# x - Faculty of Computer Science - Technische Universität Dresden

x - Faculty of Computer Science - Technische Universität Dresden

## 155 Preparation:

155 Preparation: Definition for information-theoretical security How would you define information-theoretical security for encryption? Write down at least 2 definitions and argue for them!

Definition for information-theoretical security 1. Definition for information-theoretical security (all keys are chosen with the same probability) �S � S � const � IN �x � X: |{k � K| k(x) = S}| = const. (1) The a-posteriori probability of the plaintext x is W(x|S), after the attacker got to know the ciphertext S. 2. Definition �S � S �x � X: W(x|S) = W(x). (2) Both definitions are equivalent (if W(x) > 0): According to Bayes: W ( x) �W ( S | x) W ( x | S) � W ( S) Therefore, (2) is equivalent to �S � S �x � X: W(S|x) = W(S). (3) We show that this is equivalent to �S � S � const' � IR �x � X: W(S|x) = const'. (4) 156

