WO2008140798A1 - Flexible management of security for multi-user environments - Google Patents

Flexible management of security for multi-user environments Download PDF

Info

Publication number
WO2008140798A1
WO2008140798A1 PCT/US2008/006027 US2008006027W WO2008140798A1 WO 2008140798 A1 WO2008140798 A1 WO 2008140798A1 US 2008006027 W US2008006027 W US 2008006027W WO 2008140798 A1 WO2008140798 A1 WO 2008140798A1
Authority
WO
WIPO (PCT)
Prior art keywords
group
polynomial
information
members
communication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2008/006027
Other languages
French (fr)
Inventor
Zou Xukai
Yuanshun Dai
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Indiana University Research and Technology Corp
Original Assignee
Indiana University Research and Technology Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Indiana University Research and Technology Corp filed Critical Indiana University Research and Technology Corp
Publication of WO2008140798A1 publication Critical patent/WO2008140798A1/en
Priority to US12/616,316 priority Critical patent/US20100128879A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/083Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
    • H04L9/0833Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key
    • H04L9/0836Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key using tree structure or hierarchical structure
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/60Digital content management, e.g. content distribution

Definitions

  • Multiuser environments such as trusted collaborative computing (“TCC”) environments
  • TCC trusted collaborative computing
  • SGC secure group communication
  • SDC secure dynamic conferencing
  • DIF-AC differential access control
  • HAC hierarchical access control
  • Cryptography and key management have been investigated in various attempts to secure information; however, until now there has been no mechanism which is able to address the requirements for trusted or secure information transmission and data access in TCC or other multiuser environments.
  • One embodiment is a method including computing or storing an access control polynomial. Further embodiments include systems and computer readable media including an access control polynomial. Further embodiments, forms, objects, features, advantages, aspects, and benefits shall become apparent from the following description and drawings.
  • Fig. 1 is an exemplary CC environment.
  • Fig. 2 is an exemplary access control hierarchy.
  • CC collaborative computing
  • CC applications include, but are not limited to, multi -party military actions, tele-conferencing, video conferencing, tele-medicine, video medicine, interactive and collaborative decision making or conferencing, grid-computing, information distribution, and pay per view services.
  • Further examples include enterprise management software and related applications, electronic mail systems and archives, key management systems, and others.
  • Trust and/or security in such environment can eventually determine its success and popularity due to the desire for confidentiality, privacy and integrity of personal and/or shared information.
  • Existing communication infrastructure such as the internet does not provide high assurance security for data transmission. Security patches and other computing/storage resources available to hackers result in more security vulnerabilities.
  • multiuser and CC environments may present additional challenges owing to the environments being group- oriented, involving a large number of entities and shared resources, being complex, dynamic, distributed, and heterogeneous and even possibly including hostile elements.
  • Systems experience failures due to intrusions and attacks from hostile entities.
  • insider threats by which attacks are from malicious parties inside the organizations or members of CC groups. Consequently, establishing and maintaining trusted collaborative computing (TCC) environments is very difficult.
  • exemplary CC environment 100 is complex and includes a diverse, heterogeneous group of users, resources, systems, communication links, hierarchies, access authorities, and may include internal and external threats.
  • a central server 111 may distribute information to and receive information from a plurality of group members such as group members 101, 102, 103, 103a, 103b ... 103n, 109, 112, and 116 via one or more communication links.
  • Group members can also form sub-groups, such as the sub-group including members 103, 103a, 103b ... 103n.
  • Sub groups could also include greater or fewer numbers of members.
  • the membership of groups and subgroups is dynamic and can increase or decrease.
  • server 111 may also be distributed, for example, a second server 110 may also distribute information to and receive information from a plurality of group members such as group members 113, 114, 112, and 116 via one or more communication links.
  • group members such as group members 113, 114, 112, and 116
  • the nature of the distribution may be physical, virtual, or a combination thereof.
  • the central server is a server cluster, such as a blade or rack server system, with physical and software interconnections among cluster servers.
  • Communication links may be electrical, magnetic, optical or combinations thereof. Communication links can also be wireless, such as the point-to-point wireless link interconnecting server 1 11 and group member 102, or point to multipoint wireless link between group members 106 and 107 and point to multipoint transceiver 105.
  • a point to point wireless link is a microwave transmission link.
  • a point to multipoint wireless link is a cell phone network such as one utilizing CDMA, TDMA, FDMA and other types of transmission protocols and systems.
  • Another example is a WIFI network.
  • a further example is a satellite network such as a direct broadcast satellite network.
  • An additional example is a WIMAX network.
  • the communication links may include routers such as router 108, repeaters such as repeater 104, and other communication link features such as feature 115.
  • Communication links may follow a variety of protocols such as IP, TCP, UDP, VOIP, SSL, and others, and may facilitate communication of a variety of types of information, such as packets, data, voice, picture, video and/or audio information.
  • a variety of system and user resources, such as resource 110a of server 110, and resource 116a of user 116 may also be present in environment 110.
  • a exemplary embodiment may establish a trusted collaborative computing (TCC) environment to facilitate user collaboration in which entities work together and share resources and/or information.
  • TCC trusted collaborative computing
  • One security issue for such environments is that multiple participating entities should be able to communicate securely among one another via one or more communication channels.
  • Techniques such as conventional IP multicast permit transmission of messages to a group of users; however, the open nature of conventional IP multicast makes it unable to provide strong confidentiality.
  • Another security issue is related to resource sharing and data exchange. Access to shared resources/data may need to be precisely and accurately controlled; otherwise attackers and malicious users can access resources to which they are not entitled to access, abuse, tamper, and/or damage. Selective data sharing, at different granularity levels, along with access control is another security issue.
  • security issues relevant for multi-user environments and TCC include hierarchical access control (HAC), secure group communication (SGC), secure dynamic conferencing (SDC), and differential access control (DIF-AC).
  • HAC hierarchical access control
  • SGC secure group communication
  • SDC secure dynamic conferencing
  • DIF-AC differential access control
  • Cryptography is a powerful tool to support all these and other security functions.
  • Key management is a difficult issue in such context, and the generation, distribution, updating, and revocation of keys, such public keys, private keys, security tokens, seeds, or identifiers, in such environments, which may be large and dynamic, is a significant challenge.
  • Exemplary embodiments include an Access Control Polynomial ("ACP").
  • ACP Access Control Polynomial
  • Some embodiments include an ACP through which secret information can be distributed so that only the intended recipients (i.e., their IDs are included as a term (x - /(/D)) in the polynomial) can derive that secret information.
  • Some embodiments utilize an ACP to support security in highly dynamic environments where, for example, users join/leave and there are addition/deletion of resources/data/messages, addition and removal of user/resource relations, random user/data structures/formats according to fine-tuned granularity (e.g., in the levels of users, user groups, data sets, data records, record fields), and/or anonymity (i.e., group membership and size can be hidden from both outsiders and insiders).
  • Some embodiments utilize an ACP to support a plurality of different security functions and provide integration of various application systems. Some embodiments provide resistance or immunity to various attacks, including external hackers and internal malicious members, and even collusion between internal and external attackers.
  • ACP can be described with mathematical rigor. For this discussion the following notation will be used (though different notation might also be applied in other contexts):
  • A(x) The access control polynomial in the form of A(x) ⁇ /(SID 1 , z))
  • a public cryptographic hash function It is used in the form of f(x,y) , i.e. f(x ⁇ y)
  • GID 1 Secret Group Identification, a positive integer
  • SID 1 Personal Permanent Portable Secret, a positive integer
  • VJ A certain vertex in the hierarchy
  • q is a large prime from which a finite field F q is formed, preferably a large prime number, such as 512 bits, 1024 bits, or an even greater number of bits
  • (2) / : ⁇ 0,1 ⁇ * ⁇ ⁇ 0,1 ⁇ q is a cryptographic hash function
  • An exemplary ACP is a polynomial over a finite field F q [x] and defined as follows.
  • A(X) Yl(X- Z(SID n Z)) Eq. (1) ⁇
  • denotes the user group under consideration
  • SID 1 are group members' PS- Secrets assigned to the members in the group ⁇
  • z is a random integer from F p and is made public.
  • z is changed every time A(x) is computed.
  • A(x) is equated to 0 when x is substituted with /(SID 1 ,z) by a valid user with SID 1 in the group ⁇ ; otherwise, A(x) is a random value if other numbers or invalid users' P3-Secrets are used in the substitution.
  • the following polynomial can be computed (for example, by a trusted server):
  • ACP key management for a large range of security functions and applications can be accomplished.
  • ACP key management can be accomplished for SGC, SDC, DIF-AC and/or HAC.
  • SGC refers to a setting in which a group of members can communicate (or share the information) among themselves, in a way that outsiders are unable to understand the communication (or the information) even when they are able to intercept the communication (or the information).
  • the confidentiality of the SGC communication is provided by encrypting the communication with a group key which is distributed to only the group members.
  • a trusted server computes A(x) by Eq. (1) (Step 1) , P(x) by Eq. (2), and then multicasts (z, P(x)) (Step 2). Every user in the group can then compute the key via Eq. (3) (Step 3). After all group members obtain the same key, they can conduct group communication securely.
  • SDC refers to a scenario where any subset, for example a random subset, of the given user population can form a secure communication (sub)group.
  • SDC is closely related to SGC: as an extension of SGC or equivalently, SGC as a specific case of it.
  • SGC as a specific case of it.
  • the size of the universe under consideration is n, there will be 2"- «-l possible conferences. Pre- generating all these 2"-n-l conferences might not be preferred because many conferences may never need to be activated. In addition, conferences may not occur at the same time.
  • a preferred ACP embodiment includes an on-the-fly feature, which means that whenever there is a need to distribute a secret to a specific user group, just the above steps 1), 2), and 3) are executed. This feature is useful for supporting SDC.
  • the server just performs the three steps where A(x) includes 57Ds of the conference members. If a user participates in multiple conferences at the same time, the user's SID can be included in multiple corresponding A(x)'s and the user then can get the keys for all these conferences.
  • the above three steps are executed with A(x) just including the intended users.
  • group dynamics can be efficiently processed in SDC.
  • Access control is used for checking whether a user has the right to access a certain resource or information and for granting or denying access as required. Access control can be a fundamental security issue for many computing systems in which users and resources are involved.
  • DIF-AC a user can (and only can) access certain resources and a resource can (and only can) be accessed by certain users (i.e., many-to-many relation, determined by, for example, subscription and payment).
  • Exemplary applications requiring DIF-AC include, but are not limited to, e-newspapers, pay-per-view broadcast TV, multiple streaming services and/or secret or confidential communications.
  • every resource R k is associated with a dynamic key K k , and the users who can access R k are treated as a conference.
  • the server computes A k ⁇ x) and P k (x), and publicizes (z, P k (x)) .
  • the user who can access R k , can derive key K k and is granted access to resource R k .
  • the user's SIDi will be included in the Ak ⁇ x)'s of all these resources.
  • dynamics can be implemented by inclusion and exclusion of users' SIDs in the formation of new AkfxYs.
  • HAC occurs when resources (and users) have some hierarchical relation: resources are assigned levels and a user who has the access right to a resource at one level is automatically granted access to the resources which are the resource's children or descendants at lower levels. However the reverse is not allowed.
  • the most generic format of HAC can be represented as a Directed Acyclic Group (DAG) (as illustrated in Fig. 2).
  • a node in the hierarchy can represent a user, a resource, a set of users, a set of resources, or both users and resources.
  • the server also selects a dynamic key Kk for every Ck- Now, the server constructs A k (x) using this node's CID k as well as CIDs of all its ancestors:
  • the node C k i.e., the users in C k
  • C k cannot reversely get C, 's key.
  • the hierarchical access control is correctly and securely enforced.
  • the key derivation by the node's ancestors is performed in the identical way as the key computation by a node. Moreover, nodes do not need to know the exact hierarchy. The nodes that are ancestors of a node will obtain the correct key of the node when substituting their CID into P(x) but others will not.
  • node level and user level There are two level dynamics in HAC: node level and user level.
  • the node level dynamics include adding a node, deleting a node, moving a node from one place to another, adding one link between two nodes, and deleting a link between two nodes.
  • User level dynamics include addition and deletion of a user from a node group and movement of a user from one node group to another. Based on ACP, both level dynamics can be accomplished efficiently.
  • the new node CID in node C k is updated by the above polynomial excluding the term (x - /(SID 1 , z')) (Note: a new z 1 is used).
  • the new node CID of the group C is updated with the above polynomial including the term (x - f (SID 1 , z")) (Note: a new z" is used).
  • An ACP embodiment can address the HAC problem in the same manner and the same efficiency of SGC/SDC.
  • Exemplary applications involving HAC include government or private organization computer systems, digital libraries, medical information systems, systems storing proprietary information, and systems including other confidential or limited access information.
  • K is randomly and uniformly selected from 0 to q- 1.
  • the introduction of the access polynomial (no matter how high its degree is) will not reduce the size of the key space.
  • an internal user can obtain K from its own SID 1 .
  • V 1 will result in K to be disclosed, but this does not help at all because he had been allowed to get K from his own SID.
  • V 1 /(SID 1 , z) can be only used for getting this K and cannot help in determining any other keys from other P(x)'s because z is updated every time and two V 1 s in two P(X) 1 S will be different even though SID 1 is the same.
  • the internal malicious user cannot violate the security of the ACP embodiment.
  • it is useless for multiple internal users to collude because their collusion cannot help to make the inverse of the cryptographic hash function easier, thus, making impossible to get SID, from v ; .
  • the attackers may hope to glean multiple P(x)'s and try to get useful information from them; however, this attempt would also be useless due to the changing P(x')s.
  • There are different forms of collusions in the hierarchy such as two siblings trying to figure out their parent's key, a node and its nephew trying to figure out its parent key.
  • these cases of attacks can be reduced to the collusion of external attackers, or internal malicious members or internal/external users depending on whether (and how many) their SIDs are included in P(x).
  • a preferred ACP embodiment is able to defend against any such collusion.
  • the storage complexity (at both user end and server end), computation complexity (at both the user end and server end), and communication complexity can be analyzed.
  • the user- end storage cost is 0(1) since a user just needs to store its P3-Secret SID (plus its node CID if in the HAC hierarchy).
  • the server storage cost is 0(n+m) since the server needs to store all n users' 5ZDs (plus m nodes ZDs if in the HAC hierarchy).
  • n terms involved in the generation of P(x) There are two parts to consider. The first part is related to computing /(5ZD, z).
  • the running time of the cryptographic hash function totally depends on itself but is independent from the number of terms n.
  • n f ⁇ SID,z has a cost in 0(nE).
  • the other part is to multiply n terms (x-v)'s.
  • the main operations are multiplication (with modulo) and addition (with modulo).
  • the computation complexity for multiplying n terms (x-v)'s is in O(n 2 ) .
  • This polynomial computation complexity is efficient for the server.
  • n the number of current users in the group. If n is large but just a single user or few users join or leave the group, 0 ⁇ ) or O( « 2 ) is not efficient. There are several ways to improve its efficiency. 1) As for join, the server can just generate a new key and encrypt the new key with the old group key and send it to the group. The server also encrypts the new key with the SID of the joining user and sends it to the joining user. 2) In order to improve the efficiency of computing P(x), we can store and save A(x) in advance.
  • n is the number of all users and m is the size of a small group which can be managed easily and efficiently, for example, m- ⁇ 6.
  • m is the size of a small group which can be managed easily and efficiently, for example, m- ⁇ 6.
  • every m users form a first level group, so a total nlm of such groups G ⁇ ⁇ ,- - -,G ⁇ nlm are formed.
  • every m first level groups form a
  • Every group G 1 ⁇ is associated with a group key K 1 ⁇ and the K lively will be the group key for all users.
  • the group keys are
  • K x ⁇ is distributed to group G hJ by forming the ACP polynomial using the 57Ds of the users in its group,
  • P x j (x) Y ⁇ (x -f(SID t , z)) + K X j where U 1 e G hJ .
  • the generation time will be O(m 2 log m ")
  • the communication complexity is O(w log m " )
  • the key computation and derivation are also in O(m log m " ) .
  • the polynomial generation time, key computation time, and communication complexity are in 2048 units of time, 256 units of times, and 256 units of numbers for transmission.
  • An ACP embodiment can preferably hide the group membership and size from outsiders (and even insiders) preferably without member serialization.
  • the information identifying users would need to be included in the multicast packet, and the users would need to be ordered according to some strategy (referred to as serialization), so that each user knows which portion of the protected key material belongs to him and is thus able to extract the group key from that portion. This would not only result in more computation work (e.g., a user needs to search for his portion) and need synchronization due to the serialization but also unintentionally result in disclosures concerning the group membership information. Keeping group membership information private to outsiders may be important in some applications.
  • a preferred ACP embodiment provides an efficient and elegant solution to address one or more (even all) of the aforementioned features wherein a polynomial hides the group users and does not need to sort the group members. A valid user does not need to know (in fact, he cannot know if the server does not want to tell him) the membership and the order of members but he can get the group key easily by just plugging its SID into the polynomial.
  • a preferred ACP embodiment can be easily extended for the purpose of hiding group size by simply including some random pseudo terms in the polynomial such as:
  • VID x , ⁇ ⁇ ⁇ , VID d are random numbers in F q , called pseudo terms, and d ⁇ s a random positive integer.
  • d a random positive integer.
  • a preferred ACP embodiment is powerful enough to adapt to random forms of interactive/access relations among users and/or resources. These relations include, but are not limited to, equivalent users/resources, one-to-many, many-to-one, many-to-many, Hierarchy, multiple levels, etc. For example, if a node C,'s access permission needs to be transferred to a random other node C, , regardless of the relation and distance between the two nodes in the hierarchy, just include C/s CID j in the construction ofA, ⁇ x).
  • An additional exemplary embodiment includes software stored in a computer accessible medium including an ACP which is: adaptable to different kinds of key management and different kinds of access control relation schemes; able to enforce access control and secure group communication at a plurality of scales and granularities; able, to integrate heterogeneous data sources and systems; able to protect against external attacks, internal attacks, and combined external and internal attacks; supports dynamic environments including the adding and/or revocation of members and/or resources; does not require member serialization or synchronization and does not disclose membership; able to hide the identities of members of the group and the group size; and able to implement flexible key management on the fly.
  • a further exemplary embodiment is a system which utilizes such software.
  • Another exemplary embodiment is a method which utilizes the functionalities of such software.
  • One exemplary embodiment is a method including computing or storing in a computer accessible medium a first polynomial which is a function of a set of numbers each associated with a member of a group to be provided a cryptographic information, determining a second polynomial which is a function of the first polynomial and an information to be privately shared with the group, and using at least one of the first polynomial and the second polynomial in providing communication between or among two or more members of the group.
  • a further exemplary embodiment includes the providing communication between or among two or more members of the group includes providing at least one of a trusted collaborative computing environment, a secure dynamic conferencing environment, a differential access control environment, and a hierarchical access control environment.
  • the first polynomial is a function of a public random number, hi a further exemplary embodiment the first polynomial includes a term which is zero when evaluated with one of the set of numbers each associated with a member of a group to be provided a cryptographic key. In a further exemplary embodiment the first polynomial is described by the formula:
  • A(x) denotes the first polynomial
  • i denotes a member of the group
  • denotes the
  • the cryptographic information is a cryptographic key.
  • a further exemplary embodiment includes distributing the second polynomial to the group.
  • a further exemplary embodiment includes at least one member of the group receiving the second polynomial.
  • a further exemplary embodiment includes obtaining the cryptographic information from a distributed polynomial.
  • a further exemplary embodiment includes communicating among two or more members of the group and utilizing the cryptographic information to secure the communication.
  • a further exemplary embodiment includes conditionally granting access to a resource to one or more members of the group.
  • the first polynomial is defined in a finite field which is formed from a prime number.
  • the resource is one of a broadcast of information and a stream of digital information.
  • a further exemplary embodiment includes adding a member to the group.
  • a further exemplary embodiment includes storing computing or storing a third polynomial which is a function of a new group including one or more added members.
  • a further exemplary embodiment includes removing a member from the group.
  • the removing a member from the group includes computing a third polynomial which is a function of a new group removing one or more members.
  • the providing communication between or among two or more members of the group includes providing secure group communication, secure dynamic conferencing, differential access control, and hierarchical access control.
  • the communication between or among two or more members includes communication via at least one of a packet switched communication link, a wireless communication link, a WIFI communication link, a WIMAX communication link, a communication link utilizing a IP, TCP, UDP, VOIP or SSL, and a communication link utilizing CDMA, TDMA, or FDMA.
  • the removing a member from the group includes determining a fourth polynomial which is a function of the third polynomial.
  • One exemplary embodiment is a system including at least one computer accessible memory configured to store an access control polynomial which is a function of a set of integers personal to and secret to members of a group, a processor operable to process the access control polynomial and information to be shared with at least one member of the group to generate a public polynomial, and an interface to a communication link operable to output the information to be shared with at least one member of the group to the communication link.
  • the computer accessible memory is configured to store instructions for distributing the public polynomial.
  • the information to be shared with at least one member of the group information is a key.
  • the computer accessible memory further includes instructions for distributing the key to the group members.
  • the computer accessible memory further includes instructions for providing SGC. In a further exemplary embodiment the computer accessible memory further includes instructions for providing SDC. In a further exemplary embodiment the computer accessible memory further includes instructions for providing DIF-AC. In a further exemplary embodiment the computer accessible memory further includes instructions for providing HAC. hi a further exemplary embodiment the computer accessible memory further includes instructions for providing SGC, SDC, DIF-AC, and HAC.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)

Abstract

One embodiment is a method including computing or storing in a computer accessible medium a first polynomial which is a function of a set of numbers each associated with a member of a group to be provided a cryptographic information, determining a second polynomial which is a function of the first polynomial and an information to be privately shared with the group, and using at least one of the first polynomial and the second polynomial in providing communication between or among two or more members of the group. Further embodiments include systems and computer readable media including an access control polynomial.

Description

FLEXIBLE MANAGEMENT OF SECURITY FOR MULTI-USER ENVIRONMENTS
BACKGROUND
Multiuser environments, such as trusted collaborative computing ("TCC") environments, present a number of unmet challenges including those relating to secure group communication (SGC), secure dynamic conferencing (SDC), differential access control (DIF-AC), hierarchical access control (HAC), and other functionalities. Cryptography and key management have been investigated in various attempts to secure information; however, until now there has been no mechanism which is able to address the requirements for trusted or secure information transmission and data access in TCC or other multiuser environments.
SUMMARY
One embodiment is a method including computing or storing an access control polynomial. Further embodiments include systems and computer readable media including an access control polynomial. Further embodiments, forms, objects, features, advantages, aspects, and benefits shall become apparent from the following description and drawings.
BRIEF DESCRIPTION OF THE FIGURES
Fig. 1 is an exemplary CC environment.
Fig. 2 is an exemplary access control hierarchy.
DETAILED DESCRIPTION
For the purposes of promoting an understanding of the principles of the invention, reference will now be made to the embodiments illustrated in the drawings and specific language will be used to describe the same. It will nevertheless be understood that no limitation of the scope of the invention is thereby intended, and that all alterations and further modifications of the following embodiments and such further applications of the principles of the invention as would occur to one skilled in the art to which the invention relates are contemplated.
With reference to Fig. 1, there is illustrated an exemplary collaborative computing ("CC") environment 100. Exemplary CC applications include, but are not limited to, multi -party military actions, tele-conferencing, video conferencing, tele-medicine, video medicine, interactive and collaborative decision making or conferencing, grid-computing, information distribution, and pay per view services. Further examples include enterprise management software and related applications, electronic mail systems and archives, key management systems, and others. Trust and/or security in such environment can eventually determine its success and popularity due to the desire for confidentiality, privacy and integrity of personal and/or shared information. Existing communication infrastructure such as the internet does not provide high assurance security for data transmission. Security patches and other computing/storage resources available to hackers result in more security vulnerabilities. Compared to two-party interaction models (such as the client-server service model), multiuser and CC environments may present additional challenges owing to the environments being group- oriented, involving a large number of entities and shared resources, being complex, dynamic, distributed, and heterogeneous and even possibly including hostile elements. Systems experience failures due to intrusions and attacks from hostile entities. In addition, there is the problem of insider threats, by which attacks are from malicious parties inside the organizations or members of CC groups. Consequently, establishing and maintaining trusted collaborative computing (TCC) environments is very difficult.
As illustrated in Fig. 1, exemplary CC environment 100 is complex and includes a diverse, heterogeneous group of users, resources, systems, communication links, hierarchies, access authorities, and may include internal and external threats. A central server 111 may distribute information to and receive information from a plurality of group members such as group members 101, 102, 103, 103a, 103b ... 103n, 109, 112, and 116 via one or more communication links. Group members can also form sub-groups, such as the sub-group including members 103, 103a, 103b ... 103n. Sub groups could also include greater or fewer numbers of members. The membership of groups and subgroups is dynamic and can increase or decrease. The functionalities of server 111 may also be distributed, for example, a second server 110 may also distribute information to and receive information from a plurality of group members such as group members 113, 114, 112, and 116 via one or more communication links. The nature of the distribution may be physical, virtual, or a combination thereof. In a exemplary embodiment, the central server is a server cluster, such as a blade or rack server system, with physical and software interconnections among cluster servers.
A variety of communication links are also illustrated in environment 100. Communication links may be electrical, magnetic, optical or combinations thereof. Communication links can also be wireless, such as the point-to-point wireless link interconnecting server 1 11 and group member 102, or point to multipoint wireless link between group members 106 and 107 and point to multipoint transceiver 105. One example of a point to point wireless link is a microwave transmission link. One example of a point to multipoint wireless link is a cell phone network such as one utilizing CDMA, TDMA, FDMA and other types of transmission protocols and systems. Another example is a WIFI network. A further example is a satellite network such as a direct broadcast satellite network. An additional example is a WIMAX network. There are a plurality of user types that may utilize such networks including cell phone, computer, PDA, video conferencing, audio conferencing, and other types of users. The communication links may include routers such as router 108, repeaters such as repeater 104, and other communication link features such as feature 115. Communication links may follow a variety of protocols such as IP, TCP, UDP, VOIP, SSL, and others, and may facilitate communication of a variety of types of information, such as packets, data, voice, picture, video and/or audio information. A variety of system and user resources, such as resource 110a of server 110, and resource 116a of user 116 may also be present in environment 110.
A exemplary embodiment may establish a trusted collaborative computing (TCC) environment to facilitate user collaboration in which entities work together and share resources and/or information. One security issue for such environments is that multiple participating entities should be able to communicate securely among one another via one or more communication channels. Techniques such as conventional IP multicast permit transmission of messages to a group of users; however, the open nature of conventional IP multicast makes it unable to provide strong confidentiality. Another security issue is related to resource sharing and data exchange. Access to shared resources/data may need to be precisely and accurately controlled; otherwise attackers and malicious users can access resources to which they are not entitled to access, abuse, tamper, and/or damage. Selective data sharing, at different granularity levels, along with access control is another security issue. It may be desirable for these classes of functions to be sufficiently flexible as to support various possible forms of interactive access relations between the parties and the resources in the system. Thus, security issues relevant for multi-user environments and TCC include hierarchical access control (HAC), secure group communication (SGC), secure dynamic conferencing (SDC), and differential access control (DIF-AC). Cryptography is a powerful tool to support all these and other security functions. Key management is a difficult issue in such context, and the generation, distribution, updating, and revocation of keys, such public keys, private keys, security tokens, seeds, or identifiers, in such environments, which may be large and dynamic, is a significant challenge.
Exemplary embodiments include an Access Control Polynomial ("ACP"). Some embodiments include an ACP through which secret information can be distributed so that only the intended recipients (i.e., their IDs are included as a term (x - /(/D)) in the polynomial) can derive that secret information. Some embodiments utilize an ACP to support security in highly dynamic environments where, for example, users join/leave and there are addition/deletion of resources/data/messages, addition and removal of user/resource relations, random user/data structures/formats according to fine-tuned granularity (e.g., in the levels of users, user groups, data sets, data records, record fields), and/or anonymity (i.e., group membership and size can be hidden from both outsiders and insiders). Some embodiments utilize an ACP to support a plurality of different security functions and provide integration of various application systems. Some embodiments provide resistance or immunity to various attacks, including external hackers and internal malicious members, and even collusion between internal and external attackers.
An ACP can be described with mathematical rigor. For this discussion the following notation will be used (though different notation might also be applied in other contexts): A(x) The access control polynomial in the form of A(x) ~ /(SID1 , z))
Figure imgf000009_0001
Fq: The finite field
/ : A public cryptographic hash function. It is used in the form of f(x,y) , i.e. f(x \\ y)
GID1 : Secret Group Identification, a positive integer
P(x) The public polynomial sent to users for key distribution, P(x) = A(x) + K q: A large prime, as a predefined system parameter
SID1: Personal Permanent Portable Secret, a positive integer
U1 A group member in a certain group
VJ A certain vertex in the hierarchy
z A random integer which is changed and made public every time.
% Mod operation
Let us consider exemplary environments having the following characteristics: (1) q is a large prime from which a finite field Fq is formed, preferably a large prime number, such as 512 bits, 1024 bits, or an even greater number of bits, (2) / : {0,1}* → {0,1} q is a cryptographic hash function, and (3) there is a trusted system component, resource, or computer, such as, for example, a server. Every valid user, say U1, in the system is assigned a Personal Permanent Portable Secret, called P3-Secret and denoted as SIDi (a random positive integer less than q). This secret is only known to the user and the central server. Since users are generally required to register to the system, the assignment of an SID to a user can be performed during the registration procedure, for example, by using a two-party security mechanism.
An exemplary ACP is a polynomial over a finite field Fq [x] and defined as follows. A(X) = Yl(X- Z(SIDnZ)) Eq. (1) ιεψ where ψ denotes the user group under consideration, SID1 are group members' PS- Secrets assigned to the members in the group ψ , and z is a random integer from Fp and is made public. In addition, z is changed every time A(x) is computed. A(x) is equated to 0 when x is substituted with /(SID1 ,z) by a valid user with SID1 in the group ψ ; otherwise, A(x) is a random value if other numbers or invalid users' P3-Secrets are used in the substitution.
In order to broadcast a secret value such as K to the users in group ψ , the following polynomial can be computed (for example, by a trusted server):
P(x) = A(x) + K Eq. (2)
Then, (z,P(x)) is distributed or publicized (for example, broadcast) and K is hidden, mixed with A(x) . From this public information, any group member U1 with SIDj can obtain the secret value, K, by:
K = P(Z(SIDn Z)) Eq. (3)
Utilizing an ACP, key management for a large range of security functions and applications can be accomplished. For example, ACP key management can be accomplished for SGC, SDC, DIF-AC and/or HAC.
SGC refers to a setting in which a group of members can communicate (or share the information) among themselves, in a way that outsiders are unable to understand the communication (or the information) even when they are able to intercept the communication (or the information). The confidentiality of the SGC communication is provided by encrypting the communication with a group key which is distributed to only the group members. In one SGC embodiment a trusted server computes A(x) by Eq. (1) (Step 1) , P(x) by Eq. (2), and then multicasts (z, P(x)) (Step 2). Every user in the group can then compute the key via Eq. (3) (Step 3). After all group members obtain the same key, they can conduct group communication securely.
Let us consider group dynamics. Users can join, leave or be revoked from the system. From the construction of A(x), it can be seen that regardless of whether we deal with single join, single leave, multiple joins, multiple leaves, or multiple joins and leaves simultaneously, dynamics can be implemented with great elegance and easily: the above steps 1), 2), and 3) are followed but in the formation of A(x), just the joining users' SIDs (in fact, / (SID1, z) ) are included and the leaving users' SIDs are excluded. Note that z and K in these steps are new random numbers. Once the key is changed, the encryption with the new key will prevent the leaving (or joining) users from accessing the future (or the past) information.
SDC refers to a scenario where any subset, for example a random subset, of the given user population can form a secure communication (sub)group. As it is evident, SDC is closely related to SGC: as an extension of SGC or equivalently, SGC as a specific case of it. Suppose the size of the universe under consideration is n, there will be 2"-«-l possible conferences. Pre- generating all these 2"-n-l conferences might not be preferred because many conferences may never need to be activated. In addition, conferences may not occur at the same time.
A preferred ACP embodiment includes an on-the-fly feature, which means that whenever there is a need to distribute a secret to a specific user group, just the above steps 1), 2), and 3) are executed. This feature is useful for supporting SDC. Whenever there will be a conference of any subset of users, the server just performs the three steps where A(x) includes 57Ds of the conference members. If a user participates in multiple conferences at the same time, the user's SID can be included in multiple corresponding A(x)'s and the user then can get the keys for all these conferences. Whenever users want to join or leave a conference, the above three steps are executed with A(x) just including the intended users. Thus, group dynamics can be efficiently processed in SDC.
Access control is used for checking whether a user has the right to access a certain resource or information and for granting or denying access as required. Access control can be a fundamental security issue for many computing systems in which users and resources are involved. In DIF-AC, a user can (and only can) access certain resources and a resource can (and only can) be accessed by certain users (i.e., many-to-many relation, determined by, for example, subscription and payment). Exemplary applications requiring DIF-AC include, but are not limited to, e-newspapers, pay-per-view broadcast TV, multiple streaming services and/or secret or confidential communications.
Like the above SDC scheme, every resource Rk is associated with a dynamic key Kk, and the users who can access Rk are treated as a conference. The server computes Ak{x) and Pk(x), and publicizes (z, Pk (x)) . Thus, the user, who can access Rk, can derive key Kk and is granted access to resource Rk. If a user can access multiple resources, the user's SIDi will be included in the Ak{x)'s of all these resources. Thus, the user can access all these resources. Similarly, dynamics can be implemented by inclusion and exclusion of users' SIDs in the formation of new AkfxYs.
HAC occurs when resources (and users) have some hierarchical relation: resources are assigned levels and a user who has the access right to a resource at one level is automatically granted access to the resources which are the resource's children or descendants at lower levels. However the reverse is not allowed. The most generic format of HAC can be represented as a Directed Acyclic Group (DAG) (as illustrated in Fig. 2). A node in the hierarchy can represent a user, a resource, a set of users, a set of resources, or both users and resources.
For every node/class Q in the hierarchy, the server selects a unique CIDk and distributes securely CIDk to Q's users {£/, ,U2 ,- --,Un} using the same scheme as that in SGC, i.e., the server computes P(x) = (x - /(SID, , z)) • (x - /(SID2 , z)) • • (x - /(SIDn, z)) + CID k and multicasts (z, P(x)) to Ck's users. The server also selects a dynamic key Kk for every Ck- Now, the server constructs Ak(x) using this node's CIDk as well as CIDs of all its ancestors:
Λ W = (* " f{CIDk , z»π (* - /(CID1 , z)) Eq. (4) teψ
where the first term is Q itself and the next terms are associated with all the ancestors C1 of Q ( ψ is the set of ancestors of C*). Then, the server constructs Pk(A = Ak(x) + Kk and publicizes (zJPk(x)). The node Ck (i.e., the users in Ck) can compute the key Kk as Kk = Pk (/(CIDk ,z)) . Furthermore, any ancestor (i.e., the users in) C1 of Q can also derive the key Kk as Kk = Pk (/(CID1 , z)) . However, Ck cannot reversely get C, 's key. Thus, the hierarchical access control is correctly and securely enforced.
In this ACP-based HAC scheme, the key derivation by the node's ancestors is performed in the identical way as the key computation by a node. Moreover, nodes do not need to know the exact hierarchy. The nodes that are ancestors of a node will obtain the correct key of the node when substituting their CID into P(x) but others will not.
There are two level dynamics in HAC: node level and user level. The node level dynamics include adding a node, deleting a node, moving a node from one place to another, adding one link between two nodes, and deleting a link between two nodes. User level dynamics include addition and deletion of a user from a node group and movement of a user from one node group to another. Based on ACP, both level dynamics can be accomplished efficiently.
Let us consider the operation of deleting a node, since revocation/deletion is generally more difficult to deal with than joining/addition. There are two cases to consider: a leaf node and an internal node. If the deleted node is a leaf node, nothing needs to be done other than discarding the information/values related to this node. If the deleted node is an internal node, a technique should be used to relocate the node's children, for example, a relocation policy or algorithm. However, the particular technique used for such purpose does not matter here. Since the deleted node knew the keys of all its descendants, these keys need to be changed, which is easy. For each of the descendant nodes of the deleted node, the server computes A(x) which includes the CIDs of all new ancestors of the node but excludes the CID of the deleted node and multicasts (z, P(x)=A(x)+K).
Consider the second level dynamics. For example, if one member (with SIDi) leaves group Ck and attends another group Cj, the following two steps complete the update.
1) The new node CID in node Ck is updated by the above polynomial excluding the term (x - /(SID1, z')) (Note: a new z1 is used).
2) The new node CID of the group C, is updated with the above polynomial including the term (x - f (SID1 , z")) (Note: a new z" is used).
An ACP embodiment can address the HAC problem in the same manner and the same efficiency of SGC/SDC. Exemplary applications involving HAC include government or private organization computer systems, digital libraries, medical information systems, systems storing proprietary information, and systems including other confidential or limited access information. We now analyze the security and performance of the above ACP embodiment. By the security analysis, we show that the proposed ACP mechanism is very robust and secure not only against outside attackers which do not know the shared key but also against the insiders which know the shared key. By the performance analysis, we show that the ACP mechanism is very efficient.
We discuss the security of ACP embodiments in terms of external attackers, internal attackers, and collusion of attackers. First, let us consider the key space and the guessing or brute-force attack. K is randomly and uniformly selected from 0 to q- 1. In addition, K can be coincident with any of SID1 and v. = /(5ZD1 , z) , for/ = l, --,rc since it will not affect the correctness of the ACP mechanism. Thus, the introduction of the access polynomial (no matter how high its degree is) will not reduce the size of the key space. As for the brute-force attack, an external attacker can either guess K directly or guess one of v, and then compute K, or guess one of SID1 and compute v, and then K. The probability that a random guess hits K is XIq whereas it is n I q to hit any of V1 and another n I q to hit any of 5ZD1. . Thus, the overall probability for a random trial to success is (2n + 1) / q . This means that the access control polynomial increases the success chance of the brute- force attack by a factor of 2«. The more users are included in the polynomial, the higher the probability of success by the brute-force attack. However, due to the efficiency of the ACP mechanism (as discussed below), q can be selected to be very large, thus, making the brute-force attack inapplicable. Next, let us consider the attacks in which an external attacker tries to obtain the group key K or group users' 5ZDs from P{x) . The K is hidden in the publicized constant term of P(x), i.e. co = (K + V)%q where V = V1 v2 - - -Vn and v, = /(5ZD, ,z) , for/ = !,- • •,« . Since there are many other pairs of K' and V such that C0 = K'+V , the attacker cannot uniquely determine K from c0 As for trying to determine all of K,v] , v2 , , vn from (the coefficients of) P(x) at the same time, the attacker will fail because only n equations can be formed for «+1 unknown K,vx ,v2 ,- - -,vn . As for trying to determine SID1, the only relevant value is v, = /(SID1 , z) which is difficult to be obtained from P(x) as discussed above. Even if the attacker were able to determine v, = /(SID1 , z) somehow, the attacker still would not be able to get SID1 since this would require inversion of the cryptographic hash function / Finally, multiple external attackers may collude to determine K or SID1, but their collusion provides no more information than the information that would be obtained by a single attacker; collusion is thus useless. ACP embodiments are resistant to external attacks.
We now consider the case of internal malicious users. Obviously, an internal user can obtain K from its own SID1. Thus the purpose of an internal malicious user is to obtain the SZDs of some other users so that he can get the secret information, reserved to other users, to which he is not authorized to access. He can obtain the exact polynomial A(x) as A(x)=P(x)-K and then set A(x)=Q to determine the roots of A(x). He may find v, = /(SID1 , z) , however, it is computationally infeasible to get SID1 from v, = /(SID1 , z) due to the one-way feature of the cryptographic hash function/ Getting v, of the other user does not therefore help the attacker. First, V1 will result in K to be disclosed, but this does not help at all because he had been allowed to get K from his own SID. Additionally, this V1 = /(SID1 , z) can be only used for getting this K and cannot help in determining any other keys from other P(x)'s because z is updated every time and two V1 s in two P(X)1S will be different even though SID1 is the same. As a result, the internal malicious user cannot violate the security of the ACP embodiment. Furthermore, it is useless for multiple internal users to collude because their collusion cannot help to make the inverse of the cryptographic hash function easier, thus, making impossible to get SID, from v; . The collusion of internal malicious users and external attackers is also useless in getting other users' SID (Note: the collusion here does not include the case of an internal user giving his SID or the key to an outsider so that the outsider can access the information. If this case is considered as a collusion, then it is inherent in all cryptosystems and there is no technological solution to it).
The attackers may hope to glean multiple P(x)'s and try to get useful information from them; however, this attempt would also be useless due to the changing P(x')s. There are different forms of collusions in the hierarchy such as two siblings trying to figure out their parent's key, a node and its nephew trying to figure out its parent key. However, these cases of attacks can be reduced to the collusion of external attackers, or internal malicious members or internal/external users depending on whether (and how many) their SIDs are included in P(x). As discussed above, a preferred ACP embodiment is able to defend against any such collusion.
The storage complexity (at both user end and server end), computation complexity (at both the user end and server end), and communication complexity can be analyzed. The user- end storage cost is 0(1) since a user just needs to store its P3-Secret SID (plus its node CID if in the HAC hierarchy). The server storage cost is 0(n+m) since the server needs to store all n users' 5ZDs (plus m nodes ZDs if in the HAC hierarchy). Suppose there are n terms involved in the generation of P(x). There are two parts to consider. The first part is related to computing /(5ZD, z). The running time of the cryptographic hash function totally depends on itself but is independent from the number of terms n. Suppose its running time is 0(B), then computing n f{SID,z) has a cost in 0(nE). The other part is to multiply n terms (x-v)'s. The main operations are multiplication (with modulo) and addition (with modulo). There are in total O(n2) of such operations. The computation complexity for multiplying n terms (x-v)'s is in O(n2) . Thus, the total computation complexity for generating P(x) is in O(nB + n2) = O(n2) . This polynomial computation complexity is efficient for the server. We now consider the computation complexity for computing the key from a polynomial P(x) of degree n when replacing x with the computed value v = f(SID,z) . The main operations here are: 1) the computation of v,v2 %q,- - -,v" %q which requires n multiplications (with modulo); 2) the multiplication of each of these values with its corresponding coefficient, which requires another n multiplications; and 3) the addition of the results, which requires n additions. In total, the complexity of computing the key from P(x) is in 0{ή) . With respect to the communication complexity, broadcasting P{x) = anx" + an_λx"~x H \- axx + a0 requires to broadcast the coefficients an , an_λ ,- ~,aλ ,aϋ . Thus, the communication complexity is in 0{ή). These complexities are summarized in Table 1 below. Note: key derivation is similar to key computation.
Table 1. Complexities of the ACP based key management
Figure imgf000018_0001
From the above complexity analysis, it is clear that all complexities are proportional to n, the number of current users in the group. If n is large but just a single user or few users join or leave the group, 0{ή) or O(«2) is not efficient. There are several ways to improve its efficiency. 1) As for join, the server can just generate a new key and encrypt the new key with the old group key and send it to the group. The server also encrypts the new key with the SID of the joining user and sends it to the joining user. 2) In order to improve the efficiency of computing P(x), we can store and save A(x) in advance. If one or a few users Ux ,- - -,Uk leave, we can get the new A(x) by directly dividing A(x) by (x — /(SID1 ,z)) (x - f(SIDk , z)) , thus, the complexity for P(x) generation will reduce to O(n). 3). For improving the efficiency of key computation and derivation, we can divide the n users into k=n/l separate groups of / users each. The server forms k polynomials of degree / each. Every user can obtain the key by replacing its own SID to its corresponding polynomial. Thus, the complexity for key computation/derivation will reduce to 0(1) . Next, we describe a mechanism which can improve the efficiency greatly: tree based multiple level and hierarchical grouping.
Suppose n is the number of all users and m is the size of a small group which can be managed easily and efficiently, for example, m-\6. Then every m users form a first level group, so a total nlm of such groups Gλ λ ,- - -,Gλ nlm are formed. Next, every m first level groups form a
second level group, thus, a total n lm2 of such groups G2 , ,- • -, G 2 are formed. By
continuing with this strategy, finally a highest level group is formed G^ „ | . All these groups
can be treated as nodes in an /w-ary tree of height logm" . Every group G1 } is associated with a group key K1 } and the K „ will be the group key for all users. The group keys are
distributed to their members using an ACP embodiment. For example, Kx } is distributed to group GhJ by forming the ACP polynomial using the 57Ds of the users in its group,
i.e. Px j (x) = Y\ (x -f(SIDt , z)) + KX j where U1 e GhJ . The second level keyK2 j is distributed to all users belonging to group G2 by forming the ACP polynomial using the group keys of its first level groups, i.e. P2 j (x) = A2 j (x) + K2 j = Y[(x - f(KX l ,z)) + K2 j where G1 , e G2 } . Finally, the highest level key will be distributed by forming P108-. , = Y[(x- /(K^^z^+K^^ .
Let us consider the case of a single user leaving his group. The group keys along the path from the leaf group of the leaving user to the root group need to be changed. Total logm" polynomials of degree m need to be computed and broadcast. Thus, the total polynomial
generation time will be O(m2 logm") , the communication complexity is O(w logm" ) , and the key computation and derivation are also in O(m logm" ) . For example, suppose m=16, n = 2M , then the polynomial generation time, key computation time, and communication complexity are in 2048 units of time, 256 units of times, and 256 units of numbers for transmission.
An ACP embodiment can preferably hide the group membership and size from outsiders (and even insiders) preferably without member serialization. Without a preferred ACP embodiment, in a multicast to a group of users, the information identifying users would need to be included in the multicast packet, and the users would need to be ordered according to some strategy (referred to as serialization), so that each user knows which portion of the protected key material belongs to him and is thus able to extract the group key from that portion. This would not only result in more computation work (e.g., a user needs to search for his portion) and need synchronization due to the serialization but also unintentionally result in disclosures concerning the group membership information. Keeping group membership information private to outsiders may be important in some applications. Furthermore, it may be desirable or even necessary to hide the group membership from the group users themselves in some applications, for example, a user knows that he is in the group but does not have knowledge about which are the other members of the group. It may also be desirable to hide the size of the group. A preferred ACP embodiment provides an efficient and elegant solution to address one or more (even all) of the aforementioned features wherein a polynomial hides the group users and does not need to sort the group members. A valid user does not need to know (in fact, he cannot know if the server does not want to tell him) the membership and the order of members but he can get the group key easily by just plugging its SID into the polynomial. A preferred ACP embodiment can be easily extended for the purpose of hiding group size by simply including some random pseudo terms in the polynomial such as:
A(X) = Yl(X - /(SID1 , z)) JJ (x - VIDj ) iεψ J=I-- -d
where VIDx , ■ ■ ■, VID d are random numbers in Fq, called pseudo terms, and d \s a random positive integer. As a result, the degree of P(x) does not indicate the number of members involved in the computation. These pseudo terms make P(x) even more randomized.
Adding random terms will increase the degree of P(x), thus, impacting the efficiency of the ACP embodiment. However, using the extended tree-based key distribution mechanism discussed above, the impact on efficiency is reduced. Decisions whether to add or how many random terms to be added is a trade-off between security and efficiency, and are preferably determined based on the requirements of concrete applications.
A preferred ACP embodiment is powerful enough to adapt to random forms of interactive/access relations among users and/or resources. These relations include, but are not limited to, equivalent users/resources, one-to-many, many-to-one, many-to-many, Hierarchy, multiple levels, etc. For example, if a node C,'s access permission needs to be transferred to a random other node C, , regardless of the relation and distance between the two nodes in the hierarchy, just include C/s CIDj in the construction ofA,{x). An additional exemplary embodiment includes software stored in a computer accessible medium including an ACP which is: adaptable to different kinds of key management and different kinds of access control relation schemes; able to enforce access control and secure group communication at a plurality of scales and granularities; able, to integrate heterogeneous data sources and systems; able to protect against external attacks, internal attacks, and combined external and internal attacks; supports dynamic environments including the adding and/or revocation of members and/or resources; does not require member serialization or synchronization and does not disclose membership; able to hide the identities of members of the group and the group size; and able to implement flexible key management on the fly. A further exemplary embodiment is a system which utilizes such software. Another exemplary embodiment is a method which utilizes the functionalities of such software.
One exemplary embodiment is a method including computing or storing in a computer accessible medium a first polynomial which is a function of a set of numbers each associated with a member of a group to be provided a cryptographic information, determining a second polynomial which is a function of the first polynomial and an information to be privately shared with the group, and using at least one of the first polynomial and the second polynomial in providing communication between or among two or more members of the group. A further exemplary embodiment includes the providing communication between or among two or more members of the group includes providing at least one of a trusted collaborative computing environment, a secure dynamic conferencing environment, a differential access control environment, and a hierarchical access control environment. In a further exemplary embodiment the first polynomial is a function of a public random number, hi a further exemplary embodiment the first polynomial includes a term which is zero when evaluated with one of the set of numbers each associated with a member of a group to be provided a cryptographic key. In a further exemplary embodiment the first polynomial is described by the formula:
A(x) = π (x - /(SID1 ,z)) i≡ψ
where A(x) denotes the first polynomial, i denotes a member of the group, ^ denotes the
group, SIDj denotes the numbers each associated with a member of the group, and z denotes a random number. In a further exemplary embodiment the cryptographic information is a cryptographic key. A further exemplary embodiment includes distributing the second polynomial to the group. A further exemplary embodiment includes at least one member of the group receiving the second polynomial. A further exemplary embodiment includes obtaining the cryptographic information from a distributed polynomial. A further exemplary embodiment the includes obtaining the cryptographic information by calculating
Figure imgf000023_0001
where K denotes the cryptographic information, P denotes second polynomial, i denotes a member of the group, SIDj denotes the numbers each associated with a member of the group, and z denotes a random number. A further exemplary embodiment includes communicating among two or more members of the group and utilizing the cryptographic information to secure the communication. A further exemplary embodiment the includes defining a subset of the group, communicating among the subset, and utilizing the cryptographic information to allow access to the communication only to the subset. A further exemplary embodiment includes conditionally granting access to a resource to one or more members of the group. In a further exemplary embodiment the first polynomial is defined in a finite field which is formed from a prime number. In a further exemplary embodiment the resource is one of a broadcast of information and a stream of digital information. A further exemplary embodiment includes adding a member to the group. A further exemplary embodiment includes storing computing or storing a third polynomial which is a function of a new group including one or more added members. A further exemplary embodiment includes removing a member from the group. In a further exemplary embodiment the removing a member from the group includes computing a third polynomial which is a function of a new group removing one or more members. In a further exemplary embodiment the providing communication between or among two or more members of the group includes providing secure group communication, secure dynamic conferencing, differential access control, and hierarchical access control. In a further exemplary embodiment the communication between or among two or more members includes communication via at least one of a packet switched communication link, a wireless communication link, a WIFI communication link, a WIMAX communication link, a communication link utilizing a IP, TCP, UDP, VOIP or SSL, and a communication link utilizing CDMA, TDMA, or FDMA. In a further exemplary embodiment the removing a member from the group includes determining a fourth polynomial which is a function of the third polynomial.
One exemplary embodiment is a system including at least one computer accessible memory configured to store an access control polynomial which is a function of a set of integers personal to and secret to members of a group, a processor operable to process the access control polynomial and information to be shared with at least one member of the group to generate a public polynomial, and an interface to a communication link operable to output the information to be shared with at least one member of the group to the communication link. In a further exemplary embodiment the computer accessible memory is configured to store instructions for distributing the public polynomial. In a further exemplary embodiment the information to be shared with at least one member of the group information is a key. In a further exemplary embodiment the computer accessible memory further includes instructions for distributing the key to the group members. In a further exemplary embodiment the computer accessible memory further includes instructions for providing SGC. In a further exemplary embodiment the computer accessible memory further includes instructions for providing SDC. In a further exemplary embodiment the computer accessible memory further includes instructions for providing DIF-AC. In a further exemplary embodiment the computer accessible memory further includes instructions for providing HAC. hi a further exemplary embodiment the computer accessible memory further includes instructions for providing SGC, SDC, DIF-AC, and HAC.
While multiple embodiments, forms, objects, features, advantages, aspects, and benefits have been illustrated and described in detail in the drawings and foregoing description, the same are to be considered as illustrative and not restrictive in character, it being understood that only exemplary embodiments have been shown and described and that all changes and modifications that come within the spirit of the inventions shall be protected. It should be understood that while the use of words such as exemplary, preferable, preferably, preferred or more preferred utilized in the description above indicate that the feature so described may be more desirable, it nonetheless may not be necessary and embodiments lacking the same may be contemplated as within the scope of the invention, the scope being defined by the claims that follow. It is intended that words such as "a," "an," "at least one," or "at least one portion" are not limited to only one item unless specifically stated to the contrary. When the language "at least a portion" and/or "a portion" is used the item can include a portion and/or the entire item unless specifically stated to the contrary.

Claims

1. A method comprising: computing or storing in a computer accessible medium a first polynomial which is a function of a set of numbers each associated with a member of a group to be provided a cryptographic information; determining a second polynomial which is a function of the first polynomial and an information to be privately shared with the group; and using at least one of the first polynomial and the second polynomial in providing communication between or among two or more members of the group.
2. A method according to claim 1 wherein the providing communication between or among two' or more members of the group includes providing at least one of a trusted collaborative computing environment, a secure dynamic conferencing environment, a differential access control environment, and a hierarchical access control environment.
3. A method according to claim.1 wherein the first polynomial is a function of a public random number.
4. A method according to claim 1 wherein the first polynomial includes a term which is zero when evaluated with one of the set of numbers each associated with a member of a group to be provided a cryptographic key.
5. A method according to claim 1 wherein the first polynomial is described by the formula:
Figure imgf000027_0001
where A(x) denotes the first polynomial, i denotes a member of the group, ^" denotes the group, SIDi denotes the numbers each associated with a member of the group, and z denotes a random number.
6. A method according to claim 1 wherein the cryptographic information is a cryptographic key.
7. A method according to any of the preceding claims further comprising distributing the second polynomial to the group.
8. A method according to any of the preceding claims further comprising at least one member of the group receiving the second polynomial.
9. A method according to any of the preceding claims further comprising obtaining the cryptographic information from a distributed polynomial.
10. A method according to claim 9 further comprising obtaining the cryptographic information by calculating
K = P(T(SIDt , z)) where K denotes the cryptographic information, P denotes second polynomial, i denotes a member of the group, SID1 denotes the numbers each associated with a member of the group, and z denotes a random number.
11. A method according to any of the preceding claims further comprising communicating among two or more members of the group and utilizing the cryptographic information to secure the communication.
12. A method according to any of the preceding further comprising defining a subset of the group, communicating among the subset, and utilizing the cryptographic information to allow access to the communication only to the subset.
13. A method according to any of the preceding further comprising conditionally granting access to a resource to one or more members of the group.
14. A method according to claim 1 wherein the first polynomial is defined in a finite field which is formed from a prime number.
15. A method according to claim 13 wherein the resource is one of a broadcast of information and a stream of digital information.
16. A method according to any of the preceding further comprising adding a member to the group.
17. A method according to claim 16 wherein the adding a member to the group includes storing computing or storing a third polynomial which is a function of a new group including one or more added members.
18. A method according to any of the preceding claims further comprising removing a member from the group.
19. A method according to claim 18 wherein the removing a member from the group includes computing a third polynomial which is a function of a new group removing one or more members.
20. A method according to any of the preceding claims wherein the providing communication between or among two or more members of the group includes providing secure group communication, secure dynamic conferencing, differential access control, and hierarchical access control.
21. A method according to any of the preceding claims wherein the communication between or among two or more members includes communication via at least one of a packet switched communication link, a wireless communication link, a WIFI communication link, a WEvIAX communication link, a communication link utilizing a IP, TCP, UDP, VOIP or SSL, and a communication link utilizing CDMA, TDMA, or FDMA.
22. A method according to claim 18 wherein the removing a member from the group includes determining a fourth polynomial which is a function of the third polynomial.
23. A system including at least one computer accessible memory configured to store an access control polynomial which is a function of a set of integers personal to and secret to members of a group, a processor operable to process the access control polynomial and information to be shared with at least one member of the group to generate a public polynomial, and an interface to a communication link operable to output the information to be shared with at least one member of the group to the communication link.
24. A system according to claim 23 wherein the computer accessible memory is configured to store instructions for distributing the public polynomial.
25. A system according to claim 23 wherein the information to be shared with at least one member of the group information is a key.
26. A system according to claim 23 wherein the computer accessible memory further includes instructions for distributing the key to the group members.
27. A system according to claim 23 wherein the computer accessible memory further includes instructions for providing SGC.
28. A system according to claim 23 wherein the computer accessible memory further includes instructions for providing SDC.
29. A system according to claim 23 wherein the computer accessible memory further includes instructions for providing DIF-AC.
30. A system according to claim 23 wherein the computer accessible memory further includes instructions for providing HAC.
31. A system according to claim 23 wherein the computer accessible memory further includes instructions for providing SGC, SDC, DIF-AC, and HAC.
PCT/US2008/006027 2007-05-11 2008-05-12 Flexible management of security for multi-user environments Ceased WO2008140798A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US12/616,316 US20100128879A1 (en) 2007-05-11 2009-11-11 Flexible management of security for multi-user environments

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US92871607P 2007-05-11 2007-05-11
US60/928,716 2007-05-11

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US12/616,316 Continuation US20100128879A1 (en) 2007-05-11 2009-11-11 Flexible management of security for multi-user environments

Publications (1)

Publication Number Publication Date
WO2008140798A1 true WO2008140798A1 (en) 2008-11-20

Family

ID=40002554

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2008/006027 Ceased WO2008140798A1 (en) 2007-05-11 2008-05-12 Flexible management of security for multi-user environments

Country Status (2)

Country Link
US (1) US20100128879A1 (en)
WO (1) WO2008140798A1 (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8230086B2 (en) * 2007-06-18 2012-07-24 International Business Machines Corporation Hidden group membership in clustered computer system
US8966017B2 (en) * 2009-07-09 2015-02-24 Novell, Inc. Techniques for cloud control and management
US12388638B2 (en) * 2022-05-26 2025-08-12 Samsung Sds Co., Ltd. Method and apparatus for providing secure messaging service

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5202921A (en) * 1991-04-01 1993-04-13 International Business Machines Corporation Method and apparatus for authenticating users of a communication system to each other
US20040196842A1 (en) * 2003-04-04 2004-10-07 Dobbins Kurt A. Method and system for according preferred transport based on node identification
US20040225570A1 (en) * 2003-05-05 2004-11-11 International Business Machines Corporation Method and system for processing a request of a customer
US20060259965A1 (en) * 2005-05-11 2006-11-16 Chen Xuemin S Method and system for using shared secrets to protect access to testing keys for set-top box

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5533026A (en) * 1995-03-06 1996-07-02 International Business Machines Corporation Communication system including method and apparatus for maintaining communications with a mobile terminal
US20030233538A1 (en) * 2002-05-31 2003-12-18 Bruno Dutertre System for dynamic, scalable secure sub-grouping in mobile ad-hoc networks
JP4292835B2 (en) * 2003-03-13 2009-07-08 沖電気工業株式会社 Secret reconstruction method, distributed secret reconstruction device, and secret reconstruction system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5202921A (en) * 1991-04-01 1993-04-13 International Business Machines Corporation Method and apparatus for authenticating users of a communication system to each other
US20040196842A1 (en) * 2003-04-04 2004-10-07 Dobbins Kurt A. Method and system for according preferred transport based on node identification
US20040225570A1 (en) * 2003-05-05 2004-11-11 International Business Machines Corporation Method and system for processing a request of a customer
US20060259965A1 (en) * 2005-05-11 2006-11-16 Chen Xuemin S Method and system for using shared secrets to protect access to testing keys for set-top box

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
KARANDIKAR ET AL.: "An Effective Key Management Approach to Differential Access Control in Dynamic Environments", JOURNAL OF COMPUTER SCIENCE, vol. 2, no. 6, 2006, pages 542 - 549, Retrieved from the Internet <URL:http://www.scipub.org/fulltext/jcs/jcs26542-549.pdf> *
ZOU ET AL.: "Dual-Level Key Management for secure grid communication in dynamic and hierarchical groups", SCIENCE DIRECT, 11 December 2006 (2006-12-11), pages 1 - 11, Retrieved from the Internet <URL:http://www.cs.lupui.edu/~xkzou/Papers/FGCS-DGKM.pdf> *

Also Published As

Publication number Publication date
US20100128879A1 (en) 2010-05-27

Similar Documents

Publication Publication Date Title
Shen et al. Block design-based key agreement for group data sharing in cloud computing
Zou et al. A practical and flexible key management mechanism for trusted collaborative computing
Hur et al. Secure data retrieval for decentralized disruption-tolerant military networks
US6941457B1 (en) Establishing a new shared secret key over a broadcast channel for a multicast group based on an old shared secret key
Pathak et al. Byzantine fault tolerant public key authentication in peer-to-peer systems
Li et al. Enabling efficient and secure data sharing in cloud computing
Lin et al. Secure and efficient group key management with shared key derivation
CN111865588B (en) Efficient quantum secret information interchange method, system and storage medium
Huang et al. An efficient RLWE-based privacy-preserving authentication scheme based on edge computing in Industrial Internet of Things
Huang et al. EASNs: efficient anonymous social networks with enhanced security and high scalability
Naresh et al. Provably secure group key agreement protocol based on ECDH with integrated signature
Iovane Computational quantum key distribution (CQKD) on decentralized ledger and blockchain
Ibrahim et al. Attribute-based authentication on the cloud for thin clients
Farash Cryptanalysis and improvement of ‘an improved authentication with key agreement scheme on elliptic curve cryptosystem for global mobility networks’
Yang et al. Efficient and decentralized dual access control for cloud-based industrial internet of things
US20100128879A1 (en) Flexible management of security for multi-user environments
Fu et al. Secure multi-receiver communications: Models, proofs, and implementation
Li et al. Distributed key management scheme for peer‐to‐peer live streaming services
Nam et al. Secure group communications over combined wired and wireless networks
Yang et al. Identity‐Based Unidirectional Collusion‐Resistant Proxy Re‐Encryption from U‐LWE
Scheikl et al. Multi-level secure multicast: the rethinking of secure locks
Wang et al. Encrypted domain reversible data hiding based on proxy re-encryption in distributed environment
Pareek et al. Blockchain-based decentralised access control scheme for dynamic hierarchies
Chaudhari et al. Towards lightweight provable data possession for cloud storage using indistinguishability obfuscation
Wang et al. Password-Authenticated Key Exchange Protocols: A Survey

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 08754354

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 08754354

Country of ref document: EP

Kind code of ref document: A1