摘要
对称群密钥协商方案的目的是协商一个只有群成员能够用来加解密消息的对称加解密密钥.为了满足网络通信的公开性,非对称群密钥协商方案在2009年被首次提出.非对称群密钥协商方案只需要协商出一个共享的群加密密钥,该加密密钥是公开的,且对应多个不同的解密密钥,即每个群成员都可以计算出一个对应于该加密密钥的解密密钥.任何人都可以利用公开信息计算加密密钥从而可以给群成员发消息,但只有群成员可以正确解密.本文基于无证书公钥密码体系提出一个无证书可认证的非对称群密钥协商方案.首先实现了对群成员身份的认证、对公开信息正确性,完整性的验证,保证了群成员间的安全通信.其次分析了群用户的加入和退出,在成员加入退出后更新密钥以保证前向安全性和后向安全性.最后对方案进行了安全性分析和效率分析,在随机预言机模型中证明了该方案满足选择明文安全,通过与其它方案的效率对比说明该方案在实现相同功能和满足相同安全性的情况下效率更高.
Symmetric group key agreement scheme is aimed at negotiating a symmetric key among the participants. Only group members can use this key to encrypt and decrypt messages. In order to meet the demands of openness in network communication, asymmetric group key agreement scheme was firstly proposed in 2009. Asymmetric group key agreement scheme only needs to negotiate a shared encryption group key which is public and have different decryption keys corresponding to it. This means that each group member can calculate a decryption key corresponding to the encryption key. Anyone can calculate the encryption key using some public information and send encrypted messages to group members which can only be decrypted by group members correctly. This paper proposes an authenticated certificateless asymmetric group key agreement protocols based on certificateless public key cryptography system. The scheme can achieve the identity authentication for the group members, and can verify the correctness, the integrity of the public information to ensure the secure communication between group members. Furthermore, we also deal with the situation for new group members to join the group, and to remove existing members, and the scheme can achieve the forward and backward security after group members join in or removed. Finally we give the proof of chosen-message security in the oracle model, the performance comparisons show that our scheme has high efficiency for achieving the same security demand.
出处
《密码学报》
CSCD
2016年第4期382-398,共17页
Journal of Cryptologic Research
基金
国家自然科学基金(61102056
61201132
61402351)
中央高校基础业务费(K5051301013)
关键词
无证书公钥密码
群密钥协商
可认证
certificateless public key cryptography
group key agreement
authentication