CPAKE: Dynamic Batch Authenticated Key Exchange with Conditional Privacy
摘要
Authenticated key exchange (AKE) needs to be designed for realizing point-to-multipoint secure communications in blockchain networks (BNet). However, since BNet is open, untrusted and decentralized, traditional certificateless AKE schemes are difficult to overcome two technical bottlenecks, i.e., private distribution of partial keys and accurate identification of anonymous traitors. This paper proposes a conditionally private and dynamic batch AKE scheme (CPAKE) in BNet. We first develop a privacy-preserving certificateless key generation algorithm to prevent the disclosure of nodes’ privacy during partial key distribution. Then, we design a simple anonymous traitor tracing mechanism against Byzantine adversaries to accurately identify and trace the traitor’s identity. Finally, we build a dynamic batch authentication protocol with decentralized node management to ensure the final validity of honest nodes. Moreover, performance analysis indicates that our scheme reduces the signing and batch-verifying time by approximately 193.10 ms and 10.93 ms respectively over state-of-the-art.