节点文献
叛徒追踪技术研究
Research on Traitor Tracing Techniques
【作者】 苏加军;
【导师】 王新梅;
【作者基本信息】 西安电子科技大学 , 通信与信息系统, 2015, 博士
【摘要】 随着互联网技术和计算机技术的迅速发展,各种类型的数字多媒体内容(音频、图像、视频等)纷纷选择在不同类型的网络中进行发布,与此同时,开放环境下的版权保护也正成为一个迫切需要关注与解决的问题。在诸如付费电视系统、在线数据库访问系统和CD在线发布系统等广播加密业务中,数据供应商DS(Data Supplier)经常面临两种典型的威胁:共谋密钥攻击和重放攻击。通常,这两种攻击中的攻击者被称为叛徒(叛逆者)。叛徒追踪方案就是DS为保护自己的合法权益(版权或机密信息),用来追踪及识别叛徒的有效措施。目前,广播加密分为有状态广播加密和无状态广播加密。而具有工程应用价值的无状态广播加密又可分为基于对称密钥的广播加密和基于公钥的广播加密。叛徒追踪技术主要分为对抗共谋密钥攻击的叛徒追踪技术和对抗重放攻击的叛徒追踪技术。其中,对抗共谋密钥攻击的叛徒追踪方案主要有对称追踪方案、非对称追踪方案、门限追踪方案;而对抗重放攻击的叛徒追踪方案主要有动态追踪方案以及连续追踪方案等。本文对广播加密业务中的叛徒追踪技术进行了系统的研究,所取得的主要研究成果为:1.研究了广播加密技术。在广播加密方案中,如何最小化系统带宽需求(广播中心数据传输量),用户密钥存储量,以及用户密钥计算复杂度是方案构造的关键。本文提出了一种基于安全防诬陷码的广播加密方案。该方案针对一种付费用户规模受限的广播情形,只要求用户存储一个用户密钥,系统广播一次加密信息,优化了用户密钥存储量和系统带宽需求两个关键指标。2.研究了对抗共谋密钥攻击的对称叛徒追踪技术。共谋密钥攻击是广播加密业务中常见的一种攻击模式。利用hash函数类理论,本文构造了一种三级对称叛徒追踪方案。对比已有的CFN对称方案,三级对称叛徒追踪方案显著优化了三个主要性能参数:用户密钥存储复杂度、系统带宽需求和用户解密盒计算复杂度。利用具体的Hash函数和子密钥值实例化本方案,可以构建一个应用型的广播加密解决方案。3.研究了对抗共谋密钥攻击的非对称叛徒追踪技术。对抗共谋密钥攻击的对称叛徒追踪方案存在用户端密钥存储量过大和广播中心可以随意诬陷守法用户两个问题。针对这两个问题,本文提出了一种改进的具有自撤消特性的非对称方案。该方案利用RSA密码体制构建了密文密钥的安全方案,同时基于离散对数求逆难和不经意多项式估值协议OPE协议构建了授权分组的安全方案。新方案具有多服务,抗共谋,防诬陷和自撤销等安全性特点。4.研究了对抗非法重放攻击的动态叛徒追踪技术。非法重放攻击是在广播加密业务中常见的另一种攻击模式。本文利用水印标识用户,采用逐层寻址思想,构造了一种基于用户分层的动态叛徒追踪方案.该方案可以有效地对抗即时重放攻击。通过引入一个均衡参数,该方案不仅可以动态的追踪叛徒,而且可以动态的适应于不同用户容量的信息发布系统。综合来说,该方案具有一定的理论价值和版权保护方面的工程实用价值。
【Abstract】 With the rapid development of digital technology and network technology, various forms of multimedia digital works(images, video, audio, etc.) have been distributed to subscribers in various types of networks, the copyright protection of which is becoming an urgent issue to be solved under the open application environment. In the broadcast encryption systems, such as pay-TV systems, on-line access to the database and CD distribution system, DS(Data Supplier) often face two representative threats: collusion key attacks and illegal replay attacks, the attackers in which are usually called traitors. Traitor tracing schemes are efficient methods for Data Suppliers to protect their copyrights against the above attacks and identify the traitors.Currently, the broadcast encryption is divided into the state broadcast encryption and stateless broadcast encryption. And stateless broadcast encryption with engineering application value can be divided into the symmetric key-based broadcast encryption and public key-based broadcast encryption. And the traitor tracing technology is mainly divided into the traitor tracing technology against collusion key attack and the traitor tracing technology against illegal rebroadcast attack. There are three kinds of traitor tracing schemes against collusion key attack, which are symmetrical traitor tracing schemes, asymmetrical traitor tracing schemes and threshold schemes; and there are two kinds of traitor tracing schemes against illegal rebroadcast attack, which are dynamic traitor tracing schemes and sequential traitor tracing schemes.In this dissertation, the traitor tracing technology for the broadcast encryption is systematically studied, and the main achievements of this dissertation are briefly listed as follows:1. Broadcast encryption technology is studied in detailed. How to minimize DS bandwidth requirements, the user key storage and the user key decoding complexity in the broadcast encryption scheme is a key issue. In this dissertation, a resilient broadcast encryption scheme based on secure frameproof codes is constructed, which is applicable for an especially broadcast encryption situation where the privilege user set has an upper bound. The scheme optimizes two parameters of the user key storage and the bandwidth requirements to finish the broadcast task even if DS transmits the encrypted message one time and the user stores only one key.2. Symmetrical traitor tracing technology against the collusion key attack is studied in detailed. The collusion key attack is a common attack mode in the broadcast encryption. In this dissertation, based on the broadcast encryption techniques and Hash function theory, a new three-level symmetrical scheme of traitor tracing is constructed which can combat with the collusion attack. Compared with the typical CFN schemes, the three-level scheme significantly optimizes the three main parameters, which are the user key storage, DS bandwidth requirements and the user key decoding complexity. The application-oriented broadcast encryption can be built using hash functions and specific sub-key value based on the three-level scheme.3. Asymmetrical traitor tracing technology against the collusion key attack is studied in detailed. The two problems of excessive user key storage and framing legal subscriber by DS in symmetrical schemes are considering. In this dissertation, an improved Asymmetrical traitor tracing scheme with automatic revoking is presented, in which the security scheme of session keys is constructed based on RSA and the security scheme of Enable Block(EB) is constructed based on discrete logarithm difficult and Oblivious Polynomial Evaluation protocol(OPE). The improved scheme possesses multi-service, anti-collusion, anti-framed and auto-revoking security features.4. Dynamic traitor tracing technology against the illegal replay attack is studied in detailed. The illegal replay attack is another common attack mode in the broadcast encryption. In this dissertation, a new dynamic traitor tracing scheme based on user set hierarchical structure is constructed, in which user IDs are marked by the watermarks and traitors are identified by the idea of layer by layer addressing. The new scheme can combat with the immediate rebroadcast attack efficiently and be applicable to the broadcast systems with different sizes of subscriber set by a balanced parameter, which has a certain theoretical value and copyright protection engineering value.
【Key words】 Copyright Protection; Broadcast Encryption; Traitor Tracing; Collusion Key Attack; Rebroadcast Attack;