基于自认证公钥体制和门限密码机制,为Ad hoc网络提出了一种新的分布式密钥管理方案。方案中节点公钥具有自认证功能,不需要证书管理,降低了网络节点的存储和通信需求;解决了基于身份公钥体制方案中的密钥托管问题,提高了系统安全性;将组合公钥的思想引入到门限密钥分发的随机数选择,简化了传统ElGamal型门限签名方案在签名前协商随机数的过程,大大降低了网络节点的通信量和计算量。分析表明,同以往提出的基于公钥密码体制的密钥管理方案相比,该方案有更高的效率和安全性。
A new distributed key management scheme based on self-certified public key system and threshold cryptography is proposed for Ad hoe network. The storage space and the communication overheads can be reduced because the public key is self certified and the certificate is unnecessary. There is no key escrow problem since the key distribution center (KDC) does not know the users' private keys. The idea of composite public key (CPK) is introduced for selecting random number for threshold key distribution. It reducesthe process of generating a random number before threshold signature is issued in traditional E1Gamal type threshold signature and so it reduces the communication and computation overheads of network nodes. The analysis shows that the scheme is more secure and efficient than previous works implemented with public key systems.