25th IEEE International Conference on Distributed Computing Systems (ICDCS'05)
Efficient Group Rekeying Using Application-Layer Multicast
Columbus, Ohio, USA
June 06-June 10
ISBN: 0-7695-2331-5
In secure group communications, there are both rekey and data traffic. We propose to use application-layer multicast to support concurrent rekey and data transport. Rekey traffic is bursty and requires fast delivery. It is desired to reduce rekey bandwidth overhead as much as possible since it competes for bandwidth with data traffic. Towards this goal, we propose a multicast scheme that exploits proximity in the underlying network. We further propose a rekey message splitting scheme to significantly reduce rekey bandwidth overhead at each user access link and network link. We formulate and prove correctness properties for the multicast scheme and rekey message splitting scheme. We have conducted extensive simulations to evaluate our approach. Our simulation results show that our approach can reduce rekey bandwidth overhead from several thousand encrypted new keys (encryptions, in short) to less than ten encryptions for more than 90% of users in a group of 1024 users.
Citation:
X. Brian Zhang, Simon S. Lam, Huaiyu Liu, "Efficient Group Rekeying Using Application-Layer Multicast," icdcs, pp.303-313, 25th IEEE International Conference on Distributed Computing Systems (ICDCS'05), 2005