{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T14:37:05Z","timestamp":1777300625580,"version":"3.51.4"},"reference-count":37,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2008,12,26]],"date-time":"2008-12-26T00:00:00Z","timestamp":1230249600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["MA 4957"],"award-info":[{"award-number":["MA 4957"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2011,12]]},"abstract":"<jats:p>\n            Two-party key exchange (2PKE) protocols have been rigorously analyzed under various models considering different adversarial actions. However, the analysis of group key exchange (GKE) protocols has not been as extensive as that of 2PKE protocols. Particularly, an important security attribute called\n            <jats:italic>key compromise impersonation (KCI) resilience<\/jats:italic>\n            has been completely ignored for the case of GKE protocols. Informally, a protocol is said to provide KCI resilience if the compromise of the long-term secret key of a protocol participant\n            <jats:italic>A<\/jats:italic>\n            does not allow the adversary to impersonate an honest participant\n            <jats:italic>B<\/jats:italic>\n            to\n            <jats:italic>A<\/jats:italic>\n            . In this paper, we argue that KCI resilience for GKE protocols is at least as important as it is for 2PKE protocols.\n          <\/jats:p>\n          <jats:p>Our first contribution is revised definitions of security for GKE protocols considering KCI attacks by both outsider and insider adversaries. We also give a new proof of security for an existing two-round GKE protocol under the revised security definitions assuming random oracles. We then show how to achieve insider KCIR in a generic way using a known compiler in the literature. As one may expect, this additional security assurance comes at the cost of an extra round of communication. Finally, we show that a few existing protocols are not secure against outsider KCI attacks. The attacks on these protocols illustrate the necessity of considering KCI resilience for GKE protocols.<\/jats:p>","DOI":"10.1145\/2043628.2043629","type":"journal-article","created":{"date-parts":[[2011,12,27]],"date-time":"2011-12-27T15:22:22Z","timestamp":1324999342000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":16,"title":["Modeling key compromise impersonation attacks on group key exchange protocols"],"prefix":"10.1145","volume":"14","author":[{"given":"M. C.","family":"Gorantla","sequence":"first","affiliation":[{"name":"Infosys Ltd., India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Colin","family":"Boyd","sequence":"additional","affiliation":[{"name":"Queensland University of Technology, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juan Manuel Gonz\u00e1lez","family":"Nieto","sequence":"additional","affiliation":[{"name":"Queensland University of Technology, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Manulis","sequence":"additional","affiliation":[{"name":"TUDarmstadt and CASED, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,12,26]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-40974-8_27"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/288090.288094"},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the Annual Cryptology Conference (CRYPTO'93)","volume":"773","author":"Bellare M.","unstructured":"Bellare , M. and Rogaway , P . 1993. Entity authentication and key distribution . In Proceedings of the Annual Cryptology Conference (CRYPTO'93) . Lecture Notes in Computer Science , vol. 773 . Springer, 232--249. Bellare, M. and Rogaway, P. 1993. Entity authentication and key distribution. In Proceedings of the Annual Cryptology Conference (CRYPTO'93). Lecture Notes in Computer Science, vol. 773. Springer, 232--249."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-007-0018-x"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the Annual Cryptology Conference (CRYPTO'01)","volume":"2139","author":"Boneh D.","unstructured":"Boneh , D. and Franklin , M. K . 2001. Identity-based encryption from the Weil pairing . In Proceedings of the Annual Cryptology Conference (CRYPTO'01) . Lecture Notes in Computer Science , vol. 2139 . Springer, 213--229. Boneh, D. and Franklin, M. K. 2001. Identity-based encryption from the Weil pairing. In Proceedings of the Annual Cryptology Conference (CRYPTO'01). Lecture Notes in Computer Science, vol. 2139. Springer, 213--229."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/648120.746927"},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the IFIP Joint Conference on Mobile and Wireless Communications Networks (MWCN'03)","author":"Bresson E.","unstructured":"Bresson , E. , Chevassut , O. , Essiari , A. , and Pointcheval , D . 2003. Mutual authentication and group key agreement for low-power mobile devices . In Proceedings of the IFIP Joint Conference on Mobile and Wireless Communications Networks (MWCN'03) . World Scientific Publishing, 59--62. Bresson, E., Chevassut, O., Essiari, A., and Pointcheval, D. 2003. Mutual authentication and group key agreement for low-power mobile devices. In Proceedings of the IFIP Joint Conference on Mobile and Wireless Communications Networks (MWCN'03). World Scientific Publishing, 59--62."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5555\/647097.717018"},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the Annual Cryptology Conference (EUROCRYPT'02)","volume":"2332","author":"Bresson E.","unstructured":"Bresson , E. , Chevassut , O. , and Pointcheval , D . 2002. Dynamic Group Diffie-Hellman Key Exchange under Standard Assumptions . In Proceedings of the Annual Cryptology Conference (EUROCRYPT'02) . Lecture Notes in Computer Science , vol. 2332 . Springer, 321--336. Bresson, E., Chevassut, O., and Pointcheval, D. 2002. Dynamic Group Diffie-Hellman Key Exchange under Standard Assumptions. In Proceedings of the Annual Cryptology Conference (EUROCRYPT'02). Lecture Notes in Computer Science, vol. 2332. Springer, 321--336."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/501983.502018"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368310.1368347"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the Annual Cryptology Conference (EUROCRYPT'94)","author":"Burmester M.","unstructured":"Burmester , M. and Desmedt , Y . 1994. A secure and efficient conference key distribution system (extended abstract) . In Proceedings of the Annual Cryptology Conference (EUROCRYPT'94) . 275--286. Burmester, M. and Desmedt, Y. 1994. A secure and efficient conference key distribution system (extended abstract). In Proceedings of the Annual Cryptology Conference (EUROCRYPT'94). 275--286."},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the International Workshop on Security Protocols. Springer-Verlag, 119--129","author":"Burmester M.","unstructured":"Burmester , M. and Desmedt , Y . 1997. Efficient and secure conference-key distribution . In Proceedings of the International Workshop on Security Protocols. Springer-Verlag, 119--129 . Burmester, M. and Desmedt, Y. 1997. Efficient and secure conference-key distribution. In Proceedings of the International Workshop on Security Protocols. Springer-Verlag, 119--129."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/874063.875553"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/11593447_34"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2008.920224"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/1756123.1756165"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-85855-3_26"},{"key":"e_1_2_1_19_1","volume-title":"Foundations of Cryptography (Basic Tools)","author":"Goldreich O.","unstructured":"Goldreich , O. 2001. Foundations of Cryptography (Basic Tools) . Cambridge University Press . Goldreich, O. 2001. Foundations of Cryptography (Basic Tools). Cambridge University Press."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/6490.6503"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1137\/0217017"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00468-1_7"},{"key":"e_1_2_1_24_1","volume-title":"InProceedings of the 12th International Conference on Information Security and Cryptology (ICISC'09)","author":"Gorantla M. C.","unstructured":"Gorantla , M. C. , Boyd , C. , Gonz\u00e1lez Nieto , J. M. , and Manulis , M . 2009b. Generic one round group key exchange in the standard model . InProceedings of the 12th International Conference on Information Security and Cryptology (ICISC'09) . Springer. Gorantla, M. C., Boyd, C., Gonz\u00e1lez Nieto, J. M., and Manulis, M. 2009b. Generic one round group key exchange in the standard model. InProceedings of the 12th International Conference on Information Security and Cryptology (ICISC'09). Springer."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1982.1056542"},{"key":"e_1_2_1_26_1","series-title":"Lecture Notes in Computer Science","volume-title":"Proceedings of the International Symposium on Algorithmic Number Theory","author":"Joux A.","unstructured":"Joux , A. 2000. A one round protocol for tripartite Diffie-Hellman . In Proceedings of the International Symposium on Algorithmic Number Theory . Lecture Notes in Computer Science , vol. 1838 , Springer , 385--394. Joux, A. 2000. A one round protocol for tripartite Diffie-Hellman. In Proceedings of the International Symposium on Algorithmic Number Theory. Lecture Notes in Computer Science, vol. 1838, Springer, 385--394."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.5555\/647093.716554"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102146"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45146-4_7"},{"key":"e_1_2_1_30_1","first-page":"24","article-title":"Constant-round authenticated group key exchange d dynamic groups. In Proceedings of the Annual Cryptology Conference (ASIACRYPT'04)","volume":"3329","author":"Kim H.-J.","year":"2004","unstructured":"Kim , H.-J. , Lee , S.-M. , and Lee , D. H. 2004 . Constant-round authenticated group key exchange d dynamic groups. In Proceedings of the Annual Cryptology Conference (ASIACRYPT'04) . Lecture Notes in Computer Science , vol. 3329 , Spring er, 24 -- 259 . Kim, H.-J., Lee, S.-M., and Lee, D. H. 2004. Constant-round authenticated group key exchange d dynamic groups. In Proceedings of the Annual Cryptology Conference (ASIACRYPT'04). Lecture Notes in Computer Science, vol. 3329, Springer, 24--259.","journal-title":"Lecture Notes in Computer Science"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/11535218_33"},{"key":"e_1_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Lamacchia B. A. Lauter K. and \n      Mityagin A\n  . \n  2007\n  . Stronger security of authenticated key exchange. In Proceedings of the 1st International Conference on Provable Security (ProvSec'07). W. Susilo J. K. Liu and Y. Mu Eds. Lecture Notes in Computer Science vol. \n  4784 Springer 1--16.   Lamacchia B. A. Lauter K. and Mityagin A. 2007. Stronger security of authenticated key exchange. In Proceedings of the 1st International Conference on Provable Security (ProvSec'07). W. Susilo J. K. Liu and Y. Mu Eds. Lecture Notes in Computer Science vol. 4784 Springer 1--16.","DOI":"10.1007\/978-3-540-75670-5_1"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1022595222606"},{"key":"e_1_2_1_34_1","series-title":"IT Security Series","volume-title":"Provably Secure Group Key Exchange","author":"Manulis M.","unstructured":"Manulis , M. 2007. Provably Secure Group Key Exchange . IT Security Series , vol. 5 . Europaischer Universitatsverlag . Manulis, M. 2007. Provably Secure Group Key Exchange. IT Security Series, vol. 5. Europaischer Universitatsverlag."},{"key":"e_1_2_1_35_1","unstructured":"Matsumoto T. Takashima Y and Imai H. 1986. On seeking smart public-key distribution systems. Trans. IECE Japan E69 99--106.  Matsumoto T. Takashima Y and Imai H. 1986. On seeking smart public-key distribution systems. Trans. IECE Japan E69 99--106."},{"key":"e_1_2_1_37_1","doi-asserted-by":"crossref","unstructured":"Steer D. G. Strawczynski L. Diffie W. and \n      Wiener M. J\n  . \n  1990\n  . A secure audio teleconference system. In Proceedings of the Annual Cryptology Conference (CRYPTO'88). S. Goldwasser Ed. Lecture Notes in Computer Science vol. \n  403 Springer 520--528.   Steer D. G. Strawczynski L. Diffie W. and Wiener M. J. 1990. A secure audio teleconference system. In Proceedings of the Annual Cryptology Conference (CRYPTO'88). S. Goldwasser Ed. Lecture Notes in Computer Science vol. 403 Springer 520--528.","DOI":"10.1007\/0-387-34799-2_37"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/238168.238182"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-007-9159-1"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2043628.2043629","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2043628.2043629","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:54:19Z","timestamp":1750240459000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2043628.2043629"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,12,26]]},"references-count":37,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2011,12]]}},"alternative-id":["10.1145\/2043628.2043629"],"URL":"https:\/\/doi.org\/10.1145\/2043628.2043629","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2008,12,26]]},"assertion":[{"value":"2010-06-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2008-12-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}