X. Brian Zhang

dblp:09/241 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
0since 2021 · last 2005
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 3 first-authorSystems, architecture and hardware · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Cryptographic protocols and secure computation · 78% Network security · 22%
Computer networks
1 paper
Internet architecture and protocols · 100%

Topics — the 5 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic protocols and secure computation › key management
group key management
0.122003
Protocol design for scalable and reliable group rekeying · IEEE/ACM Trans. Netw. 2003
Reliable group rekeying: a performance analysis · SIGCOMM 2001
Cryptographic protocols and secure computation › key management › group key management
group rekeying
0.122003
Protocol design for scalable and reliable group rekeying · IEEE/ACM Trans. Netw. 2003
Reliable group rekeying: a performance analysis · SIGCOMM 2001
Network security › secure communication
secure group communication
0.012003
Protocol design for scalable and reliable group rekeying · IEEE/ACM Trans. Netw. 2003
Cryptographic protocols and secure computation › key management › group key management
batch rekeying
0.012001
Reliable group rekeying: a performance analysis · SIGCOMM 2001
Internet architecture and protocols › multicast
reliable multicast
0.012003
Protocol design for scalable and reliable group rekeying · IEEE/ACM Trans. Netw. 2003

Methods — techniques the papers use, named apart from their topics

proactive forward error correction · 0.1batch rekeying · 0.1key trees · 0.1key-tree · 0.0proactive FEC · 0.0
YearPublicationVenuePosition
2005 Efficient Group Rekeying Using Application-Layer Multicast
abstract
In secure group communications, there are both rekey and data traffic. We propose to use application-layer multicast to support concurrent rekey and data transport. Rekey traffic is bursty and requires fast delivery. It is desired to reduce rekey bandwidth overhead as much as possible since it competes for bandwidth with data traffic. Towards this goal, we propose a multicast scheme that exploits proximity in the underlying network. We further propose a rekey message splitting scheme to significantly reduce rekey bandwidth overhead at each user access link and network link. We formulate and prove correctness properties for the multicast scheme and rekey message splitting scheme. We have conducted extensive simulations to evaluate our approach. Our simulation results show that our approach can reduce rekey bandwidth overhead from several thousand encrypted new keys (encryptions, in short) to less than ten encryptions for more than 90% of users in a group of 1024 users.
X. Brian Zhang, Simon S. Lam, Huaiyu Liu
ICDCS1
2004 Group rekeying with limited unicast recovery
X. Brian Zhang, Simon S. Lam, Dong-Young Lee
Comput. Networks1
2003 Group rekeying with limited unicast recovery
abstract
In secure group communications, a key server can deliver a group-oriented rekey message [Chung Kei Wong et al., 1998] to a large number of users efficiently using IP multicast. For reliable delivery, Keystone [Chung Kei Wong and Lam, SS, 2000] proposed the use of forward error correction (FEC) in an initial multicast, followed by the use of unicast delivery for users that cannot recover their new keys from the multicast. In this paper, we investigate how to limit unicast recovery to a small fraction /spl gamma/ of the user population. By specifying a very small /spl gamma/, almost all users in the group will receive their new keys within a single multicast round. We present analytic models for deriving /spl gamma/ as a function of the amount of FEC redundant information and the keying interval duration for both Bernoulli and two-state Markov Chain loss models. From our analyses, we conclude that /spl gamma/ decreases roughly at an exponential rate as h increases. we then present a protocol designed to adaptively adjust (h,T) to achieve a specified /spl gamma/. In particular, our protocol chooses from among all feasible (h,T) pairs one with h and T values close to their feasible minima. Our protocol also adapts to an increase in network traffic. Simulation results using ns-2 show that with network congestion our adaptive FEC protocol can still achieve a specified /spl gamma/ by adjusting values of h and T.
X. Brian Zhang, Simon S. Lam, Dong-Young Lee
ICC1
2003 Protocol design for scalable and reliable group rekeying
abstract
We present the design and specification of a protocol for scalable and reliable group rekeying together with performance evaluation results. The protocol is based upon the use of key trees for secure groups and periodic batch rekeying. At the beginning of each rekey interval, the key server sends a rekey message to all users consisting of encrypted new keys (encryptions, in short) carried in a sequence of packets. We present a scheme for identifying keys, encryptions, and users, and a key assignment algorithm that ensures that the encryptions needed by a user are in the same packet. Our protocol provides reliable delivery of new keys to all users eventually. It also attempts to deliver new keys to all users with a high probability by the end of the rekey interval. For each rekey message, the protocol runs in two steps: a multicast step followed by a unicast step. Proactive forward error correction (FEC) multicast is used to reduce delivery latency. Our experiments show that a small FEC block size can be used to reduce encoding time at the server without increasing server bandwidth overhead. Early transition to unicast, after at most two multicast rounds, further reduces the worst-case delivery latency as well as user bandwidth requirement. The key server adaptively adjusts the proactivity factor based upon past feedback information; our experiments show that the number of NACKs after a multicast round can be effectively controlled around a target number. Throughout the protocol design, we strive to minimize processing and bandwidth requirements for both the key server and users.
X. Brian Zhang, Simon S. Lam, Dong-Young Lee, Yang Richard Yang
IEEE/ACM Trans. Netw.1
2001 Reliable group rekeying: a performance analysis
abstract
In secure group communications, users of a group share a common group key. A key server sends the group key to authorized new users as well as performs group rekeying for group users whenever the key changes. In this paper, we investigate scalability issues of reliable group rekeying, and provide a performance analysis of our group key management system (called keygem) based upon the use of key trees. Instead of rekeying after each join or leave, we use periodic batch rekeying to improve scalability and alleviate out-of-sync problems among rekey messages as well as between rekey and data messages. Our analyses show that batch rekeying can achieve large performance gains. We then investigate reliable multicast of rekey messages using proactive FEC. We observe that rekey transport has an eventual reliability and a soft real-time requirement, and that the rekey workload has a sparseness property, that is, each group user only needs to receive a small fraction of the packets that carry a rekey message sent by the key server. We also investigate tradeoffs between server and receiver bandwidth requirements versus group rekey interval, and show how to determine the maximum number of group users a key server can support.
Yang Richard Yang, Xiaozhou Li 0001, X. Brian Zhang, Simon S. Lam
SIGCOMM3