作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (20): 150-152. doi: 10.3969/j.issn.1000-3428.2010.20.052

• 安全技术 • 上一篇    下一篇

无证书密钥协商协议对跨域Kerberos的改进

陈家琪,冯 俊,郝 妍   

  1. (上海理工大学光电信息与计算机工程学院,上海 200093)
  • 出版日期:2010-10-20 发布日期:2010-10-18
  • 作者简介:陈家琪(1957-),男,教授,主研方向:网络与信息安全,计算机控制系统;冯 俊、郝 妍,硕士研究生

Improvement of Cross-realm Kerberos with Certificateless Key Agreement Protocol

CHEN Jia-qi, FENG Jun, HAO Yan   

  1. (School of Optical-Electrical and Computer Engineering, University of Shanghai for Science and Technology, Shanghai 200093, China)
  • Online:2010-10-20 Published:2010-10-18

摘要: 针对Kerberos域间认证方案中存在的密钥数量庞大和系统安全性脆弱等问题,提出一种可认证的无证书密钥协商协议。该协议通过无证书密码学理论弥补原Kerberos域间认证的缺陷,只需一轮消息交换即可建立安全的域间会话密钥,并提供完善的前向安全性。安全性分析结果表明,改进的协议可以有效解决密钥的管理问题及第三方无举证窃听。

关键词: Kerberos协议, 域间认证, 密钥协商, 无证书密码学

Abstract: In order to solve the problems of enormous keys in Kerberos inter-realm authentication, an authenticated certificateless key agreement protocol is proposed. It can overcome the limitations of original Kerberos authentication. It builds a security inter-realm session key only with one round message exchange, and it provides perfect forward secrecy. Security analysis result shows that the improved protocol can solve key management problem and the interception which can not be proved, and it makes the system more secure.

Key words: Kerberos protocol, inter-realm authentication, key agreement, certificateless cryptography

中图分类号: