- 1
- 0
- 约3.41千字
- 约 23页
- 2017-06-02 发布于天津
- 举报
Kerberos协议简介 - 科学院高能物理研究所.ppt
Introduction of Kerberos What is Kerberos? Kerberos is a network authentication protocol. It is designed to provide strong authentication for client/server applications by using secret-key cryptography. Why needs Kerberos? The Internet is an insecure place. Many Internet protocols ~ no security. malicious hackers ~ sniff passwords Application Sending unencrypted passwords ~ extremely vulnerable. Client/server ~ the client program to be honest Client/server ~ the client to restrict its activities to those which it is allowed to do Firewall~ security problems? A very bad assumption that the bad guys are on the outside ~Most of the really damaging incidents of computer crime are carried out by insiders. A significant disadvantage~ Restrict how your users can use the Internet. In many places, these restrictions are simply unrealistic and unacceptable. Who ~ Kerberos? 1988,MIT, as a solution to these network security problems. The Kerberos protocol uses strong cryptography so that a client can prove its identity to a server (and vice versa) across an insecure network connection. After this, they can also encrypt all of their communications to assure privacy and data integrity as they go about their business. The Whole Authentication Simplified Principle Two Concepts Long-term Key/Master Key: 使用原则:被Long-termKey加密的数据不应该在网络上传输。 但是密码却又是证明身份的凭据,所以必须通过基于你密码的派生的信息来证明用户的真实身份,在这种情况下,一般将你的密码进行Hash运算得到一个Hash code, 这叫做Master Key。 由于Hash Algorithm是不可逆的,同时保证密码和Master Key是一一对应的,这样既保证了你密码的保密性,又同时保证你的Master Key和密码本身在证明你身份的时候具有相同的效力。 Short-term Key/Session Key: Where ? Key? Short-termKey Session Key(SServer-Client) Kerberos Distribution Center (KDC) 所有帐户的Account Database ~ Master Key KDC ? SServer-Client ↑ ~ Authenticator 只要通过一个双方知晓的Key就可以对对方进行有效的认证,但是在一个网络的环境中,这种简单的做法是具有安全漏洞,为此,Client需要提供更多的证明信息,我们把这种证明信息称为Authenticator Authenticator = ClientInfo + Timestamp Session Ticket =被Server的Master Key加密过的 (ClientInfo + Session Key ) Some Advantages Why Timestamp? Mutual Auth
您可能关注的文档
- Ex_TMCM0_NT_SOP_SC_0 - ….doc
- Huawei A&S e-Education Solution Overview - 世界大学城.ppt
- IBM HRL template - 广电小区宽带认证计费系统设备 电信 .ppt
- IC产业现况 - 义守大学 I-Shou University.doc
- Introduction To Java Programming - 工业电器网-工 ….ppt
- IPv6技术基础讲座 - 物联网--物联网门户网站, .ppt
- Kirkpatrick 四层次评鉴模式 与.doc
- LCG计算系统用户知识讲座 - 科学院高能物理研究所.ppt
- LEDVISION 软件使用手册(用于5i5A系列卡).doc
- LME交易方式-三种交易方式.ppt
- 2025-2026学年天津市和平区高三(上)期末数学试卷(含解析).pdf
- 2025-2026学年云南省楚雄州高三(上)期末数学试卷(含答案).pdf
- 2025-2026学年甘肃省天水市张家川实验中学高三(上)期末数学试卷(含答案).docx
- 2025-2026学年福建省厦门市松柏中学高二(上)期末数学试卷(含答案).docx
- 2025-2026学年广西钦州市高一(上)期末物理试卷(含答案).docx
- 2025-2026学年河北省邯郸市临漳县九年级(上)期末化学试卷(含答案).docx
- 2025-2026学年河北省石家庄二十三中七年级(上)期末历史试卷(含答案).docx
- 2025-2026学年海南省五指山市九年级(上)期末化学试卷(含答案).docx
- 2025-2026学年河北省唐山市玉田县九年级(上)期末化学试卷(含答案).docx
- 2025-2026学年河北省邢台市市区九年级(上)期末化学试卷(含答案).docx
最近下载
- 课件第3讲gps伪距测量原理.pptx VIP
- 焊割工操作安全培训内容课件.pptx VIP
- 蚌埠市博物馆展览陈列大纲.pdf VIP
- 《爷爷的爷爷从哪里来》整本书阅读 课件 四年级下册语文(统编版).pptx VIP
- 指南共识│咯血诊治专家共识.pptx
- 博物馆陈列展览大纲精编.docx VIP
- Q/GDW 376.1-2009《电力用户用电信息采集系统通信协议:主站与采集终端通信协议》及编制说明1.doc VIP
- 阀门电动执行装置设计毕业设计(论文).doc VIP
- 中考数学二轮复习 专题11 二次函数与矩形、菱形的存在性问题(知识解读)(解析版).doc VIP
- 博物馆陈列展览大纲(2019最新版).docx VIP
原创力文档

文档评论(0)