arXiv:2507.14768cs.ITcs.CR2025-07被引 13

解决多层级安全聚合中不同用户不同防护需求的难题

Hierarchical Secure Aggregation with Heterogeneous Security Constraints and Arbitrary User Collusion

  • 按用户分组设定差异化的安全级别,支持任意用户合谋场景
  • 首次给出所有参数下通信率最优解,涵盖不同安全约束组合
  • 精确刻画用户所需最小密钥量,提供紧致理论边界与近似方案

在分层安全聚合(HSA)中,服务器通过中间代理层与分组用户通信,需在服务器安全和代理安全双重要求下计算用户输入之和。服务器安全指即使与部分用户合谋,服务器也仅能获知预期总和;代理安全则要求每个代理在合谋下仍无法获取用户输入。现有工作采用同质安全机制,即所有输入必须抵御任意规模至阈值的合谋攻击。但现实中不同用户对保护级别需求各异。本文研究具有异构安全需求和任意用户合谋的分层安全聚合问题,考虑特定用户组的输入需在服务器或任一代理与任意其他用户合谋时,仍保持信息论意义上的安全。在服务器安全下,服务器无法从受保护输入中推断出任何额外信息;在代理安全下,各代理同样无法获取受保护输入。本文刻画了所有层级在各种参数配置下的最优通信率,并研究用户端所需最小源密钥量。针对该密钥需求,本文在两类由安全与合谋约束决定的广泛情形下给出了紧致表征,并为剩余情形建立了通用信息论下界,同时提出逼近该下界的可行方案。

原文摘要 · Abstract (English)

In hierarchical secure aggregation (HSA), a server communicates with clustered users through an intermediate layer of relays to compute the sum of users' inputs under two security requirements -- server security and relay security. Server security requires that the server learns nothing beyond the desired sum even when colluding with a subset of users, while relay security requires that each relay remains oblivious to the users' inputs under collusion. Existing work on HSA enforces homogeneous security where \tit{all} inputs must be protected against \tit{any} subset of potential colluding users with sizes up to a predefined threshold. Such a \homo formulation cannot capture scenarios with \tit{\het} \secty \reqs where \diff users may demand various levels of protection. In this paper, we study hierarchical secure aggregation (HSA) with heterogeneous security requirements and arbitrary user collusion. Specifically, we consider scenarios where the inputs of certain groups of users must remain information-theoretically secure against inference by the server or any relay, even if the server or any relay colludes with an arbitrary subset of other users. Under server security, the server learns nothing about these protected inputs beyond the prescribed aggregate sum, despite any such collusion. Under relay security, each relay similarly obtains no information about the protected inputs under the same collusion model. We characterize the optimal communication rates achievable across all layers for all parameter regimes. Furthermore, we study the minimum source keys required at the users to ensure security. For this source key requirement, we provide tight characterizations in two broad regimes determined by the security and collusion constraints, and establish a general information-theoretic lower bound together with a bounded-gap achievable scheme for the remaining regime.

安全聚合分层系统异构安全信息论安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。