Papers
Topics
Authors
Recent
Search
2000 character limit reached

Bilinear Compressive Security (BCS)

Updated 24 October 2025
  • Bilinear Compressive Security is a cryptographic framework that embeds random convolution into linear compressive measurements, substantially complicating key recovery for adversaries.
  • It employs a two-step process—first encoding with a fixed measurement matrix followed by a per-transmission random convolution—to introduce effective ciphertext ambiguity.
  • The framework enables efficient decryption via blind deconvolution and is particularly suited to applications like IoT where energy and computational efficiency are critical.

Bilinear Compressive Security (BCS) is a cryptographic framework designed to enhance the security of compressed sensing–based systems by embedding the key-dependent linear measurement into a bilinear (typically convolutional) structure, thereby robustly safeguarding against known plaintext attacks even under adversary-favorable conditions such as repeated transmissions and plaintext observability (Flinth et al., 17 Oct 2025). Unlike conventional compressive security, which encodes a sparse signal xx with a secret matrix QQ as y=Qxy=Qx, BCS conjoins this embedding with a random convolution filter hh per transmission, resulting in ciphertext y=h∗Qxy = h * Qx. The critical insight is that the additional bilinear mixing complicates key recovery for the adversary, rendering standard attacks insufficient and forcing a substantial increase in required attack complexity.

1. Augmenting Linear Compressive Security: Motivations and Foundations

Traditional compressive security schemes employ a fixed, secret, complex measurement matrix Q∈Cm×nQ \in \mathbb{C}^{m \times n} to linearly encode sparse messages x∈Cnx \in \mathbb{C}^n, achieving security comparable to a one-time pad if QQ is changed for every message (Flinth et al., 17 Oct 2025). However, the reuse of QQ fundamentally undermines security: nn independent plaintext–ciphertext pairs suffice for an adversary to reconstruct QQ0 in full. Bilinear Compressive Security is introduced to address this limitation by integrating a second layer—random convolution with QQ1—thereby increasing the ambiguity in the ciphertext space and complicating key recovery via injection of independent, distributionally symmetric noise.

2. Encryption Construction and Transmission Protocol

The BCS encryption mechanism comprises two serial operations:

  1. Linear Measurement: Given a fixed (per sender) measurement matrix QQ2 and a sparse message QQ3, form the vector QQ4.
  2. Random Convolution Filter: For each transmission, independently draw a random filter QQ5 from a prescribed distribution QQ6 (often phase symmetric), then compute the ciphertext as

QQ7

where QQ8 denotes (circular) convolution. Equivalently, in the Fourier domain using the convolution theorem,

QQ9

with y=Qxy=Qx0 indicating elementwise multiplication.

This sequential composition ensures that, for each message, the y=Qxy=Qx1-embedding is entangled with an independently randomized filter, resulting in a bilinear relation between the key, message, and per-transmission noise.

3. Security Analysis: Known Plaintext Attacks and Phase Retrieval Reductions

Security against known plaintext attacks is the central theoretical contribution. In standard compressive security, y=Qxy=Qx2 linearly independent y=Qxy=Qx3 pairs uniquely determine y=Qxy=Qx4. In BCS, even an adversary granted complete access to the distributions y=Qxy=Qx5 for known sparse y=Qxy=Qx6 must solve a coupled system of phase retrieval problems. Specifically, under a phase symmetry assumption for y=Qxy=Qx7 (the distribution is invariant under multiplication by unit-modulus complex scalars), the main result (Theorem 4 (Flinth et al., 17 Oct 2025)) establishes:

  • For sparsity y=Qxy=Qx8, recovering y=Qxy=Qx9 from hh0 plaintext–ciphertext pairs demands

hh1

  • If hh2, recovery becomes theoretically impossible: key cannot be determined even up to a unitary phase from any finite hh3.

This result is derived by mapping the key recovery challenge to classical phase retrieval, reduced to injectivity of hh4 up to a global phase. Standard lower bounds for the number of samples needed for phase retrieval then yield the security threshold above.

4. Decryption and Blind Deconvolution Algorithms

The receiver (Bob) reconstructs hh5 from hh6 without knowledge of hh7, resulting in a blind deconvolution problem. Both hh8 and hh9 are assumed sparse, a critical restriction that enables efficient demixing algorithms such as HiHTP (hierarchical hard thresholding pursuit):

  • Bob knows y=h∗Qxy = h * Qx0, receives y=h∗Qxy = h * Qx1, and (assuming knowledge of the sparsity levels) applies sparse blind deconvolution methods to jointly recover y=h∗Qxy = h * Qx2 up to an inherent scaling ambiguity: y=h∗Qxy = h * Qx3 and y=h∗Qxy = h * Qx4 yield the same y=h∗Qxy = h * Qx5 for any y=h∗Qxy = h * Qx6.

Blind deconvolution in the sparse regime is computationally tractable and robust, with recovery correctness guaranteed under standard random matrix and filter assumptions [(Flinth et al., 17 Oct 2025), Theorem 1].

5. Practical Impact and System Integration

BCS confers several practical advantages over classical compressive security methodologies:

  • Energy and Computational Efficiency: The scheme retains the compression and reduced complexity of compressed sensing, making it suitable for resource-constrained environments, notably IoT.
  • Physical Layer Compatibility: The convolution with y=h∗Qxy = h * Qx7 seamlessly accommodates physical channels exhibiting sparse multipath effects, aligning cryptographic processes with natural channel diversity.
  • Dynamic Key Concealment: As y=h∗Qxy = h * Qx8 is regenerated for each transmission and unshared with the receiver, each message is effectively masked, bolstering security against ciphertext aggregation attacks.
  • Key Reuse Security: Unlike the linear case, the same y=h∗Qxy = h * Qx9 may be safely reused for many transmissions, obviating the (otherwise fundamental) need to change encryption keys per message.

6. Theoretical Guarantees and Mathematical Formalism

The mathematical results in BCS quantify both correctness and security. Notably:

  • Correctness: Provided Q∈Cm×nQ \in \mathbb{C}^{m \times n}0 is Q∈Cm×nQ \in \mathbb{C}^{m \times n}1-sparse, Q∈Cm×nQ \in \mathbb{C}^{m \times n}2 is Q∈Cm×nQ \in \mathbb{C}^{m \times n}3-sparse, and Q∈Cm×nQ \in \mathbb{C}^{m \times n}4 is drawn iid random (e.g., Gaussian), algorithms such as HiHTP recover Q∈Cm×nQ \in \mathbb{C}^{m \times n}5 from Q∈Cm×nQ \in \mathbb{C}^{m \times n}6 with high probability and computational efficiency.
  • Security: Under phase-symmetric Q∈Cm×nQ \in \mathbb{C}^{m \times n}7 distributions, recovery of Q∈Cm×nQ \in \mathbb{C}^{m \times n}8 through any number of Q∈Cm×nQ \in \mathbb{C}^{m \times n}9-sparse x∈Cnx \in \mathbb{C}^n0 pairs is infeasible for x∈Cnx \in \mathbb{C}^n1.
  • Phase Retrieval Barrier: The reduction to phase retrieval provides a rigorous lower bound on attack complexity, with the mapping x∈Cnx \in \mathbb{C}^n2 only injective (modulo phase) if x∈Cnx \in \mathbb{C}^n3 spans phase retrieval, known to require x∈Cnx \in \mathbb{C}^n4 samples for x∈Cnx \in \mathbb{C}^n5-sparse vectors.

7. Future Directions and Open Questions

Several avenues for further research are identified:

  • Extension of phase symmetry assumptions to more general or realistic x∈Cnx \in \mathbb{C}^n6 distributions.
  • Design and analysis of practical attack algorithms and evaluation of their empirical limits.
  • Incorporation of modeling errors such as noise, quantization, and physical nonidealities.
  • Analysis of partial recovery scenarios for x∈Cnx \in \mathbb{C}^n7 or x∈Cnx \in \mathbb{C}^n8 given side information.

A plausible implication is that further strengthening the filter randomness and sparsity models would deepen both provable and empirical security bounds, while tailored blind deconvolution developments could extend applicability in high-noise or high-dimensional operational regimes.


Bilinear Compressive Security, by embedding random convolution into compressed sensing, presents a mathematically formalized, practically robust architecture for secure signal transmission in measurement-limited and adversary-rich environments. Its theoretical basis ensures substantially increased attack complexity and practical resilience compared to traditional linear compressive security approaches (Flinth et al., 17 Oct 2025).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Bilinear Compressive Security (BCS).