计算机应用 ›› 2019, Vol. 39 ›› Issue (2): 476-482.DOI: 10.11772/j.issn.1001-9081.2018051019

• 网络空间安全 • 上一篇    下一篇

面向Ad Hoc网络的无证书认证组密钥协商协议

曹震寰1, 顾小卓2, 顾梦鹤3   

  1. 1. 甘肃省信息中心, 兰州 730030;
    2. 中国科学院 信息工程研究所, 北京 100093;
    3. 中国科学院 西北生态环境资源研究院, 兰州 730000
  • 收稿日期:2018-05-17 修回日期:2018-08-28 出版日期:2019-02-10 发布日期:2019-02-15
  • 通讯作者: 顾小卓
  • 作者简介:曹震寰(1976-),男,甘肃庄浪人,高级工程师,CCF会员,主要研究方向:网络信息安全;顾小卓(1978-),女,甘肃白银人,高级工程师,博士,主要研究方向:网络安全协议;顾梦鹤(1974-),女,甘肃白银人,助理研究员,博士,主要研究方向:生态数学模型。
  • 基金资助:
    国家自然科学基金资助项目(61602475);国家密码基金资助项目(MMJJ20170212);甘肃省科技支撑计划项目(1504FKCA096)。

Certificateless authentication group key agreement protocol for Ad Hoc networks

CAO Zhenhuan1, GU Xiaozhuo2, GU Menghe3   

  1. 1. Gansu Information Center, Lanzhou Gansu 730030, China;
    2. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;
    3. Northwest Institute of Eco-Environment and Resources, Chinese Academy of Sciences, Lanzhou Gansu 730030, China
  • Received:2018-05-17 Revised:2018-08-28 Online:2019-02-10 Published:2019-02-15
  • Supported by:
    This work is partially supported by the National Natural Science Foundation of China (61602475), the National Cryptographic Foundation of China (MMJJ20170212), the Gansu Science and Technology Support Project (1504FKCA096).

摘要: 安全和效率是影响无证书认证组密钥协商协议能否在Ad Hoc网络中得到实际应用的两个关键因素。针对这两个关键因素,以提高Ad Hoc网络安全组通信的安全性和效率为目标,提出一个无证书认证组密钥协商协议,基于椭圆曲线密码体制(ECC)点乘运算实现无配对的无证书认证组密钥协商和身份认证;并使用Huffman密钥树优化通信轮数,以降低计算量和通信量,提高组密钥协商效率。安全分析和性能分析表明,与现有基于无证书的组密钥协商协议相比,所提方案在组密钥协商时具有较高的效率和安全性,可以满足资源受限条件下组密钥建立以及组成员变动带来的密钥更新问题。

关键词: Ad Hoc网络, 无证书公钥密码体制, 组密钥, 密钥树, 无证书认证组密钥

Abstract: Security and efficiency are two key factors that affect whether a certificateless authenticated group key agreement protocol can be applied in Ad Hoc networks. To improve the security and efficiency of key management problems in securing group communications of Ad Hoc networks, a certificateless group key agreement protocol was proposed, which utilizes Elliptic Curves Cryptography (ECC) multiplication to achieve the group key agreement and authentication without pairing. Meanwhile, the Huffman key tree was used to optimize the rounds of key negotiation, decreasing the computation and communication overheads and improving the group key negotiation efficiency. Security analysis and performance comparison demonstrate that the proposed protocol has good efficiency and security in group key negotiation, which can satisfy group key establishment and rekeying for dynamic groups with restrained resources.

Key words: Ad Hoc network, CertificateLess Public Key Cryptosystem (CL-PKC), group key, key tree, certificateless authentication group key

中图分类号: