• DocumentCode
    2755937
  • Title

    Extended Abstract: Provable-Security Analysis of Authenticated Encryption in Kerberos

  • Author

    Boldyreva, Alexandra ; Kumar, Virendra

  • Author_Institution
    Sch. of Comput. Sci., Georgia Inst. of Technol., Atlanta, GA
  • fYear
    2007
  • fDate
    20-23 May 2007
  • Firstpage
    92
  • Lastpage
    100
  • Abstract
    Kerberos is a widely-deployed network authentication protocol that is being considered for standardization. Many works have analyzed its security, identifying flaws and often suggesting fixes, thus helping the protocol´s evolution. Several recent results present successful formal-methods-based verification of a significant portion of the current version 5, and some even imply security in the computational setting. For these results to hold, encryption in Kerberos should satisfy strong cryptographic security notions. However, neither currently deployed as part of Kerberos encryption schemes nor their proposed revisions are known to provably satisfy such notions. We take a close look at Kerberos´ encryption and confirm that most of the options in the current version provably provide privacy and authenticity, some with slight modification that we suggest. Our results complement the formal-methods-based analysis of Kerberos that justifies its current design.
  • Keywords
    authorisation; cryptographic protocols; data privacy; formal verification; Kerberos; authenticated encryption; cryptographic security notions; formal methods-based verification; network authentication protocol; provable-security analysis; Authentication; Computer science; Cryptographic protocols; Cryptography; Drives; File servers; Privacy; Resists; Security; Standardization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2007. SP '07. IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-2848-1
  • Type

    conf

  • DOI
    10.1109/SP.2007.19
  • Filename
    4223217