<p>The rapid proliferation of the Internet of Things (IoT) has enabled large-scale connectivity among heterogeneous and resource-constrained devices. Although this connectivity supports applications in healthcare, transportation, industrial automation, and cyber–physical systems, it also increases the difficulty of providing secure, efficient, and privacy-preserving group communication. Conventional group key management (GKM) schemes may impose substantial rekeying, communication, and credential-management overhead, while static identifiers or public credentials can expose devices to identity tracing and session linkage. This paper presents <i>Lightweight and Privacy-Preserving Group Key Management</i> (LPP-GKM), a group key management scheme for dynamic IoT groups. The revised design combines pseudonym-based ECC mutual authentication, transcript-bound session-key establishment, hierarchy-based encrypted rekeying, and controlled pseudonym refresh. During normal authentication, a device sends its current pseudonym, an ephemeral ECC point, and freshness information without transmitting its stable public key. The trusted Group Manager (GM) resolves the corresponding public key internally from a protected registration record and establishes an authenticated device–GM session key. For membership changes, LPP-GKM uses a balanced symmetric key hierarchy. The GM refreshes the affected keys from the changed member leaf to the root and encrypts replacement keys under keys held only by authorized sibling subtrees. Consequently, a revoked device may record public rekey-update messages but cannot decrypt the replacement hierarchy keys required to derive the new group key. The design requires <InlineEquation ID="IEq1"><EquationSource Format="TEX">\(O(\log N)\)</EquationSource></InlineEquation> refreshed hierarchy keys and encrypted update components for a single membership change in a balanced group of <i>N</i> active members, while routine rekeying uses symmetric-key operations only. The security analysis scopes mutual authentication, session-key establishment, post-revocation key exclusion, backward secrecy for newly admitted members, replay resistance, and identity protection under the stated trust and cryptographic assumptions. Privacy is limited to protection against direct identity exposure and transcript-level linkage by external observers and honest-but-curious infrastructure; it is not claimed against the trusted GM, traffic analysis, physical-layer tracking, or GM compromise. The performance evaluation distinguishes device-side operations, GM-side processing, and total network-level rekey delivery cost.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

LPP-GKM: a lightweight and privacy-preserving group key management scheme to enhance security in the internet of things

  • Seyed Morteza Mousavi,
  • Mohammad Taghi Manzuri,
  • Amir Masoud Rahmani

摘要

The rapid proliferation of the Internet of Things (IoT) has enabled large-scale connectivity among heterogeneous and resource-constrained devices. Although this connectivity supports applications in healthcare, transportation, industrial automation, and cyber–physical systems, it also increases the difficulty of providing secure, efficient, and privacy-preserving group communication. Conventional group key management (GKM) schemes may impose substantial rekeying, communication, and credential-management overhead, while static identifiers or public credentials can expose devices to identity tracing and session linkage. This paper presents Lightweight and Privacy-Preserving Group Key Management (LPP-GKM), a group key management scheme for dynamic IoT groups. The revised design combines pseudonym-based ECC mutual authentication, transcript-bound session-key establishment, hierarchy-based encrypted rekeying, and controlled pseudonym refresh. During normal authentication, a device sends its current pseudonym, an ephemeral ECC point, and freshness information without transmitting its stable public key. The trusted Group Manager (GM) resolves the corresponding public key internally from a protected registration record and establishes an authenticated device–GM session key. For membership changes, LPP-GKM uses a balanced symmetric key hierarchy. The GM refreshes the affected keys from the changed member leaf to the root and encrypts replacement keys under keys held only by authorized sibling subtrees. Consequently, a revoked device may record public rekey-update messages but cannot decrypt the replacement hierarchy keys required to derive the new group key. The design requires \(O(\log N)\) refreshed hierarchy keys and encrypted update components for a single membership change in a balanced group of N active members, while routine rekeying uses symmetric-key operations only. The security analysis scopes mutual authentication, session-key establishment, post-revocation key exclusion, backward secrecy for newly admitted members, replay resistance, and identity protection under the stated trust and cryptographic assumptions. Privacy is limited to protection against direct identity exposure and transcript-level linkage by external observers and honest-but-curious infrastructure; it is not claimed against the trusted GM, traffic analysis, physical-layer tracking, or GM compromise. The performance evaluation distinguishes device-side operations, GM-side processing, and total network-level rekey delivery cost.