• DocumentCode
    1124785
  • Title

    Public-key cryptography extensions into Kerberos

  • Author

    Downnard, Ian

  • Volume
    21
  • Issue
    5
  • fYear
    2003
  • Firstpage
    30
  • Lastpage
    34
  • Abstract
    How can and why should the Kerberos authentication standard (RFC1510) be extended to support public-key cryptography? These are the questions that we explore in this article. Integrating public-key cryptography (PKC) within Kerberos shares the leading edge of proposed enhancements to the traditional Kerberos standard with initiatives like IPv6 support and hardware authentication via smart-cards. The benefits of PKC will improve scalability and security throughout the Kerberos framework. Although this enhancement has not yet completed the Internet Standards Process (RFC 2026), it has already been adopted by some companies in their products. We begin with overviews of PKC, and then discuss what improvements PKC can offer to Kerberos. After summarizing three different protocols for public-key enhanced Kerberos, we explain the performance penalties associated with PKC and reference qualitative results from other research which compares the response-time performance of the two fundamental approaches we describe for public-key based authentication. Finally, we look at some of the security issues associated with including public-key support in the traditional Kerberos framework.
  • Keywords
    code standards; message authentication; public key cryptography; telecommunication security; telecommunication standards; transport protocols; IPv6; Internet standards process; Kerberos authentication standard; RFC1510; hardware authentication; performance penalties; public-key cryptography extensions; public-key enhanced Kerberos; public-key support; research; response-time performance; scalability; security; smart-cards; Authentication; Data security; Databases; Elliptic curve cryptography; Identity-based encryption; Master-slave; Network servers; Public key; Public key cryptography; Workstations;
  • fLanguage
    English
  • Journal_Title
    Potentials, IEEE
  • Publisher
    ieee
  • ISSN
    0278-6648
  • Type

    jour

  • DOI
    10.1109/MP.2002.1166623
  • Filename
    1166623