Multicast Key Agreement, Revisited

Multicast Key Agreement, Revisited
复制标题

重新审视组播密钥协议

DOI:
--
复制
发表时间:
2021
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Yi Tang
Yi Tang
中科院分区:
--
文献类型:
--
作者:
Alexander Bienstock;Y. Dodis;Yi Tang

文献摘要

被引文献

相似文献

. 多播密钥协议(Multicast Key Agreement, MKA)是一个长期被忽视的具有重大实际意义的自然原语。在传统的MKA中,无所不知的组管理器通过一个不受信任的网络私下地将秘密分发给一组动态变化的组成员。因此,组成员能够跨时间派生共享的组秘密,主要的安全性要求是只有当前组成员才能派生当前组秘密。文献中确实存在利用对称密钥加密的非常有效的MKA方案。然而,它们缺乏正式的安全分析、关于动态变化的组的效率分析,以及关于用户状态泄漏的更现代、更健壮的安全保证:前向保密(FS)和后妥协安全(PCS)。前者保证了状态泄露前的组秘密的安全性,后者保证了状态泄露后,用户可以通过正常的协议操作快速恢复组秘密的安全性。
. Multicast Key Agreement (MKA) is a long-overlooked natural primitive of large practical interest. In traditional MKA, an omniscient group manager privately distributes secrets over an untrusted network to a dynamically-changing set of group members. The group members are thus able to derive shared group secrets across time, with the main security requirement being that only current group members can derive the current group secret. There indeed exist very efficient MKA schemes in the literature that utilize symmetric-key cryptography. However, they lack formal security analyses, efficiency analyses regarding dynamically changing groups, and more modern, robust security guarantees regarding user state leakages: forward secrecy (FS) and post-compromise security (PCS). The former ensures that group secrets prior to state leakage remain secure, while the latter ensures that after such leakages, users can quickly recover security of group secrets via normal protocol operations.