Specifying Kerberos over EAP: Towards an integrated network access and Kerberos single sign-on process

Saber Zrelli, Y. Shinoda
{"title":"Specifying Kerberos over EAP: Towards an integrated network access and Kerberos single sign-on process","authors":"Saber Zrelli, Y. Shinoda","doi":"10.1109/AINA.2007.130","DOIUrl":null,"url":null,"abstract":"Kerberos is a widely deployed authentication system used for authenticating users to various types of application services in open networks. Network access on the other hand is a service that is generally handled separately using authentication frameworks based on the extensible authentication protocol (EAP). The EAP protocol specified by the IETF in RFC3748 is well on its way to becoming an industry standard for network access control. It provides an extensible, link layer agnostic protocol for carrying various authentication methods. In this paper, we design the integration of the Kerberos protocol as an authentication method in existing EAP-based authentication frameworks. We define the architectural elements and their interactions, then we specify the encapsulation of Kerberos messages in EAP packets. The use of Kerberos as an EAP authentication mechanism allows institutions managing their individuals using a Kerberos system to re-use the same credentials for network access authentication instead of managing a different set of credentials such as Unix passwords or public key certificates. Moreover, the proposed framework allows users to sign-on in the network as a consequence of successful network access authentication, eliminating the need for additional login procedures necessary for accessing application services.","PeriodicalId":361109,"journal":{"name":"21st International Conference on Advanced Information Networking and Applications (AINA '07)","volume":"271 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-05-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"21st International Conference on Advanced Information Networking and Applications (AINA '07)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/AINA.2007.130","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14

Abstract

Kerberos is a widely deployed authentication system used for authenticating users to various types of application services in open networks. Network access on the other hand is a service that is generally handled separately using authentication frameworks based on the extensible authentication protocol (EAP). The EAP protocol specified by the IETF in RFC3748 is well on its way to becoming an industry standard for network access control. It provides an extensible, link layer agnostic protocol for carrying various authentication methods. In this paper, we design the integration of the Kerberos protocol as an authentication method in existing EAP-based authentication frameworks. We define the architectural elements and their interactions, then we specify the encapsulation of Kerberos messages in EAP packets. The use of Kerberos as an EAP authentication mechanism allows institutions managing their individuals using a Kerberos system to re-use the same credentials for network access authentication instead of managing a different set of credentials such as Unix passwords or public key certificates. Moreover, the proposed framework allows users to sign-on in the network as a consequence of successful network access authentication, eliminating the need for additional login procedures necessary for accessing application services.
通过EAP指定Kerberos:实现集成的网络访问和Kerberos单点登录过程
Kerberos是一种广泛部署的身份验证系统,用于对开放网络中各种类型的应用程序服务的用户进行身份验证。另一方面,网络访问是一种服务,通常使用基于可扩展身份验证协议(EAP)的身份验证框架单独处理。由IETF在RFC3748中指定的EAP协议正在成为网络访问控制的行业标准。它提供了一个可扩展的、与链路层无关的协议,用于承载各种身份验证方法。在本文中,我们设计了将Kerberos协议集成为现有的基于eap的身份验证框架中的一种身份验证方法。我们定义体系结构元素及其交互,然后指定在EAP数据包中封装Kerberos消息。使用Kerberos作为EAP身份验证机制,允许使用Kerberos系统管理其个人的机构重用相同的凭据进行网络访问身份验证,而不是管理一组不同的凭据,如Unix密码或公钥证书。此外,所建议的框架允许用户在成功的网络访问身份验证后登录网络,从而消除了访问应用程序服务所需的额外登录过程。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信