{"title":"网关子集差异撤销","authors":"Jeff Opper, B. DeCleene, M. Leung","doi":"10.1109/MOBHOC.2006.278662","DOIUrl":null,"url":null,"abstract":"Subset difference revocation (SDR) provides a powerful mechanism for the efficient expression of the revocation state of a large group of key recipients. However, arbitrary assignment of receivers as leaf nodes in a static binary tree can lead to inefficiencies in certain group revocation states. Gateway subset difference revocation (GSDR), developed in our ongoing SecureKeys effort, provides the ability to group receivers based upon organizational characteristics while simultaneously introducing the ability to audit rekey and data transmission, delegate rekey decisions to subordinate decision makers, and override subordinate rekey authority when necessary. GSDR extends the existing SDR scheme by deploying rekey gateways in a hierarchy that mimics an organic decision making structure. Delegation of rekey authority offloads a significant computational and communications burden from gateways high in the tree, while correspondingly partitioning the rekey traffic required to be processed by leaf nodes in the tree. GSDR also significantly reduces label storage requirements in rekey devices by limiting terminal node fan-out","PeriodicalId":345003,"journal":{"name":"2006 IEEE International Conference on Mobile Ad Hoc and Sensor Systems","volume":"74 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2006-10-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Gateway Subset Difference Revocation\",\"authors\":\"Jeff Opper, B. DeCleene, M. Leung\",\"doi\":\"10.1109/MOBHOC.2006.278662\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Subset difference revocation (SDR) provides a powerful mechanism for the efficient expression of the revocation state of a large group of key recipients. However, arbitrary assignment of receivers as leaf nodes in a static binary tree can lead to inefficiencies in certain group revocation states. Gateway subset difference revocation (GSDR), developed in our ongoing SecureKeys effort, provides the ability to group receivers based upon organizational characteristics while simultaneously introducing the ability to audit rekey and data transmission, delegate rekey decisions to subordinate decision makers, and override subordinate rekey authority when necessary. GSDR extends the existing SDR scheme by deploying rekey gateways in a hierarchy that mimics an organic decision making structure. Delegation of rekey authority offloads a significant computational and communications burden from gateways high in the tree, while correspondingly partitioning the rekey traffic required to be processed by leaf nodes in the tree. GSDR also significantly reduces label storage requirements in rekey devices by limiting terminal node fan-out\",\"PeriodicalId\":345003,\"journal\":{\"name\":\"2006 IEEE International Conference on Mobile Ad Hoc and Sensor Systems\",\"volume\":\"74 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2006-10-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2006 IEEE International Conference on Mobile Ad Hoc and Sensor Systems\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/MOBHOC.2006.278662\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2006 IEEE International Conference on Mobile Ad Hoc and Sensor Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MOBHOC.2006.278662","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Subset difference revocation (SDR) provides a powerful mechanism for the efficient expression of the revocation state of a large group of key recipients. However, arbitrary assignment of receivers as leaf nodes in a static binary tree can lead to inefficiencies in certain group revocation states. Gateway subset difference revocation (GSDR), developed in our ongoing SecureKeys effort, provides the ability to group receivers based upon organizational characteristics while simultaneously introducing the ability to audit rekey and data transmission, delegate rekey decisions to subordinate decision makers, and override subordinate rekey authority when necessary. GSDR extends the existing SDR scheme by deploying rekey gateways in a hierarchy that mimics an organic decision making structure. Delegation of rekey authority offloads a significant computational and communications burden from gateways high in the tree, while correspondingly partitioning the rekey traffic required to be processed by leaf nodes in the tree. GSDR also significantly reduces label storage requirements in rekey devices by limiting terminal node fan-out