Abstract

Subset Difference Revocation (SDR) provides a powerful mechanism for the efficient expression of the revocation state of a large group of key recipients. However, arbitrary assignment of receivers as leaf nodes in a static binary tree can lead to inefficiencies in certain group revocation states. Gateway Subset Difference Revocation (GSDR), developed in our ongoing SecureKeys effort, provides the ability to group receivers based upon organizational characteristics while simultaneously introducing the ability to audit rekey and data transmission, delegate rekey decisions to subordinate decision makers, and override subordinate rekey authority when necessary. GSDR extends the existing SDR scheme by deploying rekey gateways in a hierarchy that mimics an organic decision making structure. Delegation of rekey authority offloads a significant computational and communications burden from gateways high in the tree, while correspondingly partitioning the rekey traffic required to be processed by leaf nodes in the tree. GSDR also significantly reduces label storage requirements in rekey devices by limiting terminal node fan-out.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.