Sanjeev Setia, Samir Koussih, S. Jajodia, E. Harder
{"title":"Kronos: a scalable group re-keying approach for secure multicast","authors":"Sanjeev Setia, Samir Koussih, S. Jajodia, E. Harder","doi":"10.1109/SECPRI.2000.848459","DOIUrl":null,"url":null,"abstract":"The authors describe a novel approach to scalable group re-keying for secure multicast. Our approach, which we call Kronos, is based upon the idea of periodic group re-keying. We first motivate our approach by showing that if a group is re-keyed on each membership change, as the size of the group increases and/or the rate at which members leave and join the group increases, the frequency of rekeying becomes the primary bottle neck for scalable group re-keying. In contrast, Kronos can scale to handle large and dynamic groups because the frequency of re-keying is independent of the size and membership dynamics of the group. Next, we describe how Kronos can be used in conjunction with distributed key management frameworks such as IGKMP (T. Hardjono et al., 1998) that use a single group-wide session key for encrypting communications between members of the group. Using a detailed simulation, we compare the performance tradeoffs between Kronos and other key management protocols.","PeriodicalId":373624,"journal":{"name":"Proceeding 2000 IEEE Symposium on Security and Privacy. S&P 2000","volume":"138 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2000-05-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"302","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceeding 2000 IEEE Symposium on Security and Privacy. S&P 2000","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SECPRI.2000.848459","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 302
Abstract
The authors describe a novel approach to scalable group re-keying for secure multicast. Our approach, which we call Kronos, is based upon the idea of periodic group re-keying. We first motivate our approach by showing that if a group is re-keyed on each membership change, as the size of the group increases and/or the rate at which members leave and join the group increases, the frequency of rekeying becomes the primary bottle neck for scalable group re-keying. In contrast, Kronos can scale to handle large and dynamic groups because the frequency of re-keying is independent of the size and membership dynamics of the group. Next, we describe how Kronos can be used in conjunction with distributed key management frameworks such as IGKMP (T. Hardjono et al., 1998) that use a single group-wide session key for encrypting communications between members of the group. Using a detailed simulation, we compare the performance tradeoffs between Kronos and other key management protocols.
作者描述了一种安全组播的可扩展组重密钥的新方法。我们的方法,我们称之为Kronos,是基于周期性组重键的想法。我们首先通过展示如果一个组在每次成员更改时都重新进行密钥设置来激励我们的方法,随着组的规模增加和/或成员离开和加入组的速度增加,重新进行密钥设置的频率成为可扩展组重新进行密钥设置的主要瓶颈。相反,Kronos可以扩展到处理大型动态组,因为重键的频率与组的大小和成员动态无关。接下来,我们描述了Kronos如何与分布式密钥管理框架(如IGKMP) (T. Hardjono等人,1998)结合使用,该框架使用单个组范围的会话密钥来加密组成员之间的通信。通过详细的模拟,我们比较了Kronos和其他密钥管理协议之间的性能权衡。