NEW CONSTRUCTION OF A
Department of Mathematics and Informatic, University of Science, Technics and Technologies,
ARTICLE INFO ABSTRACT
Many mathematicians have worked in this erea by using classical groups, normal form some known vector spaces
spaces to construct authentication codes with arbitration. construction of authentication code with arbitration b
parameters and probabilities from this code. The main objective of studying authentication codes with arbitration is to use them for the provision of better security in practical information communications. In the
The historical perspective of the development of authentication code with arbitration is also presented. In the part two of this paper some essential conc
field, which constitute the basic of this paper are introduced. In the same way
given, then parameters and probabilities of authentication code with arbitration are easily computed. In part thr
presented. In our discussion
use this method to deal with the counting problems in the comput probabilities.
Copyright © 2015 Boubacar Abba. This is an open access article distributed under the Creative Commons Att distribution, and reproduction in any medium, provided the original work is properly cited.
INTRODUCTION
In the model of A-code the transmitter and the receiver are both honest and believe each other because they use the same encoding rules. So this system cannot protect the
between them. For example when the receiver receives nothing, he can say he had received some legal information (because the receiver knows the encoding rule he can easily make a false information like this). Simil
receiver receives legal information, he can also say that he had received other information. In the condition of these two things, the transmitter can only think that the opponent succeeds in his attack. Moreover, when the transmitter se piece of information, he can also say that he had never sent an information. During this time, the receiver can only regard that the opponent succeeds in the attack of the system. Then it is natural to see some disputes will occur between the transmitter and the receiver. However, it is not always the case that two parties want to trust each other. Inspired by this problem. Simmons introduced an extended model, called the A
*Corresponding author: Boubacar Abba,
Department of Mathematics and Informatic, University of Science, Technics and Technologies, Bamako BP:E3206, Mali
ISSN: 0975-833X
Article History:
Received 28th February, 2015 Received in revised form 23rd March, 2015 Accepted 05th April, 2015 Published online 31st May,2015
Key words:
Authentication code with arbitration, Symplectic Spaces,
Finite Field.
Citation:Boubacar Abba, 2015. “New construction of A
Current Research, 7, (5), 16459-16467.
RESEARCH ARTICLE
NEW CONSTRUCTION OF A
2-MODEL FROM SYMPLECTIC SPACES OVER FINITE FIELD
*Boubacar Abba
of Mathematics and Informatic, University of Science, Technics and Technologies,
Bamako BP:E3206, Mali
ABSTRACT
Many mathematicians have worked in this erea by using classical groups, normal form
some known vector spaces and came out some good results. But few of them have used symplectic spaces to construct authentication codes with arbitration. Then in this paper we give a new construction of authentication code with arbitration based on sympletic spaces and also compute parameters and probabilities from this code. The main objective of studying authentication codes with arbitration is to use them for the provision of better security in practical information communications. first part of this paper, we present and study the concept of authentication code with arbitration. The historical perspective of the development of authentication code with arbitration is also presented. In the part two of this paper some essential conceptions of symplectic spaces
, which constitute the basic of this paper are introduced. In the same way
, then parameters and probabilities of authentication code with arbitration are easily computed. In part three a new construction of authentication code with arbitration from symplectic geometry presented. In our discussion, we describe the subspaces geometrical characteristics with matrices and use this method to deal with the counting problems in the comput
probabilities.
is an open access article distributed under the Creative Commons Attribution License, which distribution, and reproduction in any medium, provided the original work is properly cited.
code the transmitter and the receiver are both honest and believe each other because they use the same encoding rules. So this system cannot protect the deception between them. For example when the receiver receives nothing, he can say he had received some legal information (because the receiver knows the encoding rule he can easily ). Similarly, when the he can also say that he had received other information. In the condition of these two things, the transmitter can only think that the opponent , when the transmitter sends a lso say that he had never sent any , the receiver can only regard that the opponent succeeds in the attack of the system. Then it is natural to see some disputes will occur between the transmitter is not always the case that two Inspired by this problem.
Simmons introduced an extended model, called the A2-code
Department of Mathematics and Informatic, University of Science, Technics and Technologies, Bamako BP:E3206, Mali
model in which there is a fourth person
this model, caution is taken against deception by the transmitter and the receiver as well as that by the opponent. The arbiter has access to all key information of the transmitter and the receiver, and solves disputes between them. Then there are essentially five different kinds of cheating, impersonation by the opponent, substitution by the opponent, impersonation by the transmitter, impersonat
substitution by the receiver. So let us give first a mathematical description of authentication code with arbitration.
Definition
Suppose that S , M , ET , ER
:
Tg S
E
M
andh
: M E
S
{
reject
}
two maps , the six tuplet ,(S , M , E authentication code with arbitration or A
(1)
g S
:
E
T
M
is surjective and satisfies( , T) ( ', T) '
g s e g s e ss where (2) h: M E RS{reject} have g s e( , T)mh m e( , R)s
International Journal of Current Research
Vol. 7, Issue, 05, pp.16459-16467, May, 2015
INTERNATIONAL
2015. “New construction of A2-model from Symplectic spaces over finite field”,
MODEL FROM SYMPLECTIC SPACES OVER FINITE FIELD
of Mathematics and Informatic, University of Science, Technics and Technologies,
Many mathematicians have worked in this erea by using classical groups, normal form of matrices or . But few of them have used symplectic Then in this paper we give a new ased on sympletic spaces and also compute parameters and probabilities from this code. The main objective of studying authentication codes with arbitration is to use them for the provision of better security in practical information communications. , we present and study the concept of authentication code with arbitration. The historical perspective of the development of authentication code with arbitration is also eptions of symplectic spaces over finite , which constitute the basic of this paper are introduced. In the same way several theorems are , then parameters and probabilities of authentication code with arbitration are easily computed. ee a new construction of authentication code with arbitration from symplectic geometry is , we describe the subspaces geometrical characteristics with matrices and use this method to deal with the counting problems in the computation of parameters and
ribution License, which permits unrestricted use,
which there is a fourth person, called an arbiter. In this model, caution is taken against deception by the transmitter and the receiver as well as that by the opponent. ll key information of the transmitter and the receiver, and solves disputes between them. Then there are essentially five different kinds of cheating, impersonation by the opponent, substitution by the opponent, impersonation by the transmitter, impersonation by the receiver and substitution by the receiver. So let us give first a mathematical description of authentication code with arbitration.
R are four non-empty sets , let
: M E
R{
}
h
S
reject
be totwo maps , the six tuplet ,(S , M , ET , ER , g ,h )is called an
authentication code with arbitration or A2-code if
is surjective and satisfies
( , ) ( ', ) '
g s e g s e s s where
m
M
s s, 'S e, TET: M E { }
h S reject satisfies:
P e e
(
T,
R)
0
, we( , ) ( , )
g s e mh m e swhere
s
S
andm
M
. INTERNATIONAL JOURNAL OF CURRENT RESEARCHS , M , ET , ER denote respectively the set of source states, the
set of all possible messages , the set of all encoding rules of transmitter , the set of encoding rules of receiver. The two map g and h are respectively encoding and decoding functions. If g(s,eT) = m we say that m is obtained by eT encoding s and that
eT is contained in m, and if h(m,eR) = s, we say that eR is
contained in m. The cardinals |S|. |M|, |ET|, |ER| are called
parameters of the A2-code. In this model, the transmitter and the receiver are not mutually trust worthy, and hence disputes between them may occur, In order to solve possible disputes between the transmitter and the receiver , a fourth participant called arbiter is introduced. The arbiter has access to all key information and by definition, he doesn’t cheat. He is only present to solve possible disputes and does not take part in any communication activities. Code for this model provide protection against deceptions both from an outsider (opponent) and from the insiders (transmitter and receiver). Recall that we only consider unconditional security, i.e., against attacks performed with unlimited computing power. As in A-code the transmitter wants to send some information, called a source state , to the receiver in such a way that the receiver can both recover the transmitted source state and verify that the transmitted message originates from the legitimate transmitter. The source state s , taken from the set S of possible source states , is encoded by the transmitter into a message m from the lager set M of possible messages. The message m is subsequently transmitted over the channel. The mapping from S to M is determined by transmitter’s secret encoding rule eT,
chosen from the set ET of possible encoding rules . We may
assume that the transmitter uses a mapping g S: ET M .
The mapping g satisfies
g s e
( ,
T)
g s e
( ',
T)
s
s
'
. Inother words, the source state can be recovered uniquely from a transmitted message. The mapping g is deterministic, i.e., a source state cannot be mapped into several messages for a given encoding rule (splitting is not allowed). This restriction is made for simplicity and most results that will be derived are also valid for A2-model that use splitting. As usual, the opponent has access to the channel in the sense that he can either impersonate the transmitter and send a message, or replace a transmitted message with a different one. The receiver must decide whether a received message is valid or not. For this purpose the receiver uses a mapping, determined by his own secret encoding rule eR, taken from the set ER of
possible encoding rules, that determines if the message is valid, and if so, also the source state. . So we may assume a
mapping
h
: M E
R
S
{
reject
}
, where for all possible(eT, eR), i.e., P e e(T, R)0, we have g s e( , T)mh m e( , R)s.
For the receiver to accept all legal messages from the transmitter and to translate them to the correct source state, property (2) must hold for all pair (eT, eR). However, in general
not all pairs (eT, eR ) will be possible, i.e., have a positive
probability. The arbiter is the supervisory person who has access to all information, including eT and eR, but does not take
part in any communication activities on the channel. His only task is to solve possible disputes between the transmitter and the receiver whenever such occur. This is done in the following way. If the message m, received by the receiver, could have been generated by the transmitter according to his encoding
rule eT , then the arbiter decides that the message m was sent
by the transmitter, and otherwise not. The arbiter assumed to be honest.
In the authentication code with arbitration the following five type of cheating attacks are considered.
Attack I (Impersonation by the opponent). The opponent sends a message to the receiver and succeeds if this message is accepted by the receiver as authentic/
Attack S (Substitution by the opponent). The opponent observes a message that is transmitted and replaces this message with another. The opponent is successful if the other message is accepted by the receiver as authentic.
Attack T (Impersonation by the transmitter). The transmitter sends a message to the receiver and then denies having sent it. The transmitter succeeds if the message is accepted by the receiver as authentic and if this message is not one of the messages that the transmitter could have generated according to his encoding rule.
Attack R0 (Impersonation by the receiver). The receiver
claims to have received a message from the transmitter. The receiver succeeds if this message could have generated by the transmitter according this encoding rule.
Attack R1 (Substitution by the receiver). The receiver receives
a message from the transmitter, but claims to have received another message. The receiver succeeds if this message could have been generated by the transmitter according to this encoding rule.
All parameters in the model except the actual choices of encoding rules are public information. In all possible attempts to cheat it is understood that the cheating person uses an optimal strategy when choosing a message, or equivalently, that the cheating person chooses the message that maximizes his chances of success. For the five types of deceptions, we denote these cheating probabilities by PI , PS , PT , PR0 , PR1
respectively. The overall probability of deception is denoted by PD and is defined to be
P
D
max{ ,
P P P P
I S,
T,
R0,
P
R1}
. Lot of authors used geometry of classical groups and normal form of matrices , involutions and idempotents over finite field to construction cartesian authentication codes and authentication codes with arbitration. In this paper we will use symplectic space over finite fields Fq to construct an authentication codewith arbitration and compute the parameters and the probabilities of successful attacks in this construction.
2. Preliminaries: Let Fq , q is a power of odd prime , denote a
finite field , and consider
( ) ( )
0
0
v
v
I
K
I
The symplectic group of degree 2v over the finite field Fq is
V2v(Fq) be the 2v-dimensional row vector space over Fq. There
is a group action of Sp2v(Fq ) on V2v(Fq) defined as follows:
2v
(
q)
2v(
q)
2v(
q)
V
F
Sp
F
V
F
1 1 2 1 2
(( ,...,
x
x x
v,
v,....,
x
v), T)
( ,....,
x
x
v,....,
x
v)
T
The vector space V2v(Fq) together with the above group action
of symplectic group Sp2v(Fq) is called the 2v-dimensional
symplectic space over Fq with respect to K. Let P be an
m-dimensional vector subspace of
V
2v(
F
q)
. We often use the same letter P to denote a matrix representation of the vectorsubspace P , i.e., P is an
m
2
v
matrix of rank m whose rowsform a basis of P. It is easy to see that
PK P
t is an alternate matrix. Let the rank ofPK P
t be 2s, then we call the vectorsubspace P a subspace of type (m,s). Clearly
s
v
and2s
m
.From Dieudonne’s generalization of Witt’s theorem itfollows that two subspaces belong to the same orbit under Sp2v(Fq) if and only if they are of the same type. It can be
prove that the type (m, s) of a subspace satisfies the following
inequality :
2s
m
v
s
and that for any pair ofnonnegative integers (m, s) satisfying the above inequality there exist subspaces of type (m, s). Thus the number of orbits of subspaces under Sp2v(Fq) is equal to the number of pairs of
nonnegative integers (m, s) satisfying the above inequality . We computed that le latter is equal to 12
(
v
1)(
v
2)
. By the same way we mention that the length N(m , s , 2v) of the orbit of subspaces of type (m , s) of V2v(Fq) is given by
2
2 ( ) 1
2 2
1 1
( 1) ( , , 2 )
( 1) ( 1)
v i
s v s m i v s m
s m s
i i
i i
q N m s v q
q q
In particular, subspaces of type (m, 0) are called m-dimensional totally isotropic subspaces and subspaces of type (2s, s) are called 2s-dimensional non-isotropic subspaces . It is clear that a subspace P is totally isotropic if and only if
PK P
t =0, and it is non-isotropic if and only ifPK P
t is nonsingular.Two vectors x and y of V2v(Fq) are said to be orthogonal (with
respect to K ) , if
xK y
t
0
.Furthermore, for any subspaceP, define
P
{
y V
2v(
F
q) | yK x
t
0
for allx
P
}
.Lemma 2.1 Let
2
ij m v
A
a
and
1 2
ij m v
B
b
denotem-dimensional and m1-dimensional subspaces respectively. Then
the subspace A is contained in the subspace B iff there is an
1
m m
matrix Q such thatA QB
andm
m
1.Furthermore A and B represent same subspace if there is an
m
m
(note m = m1) invertible matrix Q such that A=QB.Lemma 2.2 Let V be a 2v-dimensional symplectic space over
Fq and P a subspace of type (m, 0) (
m
v
) in V. ThenP
contains a 2(v-m)-dimensional symplectic subspace Q which satisfies
Q
P
0
.Proof Let a1,….,am be a basis of P. Then there exist b1,….,bm
in V such that
b Kb
i tj
0,
b Ka
i ij
0
(i
j
) andb Ka
i it
1
.And we have
V
a b
1,
1
....
a b
m,
m
W
. It is clearthat
W
P
andP
P
. Note thatW
P
andP
bothhave dimension 2v-m . So
W
P
P
, and W is the2(v-m)-dimensional symplectic subspace contained in
P
whichsatisfies that
Q
P
0
.3.Construction of an A2-model
Let
n
2
v
,m m
,
0
satisfy1
m
0
m
v
.Let be
P
0 a fixed subspace of type(
m
0, 0)
inV
2v(
F
q)
, and1
P
a fixed(
m
0
1)
-dimensional subspace contained inP
0. Define the set of all source states S = {s|s is a subspace of type (m , 0) containingP
0 inV
2v(
F
q)
}, the set of all possible messagesM
{ |
is a subspace of type(
m
m
0, 0)
in2v
(
q)
V
F
and
P
0is a subspace of type (m , 0 ) inV
2v(
F
q)
}, the set of all encoding rules of the transmitter{
|
T T T
E
e
e
is a complementary subspace ofP
0 in2v
(
q)
V
F
},the set of all encoding rules of the receiver
{
|
R R R
E
e
e
is a complementary subspace ofP
1in2v
(
q)}
V
F
The encoding map
f
is defined as :f s e
( ,
T)
s
e
T , forall
s
S
ande
T
E
T, the decoding mapg
is defined as :0
(
0)
( ,
)
,
.
R R
P if
P
e
g
e
reject otherwise
To prove the above construction is indeed an A2-model we need the following lemma.
Lemma 3.1:Let s be a subspace of type (m, 0) in
V
2v(F )
q which containsP
0, ande
Ta complementary subspace ofP
0in2v
(F )
qV
. Thens
e
T is a subspace of type(
m
m
0, 0)
such that
(
s
e
T)
P
0is a subspace of type (m , 0).Proof Suppose the dimension of
s
e
Tisl
anda
1,....,
a
l it’s basis . Let0
1
,...,
mb
b
be a basis ofP
0. Sinces
e
Tiscontained in the complementary subspace of
P
0,0
1
,...,
mb
b
,1
,....,
la
a
are linearly independent. On the other hand ,0
1
,....,
m, ,....,
1 lb
b
a
a
s
, we havem
0
l
m
, i.e.,0
Extend the basis
0
1
,...,
mb
b
ofP
0to a basis0
1
,...,
mb
b
,0
1
,....,
m ma
a
of s ifa
i
e
T, writinga
iasa
i
x
y
where0
x
P
andy
e
T, sinceP
0
e
T
V
2v(
F
q)
, we may findi
y
a
x
s
. Replacea
iby y, we obtain a new basis0
1
,...,
mb
b
,a
1,....,
a
i1, y,a
1 1,....,
a
m m 0of s. In this way we may choosea
i(1
i
m m
0)
such thata
i
e
T. Then0
1
,....,
m m Ta
a
s
e
anddim(
s
e
T)
m
m
0.Above all,
dim(
s
e
T)
m
m
0. And the proof impliesthat
0
1
,....,
m m Ta
a
s
e
, ands
(
s
e
T)
P
0. It is obvious thats
e
Tis a subspace of type(
m
m
0, 0)
and0
(
s
e
T)
P
is a subspace of type (m, 0).Theorem 3.2 The construction provides us an A2-model
Proof Let us verify the two conditions in the definition of authentication code with arbitration or A2-model.
(1) f is surjective. In fact, for any
M
,
is a subspace of type(
m
m
0, 0)
and
P
0is a subspace of type ( m , 0 ) in2v
(F )
qV
(this implies that
P
0
0
and there is acomplementary subspace
'
ofP
0such that
'
). Let0
s
P
, thens
S
. For any complementary subspacee
Tof
P
0containing
,s
e
T
. Then we haves
e
T
and
f s e
( ,
T)
by Lemma 3.1.For any
M
,e
T
E
T, ifs s
1,
2
S
such that1 2
( ,
T)
( ,
T)
f s e
f s e
then by the proof oflemma 3.1we have
s
1
s
2(2) It is clear that
P e e
(
T,
R)
0
. Letf s e
( ,
T)
,0
(
P
)
e
R
. Theng
( ,
e
R)
P
0 by thedefinition of
g
andg
( ,
e
R)
s
by the proof of lemma 3.1 .3.1 Computation of parameters
Proposition 3.1.1 The number of source states is given by the following
0
2 1
1 1
( 1)
| |
( 1)
v m i i v m
i
q S
q
Proof Let
N m
'(
0, 0; , 0; 2 )
m
v
denote the number ofsubspaces of type
( , 0)
m
containing a fixed subspace of type0
(
m
, 0)
inV
2v(
F
q)
. Then we may prove that| |
S
0
'(
, 0; , 0; 2 )
N m
m
v
, so we need to give this lemma.Lemma 3.1.2 Let
P
be a k-dimensional subspace inV
2v(
F
q)
anda
1,...,
a
ka basis ofP
. Extenda
1,...,
a
k to a basis1
,...,
ka
a
,a
k1,...,
a
2vofV
2v(
F
q)
. Then any complementary subspace ofP
inV
2v(
F
q)
has a matrix representation as
A
(2v k )kI
(2v k )
on the above basis , whereA
(2v k )kisdetermined uniquely by the complementary subspace of
P
.Proof Let
C
C
1C
2
where C1 and C2 are(2
v k
)
k
and(2
v k
) (2
v k
)
matrices respectively denote the matrix representation of a complementary subspaceQ
ofP
inV
2v(
F
q)
with respect to the basisa
1,...,
a
k,1
,...,
2k v
a
a
. We claim that C2 is invertible. Otherwise , noloss generality, suppose its first row is a linear combination of other rows ( let
be the row vector of representationcoefficients ), then we have
1 2
3 4
0
1
0
1
C
C
C
C
. Note that
3 4
0
C
C
is full rank on rows, so
0
. Let
1 1
2
0
v k
a
a
X
a
a
ThenX
0
andX
P
Q
. ButP
Q
{0}
, this a contradiction , henceC2 is invertible . Thus
1
2 1 2
C
C
C
A
I
is also arepresentation of
Q
.Suppose that
A I
and
A
1I
both representQ
, thenthere is an invertible matrix D such that
A I
D A
1I
, i.e.,
A
I
DA
1D
, it isobvious that
D
I
, soA
is determined uniquely byQ
.Proposition 3.1.2 The number of encoding rules of the
transmitter is
|
| q
m0(2v m0)T
E
Proof From lemma 3.1.2 we know that
e
T
E
Thas a matrixrepresentation as the form
0 0 0
(2v m) m (2v m)
A
I
where0 0
(2v m) m
A
is uniquely determined bye
T. Then we have theconclusion.
Proposition 3.1.3 The number of encoding rules of the
receiver is
|
|
(m0 1)(2v m0 1)R
Proof From Lemma 3.1.2 we know that
e
R
E
R has a matrixrepresentation as the form
0 0 0
(2v m 1) (m 1) (2v m 1)
A
I
where
0 0
(2v m 1) (m 1)
A
is uniquely determined bye
R. Then wehave the result.
Proposition 3.1.4 The number of messages is computed by
0
0 0 0
2
( ) 1
1
(
1)
|
|
(
1)
v m im m m i v m m m i i
q
M
q
q
Proof Given a message
M
, we know that
P
0
{0}
and the source state corresponding to
is
P
0by definitionof
M
and Theorem 3,2. Let0
1
,....,
ma
a
a basis ofP
0, and0 1
,...,
m m
a
a
a basis ofM
. Then0
1
,....,
ma
a
,0 1
,...,
m m
a
a
is a basis of
P
0. Extend this basis to a basis0
1
,....,
ma
a
,0 1
,...,
m m
a
a
,a
m1,...,
a
2v ofV
2v(
F
q)
. Then
has a representation
0
( )
0 Im m 0 on the above basis. By lemma3.1.2,
an encoding rule
e
T of the transmitter which contains
has arepresentation
0 0 0
(2v m ) m (2v m)
A
I
where0 0
(2v m) m
A
isuniquely determined by
e
T. Rewrite
A I
as0 ( )
( 2 )
0 0 0 0 m m v m I B I C
. Note that
e
T, by Lemma 2.1,there is a matrix
Q
1Q
2
such that
0
( )
0
I
m m0
=
( 0)1 2 (2 ) 0 0 0 0 m m v m I B Q Q I C
=
Q A Q B Q1 2 1 Q2
It isobvious that
Q
1
I
,Q
2
0
and thusB
0
. So anyencoding rule
e
T contained in
has a representation0 ( ) (2 )
0
0
0
0
0
m m v mI
I
C
on the above basis and the number
of encoding rules of the transmitter , which contained in
is0(2 )
q
m v m . Since0( 2 )
|
||
|
| M |
Tm v m
S
E
q
, we get the consequence.3.2 Computation of probabilities
Proposition 3.2.1 The probability of a successful
impersonation attack is
0 0
( 1)( )
1
I m m m
P
q
Proof From the definition of the message set (set of all
possible messages), any
message satisfies that0
{0}
P
and that
P
0is a source state correspondingto
(see the proof of Theorem 3.2).Let
0
1
,....,
ma
a
a basis ofP
0such that0
1
,....,
m 1a
a
is a basisof
P
1and extend it to a basis0
1
,....,
m 1a
a
,0
m
a
,0 1
,....,
m m
a
a
of
P
0 such that0 1
,....,
m m
a
a
is a basis of
. At last extend this basis of
P
0to a basis0
1
,....,
m 1a
a
,0
,....,
m m
a
a
,a
m1,....,
a
2v ofV
2v(
F
q)
. Then
has a matrix representation
0
(m m 0) (m01)0
(m m 0) 1I
(m m 0)0
(m m 0) (2 v m )
on the above basis. Applying Lemma 3.1.2 we know that
e
Rwhich is contained in
( i.e.,
e
R) must have arepresentation in the form
0 0 0
(2v m 1) (m 1) (2v m 1)
A
I
,where
0 0
(2v m 1) (m 1)
A
is determined uniquely bye
R. Block itinto
0
3
( )
(2 )
1 0 0
0 0 0 0 m m v m A I B I
. Since
e
R, we know that
0 0
I
0
is a linear combination of rows of0 3
( ) ( 2 )
1 0 0
0 0 0 0 m m v m A I B I
. Thus we may get
A
0
and thenumber of
e
R in
isq
(m01)(2v m 1)(i.e., the number of3
B
). Then
m ax | | R I M R
the number of e in P E 0 0 0
( 1)( 2 1)
( 1)( 2 1)
m v m
m v m
q
q
0 0( 1 )( )
1
m m m
q
To compute other probabilities , choose
0
1
,....,
ma
a
a basis of0
P
such that0
1
,....,
m 1a
a
is a basis ofP
1 . By lemma 3.1 weknow that
P
0
P
0
W
where W is 2(v-m0 )-dimensionalsymplectic subspace in
V
2v(
F
q)
Let
0
1
,...,
2(v m)
be a basis of W, then0
1
,....,
m 1a
a
a
0, ,0
1
,...,
2(v m)
is a basis ofP
0
. Extend it to a basis
0
1
,....,
m 1a
a
,a
0,0
1
,...,
2(v m)
,0 0
2(v m) 1,..., 2v m
V2v(F . q)Then
P
0has a matrix representation ( 1) 0 0 01 0 0
0
m
I
on this
basis. For any source state
s
S
, sinceP
0
s
ands
P
0,s
has a matrix representation0 ( 1)
2 2
0 0 0
0 0 0 0
0
m
I
X X X
, where
X
is a
(
m
m
0) [2(v m )]
0 matrix on this basis .Furthermore
1 2 1 2
0 0 0 0 0 0 0 0
0 1 0 0 1 0 0 0 1 0 0
0 0 0 0
I I I
X X I X X X X
.
So the matrix representation of s on the basis should be
0
0
0
0 1
0
0
0
0
0
I
X
, where
0 0
X
0
denotes asubspace of type
(
m
m
0, 0)
inV
2v(
F
q)
. For anye
T
E
Tand
e
R
E
R, we know that they have a matrix representation0 0 0
0 0 0
2( ) ( 1) 2( )
( 1)
0
0
v m m v m
m
m m
A
I
I
C
and
0 0 0
0 0 0
2( ) ( 1) 2( )
( 1)
1
0
0
0
0
0
0
v m m v m
m
m m
B
I
I
D
respectively by lemma
3.1.2
For any
M
, since
P
0
P
0
W
,
has a matrixrepresentation
0 0 0 0
(m m ) (2v m)
0
(m m ) mY
on this basis.Because
P
0has a matrix representation0
( 1)
1 2
0
0
0
0
1
0
0
0
m
I
X
X
X
on this basis , we may think the
source state which corresponds to
is a subspace with therepresentation
0
0
0
0 1
0
0
0
0
0
I
X
where
0 0
X
0
denotes a subspace of type
(
m
m
0, 0)
.Proposition 3.2.2 The probability of a successful substitution
attack is
0 1
1
S m
P
q
Proof Let
and
’ be two messages corresponding todifferent source states, and
X
1X
2X
0
and
X
1'
X
2'
X
' 0
the matrix representation of
and
’respectively , where X and X’ are two different subspaces of
type
(
m
m
0, 0)
in W. It is obvious that rank0
1
'
X
m m
X
. Let
e
R be the encoding rule of receivercontained in
and
’(that is to say ,
e
Rand
'
e
R).So the subspace represented by
X
1X
2X
0
iscontained in a subspace represented by
0 0 0
0 0 0
2( ) ( 1) 2( )
( 1)
1
0
0
0
0
0
0
v m m v m
m
m m
B
I
I
D
. Then there exist a
matrix
Q
1Q
2Q
3
such that
X
1X
2X
0
=
Q
1Q
2Q
3
0 0 0
0 0 0
2( ) ( 1) 2( )
( 1)
1
0
0
0
0
0
0
v m m v m
m
m m
B
I
I
D
=
Q1Q B Q D Q2 3 1 Q2 Q3
. We have
X1 X2 X 0
=
X2
XB X2 X 0
. Similarly
X
1'
X
2'
X
' 0
=
X
2'
X B
'
X
2'
X
' 0
.Combining the two equalities, we have 2 1
' '
2 1
'
X X
X B
X X
X
, i.e., 1 2
' '
1 2
'
X X
X B
X X
X
. From ranck
0
1
'
X
m m
X
we know that the dimension of the
solution space of
0
'
tX
X
is less than or equal to
0 0 0
2(
v
m
) (
m
m
1)
2
v
m
m
1
. For a fixed
, a column of B as a solution of the system of non-homogeneous linear equations may haveq
(2v m m 01)choicesat most , so there are at most
0
01 (2v m m 1) m
q
choices forB.Thus the number of
e
Rin
and
’ is at most0 0 0 0 0 0
(m 1) (m 1)(2v m m 1) m (m 1) (m 1)(2v m)
number of B D
). From the process of PI’s calculation we know
that the number of encoding rules
e
R , which is contained inmessage
isq
(m01)(2v m 1). Therefore'
max { R '}
S M
R
the number of e in and
P max
thenumber of e in
0
0
( 1)(2 ) ( 1)(2 1)
m v m
m v m
q
q
0 1
1
m
q
.Lemma 3.3.3 Let
0
0
0
0 1
0
0
0
0
0
I
X
denote a source state s ,
0
0
2( )
0
0
v mm
I
A
I
C
a encoding rule
e
Tand0 0 0
0 0 0
2( ) ( 1) 2( )
( 1)
1
0
0
0
0
0
0
v m m v m
m
m m
B
I
I
D
an encoding rule
e
R.Then
(1) The message obtained by
e
Tencoding s ( that is theintersection of the subspaces that
e
T and s represent) has amatrix representation
XA
X
X
0
;(2) The subspace
e
R
s
has a matrix representation1
0
0
0
0
XB
X
.
Proof Let
Y
1Y
2Y
0
be a matrix representation of themessage
obtained bye
T encoding s. Since
e
T, bylemma 2.1 there is a matrix
Q
1Q
2
such that
Y
1Y
2Y
0
=
Q
1Q
2
0
0
2( )
0
0
v mm
I
A
I
C
=
Q A Q C
1
2Q
1
Q
2
Q
1Q
2
So
Q
1
Y Q
,
2
0
, and
Y
1Y
2Y
0
=
YA Y
Y
0
. On the other hand
s
, by lemma2.1 there is a matrix
D
1D
2D
3
such that
YA Y
Y
0
=
D
1D
2D
3
0
0
0
0 1
0
0
0
0
0
I
X
.
So
D
1
YA D
,
2
Y
andD X
3
Y
. Since X and Y arefull rank in rows , D3 is invertible. Thus
Y
1Y
2Y
0
=
YA Y
Y
0
=
D XA
3D X
3
D X
30
=
3
0
D XA
X
X
Since D3 is invertible, the message
has a matrixrepresentation
YA Y
Y
0
. The proof of (2) issimilar so that of (1)
Lemma 3.3.4 Given an encoding rule
e
T of transmitter, thenumber of encoding rules
e
Rof receiver contained ine
T is0 0
(m 1)(m 1)
q
’ and given an encoding rulee
Rof the receiver,the number of the related encoding rules
e
T of the transmitteris
2 0 0
2(v m) m
q
.Proof That
e
T ande
R are relative means that any messagegotten from a source state s encoding by
e
Tcan pass throughthe authentication
e
R. That is so to say, any message
XA
X
X
0
obtained bye
T encoding s =0
0
0
0 1
0
0
0
0
0
I
X
(where
0 0
X
0
is a subspace oftype
m m
00
in W) is contained in a subspace1
0
0
0
0
XB
X
. By lemma 2.1 there is a matrix
Q
1Q
2
such that
XA
X
X
0
=
Q
1Q
2
1
0
0
0
0
XB
X
=
Q
1
Q XB Q
2 1Q X
20
. So1
Q
X
andQ X
2
X
. Further, we have(
)
XA
X B
( note that
is2(
v
m
0) 1
matrix and
is a1 (
m
0
1)
matrix ). Since the block X in the matrix0 0 0 0 1 0 0 0 0 0 I
X
may take the form
0 0
( ) 2( )
1 i
m m v m
o o o
X
o
where 1 runs over every column on the first row ( note that
0 0
X
i0
is a totally isotropic subspace in W ), wehave that the