Uniform Secret Protection: Structures & Systems
- Uniform secret protection is a framework that imposes consistent secrecy guarantees across qualified participant sets, execution paths, and adversarial models.
- It encompasses methodologies from k-homogeneous secret-sharing schemes to efficient linear constructions and cost-aware policy synthesis in discrete-event systems.
- The approach also contrasts uniform protection with secret-specific guarantees in privacy-preserving machine learning, balancing utility and security.
The available literature uses the expression “uniform secret protection problem” for several related formulations in which secrecy guarantees are imposed uniformly across qualified participant sets, execution paths, or adversarial conditions. In secret sharing, the problem concerns whether a -homogeneous or -uniform access structure admits an ideal or otherwise efficient realization. In discrete-event systems and labeled Petri nets, it concerns the synthesis of minimum-cost protection policies such that every execution from an initial state to a secret state contains sufficiently many protected events. In information-theoretic and privacy-preserving learning settings, the term is tied to the role of uniformity in password distributions and to the contrast between uniform privacy guarantees and secret-specific protection (Kim et al., 2023, Kim et al., 2021, Rezaee et al., 2017, Masopust et al., 17 Sep 2025, Wang et al., 13 Oct 2025).
1. Access structures and the secret-sharing formulation
A central formulation arises from -uniform hypergraphs. A -uniform hypergraph is a hypergraph where every hyperedge has exactly vertices. A -homogeneous access structure is represented by such a hypergraph, with participants identified with vertices; a set of participants can reconstruct the secret if they are connected by a -hyperedge, while a set of non-adjacent vertices does not obtain any information about the secret (Kim et al., 2023).
This formulation is closely related to what another paper calls a forbidden -homogeneous, or -uniform, access structure. There, the minimal qualified sets are the -hyperedges, and any set of size at least 0 is also qualified. The paper studies efficient linear secret-sharing schemes for these access structures, focusing on total share size rather than ideality (Kim et al., 2021).
Within this literature, the efficiency of a secret-sharing scheme is measured by the information rate, defined as
1
A scheme with information rate equal to one is ideal, and an access structure is ideal if some ideal scheme realizes it (Kim et al., 2023). This makes the secret-sharing version of the uniform secret protection problem a structural classification problem: which uniformly sized minimal qualified sets support ideal or near-ideal sharing, and which do not.
2. Ideality, threshold structures, and the information-rate barrier
The sharpest structural result in the provided literature is the characterization of ideal 2-homogeneous access structures by the independent sequence method. For a 3-homogeneous access structure 4 such that the number of minimal qualified subsets contained in any set of 5 participants is not equal to 6 or 7, the following are equivalent: 8 is a vector space access structure; 9 is an ideal access structure; 0; and the reduced access structure of 1 is a 2-threshold access structure (Kim et al., 2023).
The reduced access structure is obtained by merging equivalent participants, that is, participants indistinguishable with respect to qualified sets. In this setting, the threshold condition is decisive: among the covered class of 3-homogeneous structures, only those whose reduced form is a threshold structure can have information rate exceeding 4, and only those can be ideal (Kim et al., 2023).
The proof uses the independent sequence method. If 5 is an independent sequence with associated minimal set 6, then
7
For the 8-homogeneous structures under consideration, this yields the barrier 9 (Kim et al., 2023). Shamir’s 0-threshold scheme is the canonical positive example: it is 1-homogeneous and ideal. By contrast, other 2-homogeneous structures cannot be ideal unless, after merging equivalent participants, they become threshold (Kim et al., 2023).
This establishes a strong version of uniform protection in the secret-sharing sense. The only 3-homogeneous structures admitting “uniform” ideal protection are threshold structures up to reduction, while all other cases incur a strict information-rate loss (Kim et al., 2023).
3. Efficient linear constructions beyond ideality
When ideality is impossible or not the relevant objective, the problem shifts to explicit efficient constructions. For sparse and dense 4-uniform access structures, linear secret-sharing schemes can be constructed with total share size
5
for constant 6, both in the sparse case 7 and in the dense case 8 (Kim et al., 2021).
The construction proceeds through hypergraph decomposition and monotone span programs. Any 9-uniform hypergraph on 0 vertices can be decomposed into 1 2-partite 3-uniform hypergraphs. Each structured component is then realized by a monotone span program, and every MSP yields a linear secret-sharing scheme for the access structure it accepts (Kim et al., 2021).
The distinction between sparse and dense instances is operationally important. In sparse structures, the number of minimal qualified sets is small; in dense structures, the complement of qualified 4-sets is sparse. The same asymptotic total-share-size expression covers both regimes (Kim et al., 2021). This suggests that, once the ideal/non-ideal dichotomy has been settled structurally, a second layer of the uniform secret protection problem concerns how efficiently one can realize large classes of uniform access structures with linear schemes.
4. Uniformity under entropy and guesswork constraints
A different formulation appears in the study of password guesswork under a total entropy budget. Here the problem is whether choosing secrets uniformly at random gives the best protection once the total Shannon entropy of the chosen word is fixed. The answer depends on the security metric (Rezaee et al., 2017).
For average guesswork, uniformity can be suboptimal. The paper shows that under a fixed total entropy budget, less uniform distributions can lead to higher average guesswork than the uniform distribution, provided the Skewentropy Condition holds. The condition is
5
where 6 is varentropy and 7 is skewentropy (Rezaee et al., 2017). The asymptotic moments of guesswork are controlled by Rényi entropy through
8
In this metric, the uniform source can be the easiest to breach under a fixed total entropy budget (Rezaee et al., 2017).
For adversaries with a total guesswork budget, the conclusion reverses. If the adversary is limited to 9 guesses, then the uniform source gives the lowest probability of successful brute-force guessing under the same total entropy budget. The corresponding large-deviations rate function is
0
and the paper proves that uniformity is optimal for this resource-limited success-probability criterion (Rezaee et al., 2017).
This literature addresses a common misconception: “uniform” need not mean “best protected” unless the threat model and performance metric are fixed. Uniformity is suboptimal for average guesswork, but optimal for limiting an adversary’s success probability under a guesswork budget (Rezaee et al., 2017).
5. Discrete-event systems: pathwise protection and minimum cost
In discrete-event systems, the secret protection problem is formulated as a policy-synthesis problem. A DES is modeled by an automaton, some states are designated as secrets, and multiple subsets of events are protectable at different cost levels. The objective is to ensure that every string reaching a secret state contains a specified number of protectable events, while minimizing the highest cost level required along such strings (Matsui et al., 2019).
The core solvability condition is pathwise. There exists a feasible policy if there is a cost level 1 such that in every path from the initial state to a secret state, at least the required number of events from the protectable classes up to cost 2 are present. The resulting solution is obtained by supervisory control synthesis and specifies, at each state, which events to protect (Matsui et al., 2019).
A usability-aware extension introduces marker states representing services or functions provided to regular users and associates each protectable event level with a usability-aware cost. The requirement becomes: every system trajectory that reaches a secret state must contain a specified number of protectable events with at least a certain security level, and the highest usability-aware cost level of these events is minimum. The paper also extends the framework to heterogeneous secrets with different levels of importance (Matsui et al., 2021).
A distributed extension models global secret information as tuples of local secret states stored across component agents. The security requirement is that at least one piece of every distributed global secret be secured by a required number of protections, while the overall cost is minimum. The solvability condition is again necessary and sufficient, and the proposed DRCMC algorithm runs in polynomial time in the number of agents, secrets, protection levels, cost classes, and automaton state size (Matsui et al., 2024).
These DES formulations make “uniform” protection concrete: the guarantee is quantified over every path to a secret, not merely over a typical or average execution.
6. Complexity of the uniform SPP in automata and Petri nets
The automata-theoretic literature isolates a uniform variant, SPP-U, in which all clearances are unit: 3 for all protectable events. A policy is valid if every run 4 reaching a secret state 5 satisfies
6
The decision problems BC-SPP and BC-SPP-U are NP-complete, and this remains true even if costs and clearance functions are constant, the security requirement function is binary, and there is only one secret state (Masopust et al., 17 Sep 2025).
The same paper strengthens earlier results by showing that the general problem becomes NP-hard as soon as the uniqueness constraint on event labels is removed. It also gives an ILP formulation with variables 7, objective 8, and path constraints of the form
9
Using iterative cut generation, the empirical evaluation handles instances up to 0 states and up to 1-symbol alphabets (Masopust et al., 17 Sep 2025).
A distinct-event variant, 2-SPP, counts only whether a protected event appears in a run, not its multiplicity. Its decision version is 3-complete, and checking whether a policy is 4-valid is coNP-complete (Masopust et al., 17 Sep 2025).
For labeled Petri nets, the framework generalizes to Parikh and indicator semantics. In the Parikh variant, each occurrence of a protected event contributes; in the indicator variant, each protected event counts only once per execution path. Both variants are solvable in exponential space, and their decision versions are ExpSpace-complete. The uniform versions are equivalent in complexity to the general ones via reductions that preserve optimal policy cost (Haar et al., 8 Nov 2025).
| Setting | Decision variant | Complexity |
|---|---|---|
| Finite automata, multiplicity semantics | BC-SPP, BC-SPP-U | NP-complete |
| Finite automata, distinct-event semantics | BC-5-SPP, BC-6-SPP-U | 7-complete |
| Labeled Petri nets, Parikh or indicator semantics | BC-Parikh-SPP(-U), BC-Indicator-SPP(-U) | ExpSpace-complete |
The complexity landscape shows that “uniform” does not imply computational simplicity. In automata, SPP-U is already NP-complete; in Petri nets, uniform and non-uniform variants are both ExpSpace-complete (Masopust et al., 17 Sep 2025, Haar et al., 8 Nov 2025).
7. From uniform guarantees to secret-specific protection in machine learning
Recent privacy-preserving machine-learning work treats uniform guarantees as a baseline that can be unnecessarily conservative. In synthetic text generation, standard differential privacy imposes uniform guarantees that often overprotect non-sensitive content, resulting in substantial utility loss and computational overhead. Secret-Protected Evolution (SecPE) replaces this with 8-secret protection, a relaxation of Gaussian DP that bounds the reconstruction probability of specific secrets rather than applying a worst-case guarantee to all data (Wang et al., 13 Oct 2025).
The GDP-to-secret-protection connection is given by
9
SecPE uses secret clustering and protected evolution; relative to uniform DP private evolution, it reduces private similarity computations from 0 to 1 when 2, and empirically achieves lower FID and higher downstream task accuracy than GDP-based Aug-PE baselines on OpenReview, PubMed, and Yelp while requiring less noise for the same level of protection (Wang et al., 13 Oct 2025).
A related training-time formulation defines secret protection through posterior reconstruction bounds rather than differential privacy. For each secret 3, one specifies a prior bound 4 and a posterior bound 5, computes 6, solves a linear program
7
and then performs Poisson sampling using the resulting weights (Ganesh et al., 30 May 2025). In the reported experiments on arXiv abstracts, the LP-based method achieved a 8 reduction in noise multiplier and a 9 lower test loss than DP-SGD on the full dataset (Ganesh et al., 30 May 2025).
This modern line of work does not discard uniform protection; rather, it reframes it as one point in a larger design space. A plausible implication is that the contemporary “uniform secret protection problem” increasingly asks when uniform guarantees are structurally necessary, and when secret-specific guarantees yield better utility, lower cost, or both.