Comments on ‘Chinese Remainder Theorem‐based centralised group key management for secure multicast communication’

Autor: Zhe Xia, Yu Yang, Fuyou Miao
Jazyk: angličtina
Rok vydání: 2023
Předmět:
Zdroj: IET Information Security, Vol 17, Iss 2, Pp 309-314 (2023)
Druh dokumentu: article
ISSN: 1751-8717
1751-8709
DOI: 10.1049/ise2.12085
Popis: Abstract To ensure private message exchange among the group members, it is desirable to construct secure and efficient group key management schemes. Moreover, these schemes are more versatile if they could support dynamic join or leave of group members. In IET Information Security 2014, Vijayakumar et al. have introduced such a group key management scheme with lightweight overheads in both computation and communication. And this scheme has been used as a building block in many cryptographic protocols afterwards. In this paper, the authors demonstrate that Vijayakumar's scheme suffers some potential security weaknesses. First, after participating in the group communications for some sessions, a group member may still be able to obtain the group key after it leaves the group, and this violates the claimed security property of forward secrecy. Second, some colluding group members may derive another group member's long term secret key, and obviously, this has more serious consequences. One of the main reasons for the existence of these attacks is that the security analyses in Vijayakumar's scheme are informal and they cannot cover the dynamic environment. To address this issue, the authors’ suggestion is that heuristic arguments of security are not adequate in the design of cryptographic protocols, but formal security definitions and proofs are required.
Databáze: Directory of Open Access Journals