Review of key management technologies for trusted data spaces
Online published: 2026-05-26
Copyright
Trusted data space is a core infrastructure for secure data circulation. With the development of the digital economy, higher security requirements have been put forward for data storage, transmission and sharing in trusted data spaces. Cryptographic technology can provide strong security support for the development of trusted data spaces in terms of distributed deployment, scalability and cross-domain collaboration. Based on a comprehensive review of domestic and foreign research on key management for trusted data spaces, this paper conducts a review from three dimensions: key management architecture and mechanism, key full-life-cycle management, and cross-domain authentication and security negotiation. This paper mainly analyzes hierarchical, distributed and lightweight key mechanisms, as well as key technologies including key update, key escrow and proxy re-encryption, and summarizes the mainstream methods of cross-domain authentication and group key negotiation. Furthermore, the deficiencies of existing researches in dynamic adaptation capability and cross-domain collaboration efficiency are summarized. Finally, the future development directions of trusted data spaces such as adaptive key management and intelligent secure key management are prospected.
Zhang Tao , Liu Zixi , Tian Shuang , Tang Xiangyun , Kang Jiawen , Wu Xuangou , Liu Jiqiang . Review of key management technologies for trusted data spaces[J]. Journal of Cybersecurity, 2026 , 4(3) : 13 -26 . DOI: 10.20172/j.issn.2097-3136.260527
表 1 密钥管理方案对比Table 1 Comparison of key management schemes |
| 方案 | 核心方法 | 计算开销 | 动态扩展性 | 优点 | 局限性 | 适用场景 |
| 文献[17] | 临时主密钥机制 | 低 | 中 | 快速建立链路 | 临时密钥管理需额外设计 | 网络初始化、快速节点接入 |
| 文献[20-21] | 对称密码、哈希动态访问控制 | 中 | 高 | 高效处理动态权限 | 随着层级加深更新延迟增加 | 大型层级结构中的动态访问控制 |
| 文献[27] | 异构传感器分布式密钥管理 | 中 | 高 | 提高复杂网络可扩展性 | 节点协同机制复杂 | 异构无线传感器网络 |
| 文献[29] | 区块链、共识机制 | 高 | 高 | 无需可信第三方,可追溯 | 区块链存储开销大 | 分布式物联网设备认证与密钥管理 |
| 文献[31] | 群组签名、分布式认证 | 中 | 中 | 降低单点认证压力 | 群组管理复杂度高 | 车载自组织网络 |
| 文献[36] | 物理不可克隆函数、阶乘树、中国剩余定理 | 低 | 高 | 群组认证高效 | 依赖硬件设备 | 物联网轻量级群组认证与密钥分发 |
表 2 密钥生命周期管理方案对比Table 2 Comparison of key lifecycle management schemes |
| 方案 | 核心方法 | 计算开销 | 动态扩展性 | 优点 | 缺点 | 适用场景 |
| 文献[41] | 无状态密钥轮换、后量子密码可插拔 | 中 | 高 | 无需集中式状态同步,支持后量子扩展 | 部署验证不充分 | 去中心化身份管理 |
| 文献[45] | 无线信道特征提取、 挑战响应 | 低 | 中 | 抗重放攻击,无需可信第三方 | 依赖信道环境 | 物联网无线密钥协商 |
| 文献[46] | 多子载波相位差 密钥生成 | 低 | 中 | 随机性与稳定性高,轻量级 | 对多径环境敏感 | 物联网、车联网物理层安全 |
| 文献[49] | 平台安全架构模型 | 中 | 中 | 硬件层实现密钥保护,提升安全性 | 依赖特定硬件平台 | 物联网设备 |
| 文献[52] | 移动边缘计算 | 高 | 高 | 去中心化存储与可审计,边缘协同提升密钥分发效率 | 区块链存储开销大 | 移动服务场景 |
| 文献[57] | 可问责代理重加密 | 中 | 中 | 提高代理节点可审计性,抗共谋 | 问责机制增加额外 计算开销 | 需审计的数据共享 |
| 文献[58] | 抗数据泄露的代理 重加密 | 中 | 高 | 抵抗算法替换攻击,计算、存储成本低 | 算法复杂度较高 | 不可信云环境下的物联网数据共享 |
| 文献[63] | 无证书阈值代理重加密 | 高 | 高 | 可抵御串谋攻击和数据篡改 | 云链协同机制复杂 | 工业互联网 |
表 3 跨域认证技术代表性方案对比Table 3 Comparison of representative cross-domain authentication schemes |
| 1 |
白玉真, 贾轩, 王思源, 等. 数据流通利用设施关键技术与建设路径研究[J]. 信息通信技术与政策, 2025, 51 (4): 34- 39.
Bai Y Z, Jia X, Wang S Y, et al. Research on key technologies and construction paths of data circulation and utilization facilities[J]. Information and Communications Technology and Policy, 2025, 51 (4): 34- 39.
|
| 2 |
李恒, 李凤华, 史欣怡, 等. 面向数据跨域安全流通的访问控制研究综述[J]. 通信学报, 2025, 46 (4): 238- 254.
Li H, Li F H, Shi X Y, et al. Research on access control for secure cross-domain data circulation[J]. Journal on Communications, 2025, 46 (4): 238- 254.
|
| 3 |
Singh A K, Sánchez M O, Caparros M G, et al. A security analysis of European data space architectures[J]. Data Science and Engineering, 2025, 10 (3): 455- 472.
|
| 4 |
Costagliola A R, Mazzocca C, Bujari A, et al. VESPACE: a verifiable blockchain-based data space solution to empower the data economy[J]. Computer Communications, 2025, 239, 108180.
|
| 5 |
Liao Y Q, Kong X G, Yin L, et al. A trusted industrial data space for automotive supply chain (TIDS-ASC): enabling secure and traceable data sharing[J]. Information Processing & Management, 2026, 63 (5): 104710.
|
| 6 |
Ghaffari F, Bertin E, Crespi N, et al. Distributed ledger technologies for authentication and access control in networking applications: a comprehensive survey[J]. Computer Science Review, 2023, 50, 100590.
|
| 7 |
Kharjana M, Pohrmen F H, Sahana S C, et al. Blockchain-based key management system in named data networking: a survey[J]. Journal of Network and Computer Applications, 2023, 220, 103732.
|
| 8 |
Badirova A, Dabbaghi S, Moghaddam F F, et al. A survey on identity and access management for cross-domain dynamic users: issues, solutions, and challenges[J]. IEEE Access, 2023, 11, 61660- 61679.
|
| 9 |
Alsheavi A N, Hawbani A, Othman W, et al. IoT authentication protocols: challenges, and comparative analysis[J]. ACM Computing Surveys, 2025, 57 (5): 1- 43.
|
| 10 |
Yoon S, Han S, Hwang E. Joint heterogeneous PUF-based security-enhanced IoT authentication[J]. IEEE Internet of Things Journal, 2023, 10 (20): 18082- 18096.
|
| 11 |
Wang C Y, Wang D, Duan Y H, et al. Secure and lightweight user authentication scheme for cloud-assisted Internet of Things[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 2961- 2976.
|
| 12 |
Bhuva D R, Kumar S. A novel continuous authentication method using biometrics for IOT devices[J]. Internet of Things, 2023, 24, 100927.
|
| 13 |
Sivaselvan N, Bhat K V, Rajarajan M, et al. A new scalable and secure access control scheme using blockchain technology for IoT[J]. IEEE Transactions on Network and Service Management, 2023, 20 (3): 2957- 2974.
|
| 14 |
Saleem M A, Li X, Mahmood K, et al. Secure RFID-assisted authentication protocol for vehicular cloud computing environment[J]. IEEE Transactions on Intelligent Transportation Systems, 2024, 25 (9): 12528- 12537.
|
| 15 |
Akram W, Mahmood K, Li X, et al. An energy-efficient and secure identity based RFID authentication scheme for vehicular cloud computing[J]. Computer Networks, 2022, 217, 109335.
|
| 16 |
OASIS Standard. Key management interoperability protocol (KMIP) version 3.0[S/OL]. [2026-01-12]. https://docs.oasis-open.org/kmip/kmip-spec/v3.0/csd01/kmip-spec-v3.0-csd01.pdf
|
| 17 |
Gandino F, Ferrero R, Montrucchio B, et al. Fast hierarchical key management scheme with transitory master key for wireless sensor networks[J]. IEEE Internet of Things Journal, 2016, 3 (6): 1334- 1345.
|
| 18 |
Najafi Z, Babaie S. A lightweight hierarchical key management approach for internet of things[J]. Journal of Information Security and Applications, 2023, 75, 103485.
|
| 19 |
Yu F R, Tang H, Mason P C, et al. A hierarchical identity based key management scheme in tactical mobile ad hoc networks[J]. IEEE Transactions on Network and Service Management, 2010, 7 (4): 258- 267.
|
| 20 |
Lo J W, Hwang M S, Liu C H. An efficient key assignment scheme for access control in a large leaf class hierarchy[J]. Information Sciences, 2011, 181 (4): 917- 925.
|
| 21 |
Odelu V, Das A K, Goswami A. A secure effective key management scheme for dynamic access control in a large leaf class hierarchy[J]. Information Sciences, 2014, 269, 270- 285.
|
| 22 |
Ragab H H, Bettahar H, Bouadbdallah A, et al. An efficient key management scheme for content access control for linear hierarchies[J]. Computer Networks, 2012, 56 (8): 2107- 2118.
|
| 23 |
Xu C, Ren W, Yu L C, et al. A hierarchical encryption and key management scheme for layered access control on H. 264/SVC bitstream in the Internet of Things[J]. IEEE Internet of Things Journal, 2020, 7 (9): 8932- 8942.
|
| 24 |
Abu A O, Qatawneh M, Almobaideen W, et al. A new hierarchical architecture and protocol for key distribution in the context of IoT-based smart cities[J]. Journal of Information Security and Applications, 2022, 67, 103173.
|
| 25 |
Kokoris K E, Malkhi D, Spiegelman A. Asynchronous distributed key generation for computationally-secure randomness, consensus, and threshold signatures[C]//Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2020: 1751-1767.
|
| 26 |
Das S, Xiang Z, Kokoris K L, et al. Practical asynchronous high-threshold distributed key generation and distributed polynomial sampling[C]//32nd USENIX Security Symposium (USENIX Security 23). 2023: 5359-5376.
|
| 27 |
Lu K J, Qian Y, Guizani M, et al. A framework for a distributed key management scheme in heterogeneous wireless sensor networks[J]. IEEE Transactions on Wireless Communications, 2008, 7 (2): 639- 647.
|
| 28 |
Xi W, Duan M C, Bai X X, et al. KEEP: secure and efficient communication for distributed IoT devices[J]. IEEE Internet of Things Journal, 2021, 8 (16): 12758- 12770.
|
| 29 |
Panda S S, Jena D, Mohanta B K, et al. Authentication and key management in distributed IoT using blockchain technology[J]. IEEE Internet of Things Journal, 2021, 8 (16): 12947- 12954.
|
| 30 |
De R M, Mantas G, Rodriguez J, et al. DECENT: decentralized and efficient key management to secure communication in dense and dynamic environments[J]. IEEE Transactions on Intelligent Transportation Systems, 2023, 24 (7): 7586- 7598.
|
| 31 |
Hao Y, Cheng Y, Zhou C, et al. A distributed key management framework with cooperative message authentication in VANETs[J]. IEEE Journal on Selected Areas in Communications, 2011, 29 (3): 616- 629.
|
| 32 |
Al A M, Hashim F, Jahari Hashim S, et al. Hierarchical blockchain structure for node authentication in IoT networks[J]. Egyptian Informatics Journal, 2022, 23 (2): 345- 361.
|
| 33 |
Raza S, Seitz L, Sitenkov D, et al. S3K: scalable security with symmetric keys: DTLS key establishment for the internet of things[J]. IEEE Transactions on Automation Science and Engineering, 2016, 13 (3): 1270- 1280.
|
| 34 |
Dammak M, Senouci S M, Messous M A, et al. Decentralized lightweight group key management for dynamic access control in IoT environments[J]. IEEE Transactions on Network and Service Management, 2020, 17 (3): 1742- 1757.
|
| 35 |
Gupta M, Kumar B S. Lightweight secure session key protection, mutual authentication, and access control (LSSMAC) for WBAN-assisted IoT network[J]. IEEE Sensors Journal, 2023, 23 (17): 20283- 20293.
|
| 36 |
Yildiz H, Cenk M, Onur E. PLGAKD: a PUF-based lightweight group authentication and key distribution protocol[J]. IEEE Internet of Things Journal, 2021, 8 (7): 5682- 5696.
|
| 37 |
Wazid M, Das A K, Odelu V, et al. Design of secure user authenticated key management protocol for generic IoT networks[J]. IEEE Internet of Things Journal, 2018, 5 (1): 269- 282.
|
| 38 |
Benmalek M. SEKM-IoT: secure and efficient key management for dynamic access control in smart IoT systems[C]//Proceedings of the 2024 IEEE 21st International Conference on Smart Communities: Improving Quality of Life using AI, Robotics and IoT (HONET). Piscataway: IEEE Press, 2024: 97-102.
|
| 39 |
Guo D K, Cao K, Xiong J, et al. A lightweight key generation scheme for the Internet of Things[J]. IEEE Internet of Things Journal, 2021, 8 (15): 12137- 12149.
|
| 40 |
蒋京玮, 汪定, 张国印, 等. 面向移动边缘计算的密钥管理协议[J]. 计算机学报, 2022, 45 (6): 1348- 1372.
Jiang J W, Wang D, Zhang G Y, et al. Private key management scheme for mobile edge computing[J]. Chinese Journal of Computers, 2022, 45 (6): 1348- 1372.
|
| 41 |
Wang J S. A single-root, multi-curve, context-isolated, pqc-pluggable cryptographic identity primitive with stateless secret rotation[PP]. arXiv preprint arXiv: 2511.20505, 2025.
|
| 42 |
Tan Z W, Bao Y T, Tan Y, et al. Attribute-based weight exchange with direct revocation mechanism for fine-grained data sharing[J]. IEEE Transactions on Dependable and Secure Computing, 2026, 23 (3): 6602- 6619.
|
| 43 |
Li Y F, Xu Y J, Zhang G Q, et al. HIPCAM: data stream-driven group key management for in-vehicle network with seamless key updates[J/OL]. IEEE Transactions on Vehicular Technology, 2026. DOI: 10.1109/TVT.2026.3660852.
|
| 44 |
Kajita K, Emura K, Ogawa K, et al. CGKA-FA: secure and flexible group key agreement with authentication update[J]. Journal of Information Processing, 2026, 34, 294- 308.
|
| 45 |
Huan X T, Miao K T, Chen W, et al. Kerra: an Internet of Things wireless key generation resistant to replay attacks[J]. IEEE Internet of Things Journal, 2024, 11 (17): 29035- 29048.
|
| 46 |
Yuan X W, Jiang Y, Li G Y, et al. Wireless channel key generation based on multisubcarrier phase difference[J]. IEEE Internet of Things Journal, 2024, 11 (20): 32939- 32955.
|
| 47 |
Yang H Q, Xu W T. LLMKey: LLM-powered wireless key generation scheme for next-gen IoV systems[C]//Proceedings of the IEEE INFOCOM 2025 - IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS). Piscataway: IEEE Press, 2025: 1-6.
|
| 48 |
Ghosal A, Conti M. Key management systems for smart grid advanced metering infrastructure: a survey[J]. IEEE Communications Surveys & Tutorials, 2019, 21 (3): 2831- 2848.
|
| 49 |
Jung J, Kim B, Cho J, et al. A secure platform model based on ARM platform security architecture for IoT devices[J]. IEEE Internet of Things Journal, 2022, 9 (7): 5548- 5560.
|
| 50 |
Yang J R, Chen S, Cao Y. A PUF-based key storage scheme using fuzzy vault[J]. Sensors, 2023, 23 (7): 3476.
|
| 51 |
Prabhu K B, Ganapathy S. A secured storage and privacy-preserving model using CRT for providing security on cloud and IoT-based applications[J]. Computer Networks, 2019, 151, 181- 190.
|
| 52 |
Li J X, Wu J G, Chen L, et al. Blockchain-based secure key management for mobile edge computing[J]. IEEE Transactions on Mobile Computing, 2023, 22 (1): 100- 114.
|
| 53 |
Zhao H W, Bai P D, Peng Y, et al. Efficient key management scheme for health blockchain[J]. CAAI Transactions on Intelligence Technology, 2018, 3 (2): 114- 118.
|
| 54 |
Jiang J W, Wang D, Zhang G Y. QPause: quantum-resistant password-protected data outsourcing for cloud storage[J]. IEEE Transactions on Services Computing, 2024, 17 (3): 1140- 1153.
|
| 55 |
Qin Z G, Xiong H, Wu S K, et al. A survey of proxy re-encryption for secure data sharing in cloud computing[J]. IEEE Transactions on Services Computing, 2016, (99): 1.
|
| 56 |
Nuñez D, Agudo I, Lopez J. Proxy re-encryption: analysis of constructions and its application to secure access delegation[J]. Journal of Network and Computer Applications, 2017, 87, 193- 209.
|
| 57 |
Guo H, Zhang Z F, Xu J, et al. Accountable proxy re-encryption for secure data sharing[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 18 (1): 145- 159.
|
| 58 |
Zhou Y Y, Zhao L, Li F G, et al. Exfiltration-resistant proxy re-encryption for IoT data sharing in unreliable clouds[J]. IEEE Transactions on Dependable and Secure Computing, 2025, 22 (4): 4070- 4085.
|
| 59 |
Pan G L, Tan H W, Zheng W Y, et al. Three-factor authentication and key agreement protocol with collusion resistance in VANETs[J]. Journal of Information Security and Applications, 2025, 90, 104029.
|
| 60 |
Agyekum K O, Xia Q, Sifah E B, et al. A proxy re-encryption approach to secure data sharing in the internet of things based on blockchain[J]. IEEE Systems Journal, 2022, 16 (1): 1685- 1696.
|
| 61 |
Ahsan M, An B, Kanhere S S, et al. Proxy re-encryption enabled secure and anonymous IoT data sharing platform based on blockchain[J]. Journal of Network and Computer Applications, 2020, 176 (prepublish): 102917.
|
| 62 |
Liu T, Zhang L, Kan H B, Zhang J H. Publicly verifiable threshold proxy re-encryption and its application in data rights confirmation[EB/OL]. Cryptology ePrint Archive, 2025. https://eprint.kobi.one/2025/345.pdf.
|
| 63 |
Feng J Y, Li Y, Wang T, et al. A certificateless threshold proxy re-encrypted data-sharing scheme with cloud-chain collaboration in industrial internet environments[J]. IEEE Internet of Things Journal, 2024, 11 (20): 33247- 33268.
|
| 64 |
Luo C Y. Distributed cross-domain anonymous authentication scheme in internet of things[J]. IEEE Internet of Things Journal, 2025, 12 (13): 24710- 24721.
|
| 65 |
Cui J, Liu N, Zhang Q Y, et al. Efficient and anonymous cross-domain authentication for IIoT based on blockchain[J]. IEEE Transactions on Network Science and Engineering, 2023, 10 (2): 899- 910.
|
| 66 |
Tong F, Chen X, Wang K M, et al. CCAP: a complete cross-domain authentication based on blockchain for Internet of Things[J]. IEEE Transactions on Information Forensics and Security, 2022, 17, 3789- 3800.
|
| 67 |
Shen M, Liu H S, Zhu L H, et al. Blockchain-assisted secure device authentication for cross-domain industrial IoT[J]. IEEE Journal on Selected Areas in Communications, 2020, 38 (5): 942- 954.
|
| 68 |
Zhang Y, Li B, Wu J X, et al. Efficient and privacy-preserving blockchain-based multifactor device authentication protocol for cross-domain IIoT[J]. IEEE Internet of Things Journal, 2022, 9 (22): 22501- 22515.
|
| 69 |
Hou D K, Zhang J. Blockchain assisted cross-domain key management for seaminglessly secure metaverse[J]. Blockchain: Research and Applications, 2026: 100460.
|
| 70 |
Chen J, Zhan Z Y, He K, et al. XAuth: efficient privacy-preserving cross-domain authentication[J]. IEEE Transactions on Dependable and Secure Computing, 2022, 19 (5): 3301- 3311.
|
| 71 |
王菲菲, 汪定. 基于雾计算的智能医疗三方认证与密钥协商协议[J]. 软件学报, 2023, 34 (7): 3272- 3291.
Wang F F, Wang D. Fog computing-based three-party authentication and key agreement protocol for smart healthcare[J]. Journal of Software, 2023, 34 (7): 3272- 3291.
|
| 72 |
Pérez G J C, Braeken A, Benslimane A. Blockchain-based group key management scheme for IoT with anonymity of group members[J]. IEEE Transactions on Information Forensics and Security, 2024, 19, 6709- 6721.
|
| 73 |
Ali K M, Kouicem D E, Doudou M, et al. A decentralized blockchain-based key management protocol for heterogeneous and dynamic IoT devices[J]. Computer Communications, 2022, 191, 11- 25.
|
| 74 |
Wei L, Cui J, Zhong H, et al. A decentralized authenticated key agreement scheme based on smart contract for securing vehicular ad-hoc networks[J]. IEEE Transactions on Mobile Computing, 2024, 23 (5): 4318- 4333.
|
| 75 |
Naresh V S, Allavarpu V V, Reddi S. Provably secure blockchain privacy-preserving smart contract centric dynamic group key agreement for large WSN[J]. The Journal of Supercomputing, 2022, 78 (6): 8708- 8732.
|
| 76 |
Zhou T, Hong S, Shen J, et al. An efficient iTreeKEM-based group key agreement protocol for flying ad-hoc networks[J]. IEEE Transactions on Mobile Computing, 2025.
|
| 77 |
Tan H, Fang C, Shen J, et al. Cross-domain heterogeneous data aggregation with dynamic group key agreement for hybrid satellite networks[J]. IEEE Transactions on Dependable and Secure Computing, 2026, 23 (3): 4830- 4844.
|
| 78 |
Braeken A. Pairing free asymmetric group key agreement protocol[J]. Computer Communications, 2022, 181, 267- 273.
|
/
| 〈 |
|
〉 |