计算机工程与应用 ›› 2007, Vol. 43 ›› Issue (7): 155-159.

• 网络、通信与安全 • 上一篇    下一篇

基于代理的分布式大型动态组播密钥管理协议

魏楚元 李陶深 王高才   

  1. 广西大学计算机与电子信息学院 湖南师范大学计算机系
  • 收稿日期:2006-04-06 修回日期:1900-01-01 出版日期:2007-03-01 发布日期:2007-03-01
  • 通讯作者: 魏楚元

A Distributed Group Key Management Protocol based on Agent for Large Dynamic Multicast

ChuYuan Wei   

  • Received:2006-04-06 Revised:1900-01-01 Online:2007-03-01 Published:2007-03-01
  • Contact: ChuYuan Wei

摘要: 安全组播主要的问题之一是组密钥管理。已有的组播密钥管理协议存在“1影响N”问题和重新解密与加密负载带来的较大通信延迟问题。本文参照分布式方法代表性协议Iolus提供的组播密钥管理安全框架和因特网组管理协议IGMP,设计了一种新的分布式密钥管理体系结构,组播组由一些分布的组播子组构成,采用一种改进的LKH协议实现子组内密钥管理,提出了一种基于代理的分布式的大型动态组播密钥管理协议,并通过增加签名标记改进了现有密钥管理协议对成员身份认证的不足。与LKH、Iolus协议相比,本文协议降低了“1影响N”问题,具有较好的可扩展性,有效降低了协议通信延迟和带宽等负载。

Abstract: One of the major problem areas of secure multicast is group key management. There are two problems about “1 affects N” and communication delay that is produced by overheads of decryption and re-encryption for them in existent group key management protocols. Referring to a multicast key management security infrastructure offered by a representative protocol “Iolus” of distributed model and IGMP, a new distributed key management architecture is designed in this paper. In this architecture, multicast group is constructed by some distributed subgroups. An enhanced Logical Key Hierarchy protocol is adopted for subgroup key management. A distributed group key management protocol based on agent for large dynamic multicast is presented. A drawback of existent protocols lack of membership authentication is eliminated by adding signed token to our protocol. This protocol decreases “1 affects N”, provides better scalability. Compared with LKH and Iolus, it efficiently decreases some overheads such as communication delays and bandwidth.