|
ABSTRACT
A non-interactive conference key distribution system (or, a NICKDS for short) allows conference members to calculate a shared key without interacting with each other. NICKDSs have been studied in unconditional and computational settings. In both cases security has been evaluated against an adversary who can corrupt participants. In this paper we consider an adaptive adversary who can both corrupt participants and also access the keys of conference of his choice. We re-visit security of a number of known NICKDSs in this new model and present characterizations and conditions that guarantee security of the system in the new model. We also give a generic construction for computationally secure (in the new model) NICKDSs, from unconditionally secure ones in corruption only model. To show the usefulness of the new security model, we consider two composition constructions. First, we compose a secure NICKDS with a secure MAC by using the key obtained from the NICKDS as the MAC key, and show that this results in a ring authentication that guarantees authenticity of the received message while the sender remains anonymous and this anonymity is unconditional. The security theorem for the composition guarantees security for unconditional and computational settings, both. We also consider composition of a NICKDS with a secure (CCA2 secure) encryption system and show this results in a broadcast encryption system (BES) that is CCA2 secure. This is the first CCA2 secure BES in symmetric key setting. We discuss future works and open problems.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
Mihir Bellare , Ran Canetti , Hugo Krawczyk, A modular approach to the design and analysis of authentication and key exchange protocols (extended abstract), Proceedings of the thirtieth annual ACM symposium on Theory of computing, p.419-428, May 24-26, 1998, Dallas, Texas, United States
[doi> 10.1145/276698.276854]
|
| |
2
|
|
| |
3
|
M. Bellare, D. Pointcheval and P. Rogaway, authenticated key exchange secure against dictionary attacks, Advances in Cryptology-EUROCRYPT 2000, B. Preneel (Ed.), LNCS 1807, Springer-Verlag, pp. 139--155, 2000.
|
| |
4
|
|
| |
5
|
A. Bender, J. Katz and R. Morselli, Ring Signatures: Stronger Definitions, and Constructions Without Random Oracles, TCC 2006, S. Halevi and T. Rabin (Eds.), LNCS 3876, Springer-Verlag, pp. 60--79, 2006.
|
| |
6
|
|
| |
7
|
Carlo Blundo , Alfredo De Santis , Ugo Vaccaro , Amir Herzberg , Shay Kutten , Moti Yong, Perfectly secure key distribution for dynamic conferences, Information and Computation, v.146 n.1, p.1-23, Oct. 10, 1998
[doi> 10.1006/inco.1998.2717
]
|
| |
8
|
D. Boneh and A. Silverberg, Applications of Multilinear Forms to Cryptography, Contemporary Mathematics, Vol. 324, American Mathematical Society, pp. 71--90, 2003.
|
| |
9
|
|
 |
10
|
Emmanuel Bresson , Olivier Chevassut , David Pointcheval , Jean-Jacques Quisquater, Provably authenticated group Diffie-Hellman key exchange, Proceedings of the 8th ACM conference on Computer and Communications Security, November 05-08, 2001, Philadelphia, PA, USA
[doi> 10.1145/501983.502018]
|
| |
11
|
|
| |
12
|
|
| |
13
|
D. Chaum, E. van Heyst, Group Signatures, advances in Cryptology-EUROCRYPT 1991, D. W. Davies (Ed.), LNCS 547, Springer-Verlag, pp. 257--265, 1991.
|
 |
14
|
Sherman S. M. Chow , Victor K. Wei , Joseph K. Liu , Tsz Hon Yuen, Ring signatures without random oracles, Proceedings of the 2006 ACM Symposium on Information, computer and communications security, March 21-24, 2006, Taipei, Taiwan
[doi> 10.1145/1128817.1128861]
|
| |
15
|
Y. Desmedt, V. Viswanathan, Unconditionally Secure Dynamic Conference Key Distribution, ISIT'98, pp. 383, Cambridge, MA, USA, August 16--31, 1998.
|
| |
16
|
W. Diffie and M. Hellman, new directions in cryptography, IEEE Transactions on Information Theory, Vol. 22, pp. 644--654, Nov. 1976.
|
| |
17
|
|
| |
18
|
Y. Dodis, A. Kiayias, Antonio Nicolosi and Victor Shoup, Anonymous Identification in Ad Hoc Groups, Advances in Cryptology-EUROCRYPT 2004, C. Cachin and J. Camenisch (Eds.), LNCS 3027, Springer-Verlag, pp. 609--626, 2004.
|
| |
19
|
|
| |
20
|
|
| |
21
|
J. Katz and M. Yung, Scalable Protocols for Authenticated Group Key Exchange. CRYPTO'03.
|
| |
22
|
S. Kent and K. Seo, Security Architecture for the Internet Protocol, Available at http://www.rfc-editor.org/rfc/rfc4301.txt
|
| |
23
|
|
| |
24
|
H. Kurnio, R. Safavi-Naini and H. Wang, A Group Key Distribution Scheme with Decenteralized User Join, SCN'02, S. Cimato et al. (Eds.), LNCS 2576, Springer-Verlag, pp. 146--163, 2003.
|
| |
25
|
|
| |
26
|
|
| |
27
|
|
| |
28
|
|
 |
29
|
|
| |
30
|
|
 |
31
|
|
| |
32
|
|
 |
33
|
Chung Kei Wong , Mohamed Gouda , Simon S. Lam, Secure group communications using key graphs, Proceedings of the ACM SIGCOMM '98 conference on Applications, technologies, architectures, and protocols for computer communication, p.68-79, August 31-September 04, 1998, Vancouver, British Columbia, Canada
|
|