Abstract:
The security of an authenticated group key exchange is analyzed, the results show that it is insecure due to redundancy of the exchange messages. Based on the protocol of Burmester and Desmedt, an improved protocol is proposed with merits in terms of computation and communication. The improved protocol provides not only the capability of forward secrecy and mutual authentication, but also the capability against man-in-middle attack. The protocol is proven secure in the random-oracle and ideal-cipher models under the computational Diffie-Hellman(CDH) assumption.