高级检索

    网络和分布式系统中的认证

    AUTHENTICATION IN NETWORK AND DISTRIBUTED SYSTEMS

    • 摘要: 文中在Kerberos认证协议的基础上,采用Yaksha体制,提出了一个公钥密码交互式认证体制.体制中由用户产生的时戳代替一次性随机数解决时间同步问题,以联网初始化协议代替键入口令,从而克服了Kerberos的某些局限性,可安全可靠、高速地通信.本体制可有效地防止口令猜测和重放攻击,并简化了密钥管理和存储.

       

      Abstract: Based on Kerberos protocol,a novel authentication system is presented using Yaksha security system,which overcomes several limitations of Kerberos.In this system the public key cryptosystem is used to authenticate and exchange session keys mutually.In addition,timestamps produced by the user,instead of nonces,are employed to solve the problem of time synchronization,and password scheme is replaced by initialization protocol.High security and speed can be obtained,guessing password attack and replay attack can be prevented effectively ,and the problem of key management and storage is simplified.

       

    /

    返回文章
    返回