Contributory Broadcast Encryption with Efficient Encryption and Short Ciphertexts

被引:36
作者
Wu, Qianhong [1 ,2 ,3 ]
Qin, Bo [4 ]
Zhang, Lei [5 ]
Domingo-Ferrer, Josep [6 ]
Farras, Oriol [6 ]
Manjon, Jesus A. [6 ]
机构
[1] Beihang Univ, Sch Elect & Informat Engn, Beijing 100093, Peoples R China
[2] Xidian Univ, State Key Lab Integrated Serv Networks, Beijing 100093, Peoples R China
[3] Chinese Acad Sci, State Key Lab Informat Secur, Inst Informat Engn, Beijing 100093, Peoples R China
[4] Renmin Univ China, Key Lab Data Engn & Knowledge Engn, Minist Educ, Sch Informat, ZhongGuanCun St 59, Beijing, Peoples R China
[5] E China Normal Univ, Shanghai Key Lab Trustworthy Comp, Inst Software Engn, Shanghai 200062, Peoples R China
[6] Univ Rovira & Virgili, Dept Comp Engn & Math, UNESCO Chair Data Privacy, E-43007 Tarragona, Spain
基金
北京市自然科学基金;
关键词
Broadcast encryption; group key agreement; contributory broadcast encryption; provable security; KEY MANAGEMENT SCHEME; AGREEMENT; SECURITY;
D O I
10.1109/TC.2015.2419662
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Broadcast encryption (BE) schemes allow a sender to securely broadcast to any subset of members but require a trusted party to distribute decryption keys. Group key agreement (GKA) protocols enable a group of members to negotiate a common encryption key via open networks so that only the group members can decrypt the ciphertexts encrypted under the shared encryption key, but a sender cannot exclude any particular member from decrypting the ciphertexts. In this paper, we bridge these two notions with a hybrid primitive referred to as contributory broadcast encryption (ConBE). In this new primitive, a group of members negotiate a common public encryption key while each member holds a decryption key. A sender seeing the public group encryption key can limit the decryption to a subset of members of his choice. Following this model, we propose a ConBE scheme with short ciphertexts. The scheme is proven to be fully collusion-resistant under the decision n-Bilinear Diffie-Hellman Exponentiation (BDHE) assumption in the standard model. Of independent interest, we present a new BE scheme that is aggregatable. The aggregatability property is shown to be useful to construct advanced protocols.
引用
收藏
页码:466 / 479
页数:14
相关论文
共 50 条
[41]   Key agreement in dynamic peer groups [J].
Steiner, M ;
Tsudik, G ;
Waidner, M .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2000, 11 (08) :769-780
[42]  
Tzeng WG, 2000, LECT NOTES COMPUT SC, V1976, P614
[43]   A secure fault-tolerant conference-key agreement protocol [J].
Tzeng, WG .
IEEE TRANSACTIONS ON COMPUTERS, 2002, 51 (04) :373-379
[44]  
Wallner D.M., 1999, KEY MANAGEMENT MULTI
[45]  
Wong CK, 2000, IEEE ACM T NETWORK, V8, P16, DOI 10.1109/90.836475
[46]   Fast Transmission to Remote Cooperative Groups: A New Key Management Paradigm [J].
Wu, Qianhong ;
Qin, Bo ;
Zhang, Lei ;
Domingo-Ferrer, Josep ;
Manjon, Jesus A. .
IEEE-ACM TRANSACTIONS ON NETWORKING, 2013, 21 (02) :621-633
[47]  
Wu QH, 2011, LECT NOTES COMPUT SC, V7073, P143, DOI 10.1007/978-3-642-25385-0_8
[48]  
Wu QH, 2009, LECT NOTES COMPUT SC, V5479, P153
[49]   Identity-based fault-tolerant conference key agreement [J].
Yi, X .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2004, 1 (03) :170-178
[50]   A key management scheme using deployment knowledge for wireless sensor networks [J].
Yu, Zhen ;
Guan, Yong .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2008, 19 (10) :1411-1425