secure services for group cliques comm unication gene
play

Secure Services for Group CLIQUES: Comm unication Gene Tsudik - PowerPoint PPT Presentation

Secure Services for Group CLIQUES: Comm unication Gene Tsudik gts@isi.edu D ARP A High Condence Net w o rking W o rkshop, 06/12/98, Ro ckp o rt, MA. USC Info rmation Sciences Institute D ARP A High Condence


  1. Secure Services for Group CLIQUES: Comm unication Gene Tsudik gts@isi.edu D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98, Ro ckp o rt, MA. USC Info rmation Sciences Institute

  2. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 1 The Setting Dynamic P eer Groups (DPGs): Relatively small (100s of memb ers) � No Hiera rchy � F requent Memb ership Changes � Elected o r App ointed (but not p ermanent) Group Controller � Notable Examples: Replicated Servers � Group-w o rk � Video/audio Conferencin g � Ad Ho c Net w o rks � USC Info rmation Sciences Institute Gene Tsudik

  3. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 2 DPG Memb ership Op erations Group Genesis (IKA) Member Addition Member Exclusion Mass Join Mass Leave Group Fusion Group Fission USC Info rmation Sciences Institute Gene Tsudik

  4. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 3 The Problem Ho w to maintain securit y with constantly changing memb ership ? Securit y Services in DPG setting: Authentic, p rivate communication within group � Authentic, p rivate communication with outsiders � Authentication �avo rs: any memb er o r sp eci�c memb er � Group signatures � Non-repudiation of Memb ership � Observations: Centralized (TTP) app roaches do not w o rk w ell � Simple extensions of 2-pa rt y metho ds a re ine�cient � Key Agreement { most basic service � Key Distribution Key Agreement NOTE: � 6 = USC Info rmation Sciences Institute Gene Tsudik

  5. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 4 V a riables Key Agreement: IKA: Initial Key Agreement (group genesis, re-k ey) � AKA: Auxilia ry Key Agreement (memb ership changes) � Centralized: Key Distribution/T ransp o rt � Contributo ry: Equal Sha re b y Every one � Design P a rameters: Di�e-Hellman mo del � Contributo ry KA � Group Controller (�xed o r �oating) � No a p rio ri o rdering � No p olicy assumptions! � No reliance on lo cal environment � USC Info rmation Sciences Institute Gene Tsudik

  6. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 5 Progress... Publication s: \Di�e-Hellman Key Distribution Extended to Groups" , 1996 A CM CCCS. � \CLIQUES: A New App roach to Group Key Agreement" , 1998 IEEE ICDCS. � \Authenticated Group Key Agreement and F riends" , 1998 A CM CCCS. � \Key Agreement in Dynamic P eer Groups" , in submission. � \An E�cient Group Signature Metho d" , in submission. � 1998 Financial Cryptography . \Group Ba rter: Multi-P a rt y F air Exchange..." � Real W o rk: CLIQUES T o olkit: JA V A, C/C++ (under dev.) � Collab o ration with JHU (SPREADS, COMMEDIA) � Collab o ration with IBM Resea rch (RS6K, etc.) � ISI's GLOBUS Metacomputing p roject � Eagerly lo oking fo r other collab o ration opp o rtunities!!! USC Info rmation Sciences Institute Gene Tsudik

  7. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 6 Memb ership Changes Proto cols: Memb er Addition � Memb er Deletion � Mass Join * � Mass Leave * � Group F usion � Prop erties: Key Indep endence � Securit y equivalent to IKA (p oly . ind.) � Fixed/Floating Controller � Any one can b e group controller (subject to p olicy) � Group controller can b e easily excluded � USC Info rmation Sciences Institute Gene Tsudik

  8. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 7 Authenticated Key Agreement Proto cols: A-DH: 2-pa rt y , 2-round, PFS, KKA-resistant � A-GDH.2: n -pa rt y , n -round, A-DH/GDH.2 blend � auth. M � ! M n i SA-GDH.2: n -pa rt y , n -round � auth. $ M M i j Prop erties: Inherited: Key Indep endence, P assive A ttack Resistance � PFS � KKA Resistance � Key Con�rmation � Key Integrit y (???) � Group Integrit y � (P a rtial) Entit y Authentication � USC Info rmation Sciences Institute Gene Tsudik

  9. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 8 Authenticated Key Agreement 1 2 3 r1 r1 r2 r1r2 α α α α r1r2 α r1r3 α r2r3 α r1r2r3 α 4 r2r3r4 K 14 r1r3r4 K 24 r1r2r4 K 34 α α α 1 2 3 r1 K 12 r1 K 13 r1 K 14 r1 K 12 r2 K 21 r1r2 K 13 K 23 r1r2 K 14 K 24 α α α α α α α r1r2 K 13 K 23 α GROUP CONTROLLERS r2r3 K 21 K 31 α r1r3 K 12 K 32 α r1r2r3 K 14 K 24 K 34 α 4 r2r3r4 K 21 K 31 K 41 r1r3r4 K 12 K 32 K 42 r1r2r4 K 13 K 23 K 43 α α α USC Info rmation Sciences Institute Gene Tsudik

  10. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 9 Group Signatures Group Manager Member enroll Register Member Anyone verify sign Signed message Group "plaintiff" Manager open Signed message − GM cannot cheat − Easy Registration − Members cannot cheat − Efficient Sign, Verify, Open − Outsiders cannot cheat * Exclusion not worked out yet... − No coalitions USC Info rmation Sciences Institute Gene Tsudik

  11. D ARP A High Con�dence Net w o rking W o rkshop, 06/12/98. 10 On-going and F uture W o rk Memb er (entit y) authentic ati on � Encryption fo r/within group � Authenticati on of sp eci�c and anonymous group memb ers � CLIQUES T o olkit available 1998 � API de�nition, p erfo rmance measurements, integration exp erience � Group Signatures � CLIQUES HOME P A GE: www.isi.edu//div7//cl iq ues USC Info rmation Sciences Institute Gene Tsudik

Recommend


More recommend