在改进Huang秘密共享方案的基础上,提出了一个利用弹性多项式实现多级撤消能力的自愈密钥分发方案,该方案能够抵抗撤消成员与新加入成员发起的合谋攻击,实现了群成员与群管理员间的有效认证机制,轮数突破了固定门限的限制.用户可以自行选取个人密钥,避免初始化过程中安全信道的建立,解决了动态成员安全加入问题.本方案还将用户端的个人密钥存储量降低到常数,与先前的方案相比通信量也大大减少,实现了安全性与效率间的有效平衡.
An efficient self-healing key distribution scheme with multi level revocation capacity is proposed in this paper by using a resilient polynomial and an improved Huang's secret sharing scheme. This scheme can resist the conspiracy attacks launched by the newly-enrolled and revoked members. Besides, the round of this scheme is free of the fixed trapdoor, making it with a long life span. Finally, personal keys can be selected by the users individually and the establishment of secure channel can be avoided, ad- dressing the problem of dynamic joining. It also realizes the mutual authentication between the users and the group manager and achieves the efficient tradeoff between security and performance by decreasing the storage overhead of users to a constant and the communication overhead to a much lower level.