Unconditionally Secure Conference Key Distribution: Security Notions, Bounds and Constructions

Unconditionally Secure Conference Key Distribution: Security Notions, Bounds and Constructions
复制标题

无条件安全的会议密钥分发:安全概念、界限和结构

DOI:
10.1142/s0129054111008763
复制
发表时间:
2011
影响因子:
0.8
通讯作者:
Shaoquan Jiang
Shaoquan Jiang
中科院分区:
计算机科学4区
文献类型:
--
作者:
R. Safavi;Shaoquan Jiang

文献摘要

被引文献

相似文献

会议密钥分发是一种允许指定的用户子集计算共享私钥的协议。我们考虑无条件安全的会议密钥分发系统,其中对手拥有无限的计算能力,并重点关注 Safavi-Naini 和 Jiang 提出的更强大、更现实的对手模型,其中对手除了破坏用户子集并获取其私钥外,还可以访问许多未损坏会议的会议密钥。我们考虑此对手模型的安全性的替代定义,并展示它们之间的关系。会议密钥分发系统的一个重要效率参数是用户私钥的大小。我们得出该密钥大小的下限,并与已知界限进行比较,讨论结果。我们还考虑在新的对抗模型中使用一轮交互式会议密钥分发系统(ICKDS),其中对手除了学习受损用户的私钥和一些会议密钥之外,还可以访问一些会议的记录。我们证明,在这种新的对手模型下,Blundo 等人之前提出的一轮协议。等人。不再安全,我们在新的对抗模型中构建了具有可证明安全性的 ICKDS。
A conference key distribution is a protocol that allows designated subset of users to calculate a shared private key. We consider unconditionally secure conference key distribution systems where the adversary has unlimited computational power, and focuses on a stronger and more realistic adversary model, proposed by Safavi-Naini and Jiang, in which the adversary in addition to corrupting subsets of users and obtaining their private keys, can access the conference keys of a number of uncorrupted conferences. We consider alternative definitions of security with this adversary model and show the relationship between them. An important efficiency parameter for conference key distribution systems is the size of the users' private keys. We derive lower bounds on the size of this key and discuss the results in comparison with the known bounds. We also consider one-round Interactive Conference Key Distribution Systems (ICKDS) in the new adversarial model where the adversary in addition to learning the private keys of the corrupted users and a number of conference keys, has access to the transcripts of some conferences. We show that under this new adversary model, the previously proposed one round protocol of Blundo et. al. is no longer secure and we construct an ICKDS with provable security in the new adversarial model.