作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (20): 190-192. doi: 10.3969/j.issn.1000-3428.2008.20.069

• 安全技术 • 上一篇    下一篇

具有容侵能力的多播密钥管理方案

王小康1,2,杨 明2   

  1. (1. 中国电子设备系统工程公司,北京 100089;2. 解放军理工大学指挥自动化学院,南京 210007)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-10-20 发布日期:2008-10-20

Intrusion Tolerant Multicast Key Management Scheme

WANG Xiao-kang 1,2, YANG Ming2   

  1. (1. Electromic Equipment and Systems Engineering Co. Ltd. of China, Beijing 100089; 2. Institute of Automation Command, PLA University of Science and Technology, Nanjing 210007)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-10-20 Published:2008-10-20

摘要: 目前安全多播应用系统大多采用相对简单的集中式组密钥管理方案。单一密钥服务器容易导致单点失效和拥塞问题,系统安全性和可用性较差,恢复时延长。该文将入侵容忍的思想引入组密钥管理方案中,借助于门限秘密共享方案和信息分割算法,在集中式组密钥管理方法的基础上,提出一种具有容侵能力的组密钥管理方式。将单一的密钥服务器置换为分布式的密钥服务器组,各服务器借助于选举机制,通过相互协作来完成多播组密钥的管理以及信息的安全存储,既保持了集中式控制的优点,又有效减少了单点失效,增强了抗网络入侵的能力,提高了系统的可用性。

关键词: 多播, 密钥管理, 容侵, 管理机制, 信息分割算法

Abstract: The simple centralized group key management is used in most multicast application systems. Single point failure and congestion are often caused by single key server, and it’s difficult to recover from failure, so the security and integrity are unavailable. In order to solve these problems, this paper proposes a scheme based on Information Dispersal Algorithm(IDA) and Threshold Secret Sharing(TSS). This paper replaces the single key server in the centralized model with a set of distributed key servers. The group management operations and the storage of the group key information are performed through the collaboration of all the servers. So the security and integrity of the key management system are enhanced. The management mechanism and the method of storage and distribution of the key information are then discussed in this paper.

Key words: multicast, key management, intrusion tolerance, group management mechanism, Information Dispersal Algorithm(IDA)

中图分类号: