LPP-GKM: a lightweight and privacy-preserving group key management scheme to enhance security in the internet of things
摘要
The rapid proliferation of the Internet of Things (IoT) has enabled large-scale connectivity among heterogeneous and resource-constrained devices. Although this connectivity supports applications in healthcare, transportation, industrial automation, and cyber–physical systems, it also increases the difficulty of providing secure, efficient, and privacy-preserving group communication. Conventional group key management (GKM) schemes may impose substantial rekeying, communication, and credential-management overhead, while static identifiers or public credentials can expose devices to identity tracing and session linkage. This paper presents Lightweight and Privacy-Preserving Group Key Management (LPP-GKM), a group key management scheme for dynamic IoT groups. The revised design combines pseudonym-based ECC mutual authentication, transcript-bound session-key establishment, hierarchy-based encrypted rekeying, and controlled pseudonym refresh. During normal authentication, a device sends its current pseudonym, an ephemeral ECC point, and freshness information without transmitting its stable public key. The trusted Group Manager (GM) resolves the corresponding public key internally from a protected registration record and establishes an authenticated device–GM session key. For membership changes, LPP-GKM uses a balanced symmetric key hierarchy. The GM refreshes the affected keys from the changed member leaf to the root and encrypts replacement keys under keys held only by authorized sibling subtrees. Consequently, a revoked device may record public rekey-update messages but cannot decrypt the replacement hierarchy keys required to derive the new group key. The design requires