This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Identity-Based Fault-Tolerant Conference Key Agreement
July-September 2004 (vol. 1 no. 3)
pp. 170-178
Lots of conference key agreement protocols have been suggested to secure computer network conference. Most of them operate only when all conferees are honest, but do not work when some conferees are malicious and attempt to delay or destruct the conference. Recently, Tzeng proposed a conference key agreement protocol with fault tolerance in terms that a common secret conference key among honest conferees can be established even if malicious conferees exist. In the case where a conferee can broadcast different messages in different subnetworks, Tzeng's protocol is vulnerable to a "different key attack” from malicious conferees. In addition, Tzeng's protocol requires each conferee to broadcast to the rest of the group and receive n-1 messages in a single round (where n stands for the number of conferees). Moreover, it has to handle n simultaneous broadcasts in one round. In this paper, we propose a novel fault-tolerant conference key agreement protocol, in which each conferee only needs to send one message to a "semitrusted” conference bridge and receive one broadcast message. Our protocol is an identity-based key agreement, built on elliptic curve cryptography. It is resistant to the different key attack from malicious conferees and needs less communication cost than Tzeng's protocol.

[1] D. Reed, “A Discussion on Computer Network Conferencing,” Request for Comments: 1324, Network Working Group, May 1992.
[2] FIPS PUB 197, “Advanced Encryption Standard,” Federal Information Processing Standards Publications, US Dept. of Commerce/N.I.S.T., Nov. 2001.
[3] C.E. Shannon, “Communication Theory of Secret Systems,” Bell System Technical J., vol. 28, no. 4, pp. 656-715, 1949.
[4] M.S. Hwang, “Dynamic Participation In A Secure Conference Scheme For Mobile Communications,” IEEE Trans. Vehicular Technology, vol. 48, no. 5, pp. 1469-1474, Sept. 1999.
[5] X. Yi, C.K. Siew, and C.H. Tan, “A Secure and Efficient Conference Scheme for Mobile Communications,” IEEE Trans. Vehicular Technology, vol. 52, no. 4, pp. 784-793, July 2003.
[6] X. Yi, C.K. Siew, C.H. Tan, and Y. Ye, “A Secure Conference Scheme for Mobile Communications,” IEEE Trans. Wireless Comm., vol. 2, no. 6, pp. 1168-1177, Nov. 2003.
[7] A.J. Menezes, P.C. vanOorschot, and S.A. Vanstone, Handbook of Applied Cryptography. CRC Press, Oct. 1996.
[8] W.G. Tzeng, “A Secure Fault-Tolerant Conference Key Agreement Protocol,” IEEE Trans. Computers, vol. 51, no. 4, pp. 373-379, Apr. 2002.
[9] A. Shamir, “How to Share a Secret,” Comm. ACM, vol. 22, no. 11, pp. 656-715, Nov. 1979.
[10] M.K. Franklin and M.K. Reiter, “Fair Exchange With a Semitrusted Third Party (Extended Abstract),” Proc. Fourth ACM Conf. Computer and Comm. Security, pp. 1-5, Apr. 1997.
[11] D. Steer, L. Strawczynski, W. Diffie, and M. Wiener, “A Secure Audio Teleconference System,” Proc. CRYPTO '88 Conf., pp. 520-528, Aug. 1988.
[12] M. Burmester and Y. Desmedt, “A Secure and Efficient Conference Key Distribution System,” Proc. Eurocrypt '94 Conf., pp. 275-286, May 1994.
[13] Y. Amir, Y. Kim, C.N. Rotaru, and G. Tsudik, “On the Performance of Key Agreement Protocols,” Proc. 20th IEEE Int'l Conf. Distributed Computing Systems, pp. 330-343, Apr. 2000.
[14] G. Ateniese, M. Steiner, and G. Tsudik, “New Multiparty Authentication Services And Key Agreement Protocols,” IEEE J. Selected Areas in Comm., vol. 18, no. 4, pp. 628-639, Apr. 2000.
[15] M. Steiner, G. Tsudik, and M. Waidner, “Key Agreement in Dynamic Peer Groups,” IEEE Trans. Parallel and Distributed Systems, vol. 11, no. 8, pp. 769-780, Aug. 2000.
[16] Y. Kim, A. Perrig, and G. Tsudik, “Simple and Fault-Tolerant Key Agreement for Dynamic Collaborative Groups,” Proc. Seventh ACM Conf. Computer and Comm. Security, pp. 235-244, Nov. 2000.
[17] Y. Kim, A. Perrig, and G. Tsudik, “Group Key Agreement Efficient in Communication,” IEEE Trans. Computers, vol. 53, no. 7, pp. 905-921, July 2004.
[18] D. Boneh and M. Franklin, “Identity-Based Encryption From The Weil Pairing,” Proc. Crypto '01 Conf., pp. 213-229, Aug. 2001.
[19] V. Miller, “Short Programs for Functions on Curves,” unpublished manuscript, 1986.
[20] X. Yi, “An ID-Based Signature Scheme from the Weil Pairing,” IEEE Comm. Letters, vol. 7, no. 2, pp. 76-78, Feb. 2003.
[21] FIPS PUB 180, Secure hash standard, Federal Information Processing Standards Publications, US Dept. of Commerce/N.I.S.T., Nat'l Technical Information Service, Springfield, Virginia, May 1993.
[22] A. Shamir, “Identity-Based Cryptosystems and Signature Schemes,” Proc. Crypto '84 Conf., pp. 47-53, Aug. 1984.
[23] M. Wiener, “Performance Comparison of Public-Key Cryptosystem,” CryptoBytes, vol. 4, no. 1, pp. 1-5, Summer 1998.
[24] A. Menezes, T. Okamoto, and S. Vanstone, “Reducing Elliptic Curve Algorithms to Logarithms in a Finite Field,” IEEE Trans. Information Theory, vol. 39, no. 5, pp. 1639-1646, Sept. 1993.
[25] D. Pointcheval and J. Stern, “Security Arguments for Digital Signatures and Blind Signatures,” J. Cryptology, vol. 13, no. 3, pp. 361-396, Mar. 2000.
[26] P. Barreto, H.Y. Kim, B. Lynn, and M. Scott, “Efficient Algorithms for Pairing-Based Cryptosystems,” Proc. Crypto '02 Conf., pp. 354-369, Aug. 2002.

Index Terms:
Computer network conference, conference key agreement, fault tolerance, semitrusted, passive and active attacks.
Citation:
Xun Yi, "Identity-Based Fault-Tolerant Conference Key Agreement," IEEE Transactions on Dependable and Secure Computing, vol. 1, no. 3, pp. 170-178, July-Sept. 2004, doi:10.1109/TDSC.2004.31
Usage of this product signifies your acceptance of the Terms of Use.