• DocumentCode
    2719134
  • Title

    Specifying Kerberos over EAP: Towards an integrated network access and Kerberos single sign-on process

  • Author

    Zrelli, Saber ; Shinoda, Yoichi

  • Author_Institution
    Sch. of Inf. Sci., Japan Adv. Inst. of Sci. & Technol., Nomi
  • fYear
    2007
  • fDate
    21-23 May 2007
  • Firstpage
    490
  • Lastpage
    497
  • Abstract
    Kerberos is a widely deployed authentication system used for authenticating users to various types of application services in open networks. Network access on the other hand is a service that is generally handled separately using authentication frameworks based on the extensible authentication protocol (EAP). The EAP protocol specified by the IETF in RFC3748 is well on its way to becoming an industry standard for network access control. It provides an extensible, link layer agnostic protocol for carrying various authentication methods. In this paper, we design the integration of the Kerberos protocol as an authentication method in existing EAP-based authentication frameworks. We define the architectural elements and their interactions, then we specify the encapsulation of Kerberos messages in EAP packets. The use of Kerberos as an EAP authentication mechanism allows institutions managing their individuals using a Kerberos system to re-use the same credentials for network access authentication instead of managing a different set of credentials such as Unix passwords or public key certificates. Moreover, the proposed framework allows users to sign-on in the network as a consequence of successful network access authentication, eliminating the need for additional login procedures necessary for accessing application services.
  • Keywords
    access protocols; authorisation; formal specification; message authentication; Kerberos message encapsulation; Kerberos protocol; Kerberos single sign-on process; Kerberos specification; Kerberos system; authentication frameworks; authentication system; extensible authentication protocol; integrated network access; link layer agnostic protocol; login procedures; network access authentication; network access control; open networks; user authentication; Access control; Access protocols; Authentication; Encapsulation; Industrial control; Information science; Proposals; Public key; Public key cryptography; Scalability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications, 2007. AINA '07. 21st International Conference on
  • Conference_Location
    Niagara Falls, ON
  • ISSN
    1550-445X
  • Print_ISBN
    0-7695-2846-5
  • Type

    conf

  • DOI
    10.1109/AINA.2007.130
  • Filename
    4220932