Title :
A secure key registration system based on proactive secret-sharing scheme
Author_Institution :
Res. Lab., IBM Japan Ltd., Tokyo, Japan
Abstract :
We designed a secure key registration system based on the proactive secret-sharing scheme. A user can register important data such as a session key to a distributed system in a (t, n)-threshold scheme, which means that the data can be recovered if t sewers cooperate (in other words, that the data cannot be revealed unless t sewers collude). The proactive scheme provides stronger security against an active adversary. We designed the protocol to generate an implicit secret, to distribute shares of it, and to reconstruct the secret for proactive secret-sharing without a dealer. We also developed a prototype of a data archiving service framework on the Internet. To allow users to access the system via a Web browser, we implemented a system based on the PKI (public key infrastructure), where the client/server authentication is done by means of X.509 certification. We also used the publish/subscribe communication model to realize interaction between key management servers, because it is easy to implement the broadcasting channels used in the share update phase
Keywords :
cryptography; Web browser; client/server authentication; distributed system; key management servers; key registration; proactive secret-sharing; secure key registration; Access protocols; Authentication; Broadcasting; Certification; Data security; File servers; Prototypes; Public key; Web and internet services; Web server;
Conference_Titel :
Autonomous Decentralized Systems, 1999. Integration of Heterogeneous Systems. Proceedings. The Fourth International Symposium on
Conference_Location :
Tokyo
Print_ISBN :
0-7695-0137-0
DOI :
10.1109/ISADS.1999.838438