Kerberized credential translation: A solution to Web access control

被引:0
|
作者
Kornievskaia, O [1 ]
Honeyman, P [1 ]
Doster, B [1 ]
Coffman, K [1 ]
机构
[1] Univ Michigan, Ctr Informat Technol Integrat, Ann Arbor, MI 48109 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Kerberos, a widely used network authentication mechanism, is integrated into numerous applications: UNIX and Windows 2000 login, AFS, Telnet, and SSH to name a few. Yet, Web applications rely on SSL to establish authenticated and secure connections. SSL provides strong authentication by using certificates and public key challenge response authentication. The expansion of the Internet requires each system to leverage the strength of the other, which suggests the importance of interoperability between them. This paper describes the design, implementation, and performance of a system that provides controlled access to Kerberized services through a browser. This system provides a single sign-on that produces both Kerberos and public key credentials. The Web server uses a plugin that translates public key credentials to Kerberos credentials. The Web server's subsequent authenticated actions taken on a user's behalf are limited in time and scope, Performance measurements show how the overhead introduced by credential translation is amortized over the login session.
引用
收藏
页码:235 / 249
页数:15
相关论文
共 50 条
  • [41] Modeling and Implementing the System of Access Control On the Web
    Xu, Chungen
    Gong, Sheng
    PROCEEDINGS OF FIRST INTERNATIONAL CONFERENCE OF MODELLING AND SIMULATION, VOL II: MATHEMATICAL MODELLING, 2008, : 390 - 394
  • [42] Usable access control for the world wide web
    Balfanz, D
    19TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2003, : 406 - 415
  • [43] An adaptive access control model for Web services
    Bertino, Elisa
    Squicciarini, Anna C.
    Martino, Lorenzo
    Paci, Federica
    INTERNATIONAL JOURNAL OF WEB SERVICES RESEARCH, 2006, 3 (03) : 27 - 60
  • [44] A role based access control for Web services
    Wonohoesodo, R
    Tari, Z
    2004 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2004, : 49 - 56
  • [45] Access Control and Collaborative Authoring on the Semantic Web
    Moll, V.
    Wilges, B.
    Bastos, R. C.
    IEEE LATIN AMERICA TRANSACTIONS, 2012, 10 (01) : 1251 - 1255
  • [46] Query rewriting for access control on semantic web
    Li, Jian
    Cheung, William K.
    SECURE DATA MANAGEMENT, PROCEEDINGS, 2008, 5159 : 151 - 168
  • [47] Access Control Model for Composite Web Services
    Jiang, Huangqin
    Zhang, Hongqi
    PROCEEDINGS OF 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY, 2012, : 684 - 688
  • [48] ACMW: Access Control Model on Web Environment
    Elsheikh, Selma
    WCECS 2008: WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, 2008, : 744 - 748
  • [49] Specification of access control policies for web services
    Liu, Miao
    Zhang, Wei
    Liu, Huai-Liang
    CIS WORKSHOPS 2007: INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY WORKSHOPS, 2007, : 472 - 475
  • [50] Applying the semantic web layers to access control
    Yagüe, MI
    Maña, A
    López, J
    Troya, JM
    14TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2003, : 622 - 626