In this note, we show that a proposed secure broadcasting scheme is insecur
e. We also present a modified scheme to overcome this weakness. The modifie
d scheme has the extra advantage that each participant can derive his group
keys from group identities without the need of knowing other information.
(C) 1999 Elsevier Science BV. All rights reserved.