电子学报2024,Vol.52Issue(6) :1911-1924.DOI:10.12263/DZXB.20220727

边云协同场景中基于动态属性权限的群组密钥协商协议

Group Key Agreement Protocol Based on Dynamic Attribute Permissions for Edge-Cloud Collaboration Scenarios

张启坤 朱亮 韩桂锋 刘梦琪 金保华 李元章
电子学报2024,Vol.52Issue(6) :1911-1924.DOI:10.12263/DZXB.20220727

边云协同场景中基于动态属性权限的群组密钥协商协议

Group Key Agreement Protocol Based on Dynamic Attribute Permissions for Edge-Cloud Collaboration Scenarios

张启坤 1朱亮 2韩桂锋 1刘梦琪 1金保华 1李元章3
扫码查看

作者信息

  • 1. 郑州轻工业大学计算机与通信工程学院,河南郑州 450002
  • 2. 华东师范大学软件工程学院,上海 200062
  • 3. 北京理工大学计算机学院,北京 100081
  • 折叠

摘要

针对边云协同应用场景中多域间终端的安全通信、信息安全交换及安全资源共享等问题,提出一种基于动态属性权限的群组密钥协商(Group Key Agreement,GKA)协议,为应用场景中的群组终端之间建立了一条安全的通信信道.协议提出了一种密钥证实算法,解决了传统方案中密钥生成和密钥分发造成的安全隐患;采用隐藏属性认证技术实现对终端身份认证,同时,保障了终端的身份和属性信息不被泄露;采用属性基加密(Attribute-Based Encryp-tion,ABE)与牛顿插值多项式相结合的方式,能够支持安全细粒度的GKA;采用非对称计算,将计算任务转移到边缘服务器上执行,减轻终端的计算量;利用区块链技术不可篡改的特性,实现终端身份和通信信息的完整性验证和数据的可追溯性.此外,该协议支持属性权限动态更新,保障群组密钥的新鲜性.通过与应用的文献进行对比分析,本协议在计算时间、计算能耗和通信能耗方面具有较好的性能.

Abstract

In the edge-cloud collaborative application scenario,there are many problems in the secure communica-tion,information security exchange and secure resource sharing of multi domain terminals. In order to solve these problems,a group key agreement (GKA) protocol based on dynamic attribute permissions is proposed. In the protocol,a key verifica-tion algorithm is proposed to solve the security problems caused by key generation and key distribution in the traditional scheme. The hidden attribute authentication technology is adopted to realize terminal identity authentication. At the same time,hidden attribute authentication technology ensures that the terminal identity and attribute information are not dis-closed. In the protocol,the combination of attribute-based encryption (ABE) and Newton interpolation polynomial is adopt-ed,which can support secure fine-grained group key agreement. By adopting asymmetric computing,the computing tasks are transferred to the edge server for execution to reduce the computing load of the terminal. The tamper-proof characteris-tics of blockchain technology are applied to realize the integrity verification of terminal identity and communication infor-mation so that the data can be traced. In addition,the protocol supports dynamic updating of attribute permissions to ensure the freshness of groups. Compared with the applied literature,this protocol has good performance in computing time,com-puting energy consumption and communication energy consumption.

关键词

边云协同/群组密钥协商/牛顿插值多项式/属性基加密/动态属性权限/隐藏属性认证

Key words

edge-cloud collaboration/group key agreement/Newton interpolating polynomial/attribute-based encryption/dynamic attribute permissions/hidden attribute authentication

引用本文复制引用

基金项目

国家自然科学基金(61971380)

国家自然科学基金(62072037)

国家自然科学基金(61772477)

郑州市协同创新专项(2021ZDPY0206)

出版年

2024
电子学报
中国电子学会

电子学报

CSTPCD北大核心
影响因子:1.237
ISSN:0372-2112
参考文献量1
段落导航相关论文