Symmetric-Key Broadcast Encryption: The Multi-sender Case

نویسندگان

  • Cody Freitag
  • Jonathan Katz
  • Nathan Klein
چکیده

The problem of (stateless, symmetric-key) broadcast encryption, in which a central authority sends encrypted content that can be decrypted only by a designated subset of potential receivers, has been the focus of a significant amount of attention. Here, we consider a generalization of this problem in which all members of the group may act as both sender and receiver. The parameters of interest are the number of keys stored per user and the bandwidth required per transmission, as a function of the total number of users n and the number of revoked users r. As our main results, we show a multi-sender scheme allowing revocation of an arbitrary number of users, in which users store O(n) keys and the bandwidth is O(r log n/r). We then prove a matching lower bound on the storage in this case, showing that Ω(n) keys are necessary (regardless of the bandwidth) for unique predecessor schemes, a class of schemes capturing all recent constructions in the single-sender case. We also show a scheme with storage polylog(n) and bandwidth O(r) that can be used to revoke up to polylog(n) users.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Broadcast Encryption Based on Braid Groups

Broadcast encryption is the scheme that a sender encrypts messages for a designated group of receivers, and sends the ciphertexts by broadcast over the networks. Many research papers have done it using elliptic curve cryptography. In this paper, we propose the broadcast encryption scheme based on braid groups cryptography which is an alternative method in the public key cryptography and can red...

متن کامل

Study on Contributory Broadcast Encryption with Efficient Encryption and Short Ciphertexts

Traditional broadcast encryption (BE) schemes al-low a sender to securely broadcast to any subset of members but require a trusted party to distribute decryption keys. Group key agreement (GKA) protocols enable a group of members to negotiate a common encryption key via open networks so that only the group members can decrypt the ciphertexts encrypted under the shared encryption key, but a send...

متن کامل

Efficient Encryption Schema Using Short Cipher Texts for Broadcasting

Traditional broadcast encryption (BE) schemes allow a sender to securely broadcast to any subset of members but require a trusted party to distribute decryption keys. Group key agreement (GKA) protocols enable a group of members to negotiate a common encryption key via open networks so that only the group members can decrypt the ciphertexts encrypted under the shared encryption key, but a sende...

متن کامل

Bridging Broadcast Encryption and Group Key Agreement

Broadcast encryption (BE) schemes allow a sender to securely broadcast to any subset of members but requires a trusted party to distribute decryption keys. Group key agreement (GKA) protocols enable a group of members to negotiate a common encryption key via open networks so that only the members can decrypt the ciphertexts encrypted under the shared encryption key, but a sender cannot exclude ...

متن کامل

Public Key Broadcast Encryption for Stateless Receivers

A broadcast encryption scheme allows the sender to securely distribute data to a dynamically changing set of users over an insecure channel. One of the most challenging settings for this problem is that of stateless receivers, where each user is given a fixed set of keys which cannot be updated through the lifetime of the system. This setting was considered by Naor, Naor and Lotspiech [17], who...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017