Ad hoc network group key management method
By adopting a logical key tree structure based on the elliptic curve cryptography system and a multi-party key negotiation protocol in the Ad hoc network, the problem of group communication security when new members join or member exit is solved, and the forward and backward security of group communication is realized.
Patent Information
- Application Number
- CN202510251279.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In Ad hoc network, traditional key management methods are difficult to ensure the front-back security of group communication when new members join or existing members exit.
A logical key tree structure based on the elliptic curve cryptography system is adopted to generate node keys through mapping functions, and a group key is dynamically generated through a multi-party key negotiation protocol when group initialization. When a new member joins or a member exits, adjust the logical key tree structure and update the relevant node keys to ensure that the new member cannot decrypt the communication content before joining, and the exit member cannot decrypt the communication content after exiting.
It realizes forward and backward security of group communication in Ad hoc network, and is suitable for dynamically changing network environments.
Smart Images

Figure CN119995885A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of key management, and in particular to a method for managing a key in an Ad hoc network group. Background Art
[0002] Ad hoc networks have the characteristics of high node mobility and frequent changes in topology. Traditional key management methods are difficult to ensure the forward and backward security of group communications.
[0003] How to design a key management method to ensure that when new members join or existing members leave the group, it can prevent new members from obtaining the communication content before joining (forward security) and prevent the exiting members from obtaining the communication content after leaving (backward security) is an urgent problem to be solved. Summary of the invention
[0004] In view of the deficiencies in the prior art, the present invention proposes an Ad hoc network group key management method to solve the above technical problems.
[0005] An Ad hoc network group key management method, comprising:
[0006] Constructing a logical key tree based on the elliptic curve cryptography system, wherein the logical key tree includes leaf nodes and non-leaf nodes;
[0007] The elliptic curve points are mapped to integer domain values through a mapping function, which are used to generate the keys of each node in the logical key tree;
[0008] When the group is initialized, the group key is dynamically generated through a multi-party key agreement protocol;
[0009] When a new member joins, the logical key tree structure is adjusted and the relevant node keys are updated to ensure that the new member cannot decrypt the communication content before joining;
[0010] When a member exits, the node keys on the paths related to the exiting member are updated to ensure that the exiting member cannot decrypt the communication content after the exit.
[0011] Furthermore, the implementation of the mapping function includes:
[0012] When the domain of the elliptic curve is a prime number domain, the horizontal coordinate of the point is directly taken as the mapping result;
[0013] When the domain of the elliptic curve is a binary domain, convert the binary representation of the abscissa into an integer bit by bit.
[0014] Furthermore, the key generation of non-leaf nodes in the logical key tree includes:
[0015] Perform elliptic curve scalar multiplication on the private key of the left child node and the public key of the right child node, and map the result to an integer as the node key through a mapping function.
[0016] Furthermore, the group key initialization protocol includes:
[0017] Brother node members exchange scalar multiplication results through multiple rounds of interactions and calculate the logical key tree node keys layer by layer;
[0018] The hash value of the root node key is calculated through the hash function, and the hash values of all members are compared to see if they are consistent. If they are consistent, the group key negotiation is successful.
[0019] Furthermore, the key update protocol when a new member joins includes:
[0020] Insert the new member node into the last position at the bottom of the logical key tree;
[0021] The designated initiating member updates the node key on its key path and merges the new member's key share into the group key through elliptic curve scalar multiplication.
[0022] The remaining members update the relevant node keys according to the intersection of the key paths, and specifically recalculate the relevant node keys through elliptic curve scalar multiplication operations.
[0023] Furthermore, the key update protocol when the member exits includes:
[0024] Remove exiting member nodes and adjust the logical key tree structure;
[0025] The designated initiating member updates the node key on its key path and regenerates the key share by changing the contributed secret value;
[0026] The remaining members update the relevant node keys according to the intersection of the key paths, and specifically recalculate the relevant node keys through elliptic curve scalar multiplication operations.
[0027] Furthermore, the dynamic adjustment of the logic key tree is triggered by a designated initiating member, which is a group member at the bottom rightmost end of the relevant subtree and is responsible for initiating a key update protocol and broadcasting update data.
[0028] Furthermore, during the key update process, all messages are verified for source authenticity and integrity through digital signatures, which is specifically implemented using an elliptic curve digital signature algorithm.
[0029] Furthermore, the balance of the logical key tree is achieved by automatically adjusting the hierarchical structure when dynamically inserting or deleting nodes, specifically including automatically balancing the height of subtrees to ensure that the tree height is minimized.
[0030] Furthermore, during the group key generation and update process, members achieve distributed negotiation of key shares by broadcasting scalar multiplication results.
[0031] The invention adopting the above technical solution has the following advantages:
[0032] The present invention adopts a logical tree structure and multi-party key negotiation and has the feature of key independence; the method is based on the logical key tree structure, supports node dynamic event group key update, meets the requirements of group key forward and backward security, and is suitable for Ad hoc network environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the specific implementation of the present invention, the following will briefly introduce the drawings required for use in the specific implementation. In all the drawings, each element or part is not necessarily drawn according to the actual scale.
[0034] Figure 1 A flowchart of a method for managing a group key in an Ad hoc network according to the present invention;
[0035] Figure 2 A structural diagram of a key tree in an Ad hoc network group key management method of the present invention;
[0036] Figure 3 The key K in the Ad hoc network group key management method of the present invention is<l,v> Calculation flow chart of . DETAILED DESCRIPTION
[0037] The following embodiments of the technical solution of the present invention are described in detail in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and are therefore only used as examples, and cannot be used to limit the protection scope of the present invention.
[0038] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in this application should be the common meanings understood by technicians in the field to which the present invention belongs. The terms "first", "second", etc. in the specification and claims of the embodiments of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so as to implement the embodiments of the present disclosure described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. Unless otherwise specified, the term "multiple" means two or more. In the embodiments of the present disclosure, the character " / " indicates that the objects before and after are in an "or" relationship. For example, A / B means: A or B. The term "and / or" is a description of the association relationship of objects, indicating that there can be three relationships. For example, A and / or B means: A or B, or, A and B. The term "corresponding" can refer to an association relationship or a binding relationship, and A and B correspondingly refer to an association relationship or a binding relationship between A and B.
[0039] like Figure 1 to Figure 3 As shown, an Ad hoc network group key management method of the present invention includes:
[0040] Step S01: construct a logical key tree based on the elliptic curve cryptography system, where the logical key tree includes leaf nodes and non-leaf nodes;
[0041] Step S02: Mapping the elliptic curve point to an integer domain value through a mapping function, so as to generate a key for each node of the logical key tree;
[0042] Step S03: When the group is initialized, a group key is dynamically generated through a multi-party key agreement protocol;
[0043] Step S04: When a new member joins, the logical key tree structure is adjusted and the relevant node keys are updated to ensure that the new member cannot decrypt the communication content before joining;
[0044] Step S05: When a member withdraws, the node key on the path related to the withdrawn member is updated to ensure that the withdrawn member cannot decrypt the communication content after the withdrawal.
[0045] In some embodiments, implementation of the mapping function includes:
[0046] When the domain of the elliptic curve is a prime number domain, the horizontal coordinate of the point is directly taken as the mapping result;
[0047] When the domain of the elliptic curve is a binary domain, convert the binary representation of the abscissa into an integer bit by bit.
[0048] Specifically, a mapping function Map(Q) is used in the scheme. Let E be an elliptic curve defined on a finite field Fq. When q is a prime number, Fq is a prime field. When q=2 m When m∈N, Fq is a binary field. The mapping function E(Fq)→N from a point Q∈E(Fq) to an integer is defined as follows:
[0049]
[0050] Use the Map(Q) mapping function to map a point Q on the elliptic curve to [1,2,…,q-1]. The μTGDH protocol calculates the nodes on the key tree<l,v> The node key K <l,v> When the left child node<l+1,2v> The private key K <l+1,2v> With the right child node<l+1,2v+1> The public key PK <l+1,2v+1> Perform scalar multiplication K on the elliptic curve <l+1,2v> PK <l+1,2v+1> , and use the Map(Q) function to map the scalar multiplication result to an integer on [1,2,…,q-1], that is, Map(K <l+1,2v> PK <l+1,2v+1> ), the mapping value is<l,v> The node key K <l,v> .
[0051] Similarly, in the μSTR and μSTR-H protocols, node M i The private key k i =Map(r i K i-1 ), which will be M i The selected secret value r i Its previous node M i-1 The public key value is used to perform a scalar multiplication operation on the elliptic curve, and the scalar multiplication result is mapped to an integer using the mapping function Map(Q). The mapped value is M i The private key k i .
[0052] Design a function f(Q, k), which is used by group members to calculate key shares during group key negotiation. Suppose there is a point G on the elliptic curve E, the order of G is a prime number r, and k is an arbitrary positive integer. Given the variables Q and k, the process of solving the point G through the equation Q = kG is represented by the function f(Q, k), and the calculation process of f(Q, k) is as follows.
[0053] 1. If the order of the element G in the group |G|=r, then |G k |=r / gcd(k,r).
[0054] According to Theorem 1, given the condition |G| = r, then |Q| = |kG| = r / gcd(k,r). Since r is a prime number, we have: (1) If r = nk, then |Q| = 1. At this time, Q is the infinite point O, and G can be any point in the group. (2) If r ≠ nk, then |Q| = r. At this time, G is a determined point in the group. Next, we will discuss the method to solve G in this case.
[0055] 2. If k and r are relatively prime, then there exists a unique integer x < r such that kx ≡ 1 (mod r).
[0056] Since k and r are relatively prime, that is, gcd(k,r) = 1, then according to Theorem 2, there must exist a unique x < r such that kx ≡ 1 mod r holds. That is to say, kx - 1 is a multiple of r. Suppose
[0057] kx - 1 = ry, where y is a positive integer. kx - ry = 1 is a linear Diophantine equation. The necessary and sufficient condition for this equation to have a solution is gcd(k,r) = 1. Given that k and r are relatively prime, this equation must have a solution. We can use the Euclid algorithm to solve for the value of x. Finally, perform a scalar multiplication operation on both sides of the equation Q = kG: xQ = (kx)G = (ry + 1)G = ryG + G = G, that is, G = xQ.
[0058] In some embodiments, the key generation of non-leaf nodes in the logical key tree includes:
[0059] Performing an elliptic curve scalar multiplication operation on the private key of the left child node and the public key of the right child node, and mapping the result to an integer as the key of this node through a mapping function.
[0060] Specifically, use a balanced binary tree to construct the logical key tree. Each node in the tree is represented by <l,v>, where 0 ≤ l ≤ h and h is the height of the key tree. Since there are at most 2 l nodes in the l-th layer, so 0 ≤ v ≤ 2 l - 1. Each internal node <l,v> in the tree is associated with a key pair {K <l,v> ,K <l,v>}, where K <l,v> = map(K <l,v> ). The leaf node <l i ,v i > corresponds to the group member M i . M i randomly selects k i from [1,2,…,r - 1] as its own private key, and calculates and publishes the public key PK i = k iG. Sponsor is responsible for initiating the group key update protocol.<l,v> The sponsor of a rooted (sub) tree is always the rightmost group member in the last layer of the (sub) tree. <l i ,v i > to <0,0> is called the path consisting of all node keys i The key path is P i Indicates that M i Know P i All node keys on .
[0061] For group member M i Node path P i Any node on<l,v> , M i can calculate its node key K <l,v> . Assume<l,v> The left and right subtrees of the root are represented by T 1 and T 2 , T 1 、T 2 The node sets on are represented as C 1 and C 2 , let M i ∈C 1 , S is the subtree T 2 sponsor, then M i To K <l,v> The calculation process can be expressed as Figure 3 shown.
[0062] Subtree T 2 The sponsor will node<l+1,2v+1> The public key K <l+1,2v+1> Mapped to integers, i.e. K <l+1,2v+1> =map(K <l+1,2v+1> ), then K <l+1,2v+1> With M i scalar multiplication of the public key, X s =K <l+1,2v+1> PK i , sponsor broadcasts X s .
[0063] Due to X s =K <l+1,2v+1> PK i =k i (K <l+1,2v+1> G), k i It is M i So we receive X s After that, M i Using the function f(X s ,k i)calculate<l+1,2v+1> Contributed key share K <l+1,2v+1> G, and the key share K contributed by him <l+1,2v> G and<l+1,2v+1> Add up the contributed key shares and get<l,v> The node key K <l,v> =K <l+1,2v> G+K <l+1,2v+1> G.
[0064] If M i ∈C 2 , that is, M i lie in<l,v> When the right subtree of K <l,v> The calculation method and Figure 3 Exactly the same as described in .
[0065] In some embodiments, the group key initialization protocol includes:
[0066] Brother node members exchange scalar multiplication results through multiple rounds of interactions and calculate the logical key tree node keys layer by layer;
[0067] The hash value of the root node key is calculated through the hash function, and the hash values of all members are compared to see if they are consistent. If they are consistent, the group key negotiation is successful.
[0068] Specifically, the group key is generated by group members contributing key shares.
[0069] To verify the correctness of the message source and the integrity and correctness of the message, it is assumed that all messages transmitted between members in the following protocol are signed and verified. Assume that there are n members in the group {M 1 ,…,M n}, when the key tree is a full binary tree, the group key initialization protocol is as follows:
[0070] First round: Brother group members M under the same parent node i和 M j:
[0071] (1) Randomly select the contributed secret value r from [1, 2, ..., r-1] i and r j ;
[0072] (2)M i Calculate A i =r i PK j , M j Calculate A j =r j PK i ;
[0073] (3)M i Broadcast Ai , M j Broadcast A j ;
[0074] (4) Receive A i After that, M j Using equation A i =r i PK j =r i k j G=k j (r i G), calculate
[0075] Likewise, M i Using equation A j =r j PK i =r j k i G=k i (r j G) Calculation
[0076] (5)M i and M j Calculate separately
[0077] Second round: Let l = l i -1,
[0078] (1) According to Lemma 1,<l,v> Calculate K for all group members in the root's subtree <l,v> ;
[0079] (2) Let l = l-1,
[0080] (3) Repeat steps 6 and 7 until all group members have calculated the group key K = K <0,0> .
[0081] Round 3: Each group member M i :
[0082] (1) Calculate and broadcast H i =H(x i ,y i ), where x i and i are the x and y coordinates of K respectively;
[0083] (2) Compare the H of all members i , if all are equal, the group key negotiation is successful, and the group key K = K <0,0> .
[0084] If the key tree is not a full binary tree, that is, the last member M n If there is no brother, then M n The corresponding parent node key Among them, r n is a value randomly selected from [1,2,...,r-1].
[0085] In some embodiments, the key update protocol when a new member joins includes:
[0086] Insert the new member node into the last position at the bottom of the logical key tree;
[0087] The designated initiating member updates the node key on its key path and merges the new member's key share into the group key through elliptic curve scalar multiplication.
[0088] The remaining members update the relevant node keys according to the intersection of the key paths, and specifically recalculate the relevant node keys through elliptic curve scalar multiplication operations.
[0089] Specifically, suppose there are n members in the group, represented by S1, and the host M who wants to join the group n+1 First, a join request is sent to S. The join request contains a secret value r selected from [1,2,…,r-1] n+1 With S1 group member M i Scalar multiplication result of the public key r n+1 PK i , i=1,2,…,n.
[0090] After the join request is authenticated, the insertion position of the inserted node is determined, and the inserted node should be at the bottom and last node of the key tree. All group members create new member nodes and adjust the structure of the key tree. n Initiate the group key update protocol.
[0091] (1)M n Change the secret value of your contribution to r′ n , r′ n ∈[1,2,...,r-1].
[0092] (2)M n Update its key path P n All node keys on P n Any point on<l,v> , calculate K′ <l,v> =K <l,v> -r n G+r′ n G.
[0093] (3) According to Lemma 1, in the order from the bottom layer to the 0th layer of the key tree, member M i (M i ∈S1 and M i ≠M n ) Update the set P in sequence i ∩P n The node key K of all nodes on <l,v> K′ <l,v> .
[0094] (4)M i Received from M n+1 R n+1 PK i Afterwards, by r n+1 PK i =k i (r n+1 G), calculate M n+1 Contributed key share r n+ 1 G = f(r n+1 PK i ,k i ).
[0095] (5)M i (M i ∈S1) Calculate the updated group key K = K′ <0,0> +r n+1 G.
[0096] (6) According to Lemma 1, M n+1 Calculate its key path P in sequence n+1 All nodes keys K on <l,v> , group key K = K <0,0> .
[0097] In some embodiments, the key update protocol when a member exits includes:
[0098] Remove exiting member nodes and adjust the logical key tree structure;
[0099] The designated initiating member updates the node key on its key path and regenerates the key share by changing the contributed secret value;
[0100] The remaining members update the relevant node keys according to the intersection of the key paths, and specifically recalculate the relevant node keys through elliptic curve scalar multiplication operations.
[0101] Specifically, after a member exit event occurs, the remaining group members first update the structure of the key tree, sponsor M s Change the secret value of your contribution to r′ s∈[1,2,...,r-1], and use the changed key share r′ s G updates its key path P S The node key on .
[0102] Then, the remaining group members update the node keys on the corresponding key paths according to the method described in Lemma 1.
[0103] Assume group member M L (1≤L≤n) exit the group, M L After exiting, the remaining group members are S2, M L Broadcast the exit request to the group. The sponsor in the remaining group member set S2 is M s , by M s Initiate group key update protocol;
[0104] (1)M s Change the secret value of your contribution to r′ s , r′ s ∈[1,2,...,r-1].
[0105] (2)M s Update its key path P s All node keys on P s Any point on<l,v> , calculate K′ <l,v> =K <l,v> -r S G+r′ s G.
[0106] (3) According to Lemma 1, in the order from the bottom layer to the 0th layer of the key tree, member M i (M i ∈S2 and M i ≠M s ) Update the set P in sequence i ∩P S The node key K of all nodes on <l,v> K′ <l,v> The updated group key K = K′ <0,0> .
[0107] In some embodiments, the dynamic adjustment of the logical key tree is triggered by a designated initiating member, which is the group member at the bottom and rightmost end of the relevant subtree and is responsible for initiating the key update protocol and broadcasting the update data.
[0108] In some embodiments, all messages in the key update process are verified for source authenticity and integrity through digital signatures, which is specifically implemented using an elliptic curve digital signature algorithm.
[0109] In some embodiments, the balance of the logical key tree is achieved by automatically adjusting the hierarchical structure when dynamically inserting or deleting nodes, specifically including automatically balancing the height of subtrees to ensure that the tree height is minimized.
[0110] In some embodiments, during the group key generation and update process, members achieve distributed negotiation of key shares by broadcasting scalar multiplication results.
[0111] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention.
Claims
1. A method for managing group keys in an Ad hoc network, characterized in that: include: Constructing a logical key tree based on the elliptic curve cryptography system, wherein the logical key tree includes leaf nodes and non-leaf nodes; The elliptic curve points are mapped to integer domain values through a mapping function, which are used to generate the keys of each node in the logical key tree; When the group is initialized, the group key is dynamically generated through a multi-party key agreement protocol; When a new member joins, the logical key tree structure is adjusted and the relevant node keys are updated to ensure that the new member cannot decrypt the communication content before joining; When a member exits, the node keys on the paths related to the exiting member are updated to ensure that the exiting member cannot decrypt the communication content after the exit.
2. The method according to claim 1, characterized in that The implementation of the mapping function includes: When the domain of the elliptic curve is a prime number domain, the horizontal coordinate of the point is directly taken as the mapping result; When the domain of the elliptic curve is a binary domain, convert the binary representation of the abscissa into an integer bit by bit.
3. The method according to claim 1, characterized in that The key generation of non-leaf nodes in the logical key tree includes: Perform elliptic curve scalar multiplication on the private key of the left child node and the public key of the right child node, and map the result to an integer as the node key through a mapping function.
4. The method according to claim 1, characterized in that: The group key initialization protocol includes: Brother node members exchange scalar multiplication results through multiple rounds of interactions and calculate the logical key tree node keys layer by layer; The hash value of the root node key is calculated through the hash function, and the hash values of all members are compared to see if they are consistent. If they are consistent, the group key negotiation is successful.
5. The method according to claim 1, characterized in that The key update protocol when a new member joins includes: Insert the new member node into the last position at the bottom of the logical key tree; The designated initiating member updates the node key on its key path and merges the new member's key share into the group key through elliptic curve scalar multiplication. The remaining members update the relevant node keys according to the intersection of the key paths, and specifically recalculate the relevant node keys through elliptic curve scalar multiplication operations.
6. The method according to claim 1, characterized in that The key update protocol when the member exits includes: Remove exiting member nodes and adjust the logical key tree structure; The designated initiating member updates the node key on its key path and regenerates the key share by changing the contributed secret value; The remaining members update the relevant node keys according to the intersection of the key paths, and specifically recalculate the relevant node keys through elliptic curve scalar multiplication operations.
7. The method according to claim 1, characterized in that The dynamic adjustment of the logical key tree is triggered by a designated initiating member, which is a group member at the bottom rightmost end of the relevant subtree and is responsible for initiating a key update protocol and broadcasting update data.
8. The method according to claim 1, characterized in that During the key update process, all messages are verified for source authenticity and integrity through digital signatures, which is specifically implemented using the elliptic curve digital signature algorithm.
9. The method according to claim 1, characterized in that: The balance of the logical key tree is achieved by automatically adjusting the hierarchical structure when dynamically inserting or deleting nodes, specifically including automatically balancing the height of subtrees to ensure that the tree height is minimized.
10. The method according to claim 1, characterized in that During the group key generation and update process, members achieve distributed negotiation of key shares by broadcasting scalar multiplication results.