2012 IEEE 25th Computer Security Foundations Symposium (2011)

Cernay-la-Ville, France

June 27, 2011 to June 29, 2011

ISBN: 978-0-7695-4365-9

pp: 205-217

DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/CSF.2011.21

ABSTRACT

In this paper, we investigate the computational complexity of quantitative information flow (QIF) problems. Information-theoretic quantitative relaxations of noninterference (based on Shannon entropy)have been introduced to enable more fine-grained reasoning about programs in situations where limited information flow is acceptable. The QIF bounding problem asks whether the information flow in a given program is bounded by a constant $d$. Our first result is that the QIF bounding problem is PSPACE-complete. The QIF memoryless synthesis problem asks whether it is possible to resolve nondeterministic choices in a given partial program in such a way that in the resulting deterministic program, the quantitative information flow is bounded by a given constant $d$. Our second result is that the QIF memoryless synthesis problem is also EXPTIME-complete. The QIF memoryless synthesis problem generalizes to QIF general synthesis problem which does not impose the memoryless requirement (that is, by allowing the synthesized program to have more variables then the original partial program). Our third result is that the QIF general synthesis problem is EXPTIME-hard.

INDEX TERMS

quantitative information flow, verification, synthesis, computational complexity

CITATION

Krishnendu Chatterjee,
Thomas A. Henzinger,
Pavol Cerný,
"The Complexity of Quantitative Information Flow Problems",

*2012 IEEE 25th Computer Security Foundations Symposium*, vol. 00, no. , pp. 205-217, 2011, doi:10.1109/CSF.2011.21