Paper 2026/646

On Optimal Information-Theoretic Security in Symmetric Encryption under Low-Entropy Keys

Haibo Cheng, Minzu University of China, Peking University
Haijie Su, Peking University
Dongyi Li, Peking University
Wenting Li, Beijing Institute of Graphic Communication
Ping Wang, Peking University
Kaitai Liang, University of Turku
Abstract

Low-entropy keys such as passwords and biometrics are pervasive, yet classical information-theoretic guarantees, such as perfect secrecy and entropic security, cannot generally be achieved in this regime. Honey encryption (HE) and homophonic ciphers (HC) tailor encryption to the message distribution to provide meaningful security, but their analyses do not establish optimal guarantees for arbitrary distributions. We ask: for messages and keys drawn independently from arbitrary distributions $(p_{\mathrm m},p_{\mathrm k})$, what is the optimal information-theoretic security achievable by any symmetric encryption scheme, and which conditions characterize its attainment? For key confidentiality (KC), the optimal guarantee is that the ciphertext $C$ reveals only negligible information about the key $K$, i.e., $I(K;C)=\operatorname{negl}(\ell)$. For uniform schemes, this is achieved if and only if decrypting under every fixed key yields a distribution statistically close to $p_{\mathrm m}$. HC and HE achieve this guarantee. For message-recovery security (MRS), the optimal guarantee is that no adversary guesses the message with probability above $p_{\max}+\operatorname{negl}(\ell)$, while a trivial adversary achieves at least $p_{\max}$ by guessing the most likely message or decrypting under the most likely key. We construct MRS-OE, a uniform scheme tailored to $(p_{\mathrm m},p_{\mathrm k})$ that attains $p_{\max}+O(2^{-\ell})$, and prove that $p_{\mathrm k}$-agnostic schemes, including HC and HE, cannot achieve optimal MRS in general. We also show that optimal KC and optimal MRS generally cannot be achieved simultaneously. Technically, we establish the KC characterization through flow and cut analysis on a weighted directed acyclic graph. We also introduce a continuous-ciphertext framework that separates structural constraints from discretization error.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
information-theoretic securitylow-entropy keysprobabilistic encryption
Contact author(s)
hbcheng89 @ gmail com
History
2026-09-20: last of 2 revisions
2026-04-02: received
See all versions
Short URL
https://ia.cr/2026/646
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/646,
      author = {Haibo Cheng and Haijie Su and Dongyi Li and Wenting Li and Ping Wang and Kaitai Liang},
      title = {On Optimal Information-Theoretic Security in Symmetric Encryption under Low-Entropy Keys},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/646},
      year = {2026},
      url = {https://eprint.iacr.org/2026/646}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.