论文部分内容阅读
针对集中式组密钥管理方案具有单失效点和密钥非公平产生等问题提出了一种基于单向函数树的高效分布式组密钥管理方案(D-OFT)。在该方案中,组密钥由所有合法用户共同协商产生,避免了不公平性;同时,该方案中采用分布式管理,不会形成单失效点;密钥更新消息长度保持在O(log n),具有良好的密钥更新效率;此外,方案中提供的用户加入组、离开组、组合并、组分裂等密钥更新算法均满足前向、后向安全性要求。结果表明:D-OFT方案非常适用于无中央控制节点且组成员关系动态变化的中小规模分布式安全组通信系统。
In order to solve the problem that the centralized group key management scheme has the single invalidation point and the key unfairness generation, an efficient distributed group key management scheme (D-OFT) based on one-way function tree is proposed. In this scheme, the group key is jointly negotiated by all legitimate users to avoid the unfairness. At the same time, distributed management is adopted in the scheme without single failure point. The length of the key update message is kept at O (log n ), And has good key update efficiency. In addition, the key update algorithms such as user join group, leave group, group combination, and group splitting provided in the solution meet forward and backward security requirements. The results show that D-OFT scheme is very suitable for small and medium-sized distributed security group communication systems without central control nodes and dynamic changes of group memberships.