首页> 外文期刊>Computers, IEEE Transactions on >High-Performance Rekeying Processor Architecture for Group Key Management
【24h】

High-Performance Rekeying Processor Architecture for Group Key Management

机译:用于组密钥管理的高性能密钥处理器结构

获取原文
获取原文并翻译 | 示例

摘要

Group key management is a critical task in secure multicast applications such as Pay-TV over the Internet. The communication group key must be updated and distributed after every change in the group membership. Many solutions have been proposed in the last years to minimize the cost of this rekeying process on the server side. Most of these solutions are tree-based approaches such as the logical key hierarchy. These approaches suffer from three problems. First, tree-based solutions aim at minimizing rekeying costs only by reducing the number of needed cryptographic operations such as encryption or secure hashing. Second, these solutions do not treat the time-consuming digital signing needed to authenticate rekeying messages. Third, tree-based approaches manage huge amounts of keys by software which compromises security. In this paper, a novel hardware/software architecture is proposed, which optimizes the rekeying performance not only by minimizing the number of cryptographic operations, but also by reducing the execution times of these operations including digital signing with the aid of hardware acceleration. All help-keys are generated, managed, and stored on hardware, which enhances the system security. To keep flexibility, control-intensive tasks such as tree management are performed as software functions on the embedded processor. The presented rekeying processor is designed based on a comprehensive security analysis with the aid of a novel illustration for security threats, requirements, and technical solutions, a so-called Security Y-Diagram. A performance measurement on a prototype implementation shows that the rekeying processor can join and disjoin members much faster than software solutions besides supporting much larger groups.
机译:组密钥管理是安全多播应用程序中的一项关键任务,例如Internet上的付费电视。每次更改组成员身份后,必须更新并分发通信组密钥。近年来,已经提出了许多解决方案,以最大程度地减少服务器端此密钥更新过程的成本。这些解决方案大多数是基于树的方法,例如逻辑密钥层次结构。这些方法存在三个问题。首先,基于树的解决方案旨在仅通过减少所需的加密操作(例如加密或安全哈希)的数量来最大程度地减少重新生成密钥的成本。其次,这些解决方案不处理验证密钥更新消息所需的耗时的数字签名。第三,基于树的方法通过软件来管理大量密钥,这危及了安全性。在本文中,提出了一种新颖的硬件/软件体系结构,该体系结构不仅通过最小化加密操作的数量,而且还通过借助硬件加速减少了包括数字签名在内的这些操作的执行时间,来优化了密钥更新性能。所有帮助键都是在硬件上生成,管理和存储的,从而增强了系统安全性。为了保持灵活性,控制密集型任务(例如树管理)在嵌入式处理器上作为软件功能执行。提出的密钥更新处理器是基于全面的安全分析而设计的,并通过新颖的图解说明了安全威胁,要求和技术解决方案,即所谓的“安全Y-图”。对原型实现的性能评估表明,除支持更大的组外,重新生成密钥的处理器可以比软件解决方案更快地加入和断开成员。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号