Scalable public-key tracing and revoking

Scalable public-key tracing and revoking
复制标题

可扩展的公钥追踪和撤销

DOI:
10.1007/s00446-004-0120-5
复制
发表时间:
2003
影响因子:
1.3
通讯作者:
M. Yung
M. Yung
中科院分区:
计算机科学3区
文献类型:
--
作者:
Y. Dodis;Nelly Fazio;A. Kiayias;M. Yung

文献摘要

被引文献

相似文献

叛徒追踪计划是数字内容广播领域打击盗版的非常有用的工具。在这种多接收者加密方案中,每个解密密钥都带有指纹,当发现盗版解码器时,当局可以追踪参与其构造的用户(称为叛徒)的身份。公钥叛徒追踪方案允许多个不可信内容提供商使用同一组密钥,这使得该方案“服务器端可扩展”。为了使此类方案也“客户端可扩展”,即长期存在并可供随时间动态变化的大量订户使用,实现高效的添加用户和删除用户操作至关重要。先前关于公钥叛徒追踪的工作并没有彻底解决这种动态场景,并且没有有效的可扩展公钥叛徒追踪方案来允许越来越多的添加用户和删除用户操作。为了解决这些问题,我们引入了可扩展公钥叛徒追踪模型,并提出了该方案的第一个构造。我们的模型要求进行确定性的叛徒追踪以及无限数量的高效添加用户操作和删除用户操作。可扩展的系统通过将系统的运行时间划分为多个时间段来实现无限数量的撤销,同时保持高水平的效率。每个时期都有一个撤销数量的饱和水平。当周期饱和时,系统服务器会发出有效的新周期操作,重置饱和级别。我们为我们的系统提出了一个正式的对抗模型,考虑到其周期结构,并证明我们的构建是安全的,既可以对抗试图欺骗撤销机制的对手,也可以对抗试图欺骗叛徒追踪机制的对手。
Traitor Tracing Schemes constitute a very useful tool against piracy in the context of digital content broadcast. In such multi-recipient encryption schemes, each decryption key is fingerprinted and when a pirate decoder is discovered, the authorities can trace the identities of the users that contributed in its construction (called traitors). Public-key traitor tracing schemes allow for a multitude of non trusted content providers using the same set of keys, which makes the scheme "server-side scalable." To make such schemes also "client-side scalable," i.e. long lived and usable for a large population of subscribers that changes dynamically over time, it is crucial to implement efficient Add-user and Remove-user operations. Previous work on public-key traitor tracing did not address this dynamic scenario thoroughly, and there is no efficient scalable public key traitor tracing scheme that allows an increasing number of Add-user and Remove-user operations.To address these issues, we introduce the model of Scalable Public-Key Traitor Tracing, and present the first construction of such a scheme. Our model mandates for deterministic traitor tracing and an unlimited number of efficient Add-user operations and Remove-user operations. A scalable system achieves an unlimited number of revocations while retaining high level of efficiency by dividing the run-time of the system into periods. Each period has a saturation level for the number of revocations. When a period becomes saturated, anefficientnew-period operation is issued by the system server that resets the saturation level. We present a formal adversarial model for our system taking into account its periodic structure, and we prove our construction secure, both against adversaries that attempt to cheat the revocation mechanism as well as against adversaries that attempt to cheat the traitor tracing mechanism.