摘要
在多权限群组通信中,由于用户可根据不同权限获取不同的数据资源,因此其安全问题比传统(单一权限)群组通信更难处理。为此,提出一种新的集中式多权限群组密钥管理方案,即采用多叉树构建密钥图,并为图中节点分配ID,以便用户快速推算出节点间的关系,从而确定需更新的密钥。当群组内的用户关系发生变化时,其他用户可通过单向函数、旧密钥以及密钥更新素材来实现密钥的更新。理论分析与模拟实验显示,相比现有的方案,新方案在保证前/后向安全性的同时,降低了密钥存储和更新的开销,具有更好的性能表现。
In multi-privileged group communications,since users can access multiple data resources according to their different privileges,security issues become more difficult to solve than that in traditional group communications.Therefore,this paper proposed a novel centralized group key management scheme for multi-privileged environments.The proposed scheme employs multiway tree to construct a key graph and assigns a unique ID for every node in the key graph,so that the relationship between keys can be deduced by an ID which will contribute to locating the affected keys efficiently.As a result,the related users can update the affected keys through previous keys or with a rekeying material by using a one-way function when membership changes dynamically.Theoretical analysis and experimental simulation resuits show that the proposed scheme can reduce the storage and rekeying overhead efficiently,and it outperforms some previous schemes.Meanwhile,the forward and backward security is also guaranteed.
出处
《计算机科学》
CSCD
北大核心
2014年第5期41-45,共5页
Computer Science
基金
国家自然科学基金项目(61272151
61073037)
高等学校博士学科点专项科研基金(20110162110043)资助
关键词
多权限群组通信
密钥管理
多叉树
单向函数
密钥更新素材
Multi-privileged group communications
Key management
Multiway tree
One-way function
Rekeying material