首页> 外文会议>European Symposium on Research in Computer Security >A Browser-Based Kerberos AuthenticationScheme
【24h】

A Browser-Based Kerberos AuthenticationScheme

机译:基于浏览器的Kerberos身份认证化学

获取原文

摘要

When two players wish to share a security token (e.g., forthe purpose of authentication and accounting), they call a trusted thirdparty. This idea is the essence of Kerberos protocols, which are widelydeployed in a large scale of computer networks. Browser-based Kerberosprotocols are the derivates with the exception that the Kerberos clientapplication is a commodity Web browser. Whereas the native Kerberosprotocol has been repeatedly peer-reviewed without finding flaws, thehistory of browser-based Kerberos protocols is tarnished with negativeresults due to the fact that subtleties of browsers have been disregarded.We propose a browser-based Kerberos protocol based on client certifi-cates and prove its security in the extended formal model for browser-based mutual authentication introduced at ACM ASIACCS08.
机译:当两个玩家希望分享安全令牌时(例如,验证和会计的目的),他们称之为值得信赖的第三部分。这个想法是Kerberos协议的本质,它以大规模的计算机网络广泛地运送。基于浏览器的KerberosProtocols是衍生的例外,异常kerberos客户端应用程序是商品Web浏览器。虽然本机KerberosProtocol在没有发现缺陷的情况下重复进行对等审查,但是基于浏览器的Kerberos协议的History由于浏览器的微妙之处被忽略了,而基于浏览器的Kerberos协议被玷污。我们提出了一种基于客户端证书的基于浏览器的Kerberos协议 - 在ACM AsiaCCS08引入的基于浏览器的相互身份验证的扩展正式模型中的安全性并证明了其安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号