Security Analysis of Joint Group Key Agreement Protocol
C.-H. TAN · IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences · 2007
In a secure group communication, a group key agreement is to provide a secret key exchange among a group of users. When a new user joins the group, a new group key will be established. In this paper, we analyse Horng's joint protocol and show that this protocol does not provide backward secrecy. This means that a new joining user is able to discover the previous group key used by the previous group member.