XKDCP: An Inter-KDC Protocol for Dependable Kerberos Cross-Realm Operations
نویسندگان
چکیده
The wide popularity of Kerberos made it the de-facto standard for authentication in enterprise networks. Moreover, the lightweight nature of Kerberos makes it a candidate of choice for securing network communications in emerging non-enterprise information systems such as industrial control networks, building automation and intelligent transportation systems. Many of these potential applications of Kerberos involve infrastructures characterized by their large scale and strict dependability requirements. However, such requirements may not be met when crossrealm Kerberos operations are involved. In this paper, we outline the issues with the current Kerberos crossrealm model and present XKDCP (Inter Key Distribution Center Protocol), a new Kerberos cross-realm authentication model that improves on scalability and dependability by (1) relying on public key cryptography to dynamically maintain direct trust relationships between Kerberos realms and (2) adopting a proxy model to offload inter-domain exchanges and processing from the low-end devices to the Kerberos authentication servers.
منابع مشابه
RFC 6806 KDC Referrals
This memo documents a method for a Kerberos Key Distribution Center (KDC) to respond to client requests for Kerberos tickets when the client does not have detailed configuration information on the realms of users or services. The KDC will handle requests for principals in other realms by returning either a referral error or a cross-realm Ticket-Granting Ticket (TGT) to another realm on the refe...
متن کاملKerberos Working Group
The draft documents a method for a Kerberos Key Distribution Center (KDC) to respond to client requests for Kerberos tickets when the client does not have detailed configuration information on the realms of users or services. The KDC will handle requests for principals in other realms by returning either a referral error or a cross-realm TGT to another realm on the referral path. The clients wi...
متن کاملA Network Authentication Protocol Based on Kerberos
We will focus on cryptographic protocols intended to achieve authentication over the networks. We aim to design a user authentication protocol that is not susceptible to password guessing attacks. We will present an authentication protocol based on the widely deployed Kerberos protocol with a little modification in the Kerberos database. The proposed protocol will be independent of the user pas...
متن کاملKerberos Interoperability Issues
MIT’s computing environment is a heterogeneous environment that has used Kerberos as a primary authentication method for over a decade. Instead of migrating our existing KDCs to Windows 2000 we have chosen to use cross realm trust to support our Windows 2000 computing environment. During our deployment project we have encountered some interoperability problems and have worked with Microsoft to ...
متن کاملImplementation of Crossrealm Referral Handling in the MIT Kerberos Client
The Windows 2000 Kerberos implementation [1, 2] uses a di erent approach to solve the Kerberos realm resolution problem than has traditionally been used by MIT Kerberos implementations. In this paper, we present the details of the two approaches and compare them. To facilitate more e ective use of the Kerberos ticket cache, we propose a new format for referral data that includes a list of alias...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- JNW
دوره 8 شماره
صفحات -
تاریخ انتشار 2013