Broadcast Encryption Scheme π.pdfVIP

  • 5
  • 0
  • 约4.17万字
  • 约 18页
  • 2017-04-13 发布于江苏
  • 举报
Broadcast Encryption Scheme π

Broadcast Encryption Scheme π ? Nam-Su Jho, Jung Hee Cheon, Myung-Hwan Kim, and Eun Sun Yoo ISaC and Department of Mathematical Sciences, Seoul National University, Seoul 151-747, Korea { drake, jhcheon, mhkim, eunsun}@math.snu.ac.kr Abstract. We propose a new broadcast encryption scheme π based on the idea of ‘one key per each punctured interval’. Let N and r be the numbers of total users and revoked users, respectively. In our scheme with p-punctured c-intervals, the transmis- sion overhead is asymptotically rp+1 as r grows. We also introduce two variants of our scheme to improve the efficiency for small r. Our scheme is very flexible with two parameters p and c. We may take p as large as possible if a user device allows a large key storage, and set c as small as possible if the storage size and the computing power is limited. Our scheme also possesses another remarkable feature that any number of new users can join at any time without key refreshment, which is not possible in other known practical schemes. 1 Introduction Broadcast encryption (BE) is a cryptographic method for a center to efficiently broadcast digital contents to a large set of users so that only non-revoked users can decrypt the contents. BE has a wide range of applications such as internet or mobile broadcast of movies, news or games, pay TV, and even CD or DVD, to name a few. In broadcast encryption, the center distributes to each user u the set Ku of keys, called the user key set of u, in the system setup stage. We assume that the user keys are not updated afterwards, that is, user keys are stateless. A session is a time interval during which only one encrypted message (digital contents) is broadcasted. The session key, say SK, is the key used to encrypt the contents of the session. In order to broadcast a message M , the center encrypts M using the session key SK and broadcasts the encrypted message together with a header, which contains encryptions of SK and the information for non-revoked u

文档评论(0)

1亿VIP精品文档

相关文档