Keystone: a Group Key Management Service

A major problem area in securing group communications is group key management. In this paper, we present the design and architecture of a scalable group key management system called Keystone. Key-stone uses a novel key graph technique for scalable group key management. In Keystone, the authentica-tion of client identity can be oooaded to one or more registrars to improve performance. For eecient and reliable key updates, Keystone uses UDP/IP mul-ticast delivery with forward error correction (FEC) to reduce message loss, and provides an eecient re-synchronization mechanism for clients to reliably update their keys in case of actual message loss. A prototype of Keystone has been implemented and its performance results are reported.