Kerberized credential translation: A solution to Web access control

被引:0
|
作者
Kornievskaia, O [1 ]
Honeyman, P [1 ]
Doster, B [1 ]
Coffman, K [1 ]
机构
[1] Univ Michigan, Ctr Informat Technol Integrat, Ann Arbor, MI 48109 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Kerberos, a widely used network authentication mechanism, is integrated into numerous applications: UNIX and Windows 2000 login, AFS, Telnet, and SSH to name a few. Yet, Web applications rely on SSL to establish authenticated and secure connections. SSL provides strong authentication by using certificates and public key challenge response authentication. The expansion of the Internet requires each system to leverage the strength of the other, which suggests the importance of interoperability between them. This paper describes the design, implementation, and performance of a system that provides controlled access to Kerberized services through a browser. This system provides a single sign-on that produces both Kerberos and public key credentials. The Web server uses a plugin that translates public key credentials to Kerberos credentials. The Web server's subsequent authenticated actions taken on a user's behalf are limited in time and scope, Performance measurements show how the overhead introduced by credential translation is amortized over the login session.
引用
收藏
页码:235 / 249
页数:15
相关论文
共 50 条
  • [21] An Access Control Model for Web Databases
    Bouchahda-Ben Tekaya, Ahlem
    Le Thanh, Nhan
    Bouhoula, Adel
    Labbene-Ayachi, Faten
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXIV, PROCEEDINGS, 2010, 6166 : 287 - +
  • [22] Access control architecture for web services
    Yuan, SJ
    Hu, YF
    GRID AND COOPERATIVE COMPUTING, PT 1, 2004, 3032 : 1004 - 1007
  • [23] An Access Control Framework for the Web of Data
    Sacco, Owen
    Passant, Alexandre
    Decker, Stefan
    TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 456 - 463
  • [24] Towards Web Service access control
    Coetzee, M
    Eloff, JHP
    COMPUTERS & SECURITY, 2004, 23 (07) : 559 - 570
  • [25] Interactive access control for Web Services
    Koshutanski, H
    Massacci, F
    SECURITY AND PROTECTION IN INFORMATION PROCESSING SYSTEMS, 2004, 147 : 151 - 166
  • [26] Embedded role based access control unit for the web document access control
    Shim, WB
    Park, S
    6TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL V, PROCEEDINGS: COMPUTER SCI I, 2002, : 247 - 252
  • [28] Combined Web/mobile authentication for secure Web access control
    Al-Qayedi, A
    Adi, W
    Zahro, A
    Mabrouk, A
    2004 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE, VOLS 1-4: BROADBAND WIRELESS - THE TIME IS NOW, 2004, : 677 - 681
  • [29] WEB ACCESS FOR PEOPLE WITH VISUAL DISABILITY: INCLUSITE® SOLUTION
    Marquez, Sebastian
    Moreno, Frank
    Coret, Javier
    Jimenez, Esteban
    Alcantud, Francisco
    Guarinos, Ignacio
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON INTERACCION PERSONA-ORDENADOR (INTERACCION'12), 2012,
  • [30] SecurOntology: A semantic web access control framework
    Garcia-Crespo, Angel
    Miguel Gomez-Berbis, Juan
    Colomo-Palacios, Ricardo
    Alor-Hernandez, Giner
    COMPUTER STANDARDS & INTERFACES, 2011, 33 (01) : 42 - 49