Kerberized credential translation: A solution to Web access control

被引:0
|
作者
Kornievskaia, O [1 ]
Honeyman, P [1 ]
Doster, B [1 ]
Coffman, K [1 ]
机构
[1] Univ Michigan, Ctr Informat Technol Integrat, Ann Arbor, MI 48109 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Kerberos, a widely used network authentication mechanism, is integrated into numerous applications: UNIX and Windows 2000 login, AFS, Telnet, and SSH to name a few. Yet, Web applications rely on SSL to establish authenticated and secure connections. SSL provides strong authentication by using certificates and public key challenge response authentication. The expansion of the Internet requires each system to leverage the strength of the other, which suggests the importance of interoperability between them. This paper describes the design, implementation, and performance of a system that provides controlled access to Kerberized services through a browser. This system provides a single sign-on that produces both Kerberos and public key credentials. The Web server uses a plugin that translates public key credentials to Kerberos credentials. The Web server's subsequent authenticated actions taken on a user's behalf are limited in time and scope, Performance measurements show how the overhead introduced by credential translation is amortized over the login session.
引用
收藏
页码:235 / 249
页数:15
相关论文
共 50 条
  • [1] A Credential and Encryption Based Access Control Solution for Named Data Networking
    Hamdane, Balkis
    El Fatmi, Sihem Guemara
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 1234 - 1237
  • [2] Policy Architecture for Credential Based Access Control in Open Access Environment
    Dagdee, Nirmal
    Vijaywargiya, Ruchi
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2011, 6 (01): : 39 - 47
  • [3] A cross-layer SSO solution for federating access to kerberized services in the eduroam/DAMe network
    Perez-Mendez, Alejandro
    Pereniguez-Garcia, Fernando
    Marin-Lopez, Rafael
    Lopez-Millan, Gabriel
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2012, 11 (06) : 365 - 388
  • [4] A cryptographic credential based access control mechanism for industrial control system
    Shi, Sha
    Wen, Qiaoyan
    International Journal of Advancements in Computing Technology, 2012, 4 (07) : 152 - 158
  • [5] Anonymous Credential-Based Access Control Scheme for Clouds
    Yao, Xuanxia
    Liu, Hong
    Ning, Huansheng
    Yang, Laurence T.
    Xiang, Yang
    IEEE CLOUD COMPUTING, 2015, 2 (04): : 34 - 43
  • [6] Modern Credential Access Control Approach Based On Pseudonymous Signature
    Ahmad, Faiz
    Jalnekar, Rajesh
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2007, 7 (10): : 129 - 134
  • [7] Clustering subjects in a credential-based access control framework
    Stoupa, K.
    Vakali, A.
    COMPUTERS & SECURITY, 2007, 26 (02) : 120 - 129
  • [8] A cross-layer SSO solution for federating access to kerberized services in the eduroam/DAMe network
    Alejandro Pérez-Méndez
    Fernando Pereñíguez-García
    Rafael Marín-López
    Gabriel López-Millán
    International Journal of Information Security, 2012, 11 : 365 - 388
  • [9] Constraining Credential Usage in Logic-Based Access Control
    Bauer, Lujo
    Jia, Limin
    Sharma, Divya
    2010 23RD IEEE COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSF), 2010, : 154 - 168
  • [10] Extending XACML to support credential based hybrid Access: Control
    Dagdee, Nirmal
    Vijaywargiya, Ruchi
    International Journal of Computer Science Issues, 2011, 8 (6 6-1): : 204 - 211