针对移动Ad hoc网络中的安全组通信系统,提出了一个基于群签名认证的分布式组密钥管理方案。该方案利用门限密码技术并借鉴了PKI证书管理的第三方签名认证思想,在提高认证可信度的同时,极大地减少了密钥协商过程中所需的认证开销。分析表明,该方案具有良好的容错性;达到了第3级信任;能够抵抗网络中典型的主动和被动攻击;具备完美的前向和后向保密性;极大地降低了计算和通信开销。
According to the characteristics of group communication in mobile Ad hoc networks,this paper proposed a distributed key management scheme based on group signature authentication.By adopting the threshold cryptography and the method of third-party signature authentication,this scheme enhanced the authentication reliability and reduced largely the authentication cost in key agreement process greatly.The analysis shows this scheme is provably secure against the active and passive attacks with fault-torrance,achieves the trust level 3,has perfect forward and backward secrecy,and reduces the cost of computation and communication greatly.