首页> 外文期刊>Computer standards & interfaces >Providing EAP-based Kerberos pre-authentication and advanced authorization for network federations
【24h】

Providing EAP-based Kerberos pre-authentication and advanced authorization for network federations

机译:为网络联合提供基于EAP的Kerberos预身份验证和高级授权

获取原文
获取原文并翻译 | 示例

摘要

Kerberos is a well-known standard protocol which is becoming one of the most widely deployed for authentication and key distribution in application services. However, whereas service providers use the protocol to control their own subscribers, they do not widely deploy Kerberos infrastructures to handle subscribers coming from foreign domains, as happens in network federations. Instead, the deployment of Authentication, Authorization and Accounting (AAA) infrastructures has been preferred for that operation. Thus, the lack of a correct integration between these infrastructures and Kerberos limits the service access only to service provider's subscribers. To avoid this limitation, we design an architecture which integrates a Kerberos pre-authentication mechanism, based on the use of the Extensible Authentication Protocol (EAP), and advanced authorization, based on the standards SAML and XACML, to link the end user authentication and authorization performed through an AAA infrastructure with the delivery of Kerberos tickets in the service provider's domain. We detail the interfaces, protocols, operation and extensions required for our solution. Moreover, we discuss important aspects such as the implications on existing standards.
机译:Kerberos是一种众所周知的标准协议,正在成为在应用程序服务中用于身份验证和密钥分发的最广泛部署的协议之一。但是,尽管服务提供商使用该协议来控制自己的订户,但它们并未像网络联合会那样广泛部署Kerberos基础结构来处理来自外部域的订户。取而代之的是,对于该操作,首选部署身份验证,授权和计费(AAA)基础结构。因此,这些基础结构和Kerberos之间缺乏正确的集成限制了仅对服务提供商的订户的服务访问。为避免此限制,我们设计了一种体系结构,该体系结构基于使用可扩展身份验证协议(EAP)集成了Kerberos预身份验证机制,并基于标准SAML和XACML集成了高级授权,以链接最终用户身份验证和通过AAA基础结构执行授权,并在服务提供商的域中交付Kerberos票证。我们详细介绍了解决方案所需的接口,协议,操作和扩展。此外,我们讨论了重要方面,例如对现有标准的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号