secure services for group cliques comm unication gene
play

Secure Services for Group CLIQUES: Comm unication Gene Tsudik - PowerPoint PPT Presentation

Secure Services for Group CLIQUES: Comm unication Gene Tsudik gts@isi.edu D ARP A High Condence Net w o rking W o rkshop, 06/12/98, Ro ckp o rt, MA. USC Info rmation Sciences Institute D ARP A High Condence


  1. Secure Services for Group CLIQUES: Comm unication Gene Tsudik gts@isi.edu D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98, Ro ckp o rt, MA. USC Info rmation Sciences Institute

  2. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 1 The Setting Dynamic P eer Groups (DPGs): Relatively small (100s of memb ers) � No Hiera rchy � F requent Memb ership Changes � Elected o r App ointed (but not p ermanent) Group Controller � Notable Examples: Replicated Servers � Group-w o rk � Video/audio Conferencin g � Ad Ho c Net w o rks � USC Info rmation Sciences Institute Gene Tsudik

  3. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 2 DPG Memb ership Op erations Group Genesis (IKA) Member Addition Member Exclusion Mass Join Mass Leave Group Fusion Group Fission USC Info rmation Sciences Institute Gene Tsudik

  4. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 3 The Problem Ho w to maintain securit y with constantly changing memb ership ? Securit y Services in DPG setting: Authentic, p rivate communication within group � Authentic, p rivate communication with outsiders � Authentication �avo rs: any memb er o r sp eci�c memb er � Group signatures � Non-repudiation of Memb ership � Observations: Centralized (TTP) app roaches do not w o rk w ell � Simple extensions of 2-pa rt y metho ds a re ine�cient � Key Agreement { most basic service � Key Distribution Key Agreement NOTE: � 6 = USC Info rmation Sciences Institute Gene Tsudik

  5. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 4 V a riables Key Agreement: IKA: Initial Key Agreement (group genesis, re-k ey) � AKA: Auxilia ry Key Agreement (memb ership changes) � Centralized: Key Distribution/T ransp o rt � Contributo ry: Equal Sha re b y Every one � Design P a rameters: Di�e-Hellman mo del � Contributo ry KA � Group Controller (�xed o r �oating) � No a p rio ri o rdering � No p olicy assumptions! � No reliance on lo cal environment � USC Info rmation Sciences Institute Gene Tsudik

  6. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 5 Progress... Publication s: \Di�e-Hellman Key Distribution Extended to Groups" , 1996 A CM CCCS. � \CLIQUES: A New App roach to Group Key Agreement" , 1998 IEEE ICDCS. � \Authenticated Group Key Agreement and F riends" , 1998 A CM CCCS. � \Key Agreement in Dynamic P eer Groups" , in submission. � \An E�cient Group Signature Metho d" , in submission. � 1998 Financial Cryptography . \Group Ba rter: Multi-P a rt y F air Exchange..." � Real W o rk: CLIQUES T o olkit: JA V A, C/C++ (under dev.) � Collab o ration with JHU (SPREADS, COMMEDIA) � Collab o ration with IBM Resea rch (RS6K, etc.) � ISI's GLOBUS Metacomputing p roject � Eagerly lo oking fo r other collab o ration opp o rtunities!!! USC Info rmation Sciences Institute Gene Tsudik

  7. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 6 Memb ership Changes Proto cols: Memb er Addition � Memb er Deletion � Mass Join * � Mass Leave * � Group F usion � Prop erties: Key Indep endence � Securit y equivalent to IKA (p oly . ind.) � Fixed/Floating Controller � Any one can b e group controller (subject to p olicy) � Group controller can b e easily excluded � USC Info rmation Sciences Institute Gene Tsudik

  8. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 7 Authenticated Key Agreement Proto cols: A-DH: 2-pa rt y , 2-round, PFS, KKA-resistant � A-GDH.2: n -pa rt y , n -round, A-DH/GDH.2 blend � auth. M � ! M n i SA-GDH.2: n -pa rt y , n -round � auth. $ M M i j Prop erties: Inherited: Key Indep endence, P assive A ttack Resistance � PFS � KKA Resistance � Key Con�rmation � Key Integrit y (???) � Group Integrit y � (P a rtial) Entit y Authentication � USC Info rmation Sciences Institute Gene Tsudik

  9. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 8 Authenticated Key Agreement 1 2 3 r1 r1 r2 r1r2 α α α α r1r2 α r1r3 α r2r3 α r1r2r3 α 4 r2r3r4 K 14 r1r3r4 K 24 r1r2r4 K 34 α α α 1 2 3 r1 K 12 r1 K 13 r1 K 14 r1 K 12 r2 K 21 r1r2 K 13 K 23 r1r2 K 14 K 24 α α α α α α α r1r2 K 13 K 23 α GROUP CONTROLLERS r2r3 K 21 K 31 α r1r3 K 12 K 32 α r1r2r3 K 14 K 24 K 34 α 4 r2r3r4 K 21 K 31 K 41 r1r3r4 K 12 K 32 K 42 r1r2r4 K 13 K 23 K 43 α α α USC Info rmation Sciences Institute Gene Tsudik

  10. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 9 Group Signatures Group Manager Member enroll Register Member Anyone verify sign Signed message Group "plaintiff" Manager open Signed message − GM cannot cheat − Easy Registration − Members cannot cheat − Efficient Sign, Verify, Open − Outsiders cannot cheat * Exclusion not worked out yet... − No coalitions USC Info rmation Sciences Institute Gene Tsudik

  11. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 10 On-going and F uture W o rk Memb er (entit y) authentic ati on � Encryption fo r/within group � Authenticati on of sp eci�c and anonymous group memb ers � CLIQUES T o olkit available 1998 � API de�nition, p erfo rmance measurements, integration exp erience � Group Signatures � CLIQUES HOME P A GE: www.isi.edu//div7//cl iq ues USC Info rmation Sciences Institute Gene Tsudik

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend