# x - Faculty of Computer Science - Technische Universität Dresden

## (3)�(4) is clear with

(3)�(4) is clear with const':= W(S). Conversely, we show const' = W(S): W ( S) � � � � x � x W ( x) � W ( x) � const' � const'. Proof (4) is already quite the same as (1): In general holds W(S|x) = W({k | k(x) = S}), and if all keys have the same probability, W(S|x)= |{k | k(x) = S}| / |K|. Then (4) is equivalent (1) with � � const = const' • |K|. x W(S|x) const' W ( x) 157

Another definition for information-theoretical security Sometimes, students come up with the following definition: �S � S �x � X: W(S) = W(S|x). This is not equivalent, but a slight modification is: 3. Definition �S � S �x � X with W(x)>0: W(S) = W(S|x). Definitions 2. and 3. are equivalent: Remember Bayes: W ( x) �W ( S | x) W ( x | S) � W ( S) W(x|S) = W(x) (Bayes) W ( x) �W ( S | x) ( x | S) � W ( S) W(S|x) = W(S) = W(x) (if W(x) ≠0, we can divide by W(x)) W(S|x) as proposed by some students assumes that x may be sent, i.e. W(x)>0. 158

