THHHHT
2.4 Efficient Generation of k Random Bits
2.4.3 Optimality
Corollary 2.10. The algorithm Φk generates m random bits for some m with 0 ≤ m ≤ k, and m=k with probability at least1/2.
Proof. The sequence generated by Φk is independent and unbiased. This conclusion is immediate from lemma 2.9. Assume that the input sequence x ∈ Si for some i with 1 ≤ i ≤ w, then the probability ofm=k is
⌊|S2ki|⌋2k
|Si| ,
which is at least 1/2 based on the fact that |Si| ≥2k. Since this conclusion is true for allSi with 1≤i≤w, we can claim thatm=k with probability at least 1/2.
Since the algorithm Φk generatesmrandom bits for some mwith 0≤m≤kfrom an arbitrary biased coin, we are able to generate k bits iteratively: After generating m random bits, we apply the algorithm Φk−m for generating k−m bits. Repeating this procedure, the total number of random bits generated will converge to kvery quickly. We call this scheme as an iterative scheme for generatingkrandom bits.
To generate krandom bits, we do not want to iterate Φk too many times. Fortunately, in the following theorem, we show that in our scheme the expected number of iterations is upper bounded by a constant 2.
Theorem 2.11. The expected number of iterations in the iterative scheme for generatingkrandom bits is at most2.
Proof. According to corollary 2.10, Φk generatesm=k random bits with probability at least 1/2.
Hence, the scheme stops at each iteration with probability more than 1/2. Following this fact, the result in the theorem is immediate.
Lemma 2.12. Given a biased coin with probability p being H, let n be the number of coin tosses used by the algorithm Φk, then
lim
k→∞
E[n]
k ≤ 1
H(p).
Proof. We consider the probability of having an input sequence of length at least n, denote as Pn. In this case, we can writen=k1+k2, wherek1 is the number of H’s andk2 is the number of T’s.
According to the construction of the stopping set, ( n−1
min(k1, k2)−1 )
<2k n−1 min(k1, k2)−1.
Or we can write it as
( n−2 min(k1, k2)−2
)
<2k.
Hence, we get an upper bound for min(k1, k2), which is
tn= max{i∈ {0,1, ..., n}|
(n−2 i−2 )
<2k}. (2.1)
Note that if
(n−2
n 2 −2
)
≥2k, thentn is a nondecreasing function ofn.
According to the symmetry of our criteria, we can get
Pn ≤
tn
∑
i=0
(pi(1−p)n−i+ (1−p)ipn−i) (n
i )
.
For convenience, we write
Qn=
tn
∑
i=0
(pi(1−p)n−i+ (1−p)ipn−i) (n
i )
,
thenPn≤Qn andQn is also a nondecreasing function ofn.
Now, we are ready to calculate the expected number of coin tosses required, which equals
E[n] =
∑∞ n=1
(Pn−Pn+1)n=
∑∞ n=1
Pn (2.2)
≤
k H(p)(1+ϵ)
∑
n=1
Pn+
∑∞ n=H(p)k (1+ϵ)
Qn+
∑∞ n=2H(p)k (1+ϵ)
Qn,
whereϵ >0 is a small constant. In the rest, we study the upper bounds for all the three terms when nis large enough.
For the first term, we have
k H(p)(1+ϵ)
∑
n=1
Pn≤ k
H(p)(1 +ϵ). (2.3)
Now let us consider the second term
2H(p)k (1+ϵ)
∑
n=H(p)k (1+ϵ)
Qn≤ k
H(p)(1 +ϵ)Q k H(p)(1+ϵ).
Using the Stirling bounds on factorials yields
nlim→∞
1 nlog2
(n ρn
)
=H(ρ),
whereH is the binary entropy function. Hence, following (2.1), we can get
nlim→∞H(tn
n) = lim
n→∞
k n.
Whenn= H(p)k (1 +ϵ), we can write
nlim→∞H(tn
n) = H(p) 1 +ϵ,
which implies that
nlim→∞
tn
n =p−ϵ1
for someϵ1>0. So there exists anN1 such that forn > N1, nnt ≤p−ϵ1/2.
By the weak law for the binomial distribution, given any ϵ2>0 andδ >0, there is anN2 such that forn > N2, with probability at least 1−δthere arei H’s among the ncoin tosses such that
|ni −p| ≤ϵ2. Lettingϵ2=ϵ1/2 andn=H(p)k (1 +ϵ) gives
Qn≤δ,
for anyδ >0 when n >max(N1, N2).
So for anyδ >0, whenkis large enough, we have
2H(p)k (1+ϵ)
∑
n=H(p)k (1+ϵ)
Qn≤ k
H(p)(1 +ϵ)δ. (2.4)
To calculate the third term, we notice that Qn decays very quickly as n increase when n ≥ 2H(p)k (1 +ϵ). In this case,
Qn+1
Qn
=
∑tn+1
i=0 (pi(1−p)n+1−i+ (1−p)ipn+1−i) (n+ 1
i )
∑tn
i=0(pi(1−p)n−i+ (1−p)ipn−i) (n
i )
≤
∑tn
i=0(pi(1−p)n+1−i+ (1−p)ipn+1−i) (n+ 1
i )
∑tn
i=0(pi(1−p)n−i+ (1−p)ipn−i) (n
i )
≤ maxtn
i=0
(pi(1−p)n+1−i+ (1−p)ipn+1−i) (n+ 1
i )
(pi(1−p)n−i+ (1−p)ipn−i) (n
i )
≤ (1−p)maxtn
i=1
n+ 1 n+ 1−tn
≤ (1−p)n n−tn
.
Whenn≥2H(p)k (1 +ϵ), we have
nlim→∞H(tn
n) = lim
n→∞
k
n ≤ H(p) 2(1 +ϵ).
This implies that whennis large enough,H(tnn)≤ H(p)2 . Let us define a constantαsuch thatα≤12 andH(α) = H(p)2 . Then for alln≥2H(p)k (1 +ϵ), whenkis large enough,
Qn+1
Qn ≤ 1−p 1−α<1.
Therefore, given any δ >0, whenk is large enough, the value of the third term
∑∞ n=2H(p)k (1+ϵ)
Qn ≤ Q2 k H(p)(1+ϵ)
∑∞ i=0
(1−p 1−α)i
≤ Q k H(p)(1+ϵ)
1 1−11−−αp
≤ 1−α
p−αδ. (2.5)
Substituting (2.3), (2.4), and (2.5) into (2.2) yields that for any ϵ > 0 and δ >0, if k is large enough, we have
E[n]≤ k
H(p)(1 +ϵ)(1 +δ) +1−α p−αδ, withα < p.
Then it is easy to get that
klim→∞
E[n]
k ≤ 1
H(p). This completes the proof.
Theorem 2.13. Given a biased coin with probability pbeing H, let nbe the number of coin tosses required to generatek random bits in the iterative scheme, then
klim→∞
E[n]
k = 1
H(p).
Proof. First, we prove that limk→∞E[n]k ≥H(p)1 . LetX∈ {0,1}∗ be the input sequence, then
lim
k→∞
E[n]H(p) H(X) = 1.
Shannon’s theory tells us that it is impossible to extract more than H(X) random bits fromX, i.e.,H(X)≥k. So
lim
k→∞
E[n]
k ≥ 1
H(p).
To get the conclusion in the theorem, we only need to show that
lim
k→∞
E[n]
k ≤ 1
H(p).
To distinguish thenin this theorem and the one in the previous theorem, we usen(k)denote the number of coin tosses required to generatekrandom bits in the iterative scheme and letnΦ(k)denote the number of coin tosses required by Φk. Letpmbe the probability for Φk generating mrandom bits with 0≤m≤k. Then we have that
E[n(k)] =E[nΦ(k)] +
∑k m=0
pmE[n(k−m)]. (2.6)
According to the algorithm, pk ≥ 12 and E[n(k−m)] ≤ E[n(k)]. Substituting them into the equation above gives
E[n(k)]≤E[nΦ(k)] +1
2E[n(k)], i.e.,E[n(k)]≤2E[nΦ(k)].
Now, we divide the second term in (2.6) into two parts such that
E[n(k)]≤E[nΦ(k)] +
k∑−ϵk m=0
pmE[n(k−m)] +
∑k m=k−ϵk
pmE[n(k−m)],
for a constantϵ >0. In which,
k∑−ϵk m=0
pmE[n(k−m)]≤(
k∑−ϵk m=0
pm)2E[nΦ(k)],
∑k m=k−ϵk
pmE[n(k−m)]≤2E[nΦ(ϵk)].
Hence
E[n(k)]≤E[nΦ(k)] + (
k∑−ϵk m=0
pm)2E[nΦ(k)] + 2E[nΦ(ϵk)]. (2.7)
Given k, all the possible input sequences are divided into w prefix sets S1, S2, ..., Sw, where w can be an infinite number. Given an input sequenceX ∈Si for 1≤i≤w, we are considering the probability for Φk generating a sequence of length m.
In our algorithm,|Si| ≥2k. Assume
|Si|=αk2k+αk−12k−1+...+α020,
whereαk≥1 and 0≤α0, α1, ..., αk−1≤1. Given the conditionX ∈Si, we have
k∑−ϵk m=0
pm=
∑k−ϵk i=0 αi2i
∑k
i=0αi2i ≤ 2k−ϵk+1
2k+ 2k−ϵk+1 ≤2k−ϵk+1 2k .
So given anyδ >0, whenkis large enough, we have
k∑−ϵk m=0
pm≤δ. (2.8)
Although we reach this conclusion for X ∈ Si, this conclusion holds for any Si with 0 ≤ i ≤ w.
Hence, we are able to remove this constrain thatX ∈Si.
According to the previous lemma, for anyδ >0, whenkis large enough, we have
E[nΦ(ϵk)]
ϵk ≤ 1
H(p)+δ, (2.9)
E[nΦ(k)]
k ≤ 1
H(p)+δ. (2.10)
Substituting (2.8), (2.9), and (2.10) into (2.7) gives us
E[n(k)]≤k( 1
H(p)+δ)(1 + 2δ) + 2kϵ( 1 H(p)+δ).
From which, we obtain
lim
k→∞
E[n]
k = lim
k→∞
E[n(k)]
k ≤ 1
H(p). This completes the proof.
The theorem above shows that the iterative scheme is asymptotically optimal, i.e., the expected number of coin tosses for generatingkrandom bits approaches the information theoretic bound by below whenk becomes large.