A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEs

A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEs
复制标题

DOI:
10.1145/3460120.3484817
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Keitaro Hashimoto;Shuichi Katsumata;Eamonn W. Postlethwaite;Thomas Prest;B. Westerbaan
Keitaro Hashimoto;Shuichi Katsumata;Eamonn W. Postlethwaite;Thomas Prest;B. Westerbaan
中科院分区:
其他
文献类型:
--
作者:
Keitaro Hashimoto;Shuichi Katsumata;Eamonn W. Postlethwaite;Thomas Prest;B. Westerbaan

文献摘要

相似文献

连续组密钥协商协议(CGKA)是一类可以为Signal和MLS等安全组消息协议提供强安全保证的协议。通过提交消息提供对设备危害的保护:每个组成员可以定期通过上传提交消息来更新其密钥材料,然后由所有其他成员下载和处理。在实践中,传播提交消息支配现有CGKA的带宽消耗。我们提出了Chained CmPKE,一个具有非对称带宽成本的CGKA:在一个N个成员的组中,提交消息的上传成本为O(N),下载成本为O(1),总带宽成本为O(N)。相比之下,TreeKEM在两个方向上的成本(log N),总成本(N log N)。我们的协议依赖于通用原语,因此很容易后量子。我们更进一步,提出了针对\Chained CmPKE定制的后量子原语,与朴素实例化相比,这使我们能够将上传提交消息的增长率降低两到三个数量级。最后,我们实现了链式CmPKE的软件实现。我们的实验表明,即使对于大小为N = 2^10的组,也可以在不到100 ms的时间内计算和处理提交消息。
Continuous group key agreements (CGKAs) are a class of protocols that can provide strong security guarantees to secure group messaging protocols such as Signal and MLS. Protection against device compromise is provided by commit messages: at a regular rate, each group member may refresh their key material by uploading a commit message, which is then downloaded and processed by all the other members. In practice, propagating commit messages dominates the bandwidth consumption of existing CGKAs. We propose Chained CmPKE, a CGKA with an asymmetric bandwidth cost: in a group of N members, a commit message costs O(N) to upload and O(1) to download, for a total bandwidth cost of O(N). In contrast, TreeKEM costs (log N) in both directions, for a total cost (N log N). Our protocol relies on generic primitives, and is therefore readily post-quantum. We go one step further and propose post-quantum primitives that are tailored to \Chained CmPKE, which allows us to cut the growth rate of uploaded commit messages by two or three orders of magnitude compared to naive instantiations. Finally, we realize a software implementation of Chained CmPKE. Our experiments show that even for groups with a size as large as N = 2^10, commit messages can be computed and processed in less than 100 ms.