We propose and implement a protocol for a scalable, cost-effective, information-theoretically secure key distribution and management system. The system, called Distributed Symmetric Key Exchange (DSKE), relies on pre-shared random numbers between DSKE clients and a group of Security Hubs. Any group of DSKE clients can use the DSKE protocol to distill from the pre-shared numbers a secret key. The clients are protected from Security Hub compromise via a secret sharing scheme that allows the creation of the final key without the need to trust individual Security Hubs. Precisely, if the number of compromised Security Hubs does not exceed a certain threshold, confidentiality is guaranteed to DSKE clients and, at the same time, robustness against denial-of-service (DoS) attacks. The DSKE system can be used for quantum-secure communication, can be easily integrated into existing network infrastructures, and can support arbitrary groups of communication parties that have access to a key. We discuss the high-level protocol, analyze its security, including its robustness against disruption. A proof-ofprinciple demonstration of secure communication between two distant clients with a DSKE-based VPN using Security Hubs on Amazon Web Server (AWS) nodes thousands of kilometres away from them was performed, demonstrating the feasibility of DSKEenabled secret sharing one-time-pad encryption with a data rate above 50 Mbit/s and a latency below 70 ms.
翻译:我们提议并执行一项协议,用于一个可扩展的、成本-效益高的、信息战地安全的关键分配和管理系统。这个称为分布式对称键交换(DSKE)的系统,依赖于DSKE客户和一组安全枢纽之间预先共享的随机数字。任何一批DSKE客户都可以使用DSKE协议,从预共享的数字中提取一个秘密钥匙。客户通过秘密共享计划不受安全枢纽妥协的保护,从而无需信任单个安全枢纽即可创建最后钥匙。准确地说,如果受损的安全枢纽的数量没有超过一定的门槛,则对DSKE客户的保密性得到保障,同时,对拒绝服务(DoS)袭击者之间预先共享的随机随机数字。DSKE系统可用于量安全通信,可以很容易地融入现有的网络基础设施,并且可以支持任意的通信方群体,从而无需信任单个安全枢纽。我们讨论高级别协议,分析其安全性,包括不受干扰的稳健性。在50公里以下的安全枢纽以下的安全枢纽客户之间安全保密性演示两个远端的S-CWS-S-HS-HS-S-HS-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-M-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-S-