Provably Authenticated Group Die-Hellman Key Exchange { The Dynamic Case (Full version)

Emmanuel Bresson, Olivier Chevassut, David Pointcheval · 2001

Dynamic group Die-Hellman protocols for Authenticated Key Exchange (AKE) are designed to work in a scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we dene a security model for this problem and use it to precisely dene Authenticated Key Exchange (AKE) with \implicit authentication as the fundamental goal, and the entity-authentication goal as well. We then dene in this model the execution of a protocol modied from a dynamic group Die-Hellman scheme oered in the litterature and prove its security. Group Die-Hellman schemes for Authenticated Key Exchange are designed to provide a pool of players communicating over a public network and holding long-lived secrets with a session key to be used to achieve multicast message conden tiality or multicast data integrity. In this paper, we consider the scenario in which the group membership is not known in advance { dynamic rather than static { where parties may join and leave the multicast group at any given time. After the initialization phase, and throughout the lifetime of the multicast group, the parties need to be able to engage in a conversation after each change in the membership at the end of which the session key is updated to be sk 0 . The secret value sk 0 is only known to the party in the multicast group during the period when sk 0 is the session key. The adversary may generate repeated and arbitrarily ordered changes in the membership for subsets of parties of his choice. The above scenario is a distributed application in which up to one hundred parties work together in order to get a task done where many of the parties may be sending data to the multicast group (12). Examples of such applications include replicated server (21), audio-video conferencing (20) and collaborative tools (2).

Read the paper · More papers on PaperTik