节点文献
多媒体安全组播密钥管理机制研究
Survey on Key Management Schemes in Secure Multimedia Multicast
【Author】 Jiang Zhang, Bin Li, Shi-Qiang Yang (Department of Science and Technology, Tsinghua University, Beijing 100084, China)
【机构】 清华大学计算机科学与技术系;
【摘要】 利用安全组播机制,可以高效、安全地实现多媒体数据的网络传输。本文总结了多媒体安全组播密钥管理机制的特性需求,并针对集中式、分散式、分布式三类安全组播密钥管理方案进行综述,分析比较了各典型方案的性能、特性和管理特点,最后探讨了安全组播密钥管理机制的发展趋势和研究方向。
【Abstract】 Multicast is an efficient way to deliver data to a large group of users in applications such as video on demand, live broadcasting, and video conference, etc. However, multicast by itself does not provide any mechanisms for preventing nongroup members to have access to the group communication. In order to offer such confidentiality, the encryption and decryption keys must be constantly changed upon a membership change. Key management plays an important role enforcing access control on the group key. It supports the establishment and maintenance of key relationship between valid members according to a security policy being enforced on the group. According to the properties and requirements of secure multicast, key management schemes should be efficient, scalable, reliable, robust, and secure. Researchers have proposed many different approaches to group key management. Almost all of them are based on IP Multicast. These approaches can be divided into three main classes: Centralized group key management protocols. In a centralized system, there is only one entity controlling the whole group, which performs key creation, distribution, and update. We summarize and compare the properties of the protocols such as LKH, OFT, OFCT, ELK, B-LKH, and AKMP. Decentralized group key management protocols. In the decentralized subgroup approach, the large group is split into small sub-groups. Different controllers are used to manage each sub-group. We analyse the properties of the protocols such as SMKD, IGKMP, DEP, IOLUS, and MARKS. Distributed key management protocols. In the distributed key management approach, there is no explicit KDC and all members contribute their own share to computation of the group key. We analyse the properties of the protocols such as D-LKH, VersaKey, TGDH, and STR. Our analysis made it clear that there is no unique solution that can achieve all requirements. Additionally, the best solution for a particular application may not be the best for another, hence it is important to understand fully the requirements of the application before selecting a security solution. It is a very important issue that the group rekey should be scalable and reliable. It is a new challenge to offer data confidentiality and achieve efficient key management schemes in Application Layer Multicast.
- 【会议录名称】 第一届建立和谐人机环境联合学术会议(HHME2005)论文集
- 【会议名称】第一届建立和谐人机环境联合学术会议(HHME2005)
- 【会议时间】2005-10
- 【会议地点】中国昆明
- 【分类号】TN918.6
- 【主办单位】中国计算机学会、中国图象图形学学会、ACM SIGCHI中国分会、清华大学计算机科学与技术系