Security improvement on a group key exchange protocol for mobile networks

  • Authors:
  • Junghyun Nam;Kwangwoo Lee;Juryon Paik;Woojin Paik;Dongho Won

  • Affiliations:
  • Department of Computer Engineering, Konkuk University, Korea;Department of Computer Engineering, Sungkyunkwan University, Korea;Department of Computer Engineering, Sungkyunkwan University, Korea;Department of Computer Engineering, Konkuk University, Korea;Department of Computer Engineering, Sungkyunkwan University, Korea

  • Venue:
  • ICCSA'11 Proceedings of the 2011 international conference on Computational science and its applications - Volume Part IV
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

A group key exchange (GKE) protocol is designed to allow a group of parties communicating over a public network to establish a common secret key called a session key. As group-oriented applications gain popularity over the Internet, a number of GKE protocols have been suggested to provide those applications with a secure multicast channel. Among the many protocols is the GKE protocol presented by Dutta and Dowling for mobile ad hoc networks. In this paper, we are concerned with the security of the Dutta-Dowling protocol. Their protocol carries a proof of security in the standard adversarial model which captures unknown key-share attacks. But unlike the claim of provable security, the Dutta-Dowling protocol fails to achieve unknown key-share resilience. We here reveal this security vulnerability of the protocol and show how to address it.