Distributed servers approach for large-scale secure multicast

Distributed servers approach for large-scale secure multicast
复制标题

大规模安全组播的分布式服务器方法

DOI:
10.1109/jsac.2002.803966
复制
发表时间:
2002
期刊:
IEEE J. Sel. Areas Commun.
影响因子:
--
通讯作者:
S. Chan
S. Chan
中科院分区:
--
文献类型:
--
作者:
Kin;S. Chan

文献摘要

被引文献

相似文献

为了为多播应用提供后向和前向保密性(即,新成员无法解密在加入之前发送的多播数据,而前成员无法解密在离开后发送的数据),每当用户加入或离开系统时,都必须更改数据加密密钥。这样的改变必须让所有当前用户都知道。当用户池很大时,用于这种重新密钥消息传递的带宽可能很高。我们提出了一种分布式服务器方法,通过将用户池分成多个组,每个组由一个(逻辑)服务器提供服务,从而最大限度地减少整体系统带宽(和复杂性)。在提出基于分层密钥树的系统分析模型后,我们表明存在实现最小系统带宽的最佳服务器数量。随着底层用户流量的波动,我们提出了一种简单的低开销动态方案,其中物理服务器自适应地将其流量分割和合并到多个组中,每个组由逻辑服务器服务,以最小化其总带宽。我们的结果表明,与传统的单服务器方法相比,分布式服务器方法能够大大减少所需的总带宽,特别是对于那些用户池大、持有时间短、数据流带宽相对较低的应用程序,例如互联网股票报价应用程序。
In order to offer backward and forward secrecy for multicast applications (i.e., a new member cannot decrypt the multicast data sent before its joining and a former member cannot decrypt the data sent after its leaving), the data encryption key has to be changed whenever a user joins or leaves the system. Such a change has to be made known to all the current users. The bandwidth used for such re-key messaging can be high when the user pool is large. We propose a distributed servers approach to minimize the overall system bandwidth (and complexity) by splitting the user pool into multiple groups each served by a (logical) server. After presenting an analytic model for the system based on a hierarchical key tree, we show that there is an optimal number of servers to achieve minimum system bandwidth. As the underlying user traffic fluctuates, we propose a simple dynamic scheme with low overhead where a physical server adaptively splits and merges its traffic into multiple groups each served by a logical server so as to minimize its total bandwidth. Our results show that a distributed servers approach is able to substantially reduce the total bandwidth required as compared with the traditional single-server approach, especially for those applications with a large user pool, short holding time, and relatively low bandwidth of a data stream, as in the Internet stock quote applications.