A distributed and hierarchical key issuing protocol in identity-based cryptosystem

Na Wang, Ning Zhou, Yingjian Zhi, Binqiang Wang · 2007

Key escrow is an inherent weakness of the identity-based cryptosystem. Secure key issuing proposals previously proposed either lack concrete specification, or are vulnerable to several malicious attacks. The paper proposes a novel secure key issuing protocol, called the Distributed and Hierarchical Key Issuing (DHKI) protocol, in which the system master key is distributed to n distinct sPKGs (a share of Private Key Generators), and a user firstly obtains a share of private key and an identity attestation from a primary sPKG, then requests other shares of private key from secondary sPKGs by submitting the identity attestation, to retrieve his private key. DHKI supports key revocation, and is secure against replay attack, forgery attack and stolen verifier attack etc. The paper applies DHKI in an identity-based BGP path verification mechanism proposed by us to issue a router's private key.

Read the paper · More papers on PaperTik