v1 [cs.IT] 11 Sep 2018

The ϵ\epsilon-error Capacity of Symmetric PIR
with Byzantine Adversaries

Qiwen Wang Affiliation: Department of Information Science and Engineering, KTH Royal Institute of Technology    Hua Sun Affiliation: Department of Electrical Engineering, University of North TexasEmail: {qiwenw, skoglund}@kth.se, {hua.sun}@unt.edu    Mikael Skoglund Affiliation: Department of Information Science and Engineering, KTH Royal Institute of Technology
Abstract

The capacity of symmetric private information retrieval with KK messages, NN servers (out of which any TT may collude), and an omniscient Byzantine adversary (who can corrupt any BB answers) is shown to be 1T+2BN1-\frac{T+2B}{N} [1], under the requirement of zero probability of error. In this work, we show that by weakening the adversary slightly (either providing secret low rate channels between the servers and the user, or limiting the observation of the adversary), and allowing vanishing probability of error, the capacity increases to 1T+BN1-\frac{T+B}{N}.

I Introduction

We are interested in the problem of symmetric private information retrieval (PIR) with Byzantine adversaries. In symmetric PIR (SPIR), there are KK messages, stored over NN replicated servers, and a user that wishes to retrieve 1 out of the KK messages without revealing the desired message index to any TT servers. The user fulfills this PIR task by first sending queries to the servers and then receiving 1 answer from each server. From the NN answers, the user decodes the desired message either with exactly zero probability of error or with vanishing probability of error (when the message size approaches infinity). The servers do not allow the user to learn any information beyond the desired message (so that the privacy of the dataset is symmetrically protected). The efficiency of an SPIR protocol is measured by the capacity, CC, defined as the maximum amount of information retrieved over the total download from the servers (the answer sizes). We consider the presence of Byzantine adversaries in this work. Byzantine adversaries might observe a certain number of communication links (answers) between the servers and the user and modify any BB answers. We focus on the interplay between the capability of the adversary (omniscient or limited knowledge) and the error criterion (zero-error or ϵ\epsilon-error). Among all possible models, the strongest (most restricted) requirement is that the adversary is omniscient (i.e., the adversary has full knowledge and observes all communication between the servers and the user) and the decoding at the user’s side must have exactly zero error11 1 Note that if we insist on zero error, then it does not matter whether the adversary has full or limited knowledge. The reason is that the adversary may assume an arbitrary realization of the knowledge that he is missing and the probability of guessing the missing knowledge correctly is non-zero. The zero-error decoding constraint requires that decoding error can never occur (including the case when the adversary guesses the full knowledge correctly so that full knowledge case is covered).. We call this problem 0-Bf\mbox{0-B}_{f}TSPIR, where the letter ff represents full knowledge. The weakest requirement is that the adversary has limited knowledge and the decoding at the user’s side is allowed to have vanishingly small probability of error. We call this problem ϵ-Bl\mbox{$\epsilon$-B}_{l}TSPIR, where the letter ll represents limited knowledge. This work is motivated by the following question - when we relax the problem from 0-Bf\mbox{0-B}_{f}TSPIR to ϵ-Bl\mbox{$\epsilon$-B}_{l}TSPIR, is it possible to increase the capacity of PIR, because of the presence of a less omnipotent adversary and the requirement of a less stringent decoding criterion?

Before stating our result, we first briefly summarize prior works on capacity results of SPIR and its related variants. The capacity of SPIR with no colluding servers (T=1T=1) is characterized in [2],

CSPIR=N1N=11N.C_{\text{SPIR}}=\frac{N-1}{N}=1-\frac{1}{N}.

The intuition is that out of the NN answers, 1 answer is useless because it provides no useful information of the desired message. Then we only have N1N-1 effective answers and the ratio (rate) is thus (N1)/N(N-1)/N. To see why 1 answer is independent of the desired message, note that the user can not learn anything about undesired messages (data-privacy constraint) so that any 1 answer can not contain any information about undesired messages. Further, because any 1 server does not learn anything about the desired message index (user-privacy constraint), any server can not distinguish desired and undesired messages so that the server’s answer can not contain any information about any message (including the desired one). The generalization of user-privacy from any individual server to any TT colluding servers is considered in [3] and the capacity is characterized as

CTSPIR=NTN=1TN.C_{\text{TSPIR}}=\frac{N-T}{N}=1-\frac{T}{N}.

This result could be interpreted intuitively in a similar manner, where any TT answers are of no use due to the combination of the TT-private user-privacy constraint and the data-privacy constraint. The above two capacity results hold under both zero-error and ϵ\epsilon-error criteria. The presence of a full knowledge Byzantine adversary with zero-error decoding constraint (the 0-Bf\mbox{0-B}_{f}TSPIR problem) is considered in [1], and its capacity is characterized as

C0-BfTSPIR=NTBBN=1T+2BN.C_{\mbox{\footnotesize 0-B}_{f}\mbox{\footnotesize TSPIR}}=\frac{N-T-B-B}{N}=1-\frac{T+2B}{N}.

Compared with the capacity of TSPIR, the capacity expression has an additional term of 2B2B (another 2B2B wasted answers), which could be interpreted as follows. As the Byzantine adversary may modify any BB answers, the corrupted answers might have zero information of the desired message so that these BB answers can not contribute anything to the decoding (akin to BB erasures). It turns out that we have to pay a price of another BB answers to identify and correct the BB erroneous answers (in total, 2B2B answers). The focus of this work is on the ϵ-Bl\mbox{$\epsilon$-B}_{l}TSPIR problem where the adversary is partially blind and the decoding is allowed to be erroneous occasionally, and we ask if any saving on the 2B2B wasted answers for the Byzantine adversary is possible.

Our main contribution is summarized next. The main result of this work is the capacity characterization of the ϵ-Bl\mbox{$\epsilon$-B}_{l}TSPIR problem. We show that

Cϵ-BlTSPIR=NTBN=1T+BNC_{\mbox{\footnotesize$\epsilon$-B}_{l}\mbox{\footnotesize TSPIR}}=\frac{N-T-B}{N}=1-\frac{T+B}{N}

under two models of Byzantine adversaries with limited knowledge.22 2 The two adversary models have been studied in the network coding literature [4, 5].

  1. 1.

    There exist secret channels (with vanishing rate) between the servers and the user that are not observed by the adversary.

  2. 2.

    There exists at least 1 answer that the adversary is not able to observe or corrupt (i.e., the total number of answers observed or corrupted is smaller than NN).

The interpretation of this capacity result is that as long as we may hide some information to the adversary (we have shown two examples, one with secret channels and one with limited observations) and ϵ\epsilon-error is allowed, then we can avoid the loss of the BB answers that are used to correct the BB erroneous answers and the problem with BB errors reduces to the problem with BB erasures. This is made possible through the hidden information and the allowance of small probability of decoding error. To answer the question that motivates our work, it is not only possible to increase the capacity by weakening the adversary and decoding requirement, but also the price to pay is minimal, i.e., reducing a small amount of knowledge to the omniscient adversary and relaxing zero-error to ϵ\epsilon-error.

Notation: For variables X,YX,Y, [XY][X\;Y] and [X;Y][X;Y] denote a row vector and a column vector respectively. For integers n1n2n_{1}\leq n_{2}, [n1:n2][n_{1}:n_{2}] denotes the set {n1,n1+1,,n2}\{n_{1},n_{1}+1,\cdots,n_{2}\}. For a vector =(i1,i2,,in)\mathcal{I}=(i_{1},i_{2},\cdots,i_{n}), AA_{\mathcal{I}} represents the column vector [Ai1;Ai2;;Ain][A_{i_{1}};A_{i_{2}};\cdots;A_{i_{n}}]. Denote the N×MN\times M Vandermonde matrix generated from NN distinct symbols λ1,λ2,,λN\lambda_{1},\lambda_{2},\dots,\lambda_{N} from a finite field by 𝐕M(λ1,,λN)\mathbf{V}^{M}(\lambda_{1},\dots,\lambda_{N}), where the (i.j)(i.j)-th element is λij1\lambda_{i}^{j-1}.

II Problem Setup

A dataset comprised of KK messages is stored over NN replicated servers. The messages {Wk}\{W_{k}\} are independent and each message consists of LL i.i.d. symbols from 𝔽q\mathbb{F}_{q}, i.e., H(Wk)=L,k[1:K]H(W_{k})=L,\forall k\in[1:K] and H(W1,,WK)=KLH(W_{1},\dots,W_{K})=KL. Here and throughout the paper we measure entropy to base qq.

A user wants to retrieve a message WκW_{\kappa} from the servers, where the desired message index κ\kappa is drawn from some prior distribution over [1:K][1:K]. Denote the realization of κ\kappa by kk. Based on kk, the user generates random queries to send to the servers. The query received by Server nn is denoted by Qn[k]Q_{n}^{[k]}. Let 𝒬=[Qn[k]]n[1:N],k[1:K]\mathcal{Q}=[Q_{n}^{[k]}]_{n\in[1:N],k\in[1:K]} denote the complete query scheme, i.e., the collection of all queries under all choices of the desired message index. The queries are independent of the messages.

The servers share a common random variable SS, the realization of which is unavailable to the user. The common randomness is independent of the messages and queries, i.e., I(S;W[1:K],𝒬)=0.I(S;W_{[1:K]},\mathcal{Q})=0. Let ρ\rho denote the ratio of the amount of common randomness relative to the message size, i.e.,

ρH(S)H(Wk)=H(S)L.\displaystyle\rho\triangleq\frac{H(S)}{H(W_{k})}=\frac{H(S)}{L}. (1)

The servers follow the protocol agreed with the user a priori, and generate answers based on the received query Qn[k]Q_{n}^{[k]}, the stored messages W[1:K]W_{[1:K]}, and the common random variable SS. The answer sent to the user from Server nn is denoted by An[k]A_{n}^{[k]}. We have H(An[k]|Qn[k],W[1:K],S)=0.H(A_{n}^{[k]}|Q_{n}^{[k]},W_{[1:K]},S)=0.

Any TT servers may collude. To guarantee user-privacy, from the queries and answers of any TT servers, together with the message contents and the common random variable, the servers should not be able to infer any information about the desired message index. Thus, the following user-privacy constraint must be satisfied,

I(A𝒯[κ],Q𝒯[κ],W[1:K],S;κ)=0,𝒯[1:N],|𝒯|=T.\displaystyle I(A_{\mathcal{T}}^{[\kappa]},Q_{\mathcal{T}}^{[\kappa]},W_{[1:K]},S;\kappa)=0,\forall\mathcal{T}\subset[1:N],|\mathcal{T}|=T. (2)

A Byzantine adversary hidden in the system can observe and jam the communications. We assume that the adversary has unlimited computational power, and knows the encoding and decoding scheme of the user and servers. An omniscient adversary can observe all the communications in the system; a limited knowledge adversary only observes part of the communications. In this work, we assume the adversary has limited knowledge, and can overwrite the answers of any set of servers \mathcal{B} of size BB to A~[k]\widetilde{A}_{\mathcal{B}}^{[k]}. Assume that the adversary holds some private randomness γ\gamma (independent of the messages, queries, answers and the common randomness) that he can use for jamming. Two ways of reducing the observation of the adversary are considered in this work:

Secret channel model: In this model, we assume that there exists 1 secure low rate (vanishing with message length) channel between each server and the user. The adversary can neither observe nor jam the communication on these channels, but can observe all other communication. Denote the information that Server nn sends to the user through the secret channel by Hn[k]H_{n}^{[k]}, where H(Hn[k])=o(L)H(H_{n}^{[k]})=o(L). H[1:N][k]H_{[1:N]}^{[k]} is the only information that the adversary cannot observe. The corrupted answers are a function of all information available at the adversary’s side.

H(A~[k]|γ,A[1:N][k],Q[1:N][k])=0.\displaystyle H(\widetilde{A}_{\mathcal{B}}^{[k]}|\gamma,A_{[1:N]}^{[k]},Q_{[1:N]}^{[k]})=0. (3)

Untouched server model: In this model, there is no secret channel between the servers and the user. However, the adversary can only observe the communication between EE servers (denoted by \mathcal{E}) and the user. The adversary can pick any EE servers to observe, and any BB servers to jam (the two sets can be overlapping or disjoint, but we require E+B<NE+B<N),

H(A~[k]|γ,A[k],Q[k])=0.\displaystyle H(\widetilde{A}_{\mathcal{B}}^{[k]}|\gamma,A_{\mathcal{E}}^{[k]},Q_{\mathcal{E}}^{[k]})=0. (4)

Note that the requirement E+B<NE+B<N is equivalent to that there exists at least 1 server that is neither observed nor jammed (untouched) by the adversary.

Note that the user does not know which answers are corrupted (A~[k]\widetilde{A}_{\mathcal{B}}^{[k]}), and we denote all the answers received by A~[1:N][k]={A~[k],A[1:N][k]}\widetilde{A}_{[1:N]}^{[k]}=\{\widetilde{A}_{\mathcal{B}}^{[k]},{A}_{[1:N]\setminus\mathcal{B}}^{[k]}\}. From all the answers (and the information through secret channels) downloaded and other information available to the user, the user should be able to decode the desired message with diminishing probability of error as LL tends to infinity. By Fano’s inequality, this corresponds to the following correctness constraint,

H(Wk|A~[1:N][k],𝒬,H[1:N][k])=o(L)\displaystyle H(W_{k}|\widetilde{A}_{[1:N]}^{[k]},\mathcal{Q},H_{[1:N]}^{[k]})=o(L) (5)

where for the untouched server model, H[1:N][k]=H_{[1:N]}^{[k]}=\varnothing.

The user should learn no information about the other messages besides the desired one, named the database-privacy constraint. Denote {W1,,Wk1,Wk+1,,WK}\{W_{1},\dots,W_{k-1},W_{k+1},\dots,W_{K}\} by Wk¯W_{\bar{k}},

I(Wk¯;A~[1:N][k],𝒬,H[1:N][k])=0.\displaystyle I(W_{\bar{k}};\widetilde{A}_{[1:N]}^{[k]},\mathcal{Q},H_{[1:N]}^{[k]})=0. (6)

The rate, RR of a scheme characterizes the number of desired information symbols retrieved per downloaded symbol33 3 We use the uncorrupted answers {An[k]}\{A_{n}^{[k]}\} to define the rate RR, because there is no motivation for the adversary to change the answer sizes (if so, the user can easily identify the corrupted answers and treat them as erasures)., R=Ln=1NH(An[k]).R=\frac{L}{\sum_{n=1}^{N}H(A_{n}^{[k]})}. A rate RR is said to be ϵ\epsilon-error achievable44 4 In this work, we interpret ϵ\epsilon as a term that vanishes (a typical assumption in Shannon theory). Note that this is different from the assumption in strong converse where ϵ\epsilon is a fixed positive constant. if there exists a sequence of PIR schemes with rate at least RR, and probability of error Pe0P_{e}\to 0 as LL\to\infty. The supremum of all ϵ\epsilon-error achievable rates is called the ϵ\epsilon-error capacity CC. The problem defined in this section is called ϵ-Bl\mbox{$\epsilon$-B}_{l}TSPIR.

III Main Result

Theorem 1

The capacity of the ϵ-Bl\mbox{$\epsilon$-B}_{l}TSPIR problem is

Cϵ-BlTSPIR={1T+BN,ifρTNTB,N>T+B;0,otherwise.\displaystyle~~C_{\mbox{\footnotesize$\epsilon$-B}_{l}\mbox{\footnotesize TSPIR}}=\left\{\begin{array}[]{cc}1-\frac{T+B}{N},&\mbox{if}~~\rho\geq\frac{T}{N-T-B},N>T+B;\\ 0,&\mbox{otherwise.}\end{array}\right.

The achievability proof (the main contribution of this work) is presented in the next section. The (weak) converse proof is presented in Section V.

IV Achievability

IV-A Example: N=3,T=1,B=1N=3,T=1,B=1

To illustrate the main idea, consider the setting with 2 messages, each consists of 2 symbols from 𝔽q\mathbb{F}_{q}. Denote W1=(a,a)W_{1}=(a,a^{\prime}), W2=(b,b)W_{2}=(b,b^{\prime}), and suppose W1W_{1} is desired.

The user privately chooses 2 i.i.d. random variables u,vu,v from 𝔽q\mathbb{F}_{q}. The queries to the 3 servers are generated as follows,

Q1[1]\displaystyle Q_{1}^{[1]} =\displaystyle= [u+1,v]\displaystyle[u+1,v] (8)
Q2[1]\displaystyle Q_{2}^{[1]} =\displaystyle= [u+2,v]\displaystyle[u+2,v] (9)
Q3[1]\displaystyle Q_{3}^{[1]} =\displaystyle= [u,v].\displaystyle[u,v]. (10)

The servers share a common random symbol SS from 𝔽q\mathbb{F}_{q}. Denote 𝐖1=[a;b]\mathbf{W}^{1}=[a;b]. Server nn generates a scalar answer by An=Qn[1]𝐖1+SA_{n}=Q_{n}^{[1]}\cdot\mathbf{W}^{1}+S. Let X=ua+vb+SX=ua+vb+S, then the answers are

A1\displaystyle A_{1} =\displaystyle= X+a\displaystyle X+a (11)
A2\displaystyle A_{2} =\displaystyle= X+2a\displaystyle X+2a (12)
A3\displaystyle A_{3} =\displaystyle= X.\displaystyle X. (13)

It is evident that from any 2 answers, the user can decode the symbol aa from W1W_{1}.

The user repeats the scheme for 𝐖2=[a;b]\mathbf{W}^{2}=[a^{\prime};b^{\prime}] (the same u,vu,v and queries are used, so the upload cost is not increased). Suppose the servers share another common random symbol SS^{\prime}, and let X=ua+vb+SX^{\prime}=ua^{\prime}+vb^{\prime}+S^{\prime}. The answers A1,A2,A3A_{1}^{\prime},A_{2}^{\prime},A_{3}^{\prime} are then A1=X+a,A2=X+2a,A3=XA_{1}^{\prime}=X^{\prime}+a^{\prime},A_{2}^{\prime}=X^{\prime}+2a^{\prime},A_{3}^{\prime}=X^{\prime}. The final answers sent are the collection of An,AnA_{n},A_{n}^{\prime}, i.e., An[1]=(An,An)A_{n}^{[1]}=(A_{n},A_{n}^{\prime}).

IV-A1 Secret channel model

The adversary can modify the answer from 1 server. To identify the corrupted answer, the servers use a uniform nonzero random variable p𝔽qp\in\mathbb{F}_{q} from the common randomness (secure from the adversary). Server nn calculates a hash (check sum) of its answers,

Hn=pAn+p2An.\displaystyle H_{n}=pA_{n}+p^{2}A_{n}^{\prime}. (14)

Choose an arbitrary server to transmit pp, and 2 arbitrary servers to transmit their HnH_{n} to the user through the secret channels. The user plugs in the received An,AnA_{n},A_{n}^{\prime} to check whether (14) holds.

Because the adversary does not know the values of pp and HnH_{n}, the probability that the modified A~n,A~n\widetilde{A}_{n},\widetilde{A}_{n}^{\prime} satisfies (14), i.e., p2+(A~n)1A~np(A~n)1Hn=0p^{2}+(\widetilde{A}_{n}^{\prime})^{-1}\widetilde{A}_{n}p-(\widetilde{A}_{n}^{\prime})^{-1}H_{n}=0 is at most 2/q2/q (for a proof, refer to Lemma 1), which can be made arbitrarily small as the alphabet size qq increases.

The intuition for generalizing the scheme is that as the message size and number of repetitions of the scheme increase, the sizes of pp and the hashes {Hn}\{H_{n}\} (transmitted through the secret channel) vanish when normalized by the message size. Therefore, with vanishing rate secure channels, the user decodes 22 desired symbols from 6 downloaded symbols, achieving the rate of 1/31/3.

IV-A2 Untouched server model

There is no secret channel now and the adversary can observe any E=1E=1 server and corrupt any B=1B=1 answer. As E+B=2=N1E+B=2=N-1, there is one server that is neither observed nor jammed by the adversary. Treating this problem as a point-to-point network coding problem with NN parallel links (where 1 link is untouched), from Theorem 1 in [5], the servers can send some common information to the user secretly (to the adversary), with vanishing error (bounded by N/qNN/q^{N}) and constant rate.

Because the secure transmission scheme in [5] can only send common information that is shared by all servers, we cannot use it to transmit the hashes of An,AnA_{n},A_{n}^{\prime} (distinct for each server). Instead, we will let the servers transmit hashes of the messages. The challenge here is that by the database-privacy constraint, the hashes of the messages should not contain any information about the messages. To fulfill this constraint, the servers draw independent uniform common random symbols Sa,SbS_{a},S_{b} from 𝔽q\mathbb{F}_{q}, to be added in the hash generation. The servers choose a nonzero element pp uniformly at random from 𝔽q\mathbb{F}_{q}. The hashes of W1W_{1} and W2W_{2} are generated by

Ha=pa+p2a+p3Sa;Hb=pb+p2b+p3Sb.\displaystyle H_{a}=pa+p^{2}a^{\prime}+p^{3}S_{a};H_{b}=pb+p^{2}b^{\prime}+p^{3}S_{b}. (15)

The servers use the secure transmission scheme in [5] to transmit p,Ha,Hbp,H_{a},H_{b} secretly to the user (not known to the adversary).

To check the hash HaH_{a} on the message symbols (a,a)(a,a^{\prime}), the user should also obtain the value of SaS_{a} (but he should not learn SbS_{b} for database-privacy). To do this, Sa,SbS_{a},S_{b} can be treated as extended symbols from W1,W2W_{1},W_{2}, and SaS_{a} can be retrieved by applying the scheme in (11)-(13). The probability of error in the hash checking part is bounded by 3/q3/q. Therefore, the overall probability of error vanishes as qq increases. The rate achieved is 1/31/3, as desired.

Similarly, to amortize the cost of sending p,Ha,Hbp,H_{a},H_{b}, and retrieving SaS_{a}, we will drive the message length to infinity (details to be presented in the next section).

IV-B General parameters

Without loss of generality, suppose each message consists of L=(NTB)lL=(N\!-\!T\!-\!B)\cdot l symbols from 𝔽q\mathbb{F}_{q}, where q=l2Nq=l^{2}\gg N, and WkW_{k} is desired. The idea is to concatenate a scheme for ll instances, and generate hashes of the answers of the ll instances for the secure channel model; or hashes of the messages for the untouched server model.

Divide each message to ll blocks, and collect the ii-th blocks of all messages into a column vector, 𝐖(i)=[W1(i),1;;W1(i),NTB;;WK(i),1;;WK(i),NTB]\mathbf{W}^{(i)}=[W_{1}^{(i),1};\cdots\!;W_{1}^{(i),N\!-\!T\!-\!B};\cdots\!;W_{K}^{(i),1};\cdots\!;W_{K}^{(i),N\!-\!T\!-\!B}] where i=[1:l]i=[1:l] denotes the index of the block/instance. Collect the ll column vectors to form the matrix 𝐖=[𝐖1𝐖l]\mathbf{W}=[\mathbf{W}^{1}\cdots\mathbf{W}^{l}], which represents the whole dataset.

The user privately chooses TT uniformly i.i.d. row vectors 𝐔1,,𝐔T\mathbf{U}_{1},\dots,\mathbf{U}_{T} from 𝔽qK(NTB)\mathbb{F}_{q}^{K(N\!-\!T\!-\!B)}. Let 𝐞1,,𝐞NTB\mathbf{e}_{1},\dots,\mathbf{e}_{N\!-\!T\!-\!B} be row unit vectors, where in 𝐞j\mathbf{e}_{j}, all entries are equal to zero except the ((k1)(NTB)+j)((k\!-\!1)(N\!-\!T\!-\!B)\!+\!j)-th entry. Let 𝐔=[𝐔1;;𝐔T]\mathbf{U}=[\mathbf{U}_{1};\dots;\mathbf{U}_{T}]. Similarly, denote 𝐞=[𝐞1;;𝐞NTB]\mathbf{e}=[\mathbf{e}_{1};\dots;\mathbf{e}_{N\!-\!T\!-\!B}]. Choose NN distinct nonzero elements λ1,,λN\lambda_{1},\dots,\lambda_{N} from 𝔽q\mathbb{F}_{q}. Let 𝐆𝐔=𝐕T(λ1,,λN)\mathbf{G}_{\mathbf{U}}\!=\!\mathbf{V}^{T}(\lambda_{1},\dots,\lambda_{N}), i.e., an N×TN\times T Vandermonde matrix, and 𝐆𝐞=diag(λ1T,,λNT)𝐕NTB(λ1,,λN)\mathbf{G}_{\mathbf{e}}=\text{diag}(\lambda_{1}^{T},\!\dots\!,\lambda_{N}^{T})\!\cdot\!\mathbf{V}^{N\!-\!T\!-\!B}(\lambda_{1},\!\dots\!,\lambda_{N}), Then 𝐆=[𝐆𝐔𝐆𝐞]=𝐕NB(λ1,,λN)\mathbf{G}=[\mathbf{G}_{\mathbf{U}}\;\mathbf{G}_{\mathbf{e}}]=\mathbf{V}^{N-B}(\lambda_{1},\dots,\lambda_{N}). The queries to all NN servers are generated by

Q[1:N][k]=𝐆𝐔𝐔+𝐆𝐞𝐞=𝐆[𝐔𝐞].\displaystyle Q_{[1:N]}^{[k]}=\mathbf{G}_{\mathbf{U}}\mathbf{U}+\mathbf{G}_{\mathbf{e}}\mathbf{e}=\mathbf{G}\cdot\begin{bmatrix}\mathbf{U}\\ \mathbf{e}\end{bmatrix}. (16)

The query Qn[k]Q_{n}^{[k]} is sent to Server nn. The same query is used to generate the answers for all ll instances.

To protect database-privacy from the user, the servers share TlTl uniformly i.i.d. symbols {Sj(i)}i[1:l],j[1:T]\{S_{j}^{(i)}\}_{i\in[1:l],j\in[1:T]}. For instance ii, Server nn takes the inner product of Qn[k]Q_{n}^{[k]} and 𝐖(i)\mathbf{W}^{(i)}, and adds j=1Tλnj1Sj(i)\sum_{j=1}^{T}\lambda_{n}^{j-1}S_{j}^{(i)} to generate the answer. Denote

[𝐔1𝐖1+S11𝐔1𝐖l+S1l𝐔T𝐖1+ST1𝐔T𝐖l+STlWk1,1Wkl,1Wk1,NTBWkl,NTB]=𝐗,\displaystyle\begin{bmatrix}\mathbf{U}_{1}\mathbf{W}^{1}+S_{1}^{1}&\cdots&\mathbf{U}_{1}\mathbf{W}^{l}+S_{1}^{l}\\ \vdots&\ddots&\vdots\\ \mathbf{U}_{T}\mathbf{W}^{1}+S_{T}^{1}&\cdots&\mathbf{U}_{T}\mathbf{W}^{l}+S_{T}^{l}\\ W_{k}^{1,1}&\cdots&W_{k}^{l,1}\\ \vdots&\ddots&\vdots\\ W_{k}^{1,N\!-\!T\!-\!B}&\cdots&W_{k}^{l,N\!-\!T\!-\!B}\end{bmatrix}\stackrel{{\scriptstyle\triangle}}{{=}}\mathbf{X}, (17)

then the NlNl answers generated by the servers are

[A[1:N][k],1A[1:N][k],l]\displaystyle[A_{[1:N]}^{[k],1}\cdots A_{[1:N]}^{[k],l}] (18)
=\displaystyle= 𝐆[𝐔𝐞]𝐖+𝐆[S11S1lST1STl𝟎𝟎]=𝐆𝐗.\displaystyle\mathbf{G}\cdot\begin{bmatrix}\mathbf{U}\\ \mathbf{e}\end{bmatrix}\cdot\mathbf{W}+\mathbf{G}\cdot\begin{bmatrix}S_{1}^{1}&\cdots&S_{1}^{l}\\ \vdots&\ddots&\vdots\\ S_{T}^{1}&\cdots&S_{T}^{l}\\ \bf 0&\cdots&\bf 0\end{bmatrix}=\mathbf{G}\mathbf{X}. (19)

The answers from BB servers (denoted by the set \mathcal{B}) might be overwritten by the adversary. Denote the noise added by the adversary by Z[1:l]Z_{\mathcal{B}}^{[1:l]}. The answers received by the user are

[A~[1:N][k],1A~[1:N][k],l]\displaystyle\hskip-19.91684pt[\widetilde{A}_{[1:N]}^{[k],1}\cdots\widetilde{A}_{[1:N]}^{[k],l}] =𝐆𝐗+𝐁Z[1:l]=[𝐆𝐁][𝐗Z[1:l]],\displaystyle=\mathbf{G}\mathbf{X}+\mathbf{B}Z_{\mathcal{B}}^{[1:l]}=[\mathbf{G}\;\mathbf{B}]\cdot\begin{bmatrix}\mathbf{X}\\ Z_{\mathcal{B}}^{[1:l]}\end{bmatrix}, (20)

where 𝐁\mathbf{B} is an N×BN\times B matrix with a distinct 1 in each column corresponding to the set of answers corrupted by the adversary. It is easy to check that [𝐆𝐁][\mathbf{G}\;\mathbf{B}] is invertible.

The user can exhaust all (NB){N\choose B} different 𝐁\mathbf{B} (i.e., different set of corrupted answers), and obtain a list of (NB){N\choose B} solutions of the linear system (20). For the two models of limited knowledge adversary, we design different schemes to send hashes to the user, such that the user can find the correct solution from the (NB){N\choose B} list with high probability.

IV-B1 Secret channel model

Let p1,,pαp_{1},\dots,p_{\alpha} be α\alpha distinct nonzero elements from 𝔽q\mathbb{F}_{q} chosen uniformly at random by the servers.55 5 Here α\alpha is an arbitrary fixed positive integer which determines the number of hashes for each answer and the speed of vanishing of the error probability. Let 𝐏\mathbf{P} be an l×αl\times\alpha matrix where 𝐏i,j=(pj)i\mathbf{P}_{i,j}=(p_{j})^{i}. Let 𝒩\mathcal{N} be any set of servers with size NBN-B, which are chosen to send the hashes to the user. Denote 𝐆𝒩\mathbf{G}_{\mathcal{N}} as the square matrix corresponding to the choice of set 𝒩\mathcal{N}, then it is obvious that 𝐆𝒩\mathbf{G}_{\mathcal{N}} is invertible. The hashes are generated by

A𝒩[1:l]𝐏=𝐆𝒩𝐗𝐏𝐇(NB)×α.\displaystyle A_{\mathcal{N}}^{[1:l]}\cdot\mathbf{P}=\mathbf{G}_{\mathcal{N}}\cdot\mathbf{X}\cdot\mathbf{P}\triangleq\mathbf{H}^{(N-B)\times\alpha}. (21)

These servers send p1,,pαp_{1},\dots,p_{\alpha} and 𝐇\mathbf{H} to the user through a secure channel (this transmission includes α(NB+1)\alpha(N-B+1) symbols). Because 𝐆𝒩\mathbf{G}_{\mathcal{N}} is invertible, the user obtains α\alpha hash functions for each row of 𝐗\mathbf{X} (refer to (17)). In fact, we only need the hash functions of WkW_{k}. Lemma 1 below is inspired by Claim 5 in [4].

Lemma 1

Let pp be uniformly chosen from 𝔽q{0}\mathbb{F}_{q}\setminus\{0\}, and {a0,a1,,an}\{a_{0},a_{1},\dots,a_{n}\} be symbols from 𝔽q\mathbb{F}_{q} such that anpn++a1p+a0=0a_{n}p^{n}+\cdots+a_{1}p+a_{0}=0. An adversary can observe and modify {a1,,an}\{a_{1},\dots,a_{n}\}, but can neither observe nor modify a0a_{0}. The probability (over the randomness of pp) that the modified {a~1,,a~n}\{\widetilde{a}_{1},\dots,\widetilde{a}_{n}\} satisfies a~npn++a~1p+a0=0\widetilde{a}_{n}p^{n}+\cdots+\widetilde{a}_{1}p+a_{0}=0 is at most n/qn/q.

Proof: Since the adversary cannot observe a0a_{0}, anpn++a1pa_{n}p^{n}+\cdots+a_{1}p and pp remains uniformly at random to the adversary. Therefore, the adversary can only modify a1,,ana_{1},\dots,a_{n} arbitrarily. For any modified {a~1,,a~n}\{\widetilde{a}_{1},\dots,\widetilde{a}_{n}\},

Pr(a~npn++a~1p+a0=0)\displaystyle\hskip-22.76228pt\quad\Pr(\widetilde{a}_{n}p^{n}+\cdots+\widetilde{a}_{1}p+a_{0}=0) (22)
=Pr((a~nan)pn++(a~1a1)p=0)\displaystyle\hskip-22.76228pt=\Pr((\widetilde{a}_{n}-a_{n})p^{n}+\cdots+(\widetilde{a}_{1}-a_{1})p=0) (23)
=Pr(p is a nonzero root of a polynomial with degree n)\displaystyle\hskip-19.91684pt{\color[rgb]{0,0,0}=\Pr(p\mbox{ is a nonzero root of a polynomial with degree $\leq n$})} (24)
(n1)/(q1)n/q.\displaystyle\hskip-22.76228pt\leq(n-1)/(q-1)\leq n/q. (25)

\Box

By Lemma 1, the probability that an incorrect solution satisfies all α\alpha hashes is at most (lq)α\left(\frac{l}{q}\right)^{\alpha}. There are (NB){N\choose B} solutions in the list such that by the union bound, the probability that a unique correct solution cannot be found, i.e., the probability of error, is at most (NB)(lq)α=(NB)(1l)α{N\choose B}\left(\frac{l}{q}\right)^{\alpha}={N\choose B}\left(\frac{1}{l}\right)^{\alpha} (note that q=l2q=l^{2}). Therefore, the probability of error vanishes with the message length. Note that the amount of transmission through the secret channel α(NB+1)\alpha(N-B+1) does not grow with the message size LL (the normalized rate approaches 0). Finally, the rate achieved is R=1T+BNR=1-\frac{T+B}{N}, and the randomness size is ρ=TNTB\rho=\frac{T}{N-T-B}.

IV-B2 Untouched Server Model

The query and answer generation includes two phases. The first phase does not depend on the queries and includes the transmission of random hashes of all the messages to the user. When the servers send some shared information to the user, an imaginary source node can be added and the system can be translated into a network with min-cut NN. Because E+B<NE+B<N, we can use the secure transmission scheme of Theorem 1 in [5] to send common information shared by all servers (simpler schemes might exist and are an interesting future direction).66 6 Note that in this model, the servers cannot send the hashes of the answers as in the secret channel model, because the servers cannot share the queries and answers due to the user-privacy constraint.

By database-privacy, the hashes of messages should be protected by some randomness. Therefore, we append α=(NTB)β\alpha=(N-T-B)\beta uniformly random symbols to each message, denoted by {SWk(i),j}i[1:β],j[1:NTB]\{S_{W_{k}}^{(i),j}\}_{i\in[1:\beta],j\in[1:N-T-B]}, where ii denotes the index of instances (i.e., the user downloads β\beta more instances to retrieve the {SWk(i),j}\{S_{W_{k}}^{(i),j}\} associated with the desired WkW_{k}.).

During the first phase, the servers generate and transmit (NTB)β(N-T-B)\beta uniform i.i.d. symbols p1,p2,,pαp_{1},p_{2},\dots,p_{\alpha}, and α\alpha hashes of each message to the user by the scheme in [5]. Let 𝐏\mathbf{P} be an (NTB)(l+β)×α(N-T-B)(l+\beta)\times\alpha matrix where 𝐏i,j=(pj)i\mathbf{P}_{i,j}=(p_{j})^{i}, and let [Wk,SWk][W_{k},S_{W_{k}}] denote the row vector comprised of all the symbols from WkW_{k} and {SWk(i),j}\{S_{W_{k}}^{(i),j}\}, the hashes are generated by

𝐇Wk=[Wk,SWk]𝐏.\displaystyle\mathbf{H}_{W_{k}}=[W_{k},S_{W_{k}}]\cdot\mathbf{P}. (26)

The servers send p1,,pαp_{1},\dots,p_{\alpha} and {𝐇Wk}k[1:K]\{\mathbf{H}_{W_{k}}\}_{k\in[1:K]} to the user secretly in a bit-by-bit manner using the scheme in [5]. We need to send (K+1)αlogq(K+1)\alpha\log{q} bits in this phase. For each bit, the servers send N2(NE)N^{2}(N-E) symbols over 𝔽q\mathbb{F}_{q} [5]. Therefore, the total amount of download for the first phase is N2(NE)(K+1)αlogqN^{2}(N-E)(K+1)\alpha\log{q}. By Lemma 4 in [5], the probability of error for this phase is bounded above by N/qNN/q^{N}.

The second phase is similar to that in Section IV-B, with extended message length (NTB)(l+β)(N-T-B)(l+\beta) (because the user needs also to retrieve {SWk(i),j}\{S_{W_{k}}^{(i),j}\} to check the hashes, and they should be retrieved privately). The second phase involves a total download of N(l+β)N(l+\beta) symbols.

Therefore, the total retrieval rate is

R\displaystyle R =(NTB)lN2(NE)(K+1)αlogq+N(l+β)1T+BN,\displaystyle=\frac{(N-T-B)l}{N^{2}(N-E)(K+1)\alpha\log{q}+N(l+\beta)}\to 1-\frac{T+B}{N}, (27)

as ll\to\infty (note that logq=2logl\log{q}=2\log{l} and logl/l0\log{l}/l\to 0).

Similarly, the relative amount of shared common randomness for the first phase vanishes as ll\to\infty. For the second phase, T(l+β)T(l+\beta) random shared symbols are needed. Therefore, ρTNTB\rho\to\frac{T}{N-T-B} as ll\to\infty.

An error happens in the second phase when any incorrect solution satisfies the hashes, which by Lemma 1 occurs with probability at most (NB)((NBT)(l+β)q)α{N\choose B}\left(\frac{(N-B-T)(l+\beta)}{q}\right)^{\alpha}. The error probability of the first phase is upper bounded by N/qN=Nl2NN/q^{N}=\frac{N}{l^{2N}} [5]. By the union bound, the overall probability of error is at most (NB)((NBT)(l+β)l)α+Nl2N{N\choose B}\left(\frac{(N-B-T)(l+\beta)}{l}\right)^{\alpha}+\frac{N}{l^{2N}}, which tends to 00 as ll\to\infty.

Note that for both the secret channel model and the untouched server model, user-privacy is guaranteed because every TT servers observe linearly and statistically independent queries (16). Database-privacy is guaranteed because from 𝐗\mathbf{X} in (17), the {Sj(i)}\{S_{j}^{(i)}\} symbols are uniform i.i.d. symbols, such that the user obtains no information about Wk¯W_{\bar{k}}.

V Converse

Note that the answers corrupted by the adversary A~[k]\widetilde{A}_{\mathcal{B}}^{[k]} may be useless to the user for decoding WkW_{k}. Denote the set of uncorrupted nodes by =[1:N]\mathcal{H}=[1:N]\setminus\mathcal{B}, from (5),

H(Wk|A[k],H[1:N][k],𝒬)=o(L).\displaystyle H(W_{k}|A_{\mathcal{H}}^{[k]},H_{[1:N]}^{[k]},\mathcal{Q})=o(L). (28)

Further, I(Wk;H[1:N][k]|A[k],𝒬)H(H[1:N][k])=o(L)I(W_{k};H_{[1:N]}^{[k]}|A_{\mathcal{H}}^{[k]},\mathcal{Q})\leq H(H_{[1:N]}^{[k]})=o(L). Then

H(Wk)\displaystyle\hskip-17.07182ptH(W_{k}) =H(Wk)H(Wk|A[k],H[1:N][k],𝒬)+o(L)\displaystyle=H(W_{k})-H(W_{k}|A_{\mathcal{H}}^{[k]},H_{[1:N]}^{[k]},\mathcal{Q})+o(L) (29)
=H(Wk|𝒬)H(Wk|A[k],𝒬)\displaystyle=H(W_{k}|\mathcal{Q})-H(W_{k}|A_{\mathcal{H}}^{[k]},\mathcal{Q})
+I(Wk;H[1:N][k]|A[k],𝒬)+o(L)\displaystyle~~~+I(W_{k};H_{[1:N]}^{[k]}|A_{\mathcal{H}}^{[k]},\mathcal{Q})+o(L) (30)
H(Wk|𝒬)H(Wk|A[k],𝒬)+o(L)\displaystyle\leq H(W_{k}|\mathcal{Q})-H(W_{k}|A_{\mathcal{H}}^{[k]},\mathcal{Q})+o(L) (31)
=H(A[k]|𝒬)H(A[k]|Wk,𝒬)+o(L)\displaystyle=H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(A_{\mathcal{H}}^{[k]}|W_{k},\mathcal{Q})+o(L) (32)
H(A[k]|𝒬)H(A𝒯|Wk,𝒬)+o(L)\displaystyle\leq H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(A_{\mathcal{T}}|W_{k},\mathcal{Q})+o(L) (33)
=(2)H(A[k]|𝒬)H(A𝒯|Wk,𝒬)+o(L)\displaystyle\stackrel{{\scriptstyle\eqref{eqn:userprivacy}}}{{=}}H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(A_{\mathcal{T}}|W_{k^{\prime}},\mathcal{Q})+o(L) (34)
=(6)H(A[k]|𝒬)H(A𝒯|𝒬)+o(L),\displaystyle\stackrel{{\scriptstyle\eqref{eqn:databaseprivacy}}}{{=}}H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(A_{\mathcal{T}}|\mathcal{Q})+o(L), (35)

for any 𝒯\mathcal{T}\subset\mathcal{H} with |𝒯|=T|\mathcal{T}|=T. Note that from (33), the superscript [k][k] in A𝒯A_{\mathcal{T}} can be dropped because of user-privacy (2). By Han’s inequality [6],

1(NBT)𝒯|𝒯|=TH(A𝒯|𝒬)TNBH(A[k]|𝒬).\frac{1}{{N-B\choose T}}\sum_{\begin{subarray}{c}\mathcal{T}\subset\mathcal{H}\\ |\mathcal{T}|=T\end{subarray}}H(A_{\mathcal{T}}|\mathcal{Q})\geq\frac{T}{N-B}H(A_{\mathcal{H}}^{[k]}|\mathcal{Q}). (36)

Averaging (35) over all subsets 𝒯\mathcal{T} of \mathcal{H} and combining with (36), we have

H(Wk)NBTNBH(A[k]|𝒬)+o(L).H(W_{k})\leq\frac{N-B-T}{N-B}H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})+o(L). (37)

By symmetry, we assume the answer sizes are the same. Therefore, H(Wk)NBTNBNBNn=1NH(An[k]|𝒬)+o(L)H(W_{k})\leq\frac{N-B-T}{N-B}\cdot\frac{N-B}{N}\sum_{n=1}^{N}H(A_{n}^{[k]}|\mathcal{Q})+o(L). By letting LL\to\infty,

R=H(Wk)n=1NH(An[k])H(Wk)n=1NH(An[k]|𝒬)1B+TN.\displaystyle R=\frac{H(W_{k})}{\sum_{n=1}^{N}H(A_{n}^{[k]})}\leq\frac{H(W_{k})}{\sum_{n=1}^{N}H(A_{n}^{[k]}|\mathcal{Q})}\leq 1-\frac{B+T}{N}. (38)

By database-privacy (6),

0\displaystyle 0 =I(Wk¯,A[k],𝒬)\displaystyle=I(W_{\bar{k}};A_{\mathcal{H}}^{[k]},\mathcal{Q}) (39)
=I(Wk¯;A[k]|𝒬)\displaystyle=I(W_{\bar{k}};A_{\mathcal{H}}^{[k]}|\mathcal{Q}) (40)
=H(A[k]|𝒬)H(A[k]|Wk¯,𝒬)\displaystyle=H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(A_{\mathcal{H}}^{[k]}|W_{\bar{k}},\mathcal{Q}) (41)
=H(A[k]|𝒬)H(A[k]|Wk¯,𝒬)\displaystyle=H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(A_{\mathcal{H}}^{[k]}|W_{\bar{k}},\mathcal{Q})
+H(A[k]|S,Wk,Wk¯,𝒬)\displaystyle\qquad+H(A_{\mathcal{H}}^{[k]}|S,W_{k},W_{\bar{k}},\mathcal{Q}) (42)
=H(A[k]|𝒬)H(S,Wk|Wk¯,𝒬)\displaystyle=H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(S,W_{k}|W_{\bar{k}},\mathcal{Q})
+H(S,Wk|A[k],Wk¯,𝒬)\displaystyle\qquad+H(S,W_{k}|A_{\mathcal{H}}^{[k]},W_{\bar{k}},\mathcal{Q}) (43)
=H(A[k]|𝒬)H(S)H(Wk)\displaystyle=H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(S)-H(W_{k})
+H(S,Wk|A[k],Wk¯,𝒬)\displaystyle\qquad+H(S,W_{k}|A_{\mathcal{H}}^{[k]},W_{\bar{k}},\mathcal{Q}) (44)
=H(A[k]|𝒬)H(S)H(Wk)\displaystyle=H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(S)-H(W_{k})
+H(Wk|A[k],Wk¯,𝒬)+H(S|Wk,A[k],Wk¯,𝒬)\displaystyle\qquad+H(W_{k}|A_{\mathcal{H}}^{[k]},W_{\bar{k}},\mathcal{Q})+H(S|W_{k},A_{\mathcal{H}}^{[k]},W_{\bar{k}},\mathcal{Q}) (45)
(28)H(A[k]|𝒬)H(S)H(Wk)+o(L),\displaystyle\overset{(\ref{eq:ss})}{\geq}H(A_{\mathcal{H}}^{[k]}|\mathcal{Q})-H(S)-H(W_{k})+o(L), (46)

where (42) holds because the uncorrupted answers are deterministic functions of the queries, the dataset W[1:K]W_{[1:K]}, and the randomness SS. (44) holds because the randomness SS, the messages W[1:K]W_{[1:K]}, and the queries 𝒬\mathcal{Q} are independent. Combining (46) with (37), and by letting LL\to\infty,

ρ=H(S)H(Wk)TNBT.\rho=\frac{H(S)}{H(W_{k})}\geq\frac{T}{N-B-T}. (47)

VI Conclusion

For symmetric PIR with Byzantine adversaries, we show that if the adversary has limited knowledge and a vanishingly small probability of error is allowed, the capacity increases when compared to the setting with omniscient adversaries and zero probability of error. It is interesting to see if similar results hold for the PIR problem with Byzantine adversaries [7, 8].77 7 [8] considers PIR with Byzantine adversaries, where ϵ\epsilon-error is allowed. List decoding is used therein to achieve communication cost 𝒪(BN)\mathcal{O}(BN) (upload plus download) whenever N>B+T+1N>B+T+1 (note that we raise the question for information theoretic capacity) and the focus is mainly on computational efficiency and programming implementation.

References

  • [1] Q. Wang and M. Skoglund, “Secure symmetric private information retrieval from colluding databases with adversaries,” arXiv preprint arXiv:1707.02152, 2017.
  • [2] H. Sun and S. A. Jafar, “The capacity of symmetric private information retrieval,” in Globecom Workshops (GC Wkshps), 2016 IEEE. IEEE, 2016, pp. 1–5.
  • [3] Q. Wang and M. Skoglund, “Linear symmetric private information retrieval for MDS coded distributed storage with colluding servers,” arXiv preprint arXiv:1708.05673, 2017.
  • [4] S. Jaggi, M. Langberg, S. Katti, T. Ho, D. Katabi, and M. Médard, “Resilient network coding in the presence of byzantine adversaries,” in 26th IEEE International Conference on Computer Communications. IEEE, 2007, pp. 616–624.
  • [5] H. Yao, D. Silva, S. Jaggi, and M. Langberg, “Network codes resilient to jamming and eavesdropping,” IEEE/ACM Transactions on Networking, vol. 22, no. 6, pp. 1978–1987, 2014.
  • [6] T. M. Cover and J. A. Thomas, Elements of information theory. John Wiley & Sons, 2012.
  • [7] K. Banawan and S. Ulukus, “The capacity of private information retrieval from byzantine and colluding databases,” arXiv preprint arXiv:1706.01442, 2017.
  • [8] C. Devet, I. Goldberg, and N. Heninger, “Optimally robust private information retrieval.” in USENIX Security Symposium, 2012, pp. 269–283.