Secure group communication: self-healing key distribution and nontransferable anonymous credentials
Sara Kendall More, Russell Impagliazzo · 2003
In this dissertation, we study two issues in secure group communication. First, we address session key distribution over unreliable networks, where key update messages sent by the group manager may be lost during transmission. We introduce key distribution schemes which we term self-healing, where users who missed key update information can recover keys without further interaction with the group manager. Key update information missed due to a lost transmission can be recovered by users who have received any two transmissions which sandwich the lost one—that is, any message sequentially before the lost message and any message after it. In addition, our solutions allow users to be added or removed from the group without individually redistributing keys to existing group members. We then propose a second solution which implements a sliding window approach to self-healing, where the sandwiching broadcasts used for key recovery must be within a parameter δ of the lost message. This results in shorter transmission lengths, as well as continuous self-healing ability throughout the scheme. The second group communication issue we consider is the ability for individuals in a particular group to remain anonymous while demonstrating their group membership. Specifically, we improve upon existing anonymous credential systems by developing a model and solution with stronger guarantees of non-transferability which do not sacrifice user anonymity. When anonymous credentials are implemented using only passwords or secret keys, for example, the credentials are easy to copy—users can simply tell their passwords to friends. In contrast, our model uses biometric authentication modules in tamper-resistant hardware to tie credentials directly to particular individuals, so credentials are essentially copy-resistant and useless if lent to others. Furthermore, despite the fact that the user cannot inspect the code inside the secure hardware, we ensure that the hardware cannot leak information about the user's identity without his knowledge when he displays the credential. Finally, we describe an extension which allows group members to be added to and removed from the group in a secure manner.