| J. Steiner, The Kerberos Network Authentication Service Overview, MIT Project Athena RFC, Draft 1, April 1989. |
....data integrity is somewhat secondary; also, bandwidth availability is critical. Hence, denial of service (malicious or otherwise) is of significant concern. 2. 2 Network Resources Many discussions of network security are actually discussions of end system protection in a network environment, e.g. [27, 19, 15, 14, 6, 29]. While this is an important consideration, we claim that it is not adequate in the multi AD context. For both stub and transit ADs, there are valuable network resources that are also the object of policy. This is in agreement with a well known design principle, the end to end argument[23] It ....
J. Steiner, The Kerberos Network Authentication Service Overview, MIT Project Athena RFC, Draft 1, April 1989.
....The importance of secure communication in today s distributed systems is universally acknowledged. For this reason, much effort has been recently invested into providing security services in a variety of network and operating system environments. One of the best known efforts is Kerberos [12, 13], a network security service originally developed at MIT and subsequently incorporated into a number of architectures and commercial offerings. In spite of its popularity and widespread acceptance, Kerberos has received its share of criticisms (e.g. 5] Moreover, it has a number of limitations ....
J. Steiner, The Kerberos Network Authentication Service Overview, MIT Project Athena RFC, Draft 1, April 1989.
....The importance of secure communication in today s distributed systems is universally acknowledged. For this reason, much effort has been recently invested into providing security services in a variety of network and operating system environments. One of the best known efforts is Kerberos [12, 13], a network security service originally developed at MIT and subsequently incorporated into a number of architectures and commercial offerings. In spite of its popularity and widespread acceptance, Kerberos has received its share of criticisms (e.g. 5] Moreover, it has a number of limitations ....
J. Steiner, The Kerberos Network Authentication Service Overview, MIT Project Athena RFC, Draft 1, April 1989.
....it takes, on the average, 2 128 trials before discovering one of the 2 384 messages that maps into that digest. 4 Protocol Description We suppose that two principals, A and B, would like to communicate over an insecure channel. Furthermore, there exist secure means of principal authentication [8, 16, 13]. At the time of session initiation, after mutual authentication is achieved, one of principals, say, A, generates a random 512 bit value, SAB . A then communicates SAB to B in secret (using encryption, if necessary) When A has a message M to send to B, it computes MDM = MD4(M jjS AB ) 1 It ....
J. Steiner, The Kerberos Network Authentication Service Overview, MIT Project Athena RFC, Draft 1, April 1989.
....of these protocols was the use of encryption for authentication. The protocols were subsequently shown to contain some subtle bugs and weaknesses (e.g. 6] Nonetheless, the protocols in [13] served as a basis for the well known Kerberos network security service originally developed at MIT [15, 16]. Kerberos has been subject to considerable criticism both for the protocols it is based on as well as for their implementation (see, for example, 1] More recent research efforts started to develop (or provide tools needed for developing of) authentication protocols with some assurance of ....
J. Steiner, The Kerberos Network Authentication Service Overview, MIT Project Athena RFC, Draft 1, April 1989.
....for authentication. The protocols were subsequently shown to contain some subtle weaknesses (e.g. 5] These weaknesses were subsequently fixed in [12] and the Needham Schroeder protocol family served as a basis for the well known Kerberos network security server originally developed at MIT [15, 16]. Although popular and fairly widespread, Kerberos has been subject to considerable criticism both for the protocols it is based on as well as for their implementation (see, for example, 1] More recently, research efforts began to develop (or to provide tools needed for developing) ....
J. Steiner, The Kerberos Network Authentication Service Overview, MIT Project Athena RFC, Draft 1, April 1989.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC