14
M. Kutyłowski et al.
The advantage of this approach is that the adversarial device needs to know
all keys k i 1 , . . . , k i,w to decrypt the communications of Phase 2. Of course, some
keys from the list may be known to the adversary—due to the key predistribution
mechanism.
1.3.2.3 Epoch Keys
Paradoxically, reducing the number of keys in a pool may be advantageous.
According to [146], each device holds the following:
long term keys: These are the keys from a key predistribution scheme. Long term
keys are used only to decrypt ciphertexts containing epoch keys,
epoch keys:
These keys are used for establishing communication links within
their epoch as described in previous subsections.
From time to time the system provider runs the following steps:
1. new epoch keys are generated at random,
2. for each key k from the pool of long term keys, the corresponding ciphertext
C := Enc k (η) with a MAC is created, where η is an epoch key selected for k,
3. the ciphertexts of the epoch keys are disseminated to the devices.
There might be different ways of dissemination. For example, it might be done by
broadcasting over a public radio channel or handling the new epoch keys when a
device logs into the system.
The crucial property of this approach is that the number of epoch keys is N/m,
where N is the number of long term keys, and that an epoch key is assigned to
m long term keys when creating the ciphertexts described above. The parameter m
could be a small constant such as 4. If each device holds n ≈
√
N long term keys,
and m is a small constant, then the expected number of epoch keys shared by two
devices is approximately m.
Using epoch keys has advantages from the point of view of privacy protection:
• As the number of shared keys increases the probability that a different device can
follow the communication in Phase 2 is significantly reduced. For instance, for
m = 2 the probability changes from n/N to
(
n
2 )
(
N/2
2 )
≈
n 2 /2
N 2 /8
= 4 ·
n
N
2 .
As typically
n
N 1, the progress is significant.
• Devices A and B may share epoch keys for two reasons:
– A and B share a long term key, so consequently they share the epoch key
encrypted with this long term key,
– the same epoch key has been encrypted with different long term keys
possessed, respectively, by A and B.
Précédent

- 29/268

Suivant