Probabilistic Disclosure: Maximisation vs. Minimisation

Béatrice Bérard 1, 2 Serge Haddad 3, 1 Engel Lefaucheux 4, 1
2 MoVe - Modélisation et Vérification
LIP6 - Laboratoire d'Informatique de Paris 6
3 MEXICO - Modeling and Exploitation of Interaction and Concurrency
LSV - Laboratoire Spécification et Vérification [Cachan], ENS Cachan - École normale supérieure - Cachan, Inria Saclay - Ile de France, CNRS - Centre National de la Recherche Scientifique : UMR8643
4 SUMO - SUpervision of large MOdular and distributed systems
Inria Rennes – Bretagne Atlantique , IRISA_D4 - LANGAGE ET GÉNIE LOGICIEL
Abstract : We consider opacity questions where an observation function provides to an external attacker a view of the states along executions and secret executions are those visiting some state from a fixed subset. Disclosure occurs when the observer can deduce from a finite observation that the execution is secret, the ε-disclosure variant corresponding to the execution being secret with probability greater than 1 − ε. In a probabilistic and non deterministic setting, where an internal agent can choose between actions, there are two points of view, depending on the status of this agent: the successive choices can either help the attacker trying to disclose the secret, if the system has been corrupted, or they can prevent disclosure as much as possible if these choices are part of the system design. In the former situation, corresponding to a worst case, the disclosure value is the supremum over the strategies of the probability to disclose the secret (maximisation), whereas in the latter case, the disclosure is the infimum (minimisation). We address quantitative problems (comparing the optimal value with a threshold) and qualitative ones (when the threshold is zero or one) related to both forms of disclosure for a fixed or finite horizon. For all problems, we characterise their decidability status and their complexity. We discover a surprising asymmetry: on the one hand optimal strategies may be chosen among deterministic ones in maximisation problems, while it is not the case for minimisation. On the other hand, for the questions addressed here, more minimisation problems than maximisation ones are decidable.
Document type :
Conference papers
Complete list of metadatas

Cited literature [18 references]  Display  Hide  Download
Contributor : Engel Lefaucheux <>
Submitted on : Wednesday, October 18, 2017 - 5:29:45 PM
Last modification on : Thursday, March 21, 2019 - 1:04:26 PM
Long-term archiving on : Friday, January 19, 2018 - 2:17:43 PM


Files produced by the author(s)



Béatrice Bérard, Serge Haddad, Engel Lefaucheux. Probabilistic Disclosure: Maximisation vs. Minimisation. FSTTCS 2017, Dec 2017, Kanpur, India. pp.13:1-13:14, ⟨10.4230/LIPIcs.FSTTXS.2017⟩. ⟨hal-01618955⟩



Record views


Files downloads