The VersaKey framework: Versatile group key management

被引:169
作者
Waldvogel, M [1 ]
Caronni, G
Sun, D
Weiler, N
Plattner, B
机构
[1] ETH Zurich, Comp Engn & Networks Lab, CH-8092 Zurich, Switzerland
[2] Sun Microsyst Labs, Network & Secur Grp, Palo Alto, CA 94303 USA
[3] OpenCon Syst, Piscataway, NJ 08854 USA
关键词
concurrent key distribution; distributed key management; multicast key distribution schemes; secure multicasting middleware; tree-based key distribution;
D O I
10.1109/49.790485
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Middleware supporting secure applications in a distributed environment faces several challenges. Scalable security in the contest of multicasting or broadcasting is especially hard when privacy and authenticity is to be assured to highly dynamic groups where the application allows participants to join and leave at any time. Unicast security is well-known and has widely advanced into production state. But proposals for multicast security solutions that have been published so far are complex, often require trust in network components, or are inefficient, In this paper, we propose a framework of new approaches for achieving scalable security in IP multicasting, Our solutions assure that newly joining members are not able to understand past group traffic and that leaving members may not follow future communication. For versatility, our framework supports a range of closely related schemes for key management, ranging from tightly centralized to fully distributed, and even allows snitching between these schemes on-the-fly with low overhead, Operations have low complexity (O[log N) for joins or leaves], thus granting scalability even for very large groups, We also present a novel concurrency-enabling scheme, which was devised for fully distributed key management, In this paper, we discuss the requirements for secure multicasting, present our flexible system, and evaluate its properties based on the existing prototype implementation.
引用
收藏
页码:1614 / 1631
页数:18
相关论文
共 32 条
[1]  
[Anonymous], 1998, RFC2409
[2]  
[Anonymous], 1992, DISTRIBUTED WHITEBOA
[3]  
Atkinson R., 1995, 1825 RFC
[4]  
*ATM FOR, 1995, UNI SIGN 4 0
[5]  
BALLARDIE A, 1996, 1949 RFC
[6]  
Bobak A.R, 1996, DISTRIBUTED MULTIDAT, V2nd
[7]  
BRADEN R, 1993, IEEE NETWORK, V7, P8
[8]  
BURMESTER M, 1996, P SEC PROT WORKSH, P119
[9]  
CANETTI R, 1998, TAXONOMY MULTICAST S
[10]  
CARONNI G, P IEEE 7 INT WORKSH