Алгоритм відстежування порушників в схемах багатоадресного розподілу ключів

dc.contributor.authorЗакусіло, Валерій Олегович,
dc.contributor.authorКонюшок, Сергій Миколайович
dc.date.accessioned2026-02-03T10:00:42Z
dc.date.available2026-02-03T10:00:42Z
dc.date.issued2025
dc.description.abstractСтаття присвячена дослідженню рандомізованих схем багатоадресного розподілу ключів, побудованих на основі кодових конструкцій, та їх застосуванню для реалізації схем відстежування порушників (traitor tracing). Схема багатоадресного розподілу ключів –це криптографічний протокол, в якому центр розподілу ключів здійснює передачу певної допоміжної інформації (доступ до якої повинні мати тільки авторизовані користувачі) абонентам мережі зв’язку так, що з часом, в разі компрометації криптографічних ключів частини абонентів, перелік яких центру розподілу ключів вдалося встановити, інші абоненти зможуть відновити спільний криптографічний ключ, який в зашифрованому вигляді передається з центру розподілу ключів по широкомовному каналу зв’язку. При цьому, абоненти, ключі яких були скомпрометовані, не зможуть розшифрувати передане широкомовне повідомлення. Як видно, для успішного функціонування таких схем, існує потреба в підходах та інструментах встановлення переліку скомпрометованих абонентів (для різних задач може бути потреба як в повному переліку таких абонентів, так і хоча б одного з них). Класичні схеми traitor tracing можуть стати основою для побудови таких інструментів оскільки створювались для виявлення користувача або групи недобросовісних користувачів, які передали свої ключі для створення масиву скомпрометованих ключів, яким можуть скористатись в зловмисних цілях (так званого “декодера порушника”). Однак, в умовах зростання кількості абонентів, стрімкого розвитку обчислювальних ресурсів, створення адаптивних атак та зростання вимог до приватності, такі схеми демонструють зниження ефективності.Запропонований у статті підхід спрямований на поєднання можливостей схем багатоадресного розподілу ключів і схем відстежування порушників з дотриманням балансу між точністю відстежування порушників та ефективністю доступних обчислювальних ресурсів. Завдякизастосуванню оцінок Геффдінга побудований в статті алгоритм є t-ідентифікуючим, тобто здатен гарантувати ідентифікацію хоча б одного учасника будь-якої коаліції, що не перевищує tпорушників. Наведені достатні умови на параметри кодів забезпечують суттєве покращення порівняно з класичними. Продемонстровано, що рандомізований підхід зберігає рівень стійкості системи і не погіршує безпекових властивостей оригінальної схеми, але істотно підсилює її здатність розрізняти користувачів у випадку компрометації ключів. Отримані в статті аналітичні вирази дозволяють отримати точні нижні оцінки надійності алгоритму відстежування порушників, що, в свою чергу, може бути використане при практичній побудові рандомізованих протоколів відстежування з заданою необхідною (високою) надійністю
dc.description.abstractotherThe article is devoted to the study of randomized multi-address key distribution schemes based on code constructions and their application for implementing traitor tracing schemes. A multi-address key distribution scheme is a cryptographic protocol in which a key distribution center transmits certain auxiliary information (to which only authorized users should have access) to subscribers of a communication network so that, over time, in the event of compromise of the cryptographic keys of some subscribers, whose list the key distribution center has managed to establish, other subscribers will be able to restore the shared cryptographic key, which is transmitted in encrypted form from the key distribution center via a broadcast communication channel. At the same time, subscribers whose keys have been compromised will not be able to decrypt the broadcast message. As can be seen, for such schemes to function successfully, there is a need for approaches and tools to establish a list of compromised subscribers (for different tasks, there may be a need for either a complete list of such subscribers or at least one of them). Classic traitor tracing schemes can be the basis for building such tools because they were created to identify a user or group of unscrupulous users who transferred their keys to create an array of compromised keys that can be used for malicious purposes (the so-called “violators decoder”). However, with the growing number of subscribers, the rapid development of computing resources, the creation of adaptive attacks, and increasing privacy requirements, such schemes are becoming less effective.The approach proposed in the article aims to combine the capabilities of multi-address key distribution schemes and intruder tracking schemes while maintaining a balance between the accuracy of intruder tracking and the efficiency of available computing resources. Thanks to the use of Geffding's estimates, the algorithm constructed in the article is t-identifying, i.e., it is capable of guaranteeing the identification of at least one participant in any coalition that does not exceed tviolators. The sufficient conditions given for the code parameters provide a significant improvement over the classical ones. It is demonstrated that the randomized approach preserves the stability of the system and does not degrade the security properties of the original scheme, but significantly enhances its ability to distinguish users in case of key compromise. The analytical expressions obtained in the article allow obtaining accurate lower bounds on the reliability of the traitor tracing algorithm, which, in turn, can be used in the practical construction of randomized traitor tracing protocols with a given required (high) reliability.
dc.format.pagerangeP. 216-224
dc.identifier.citationЗакусіло, В. О. Алгоритм відстежування порушників в схемах багатоадресного розподілу ключів / Валерій Закусіло, Сергій Конюшок // Information Technology and Security. – 2025. – Vol. 13, Iss. 2 (25). – P. 216-224. – Bibliogr.: 12 ref.
dc.identifier.doihttps://doi.org/10.20535/2411-1031.2025.13.2.344838
dc.identifier.orcid0000-0001-6906-2742
dc.identifier.orcid0000-0003-4121-1464
dc.identifier.urihttps://ela.kpi.ua/handle/123456789/78604
dc.language.isouk
dc.publisherInstitute of Special Communication and Information Protection of National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”
dc.publisher.placeKyiv
dc.relation.ispartofInformation Technology and Security, Vol. 13, Iss. 2 (25)
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subjectкібербезпека
dc.subjectкіберзахист
dc.subjectпостквантова криптографія
dc.subjecttraitor tracing
dc.subjectсхема багатоадресного розподілу ключів
dc.subjectcybersecurity
dc.subjectcyber defense
dc.subjectcryptography
dc.subjecttraitor tracing
dc.subjectmulti-address key distribution scheme
dc.subject.udc004.056
dc.titleАлгоритм відстежування порушників в схемах багатоадресного розподілу ключів
dc.title.alternativeAlgorithm for tracking violators in multi-address key distribution schemes
dc.typeArticle

Файли

Контейнер файлів
Зараз показуємо 1 - 1 з 1
Вантажиться...
Ескіз
Назва:
216-224.pdf
Розмір:
564.31 KB
Формат:
Adobe Portable Document Format
Ліцензійна угода
Зараз показуємо 1 - 1 з 1
Ескіз недоступний
Назва:
license.txt
Розмір:
8.98 KB
Формат:
Item-specific license agreed upon to submission
Опис: