Cited time in webofscience Cited time in scopus

Full metadata record

DC Field Value Language
dc.contributor.author Kim, Yongjune -
dc.contributor.author Guyot, Cyril -
dc.contributor.author Kim, Young-Sik -
dc.date.accessioned 2021-07-14T20:08:39Z -
dc.date.available 2021-07-14T20:08:39Z -
dc.date.created 2021-04-02 -
dc.date.issued 2021-04 -
dc.identifier.issn 1556-6013 -
dc.identifier.uri http://hdl.handle.net/20.500.11750/13820 -
dc.description.abstract The min-entropy is a widely used metric to quantify the randomness of generated random numbers in cryptographic applications; it measures the difficulty of guessing the most likely output. An important min-entropy estimator is the compression estimator of NIST Special Publication (SP) 800-90B, which relies on Maurer’s universal test. In this paper, we propose two kinds of min-entropy estimators to improve computational complexity and estimation accuracy by leveraging two variations of Maurer’s test: Coron’s test (for Shannon entropy) and Kim’s test (for Rényi entropy). First, we propose a min-entropy estimator based on Coron’s test. It is computationally more efficient than the compression estimator while maintaining the estimation accuracy. The secondly proposed estimator relies on Kim’s test that computes the Rényi entropy. This estimator improves estimation accuracy as well as computational complexity. We analytically characterize the bias-variance tradeoff, which depends on the order of Rényi entropy. By taking into account this tradeoff, we observe that the order of two is a proper assignment and focus on the min-entropy estimation based on the collision entropy (i.e., Rényi entropy of order two). The min-entropy estimation from the collision entropy can be described by a closed-form solution, whereas both the compression estimator and the proposed estimator based on Coron’s test do not have closed-form solutions. By leveraging the closed-form solution, we also propose a lightweight estimator that processes data samples in an online manner. Numerical evaluations demonstrate that the first proposed estimator achieves the same accuracy as the compression estimator with much less computation. The proposed estimator based on the collision entropy can even improve the accuracy and reduce the computational complexity. IEEE -
dc.language English -
dc.publisher Institute of Electrical and Electronics Engineers -
dc.title On the Efficient Estimation of Min-Entropy -
dc.type Article -
dc.identifier.doi 10.1109/tifs.2021.3070424 -
dc.identifier.scopusid 2-s2.0-85103782911 -
dc.identifier.bibliographicCitation IEEE Transactions on Information Forensics and Security, v.16, pp.3013 - 3025 -
dc.description.isOpenAccess FALSE -
dc.subject.keywordAuthor Entropy -
dc.subject.keywordAuthor NIST -
dc.subject.keywordAuthor Estimation -
dc.subject.keywordAuthor Computational complexity -
dc.subject.keywordAuthor Closed-form solutions -
dc.subject.keywordAuthor Cryptography -
dc.subject.keywordAuthor Random variables -
dc.subject.keywordAuthor Entropy estimation -
dc.subject.keywordAuthor min-entropy -
dc.subject.keywordAuthor Shannon entropy -
dc.subject.keywordAuthor -
dc.subject.keywordAuthor nyi entropy -
dc.subject.keywordAuthor NIST SP 800-90B -
dc.subject.keywordAuthor compression estimator -
dc.subject.keywordAuthor random number generator -
dc.citation.endPage 3025 -
dc.citation.startPage 3013 -
dc.citation.title IEEE Transactions on Information Forensics and Security -
dc.citation.volume 16 -
Files in This Item:

There are no files associated with this item.

Appears in Collections:
Department of Electrical Engineering and Computer Science Information, Computing, and Intelligence Laboratory 1. Journal Articles

qrcode

  • twitter
  • facebook
  • mendeley

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.

BROWSE