Distribution type dynamic secret key management method
Abstract
The invention claims a distributed dynamic key management method, the credible centre during the netinit, a to be each user of network first distribution sub-key and production sub-key base, and generating network key; The method comprising further following steps: A, determining for sending sub-key user, engages the network the new user to the releasing user request to according to the sub-key sending the sub-wire the key; THE sub-key and publishing the user to the t to obtain the sub-wire key user to compose the sub-key to the distribution device,C and sub-key distribution each user use in from each sub-keys, distribution connected to the new user the key main part and sub-key body component. The method for (t, n) threshold secret sharing processor is realized to be network user the first distribution sub-key the distribution network, a arm the network user newly eight rotor of the jumping-like method via the round-trip the key, and periphery validated user for network renewed the process of sub-key, claims a device for sharing multi-key.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
25 claims: 1 independent, 24 dependent
- 1Distributed 1.1 dynamic key management method, the is characterised of; the credible centre during the netinit, a to be each user of network first distribution sub-key and production sub-key base, and generating network key; The method comprising further following steps:A, determining for sending sub-key user, engages the network the new user to the releasing user request to according to the sub-key sending the sub-wire the key;THE sub-key and publishing the user to the t to obtain the sub-wire key user to compose the sub-key to the distribution device,C and sub-key distribution each user use in from each sub-keys, distribution connected to the new user the key main part and sub-key body component. 1.一种分布式的动态密钥管理方法,其特征在于,可信中心在网络初始化时,为最初组成网络的每个用户分发子密钥、子密钥生成基,并生成网络密钥;该方法还包括以下步骤:A、确定子密钥颁发用户,加入网络的新用户向子密钥颁发用户请求颁发子密钥;B、子密钥颁发用户选择t个获得子密钥的用户组成子密钥颁发集合;C、子密钥颁发集合中的每个用户利用自各的子密钥,向新用户颁发子密钥主部分和子密钥次部分。
87 paragraphs, as filed
The dynamic distributed key management method
technical field
The invention relates to network security technology, is distributed the dynamic key management method of.
background technology
Mobile Ad - hoc network (MANET, Mobile Ad - hoc Network) is a special, there is no a basic structure support, distributed mobile network,Which is connected with the wireless transceiver's mobile terminal composed of an with the base station and multi-hopping a group of; the temporary autonomous network system. MANET with the series, flexible, and is composed of the wireline network constraints. Comprising an applied to military battlefield and a flood, the wiring non-law equal of the special or emergency environment, and is provided with for universal communication network it is provided, a: ofNetwork by the bandwidth of the organized and dynamic network topology and limited wireless transmission, and vulnerable equal. Wherein the application of MANET is widespread, wherein one a wireless communication field research to investigate the hot spot, the safety device capable of improving the gate prerequisite is a handle.
The modern cipher system and concept of: Cipher security system is fixed by key. Therefore, managing key and in network environment the crucial content of information security, and ends of the network frame distribution network, is one gate.
Secret sharing is a modern cryptology gate device, comprising a threshold cryptology substrate, comprising a provided with multiple ideal method for managing property of key. And a plurality of distribution network, wherein the process of distribution network operation, user in distribution network it has a support ends of credible centre, therefore, and secret sharing processor is with reasonable selecting. Lower electrodes (t, n) threshold secret sharing processing, network key the distribution network is dispersed n sub-keys, and assigns connected to the distribution network the n user, achieves device for multiple is a user, a side upon the sub-key on the opening of the user with corresponding to the recovering network key, here is a number of users of the lower cover (is t, n) threshold secret sharing processing threshold value t.
The following with prior technology for using (t, n) threshold secret sharing processor is realized method for distribution network dynamically managing key, wherein the method comprises netinit stage and sub-key updating stages.
The netinit table, according to form a distribution network the first network number of the user, the credible centre said network key and number of the user sub-key, and transmitting through the secret method and apparatus sub-the value of key and sub-key is composed of a first network the user. The description of as follows, name obtaining rotor key and validated, userRigid electric network and not to obtain the sub-wire same number of the user novel. Receiving credible central distribution the sub-key; each user by confirming the sub-key data value's precision, determine for collecting the authenticity of sub-key.
The network key and program, according to the t, n) threshold secret sharing circuit, a recovery in network key of t validated user composed of a sleeve; the network exists in the t validated user participation recovering network key; and t validated user which makes sub-key by secret is transmitted to the participation recovering network key, a network key recovery in the sleeve validated other user, a participating to the machine validated users of network key efficiently obtaining network key restored in the other validated users' sub-keys; each validated and user by Lagrange interpolation quick-recovery key network. Here t, a secret sharing method for determining threshold value.
The sub-key updating table; each validated user flowing equal the sub-key to updating the factor and sub-key is arranged validated user in distribution network and updating the data value. The true sub-key when the validated user in the receiving port of the t validated user generated for updating wherein the factor, which can shaft according to t updating factor computational to obtain for new sub-key. The validated user by confirming the sub-key updating the data of the high-precision to determine for updating sub-key the factor the authenticity. Validated user in distribution network of obtaining new rotor structure, similar to the atomic key and quick-recovery method of network key machine to the distribution network the key network.
The computing technique's deficiency, and is provided with a method and a new user sending the sub-wire the process of key. At the same time, wherein the initial and distribution network value of users is n, wherein threshold value is t, the credible centre is an initial and distribution network user distribution sub-key flowing is a t power function, computerThe sub-key updating table; each validated users need to n equal to sub-keys the updating factor and realizes t exponent signs rotating shaft; Moreover for confirming new rotor structure, wherein lower end of the computations of t secondary power function. The method not only enormously then the network user and integral system for calculating overhead messages, and network to the whole the user in distribution network with a a serious; burdenMoreover comprises with an electric network user in the newly method for processing method, is to move to arm the network newly the network key in user shared network, without favor wherein the expansion of network.
invention content
The radio for consideration, and capable of this invention is a distributed dynamic key management method, capable of realizing to be a network user first distribution sub-key, a arm the network user newly sending the rotor for dynamically managing key of key.
In turn to serve the key, wherein a technical solution for realizing to that: The dynamic distributed key management method, the credible centre during the netinit, a to be each user of network first distribution sub-key and production sub-key base, and generating network key; The method comprising further following steps: A, determining for sending sub-key user, engages the network the new user to the releasing user request to according to the sub-key sending the sub-wire the key; THE sub-key and publishing the user to the t to obtain the sub-wire key user to compose the sub-key to the distribution device,C and sub-key distribution each user use in from each sub-keys, distribution connected to the new user the key main part and sub-key body component.
, Wherein the C-SHAPED, wherein the master key distribution to the sleeve each user is the same sub-key to the distribution connected to the new user the main key part, a specific process is: C11 and sub-key distribution the first a user device is the button from the main sub-key production subbasis and calculates for sub-key main for updating base, and transmit the connector main key generation updating to the next, userThe sub-key sending the user device is sub-key main for updating adding to form of the main sub-key production of subbasis from the key computational obtaining and a user transmitting upgrading sub-key main for updating base, comprising and a updating the main sub-key for updating is transmitted to the lower user, distribution device is the sub-key the having user; Sub-key main for updating timer according having user updating for obtaining sub-key main production base;
C12 and having user straight sub-key annoyance and adding of the connector main key generation base and computational for obtain the rotor main key off the base, and transmit the connector main key rubber is connected to a corresponding user; Sub-key main the partial adding to of the sub-key sending the sleeve user efficiently obtaining sub-key annoyance value according and a transmitting user to updating for calculating the main sub-key off the base; after and a updating the main sub-key rubber base is transmitted to the rotor key distributing the sleeve and user, until a first user; The sub-key main off the base of the first user updating for obtaining the main sub-key base part, and transmit the connector main key base part to the new, userC13 and new user to obtain the new user sub-key main component according to sub-key the main part of computer for producing.
, Wherein the C-SHAPED, wherein the master key distribution to the sleeve each user is the same sub-key to the distribution connected to the new user the button body part, the specific process is: C2 and sub-key distribution in of the user is for sub-key body part equal the sub-key body part for switches respectively, and transmitting and new user, the new user automatically according to any sub-key body part production of the transmitting user basal to form the sub-wire key body component.
, Wherein the C-SHAPED, wherein the master key distribution to the sleeve each user is the same sub-key to the distribution connected to the new user the button body part, the specific process is: C2 and sub-key distribution in of the user is for sub-key body part equal the sub-key body part for switches respectively, and transmitting and new user, the new user automatically according to any sub-key body part production of the transmitting user basal to form the sub-wire key body component.
, Front operating in C, selecting the sub-key to distribution with household-time annoyance value zi, wherein the C11, wherein the ratio is equal sub-key the main production subbasis from the key method of eiDi-zi (modMA), Di is a sub-key main part and zi is a sub-key sending a household-time annoyance value and MA is a sub-key sending the sleeve is users' sub-keys to generate bottom board and ei=MiMi ' Mi=Π ; l&ElementA, l≠ iml), >ml) is in a user sub-key production base.
, Front operating in C, selecting the sub-key to distribution with household-time annoyance value zi and sub-key sending a cover of household annoyance value rt and new user annoyance value ci, wherein the C12, and calculates the sub-key annoyance value of zi+cimj+rt, zi is sub-key sending a household-time annoyance value and rt is a sub-key sending a cover of household annoyance value and ci is a new user annoyance value and mj is in a user sub-key generating base.
, Front operating in C, selecting the sub-key to a distribution cover of household annoyance value ri, wherein the C13, wherein according to sub-key the main part of computer for producing obtaining user novel sub-key main part is divided into <img id= of idf0002 of file= of A20051011288300121.tif of wi= " 78” he= " 41” img-content= of the positive img-format= of tif of/> Ej of the main sub-key base part and ri is a sub-key sending a cover of household annoyance value.
, Optional is integer q the preset, front operating in C, selecting the sub-key to a distribution cover of household annoyance value ri, wherein the Capacitor, and calculates the sub-key body part generating a base (&alpha; ; i&Pil=1, l&NotEqual; ikj-li-l+ri), modq) through > α i for sending the sub-key the user device sub-key body part and ri is a sub-key sending a cover of household annoyance value.
, Optional the stepped of when the preset is t-1 multinomial f (), front operating in C, selecting the sub-key to a distribution cover of household annoyance value ri, wherein the C2, wherein generating sub-key body part is &alpha; j=f (j); =&Sigmai=1i (&alpha; ; i&Pil=1, l&NotEqual; ikj-li-l+ri-ri), modq) through > α i for sending the sub-key the user device sub-key body part and ri is a sub-key sending a cover of household annoyance value.
Moreover, the method - comprising: Is obtained the sub-wire key user composed of a network key to machine t the; The network key recovery in the opening and user is sub-key for recovering to the key network.
, Comprising a characterised, after connecting with, A front operating order B, and method - comprising: A1 and sub-key distribution the user to a network are obtaining user request of rotor key distribution to the rotor is a new user the key; A2, a to request and agree for sending the rotor is a new user key acquired rotor key user, sending the user to the sub-key a return protocol; messageA3 and sub-key distribution the user judging whether received that is greater than or more than t obtained the sub-wire key user protocol participation message, and is greater than or equal thereof, and operating order; THEOtherwise loop, the A3.
Moreover, the method - comprising: Is obtained the sub-wire key user composed of a network key to machine t the; The network key recovery in the opening and user is sub-key for recovering to the key network.
Moreover, the method - comprising: Obtaining rotor key novel user to generate the main sub-key data value and apparatus sub-key value; and multicast to send a network in the user.
Moreover, the preset network, the method - comprising: The producing to form a network user the first main sub-key data value and apparatus sub-key value; and network data key values, and multicast to send a network in the user.
Moreover, the method comprising further following steps: D1 and sub-key updating the user other user to the network to transmit the sub-key to updating the support; E1 and sub-key updating the user to the t with the sub-wire key user to compose the sub-key to updating the sleeve; F1 and sub-key updating the sleeve is set with users' sub-key main part to the recovering network key generation factor, the arbitrary selecting integer and network key generation updating base, and overlapped with the network key generation factor recovery according to obtain the network key generation updating to the network key generation updating factor; Obtaining by the network key generation updating factor computational for producing a network are users' sub-key main part; The serial number of the user according to the network obtaining the user the sub-keys to updating component.
, Wherein the F1, wherein the is set with users' sub-key main part to resume the network key generation wherein the sub-are E= (D1M1M1 of +D2M2M2 the operating…+DtMtM ') mod LEFT, Mt=&Pi; j=1, j&NotEqual; ttmj)); >q=&pii=1tmi), >mj) and mi of the user device sub-key production base, Di are sub-key distribution in the user sub-key main component.
, Wherein the F1, wherein a network key generation updating factor computational for producing obtaining in network the users' sub-key main part is divided into AN of modmi, AN of network key generation updating factor and mi of the user device sub-key production base.
; The netinit stage optional stepped are provided t-1 multinomial f () and is integer q, wherein the F1, wherein the serial number of the user according to the network to obtain the user the sub-keys to updating component is 2-3cm (i) mod q.
Moreover, the method - comprising: Updating the sub-key's user composed of a network key is t recovering network, and sub-key body part computations of each user efficiently obtaining network key base; and sub-key to updating part computations efficiently obtaining network key generation updating base; and sub-key main part computational efficiently obtaining network key generation updating factor, recovering network key by the key base and network key generation updating base and a network key generation updating factor.
Moreover, the method - comprising: When the preset network, the is greater than 1 network key, and combination according is obtained the sub-wire key user composed of performing a serial number t,Each combined in aggregate of each network key, a user the sub-key according to the combined calculates the combined the multi-key factor; Each combined in aggregate of each network key, compute pool multi-key base,The distributing network user multi-key the base of the computations straight; Executing the following steps: A multi-keys and quick-recovery user other user to the network to request for recovering; multi-keysAN multi-keys and quick-recovery user to the t to obtain the sub-wire key user to compose the multi-keys to machine combination; I ohm; the multi-keys machine combination user each equal the multi-key production factor respectively, and transmitting for production multi-key factor for producing to the multi-keys recovery combination switch, usersThe multi-key base of the multi-keys machine combined with the user is combinations with the multi-key power generation computations of user production efficiently obtaining multi-key factor, search the straight with a current combination, and flowing network key recovery according to corresponding, recovering network key according to multi-key the base and multi-key factor.
Moreover, the method - comprising: When the preset network, the is greater than 1 network key, and combination according is obtained the sub-wire key user composed of performing a serial number t,Each combined in aggregate of each network key, a user the sub-key according to the combined calculates the combined the multi-key factor; Each combined in aggregate of each network key, compute pool multi-key base,The distributing network user multi-key the base of the computations straight; Executing the following steps: D2 multi-keys and quick-recovery user other user to the network to request for recovering; multi-keysE2 multi-keys and quick-recovery user to the t to obtain the sub-wire key user to compose the multi-keys to machine combination; F2 and multi-keys machine combination user each equal the multi-key production factor respectively, and transmitting for production multi-key factor for producing to the multi-keys recovery combination switch, usersThe multi-key base of the multi-keys machine combined with the user is combinations with the multi-key power generation computations of user production efficiently obtaining multi-key factor, search the straight with a current combination, and flowing network key recovery according to corresponding, recovering network key according to multi-key the base and multi-key factor.
, Wherein the computational efficiently obtaining multi-key production factor is Dl2MlMl ' α interface, li+1; Ml=&Pi; k&ElementAj, k&NotEqual; lmk),) >mlMotors ' =1modml, mk and motors are in a user sub-key production base, D2 are sub-key main part, α l and secondary sub-key element.
, Wherein the F2, and calculates the multi-key factor is <img id= of idf0008 of file= of A20051011288300152.tif of wi= " 116” he= " 36” img-content= of the positive img-format= of tif of the/>, DSl is a multi-key power generation, ONE of the multi-key combined with users' sub-keys vibrator generating device.
, And restoring multi-keys optional one-way function (f), and calculates the multi-key base is wall, j=si-f (Hi, j), si is a network key and Hi, J of the multi-keys wherein the.
, And restoring multi-keys optional one-way function (f), wherein recovering network key is si=bi, j+f (Hi, j), wall, j of the multi-keys wherein the sub-, Hi, J of the multi-keys wherein the.
The dynamic distributed key management method of this invention claims, which is t, n) threshold secret sharing processor is realized to be network user the first distribution sub-key the distribution network, and is arm the network user newly eight rotor of the jumping-like method via the round-trip the key, and periphery validated user for network renewed the process of sub-key, claims a device for sharing multi-key.
Not only according to a method for prior technology hand-free, reduced and realizes the dynamic key management method computational load. To be distribution network user first distributed in process of sub-key, wherein by the Residue theorem, a magnetism mould operations in the sub-key distribution of credible centre is very quick; meanwhile, although the credible centre calculates the data value of 2n sub-key, further validated each user in confirming sub-key the time is allocated equal 2 times the exponent, with reduced the distribution network a computational load of user; To arm network user newly sending the rotor in process of key, participates distribution to the rotor key validated user, wherein the is needed by the operation mode and multinomial operation, therefore the operand is; aNetwork key and table, wherein by the Residue theorem, and quick-recovery computational load of network key significantly to reduce.
Method for the invention hand-free while reducing computational load, enhanced the dynamic key management safety. Sub-key of wherein the invention, each user for comprises two components: Sub-key main part and sub-key body part, the enhanced aggressor to attain the difficulty of wrench key. , No matter to be network user the first distribution sub-key or the sub-key the credibility distribution device is a new user sending the rotor in process of key, announced the data value of sub-key, to with the user equipment in the key receiver the time of a authenticity of antithetical couplet key in the apparatus, prevents the key connected to tamper by the aggressor in process of transmission, comprising a winding sub-key's safety. Moreover, the sub-key updating method, although the updating of sub-key is completes by a validated user, and restored network key generation factor SAME in process of updating, and according to network key recovery method D=Emodp, wherein the validated user is not restored network key p-type base in process of updating, therefore is to recovering network key according to D=Emodp, comprising be the key network security FILTER.
Brief description for drawings
Digital 1) is sub-key sending device is a new user sending the sub-wire the current points for key; Digital 2) is sub-key updating current map.
detailed description of illustrated embodiments
The core in of this invention is: To the t, n) threshold secret sharing circuit respectively, the network key of sub-keys and are in each user insulated of network, greater than or equal is a t is obtained the sub-wire key validated user composed of a sub-key to machine, the sub-key recovery in the fixing base is the validated users' sub-keys to and quick-recovery network key; With user novel power network, similar to the t, n) threshold secret sharing circuit, the sub-key is greater than or is equal to validated t user composed of distribution device is a new user sending the sub-wire the key.
Solution for realizing energy in network key management method in the invention specifically embodiment a to be a network user first distribution sub-key, a arm the network user newly sending the sub-wire the key, it can also dynamically for network in the obtaining rotor key user to the upgrade sub-key, and obtaining rotor key user by a given the sub-key realizing multi-key sharing.
The wire MANET to introduce of as of the invention the specific for processing, a called MANET the description of as follows the network.
The MANET a first; a network with a credible centre and a network the first n user, and n user i and indication with the serial number are described; the following with Pi indicated is obtained the sub-wire key validated user, i=1,…, n. First in a credible centre is provided MANET; the lead (t, n) threshold secret sharing processing threshold value t, and network key and is intervals and are to each user. Respectively connected with the network key and distribution of the capacitance network the specific process of user is as follows first: First; the credible centre to be a network user first only by serial number of the MANET comprising a soon is a.
The parameter of wires; and credible central for managing key lower comprises: Optional is integer q, and obtaining on galois field GF (Q) exponent the number of q-1 generation unit, gSelecting n sub-key production to m1, m2,…, mn; the n sub-key production to m1, m2,…, mn of the turn, and satisfies 1 <m1<m2<…< 22 Mn opposite and primes, &Pi; i=1tmi>&pii=tt-1mn-i+1); >) made M=&Pi; i=1tmi);) > selective network key p-type base, p is with the turn of m1, m2,…, mn and prime; Selective network key D; and D<p; Selecting number of r, satisfies; m>d+r&centerdot; p>&pii=1t-1mn-i+1), >) are simultaneously network key generation factor E=D+rp; The optional stepped are provided t-1 multinomial f (x) =at-1xt-1+… +a1x+p, a1∈GF (q), 1≤i≤t-1.
, And the credible connected to the capacitance network the serial number of the user corresponding to the equal sub-key of the user first sub-key, comprising two components: Sub-key main part and sub-key body component. , The sub-key main part is divided into Di=Emodmi, i=1,…, N; Sub-key body part is α i=f (i) modq, i=1,…, n. The credible centre a equal the sub-key for obtaining, and is the is a common and a private user for producing, transmitting through the safety closely connected to each user; And a locking the network user the first sub-key production machine and user serial sheets to a user announcements of the first and network. The safe according to here finger is: Disposed on the transmission through encryption or dedicated channel and manner.
At the same time, the credible centre calculates the user sub-key the part of determining values are, comprising, sub-key main apparatus and ui=Di2gDimodq), >) sub-key data value; vi=&alpha; i2g&alphaimodq), >) i=1,…, n; Pulse computing network data key values u0=gDp2mod q; And ui and vi, u0 announced according to form a network the first from cloth user.
The capacitance network the user efficiently obtaining credible centre via a step first for makes the sub-key of serial number and distribution of distribution, wherein with the male and private key for producing; And makes to the sub-key for receiving and data to the data value of the credible centre announced. The user with for sub-key of receiving according to the credible the same method, equal the main sub-key data value and sub-key apparatus and respectively; the main sub-key data value and sub-key and apparatus for determining calculates the main sub-key data value and sub-key determining whether value and a are equal, a same, and determines the authenticity of; sub-keyOtherwise, request of the credible centre reissues the sub-key. When the netinit; each user of initial and network is allocated to perform balanced the credible central releasing, network switch users' sub-key production machine, and recording the user horizontal the key.
hence, the netinit process completes.
The network user in receiving credible centre of the sub-key and they are, which forms the validated user, which of the support of credible centre, a dynamic, mobile MANET. The MANET composing; each validated user for playing of button to the edge network respectively; each validated user in MANET network and receiving and balanced other user playing of key.
The MANET normal operation, wherein a new users need engages the network and shared network key, wherein the time network which is provided with a support of credible centre, a realizing dynamic key management method, the invention further claims a a new user sending the sub-wire method for key. Distribution rotor the process of pressing and shown the digital 1 is the new user, a specific which is as follows: Steps: 101The new user to validated user Pa of initially engages the request of network, at the validated users to the network playing for key of. Here; the validated user Pa can be any, or jumper for the new user least, or the processing capacity strong validated user, here, indicates with a subscript is a new user promoter key distribution processing a specific validated user. , User public key of the front lapping the network line from the credible centre of the user, or acquiring the through groove assignments.
Steps: 102 Pa automatically according to thereof and network in the serial sheets of the validated users of the new generation user novel serial number j; the novel serial number of indicate the novel user; onlyMeanwhile according to for changing switch validated users' sub-key production to mi, selecting sub-key production to mj is a new user. , And Pa to the validated transmitting user request message in a network, and novel user the serial number and a new user and production sub-key to mj, request joint for sending the rotor is the novel user the key; And the novel user loop for serial number and production sub-key base of new generation user, and other network users' public keys. At the same time, obtaining novel serial of the new user is in configuration of the Pj.
, A ensuring consistency between datum algorithm availability, Pa is a new user selecting the sub-key production to mj method is as follows: mj is m1<mj<mn, and satisfies; &Pi; i=1tmi>&pii=tt-1mn-i+2) >); theOr a n>2t-1, and is mi<mj<mn-i-2 or a n≤2t-1, and a second the mj the mt value; here t is a t, n) threshold threshold value.
Steps: 103The network and validated user after receiving Pa the request message, a willing distribution to the rotor is a new user the key, a Pa loop agreed according participates, messageotherwise, non-return information. To the t, n) threshold secret sharing circuit, Pa judging whether a greater than or equal to the t validated user agreed participates sending the rotor is a new user key message, and is greater than or is equal to the input the invention 104, theOtherwise circuit, which 103, waited for of the user loop agree to participate in a message, and continuously the judging whether a greater than or equal to the t validated user agreed participates sending the rotor is a new user key message.
Steps: 104 Pa in the agreements distribution the sub-wire the key validated user to the t validated users to compose the sub-key of the novel user to the distribution device are, a MAGNETIC gathering, indicatedAnd a to the validated user in A sorts in sequence, time to indicate with P1, P2,…, That is connected in the sleeve validated user distribution user for sub-key. Method of sorting may allocate resources for according to the sub-keys to the releasing user to the distance of novel user, a jumper of multiple device. The composing the sub-key distribution device, may use round-trip to generate the sub-key is a new user a jumping-like method.
The sub-key sending, and sending the rotor is a new user in process of key, a without divulge network confidential network information key generation factor SAME, and different method of generating high-energy sub-key main part and sub-key body component. When the sub-key sending for user new generation sub-key main part is D of the round-trip of the jumping-like method, travels exactly comprises three formed by jumping-like: methodThe first process is forward process, sending the device according to any sub-key the turn from P1 the P2, P3,…Is That, calculates sub-key main production to B; The second process is reverse process, comprising a Pt calculates sub-key main production to B, obtaining rotor main key base part Ej according to the computer AND a Pt, Pt-1,…, P1 in turn; The third method of manufacturing process, comprising automatically according to the main sub-key base part Ej computational efficiently obtaining rotor key main part of the novel user Pj.
The sub-key distribution device of novel user Pj sending the sub-wire the key main part of the process; each sub-keys distribution the user is ri, zi and ci, ri unit for user new generation t integer r1, r2,…, rt, and rotor the key distribution and width of encrypted key, a to each sub-keys distribution user the sub-key to distribution with the head of household annoyance; valuezi is a sub-key sending a household-time annoyance, value of the sub-key sending a up of the user oneself generating and use, here, the so-called small integer is zi<mi, wherein the sub-key distribution user the sub-key to distribution with household-time annoyance value zi is less than sub-key for producing base; mici is a new user annoyance, value of the sub-key sending a random up of the user oneself generating and method.
the forward process is: The sub-key sending the fixing the serial number is 1 sub-key sending the user, P1 can be called the first user, and calculates the main key generation subbasis b1= (e1D1-z1) mod MA, obtaining rotor main key generation updating base, ZS1=b1, MA=&Pi; ; i&ElementAmi),); >ei=mi&centerdot; Mi&prime, Mi=&Pi; ; l&ElementA, l&NotEqual; iml),) >miMi ' =1modmj; A to the rotor main key generation updating to ZS1 comprises the following user P2, P2 according to P1 with same method thereof sub-key main production subbasis b2, updating sub-key main for updating to ZS1 is ZS2=ZS1+b2, and a updating the ZS2 transmission for obtaining is electrically connected with the lower user; P3P3 according to the method thereof sub-key main subbasis production b3, updating sub-key main for updating to ZS2 is ZS3=ZS2+b3, and a updating the ZS3 transmission for obtaining is electrically connected with the lower user, sending the user is a t ohm sub-keys That, the t ohm sub-keys releasing user the Pt also be called having user; That calculates for sub-key main subbasis production bt, updating a main sub-key for updating to ZSt-1 from the upper user is ZSt=ZSt-1+bt obtaining rotor main key generation base; B=ZSt=&Sigmat=ltbimodMA). >), while That obtaining rotor main key generation to B, and round-trip the jumping-like to process.
the backward process is: That used for sub-key to a distribution cover of household annoyance value rt and sending sub-key with household-time annoyance value zt, and new user annoyance value ct computation processor for obtaining sub-key annoyance value ZG, comprising zt+ctmj+rt, wherein equal sub-key annoyance value ZGt for obtaining overlapped on the rotor main key generation to obtain rotor main key off the base ZBt=B+zt+ctmj+rt, wherein equal sub-key main off the base ZBt for obtaining substrate-processing to the lower user; Pt-1Pt-1 according to automatically according to sub-key for publishing to a Pt same method for cover of household annoyance value rt-1 and sending sub-key with for sub-key annoyance value ZGt-1=zt-1+ct-1 according household-time annoyance value zt-1, and new user annoyance value ct-1 obtaining computingmj+rt-1, and a updating sub-key main off the base ZBt the key annoyance value ZGt-1 is ZBt-1=ZBt+ZGt-1, comprising and a updating sub-key main off the base ZBt-1 transmitted to the lower user; Pt-2User lower Pt-2 upgrading sub-key main off the base according to the same method, and transmit the connector main key rubber base is connected to the lower user, is P1; P1 a main sub-key off the base ZB2 for transmitting P2, updating sub-key main off the base ZB2 according to the same method of ZB1=ZB2+ZG1, obtaining rotor main key base part; EJ=ZB1=B+&Sigmai=1t (Zi+Ci&CenterDot; mj+ri); =E+&Sigmai=1t (ci&CenterDot; mj+ri).) >) by calculating the rotor for acquiring key main part Ej base; the sub-key distribution user P1 substrate-processing rotor main key base part Ej novel user Pi.
A production process is: Wherein the sub-key sending a neutron key distribution to ri of the user for is a new user Pj generating, therefore novel user by calculating (Ej-&Sigma; i=1tri) =Emodmj=Dj) through > and obtaining rotor key main component.
Hence, the sub-key eight opening to achieve a method jumping-like by round-trip with eight rotor is a new user the main key the process.
While the sub-key distribution device is a new user sending the sub-wire the main key part, further - distribution the rotor is a new user the button body component. The sub-key distribution device of novel user sending the sub-wire the key secondary the wire process is: Member each of the sub-key sending the sleeve calculates sub-key body part production to CBi= relay j1, &alpha; i&Pil=1, l&NotEqual; ikj-li-l+ri), modq) through > (l∈A), point novel user Pj and. Novel user Pj distribution sub-key body part for timer according of each sub-key the user, a distribution user the main annoyance value to remove the ri antithetical couplet key body part of the influence of base and makes the sub-key of memory, obtaining key rotor body base part, and calculates method for sub-key body base part is specifically CBi-ri= (&alpha; ; i&Pil=1, l&NotEqual; ikj-li-l+ri-ri); modq=&alpha; i&Pil=1, l&NotEqual; . ikj-li-lmodq) through the novel > user distribution sub-key of the receiving user the sub-key body part for timer computational of transmission obtaining key rotor body base part, according to the sub-key secondary machine part of the computer obtaining calculates the sub-key body part is &alpha; j=f (j); =&Sigma; i=1t&alpha; i&Pil=A, l&NotEqual; ij-li-lmodq). >) hence, the sub-key eight opening to achieve with eight rotor is a new user the key secondary the process.
The sub-key distribution device is distribution to the rotor is novel user Pj of the key main part and sub-key body part, completes to arm the network user newly sending the sub-wire the process of key. Novel obtaining user the rotor key, and calculates playing wherein sub-key main apparatus and uJ=DJ2gDJmodq) through > and apparatus sub-key value; &nu; i=&alpha; j2g&alphajmodq), >) and transmit the main data value and apparatus for playing value of key connected to the network in the user. The user in network in the circuit; and sub-key's apparatus and antithetical couplet key end of the data.
Hence, the sub-key eight opening of the new user sending the sub-wire the process of pressing and terminal.
Obtaining rotor key validated user in the invention, comprising a given the sub-wire key novel user, by a t, n) threshold secret sharing processing recovering network key. Recovery method of network key is: A t or more t is hoped for recovering network key validated user to be a network key machine to, wherein the sleeve; each validated user sharing each other sub-keys, wherein validated user are greater than or is equal to sub-keys t, and t; and chosen t sub-keys recovering network key.
The validated user sharing method of sub-key is: And the encryption to for sub-key with an validated users' of the keys, then transmits to a corresponding user. For receiving the sub-key's validated user, the user obtaining sub-key with for private a key.
To the t, n) threshold secret sharing circuit, a network key recovery in of the validated user after receiving greater than or equal to sub-key of the t validated transmitting user, which are selecting t sub-keys is used for recovering network key. The network key recovery in the sleeve validated users to quick-recovery process of network key is: First and sub-key body part of the sub-key with a to act according to the following formula to recovering network the key base: p=f (0); =&Sigma; i=1t&alpha; i&Pij=1, j&NotEqual; it-ji-jmodq); >) and using sub-key main part to obtain Di=Emodmi according to any congruence group; 1≤i≤t, and Residue theorem, a computing network key generation factor is E= (D1M1M1 of +D2M2M2 the operating…+DtMtMt '), modQ, Mi=&Pi; J=1, J&NotEqual; limj),) >mimi ' =1modmi, Q=&Pi; i=1tmi);) > finally, according to the network key base and network key generation factor, recovery efficiently obtaining network key is: D=Emodp.
The network key recovery in of the validated user a restoring the key network, performing the standard data to a network key by two steps: methodThe first method, the validated user can use in a network key data value of the preset stage with, and data to the key network. The specific method is as follows: A restoring network key D and network key base p-type calculates the gDp2modq value; the value and network key for determining u0 value of the computer obtaining are the same; and; and key D recovery according to obtain is connected; Otherwise, network key D recovery according to obtain is not connected.
The second method, network key according resumed is any validated user use in a to machine encrypts a know a pre-formed the information of a network are key, comprising and a encrypt the information end of the broadcasting, network key recovery in the sleeve validated users' of encrypted information end of the decryption, the information for determining a obtaining with the information of foreknowledge is the same, network key of each other oneself recovery is connected; A same as the network irregularity key according oneself recovery. The information can be the information in a network user layer; knowsIs capable of the following: forming(IDi, hash (D1,…, Dt)), IDi is filled of encrypted information to the identity of validated user, D1,…, Dt is in network t validated user sub-key main part.
The process of network normal operation, wherein network user free mobile and beyond the range of the network that can relate, wherein thinks of the network user left the network. The network of a network user super-junction the multiple are, a super-junction threshold value t, wherein in each user a method of sub-key by updating network protection network security same.
The need to updating in a network are validated user sub-keys time, wherein a specific validated user edge of network updating the process of sub-key; the specific validated user unit according Pb is. The validated user Pb can be with strong computing power, or the large bandwidth, or the special validated user body is takes for child updating key, a called the validated user Pb the is a sub-key updating the user. The validated user Pb time monitoring network is uniformly the network validated user the number, which is a network validated user the insulating is greater than or equal to t, start in network the sub-key updating processing of the validated user, the specific method and shown the digital 2.
Steps: 201The sub-key updating the user Pb broadcast to transmit the sub-key to updating the request message.
Steps: 202The validated user in network after receiving the sub-wire key updating the request message; and protocol participates the sub-key updating method, updating the user loop to agree to participate in a message to the sub-key, wherein agree to participate in a connecting validated user sub-key main part Di for protocol participates, and which is agree, which are not respond the sub-key to updating the user transmission the sub-key to updating the request message.
Steps: 203The sub-key updating the user Pb judging whether received that is greater than or more than t validated user loop protocol participated the sub-key updating message, and is concave; the damage 204, theA not; and loop 203, casing to wait for of the validated user loop protocol message, prior is greater than or equal to the t validated user loop protocol participates the information of the sub-key updating.
Steps: 204The sub-key updating user Pb first in the loop agreements participate the sub-key updating message in validated user, arbitrary selecting t validated user, and straight Di=Emodmi according to any congruence group of the main sub-key root part of the t validated user 1≤i≤t, and Residue theorem, a computational obtaining network key generation wherein the sub-E= (D1M1M1 of +D2M2M2 the operating…+DtMtMt '), modQ; Mi=&Pij=1, j&NotEqual; itmj),) >mimi ' =1modmi, Q=&Pi; i=1tmi); >), and sub-key updating user Pb is a P0 is a network key generation updating base, the root obtaining network key generation to updating according to network key generation updating to P0 wherein the sub-E ' =E+P0, AN is a network key generation wherein the. , And the sub-key updating user Pb to updating method using network key generation of wherein the sub-E and a network are validated users of the sub-key production machine, new generation sub-key main part Di of the validated users of =E shape; modmiAnd sub-key updating part β i=f i (modq), (f) is a sub-key updating a user optional t- stepped, multinomial f (0) =P0. The sub-key updating the user in a network are validated user the upgrade sub-key, connected with each validated users' public keys add the double-seal updating sub-key the main part and sub-key updating component, which is validated and user. The full updating method, the sub-key renewed the user to updating sub-key's the main part, and then the sub-key to updating component; the sub-key with updating ', sub-key body part α i and sub-key updating part β rotor comprises a main part i Di.
When the sub-key by using updating recovering network secret with process is not upgraded the sub-key to quick-recovery process of network key is basic, needs is composed of a network key to machine is a t or more t validated user, and network key recovery in the sleeve; each validated user recovering network key shared by each other; sub-keyParts of different is using is not renewed sub-key the front method of recovery network key to obtain network key generation updating factor AN '; and subtracts for sub-key to updating network key generation updating to p0 according β part i computations obtain to obtain network key generation factor SAME. The specific process is as follows: Composed of a network key to machine is a t or more t validated user, network key recovery in the sleeve validated user sharing each other sub-key. The network key recovery in the sleeve any validated user without to the t validated user sub-keys; and sub-key body part of computations t validated user to obtain network key base p=f (0); =&Sigma; i=1t&alpha; i&Pij=1, j&NotEqual; it-ji-jmodq), >) and using sub-key to updating part computations to obtain network key generation updating to p0=f (0); =&Sigma; i=1t&beta; i&Pij=1, j&NotEqual; it-ji-jmodq); the) and > for updating sub-key the main part to obtain network key generation updating factor STRUCTURE according to the Residue theorem computational of the (D1 M1M1 of the +D2 of M2M2 '… interface+Dt of MtMt '), modQ; Mi=&Pij=1, j&NotEqual; iimJ),) >mimi ' =1modmi, Q=&Pi; i=1imi);) > a computer network acquiring key generation updating factor SAME shape and network key generation updating to P0, and quick-recovery network key (D= STRUCTURE A p0) modp=Emodp.
Hence, renewed in a network are validated user sub-keys and using sub-key to recovering network secret the process of terminal.
The invention hand-free method, can not only of the n network user to sharing function of network key, comprising an of the n network user to sharing functions of the keys network. The multi-key sharing method, the invention uses a t, n) threshold secret sharing processing and quick-recovery network key similar, namely is greater than a network one or more than of the common participation of t validated and quick-recovery key network. The specific process of multi-key sharing method is as follows: When the netinit, wherein a credible centre is determined with multiple network keys, for network same number is m, and a configuration with s1,…, sm are. The network, the combinations of the t validated user layers are Cnt, the credible centre time of each combined from 1 to the Cnt serial number, and recording the combined the serial sheets of each validated users. Here, wherein each combination of all recovering network and buttons, therefore called wherein each of the multi-key combination. A wherein multiple key housings; the credible centre calculates multi-key factor Hi, j=&Sigma in aggregate of each network key; si; l&ElementAJ (Dl2MlMl&prime; ; +&alphali+t), modM) through > i unit for serial number of network key, Aj unit for serial number of the multi-key combination of j t, a threshold value; subscript l unit for multi-keys combining validated the user; Ajand Ml=&Pi; ; k&ElementAj, k&NotEqual; lmk),) >mlMotors ' =1modml, M=&Pi; ; k&ElementAimk), >dl) and α l unit is configured of sub-gathers Aj the sub-key the validated user for multi-keys. The credible central root's and corresponding to each multiple key combinations per-network key the multi-keys of si wherein the sub-Hi, J, calculates the multi-key bottom wall, j=si-f (Hi, j), (f) is a value; and when of multi-key bottom wall, j network si key and multi-keys communication with multi-key bottom wall, wherein j of sub-Hi, J. When the credible centre with completed per-network key si the computer of multi-key bottom of each multiple key combinations, wherein a corresponding relationships of sub-Hi, J; and a serial number of serial number and corresponding of combined transmitting multi-key bottom wall, j and a network si key and multi-keys of the computations to obtain the network in the validated users.
A method for sharing multi-key, recovering specifically process of network key is: The network validated a user multi-key for sharing method for recovering network key, wherein the called multi-keys to machine, and is of the user is Computer, at the time of the Computer is a multi-keys recovering user, the multi-keys quick-recovery first user to determine network key according si flowing machine and electric equipments in network resumes the support of network key si. The network validated other user in receiving And transmitting the support of recovery network key si; the protocol participates to machine in network key si condition together, a message of the Computer loop protocol in participates. And receiving is greater than or equal to the t-1 validated user loop protocol message, and selecting t-1 rope, a serial number of switch and a oneself t user are to compose the t-1 validated user the multi-keys combination of. Serial number of the determining the multi-keys combination, transmitting the serial number and a multi-key combined in the t-1 validated users. The serial number of the user in multi-key electrothermal-dynamoelectric combined with the determining multi-keys and quick-recovery serial number of key, a switch is equal multi-key for producing factor; DSl=Dl2MlMl&prime; +&alphali+t), >) and transmit the multi-key factor of computer for obtaining to the multi-key combined in the validated users. The user in multi-key combined automatically according to any multi-key for outputting according with a to the equal multi-key factor is Hi, j=&Sigma; ; l&Element; AJDSlmodM=&Sigma; l&ElementAj (Dl2MlMl&prime; ; +&alphali+t) modM). >), and obtaining credible centre according to any si search the preset stage production multi-key bottom wall, j, calculates si=bi, j+f (Hi, j) is si machine according to multi-key bottom wall, j and multi-key factor Hi, J.
A distribution rotor sub-key key distribution to a user Pa and sub-key the sub-key updating method for updating user Pb to and quick-recovery network key multi-keys to machine And user in multi-key for sharing the new user be different or same validated user.
The is of the is good embodiment of this invention, is not used to define the invention the has a protection.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN102143167A | Cited by | China | Search report |
| CN105356999A | Cited by | China | Search report |
| CN101895388A | Cited by | China | Search report |
| CN105897409A | Cited by | China | Search report |
| US10873449B2 | Cited by | United States of America | Applicant |
| US10797865B2 | Cited by | United States of America | Applicant |
| CN107465505A | Cited by | China | Search report |
| WO2012003689A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 200510112883 | China | A | |
| CN20051112883 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| CN1953368AThis record | China | A | |
| CN100550726C | China | C |
Numbers
- Publication
- 1953368
- Publication, DOCDB
- 1953368
- Publication, EPODOC
- CN1953368
- Application
- 101128836
- Application, DOCDB
- 200510112883
- Application, EPODOC
- CN20051112883
Titles2
- English
- Distribution type dynamic secret key management method
- Chinese
- 一种分布式的动态密钥管理方法
Classification
- IPC, 2
- H04L9 14
- H04L9 08