摘要
文章描述了在Kerberos票据框架中,应用公钥密码体制实现分布式认证的三种方法。分析了三种协议(PKINIT,PKCROSS和PKDA)的不同安全认证过程,找出了它们基于公钥的“把繁重的分布式认证工作分配到通信各方”的共性,实现了一个较Kerberosv5使用范围更广、安全性更强的方法。同时,客户方的隐私一样得到了保护,从而,补充扩展了基于公钥的Kerberos安全认证。
In this work we describe three methods for fully distributed authentication using public key cryptography within the Kerberos ticket framework.By analysing the protocols of PKINIT,PKCROSS and PKDA based on public-key cryptography,we find a way to enhance secerity and scalability in distributed realm as compared to Kerberos V5 by distributing most of the authentication workload away from the trusted intermediary and to the communicating parties. Privacy of Kerberos clients is also enhanced.
出处
《计算机工程与应用》
CSCD
北大核心
2006年第4期121-124,共4页
Computer Engineering and Applications
基金
国家973基础研究规划资助项目(编号:G20000263)