Credential management and secure single login for SPKM
Detlef Hühnlein · 1997
The GSS-API [20, 21] offers security services independent of underlying mechanisms. A possible GSS-mechanism is the Simple Public Key Mechanism (SPKM) specified in [1]. In this paper we will focus on the credential management for SPKM. If more than one connection is needed, the standard credential management requires either to cache the secret keys in insecure storage or to make the user entering a password to access the long term secret keys for every new GSS-connection. For environments in which neither one is acceptable we propose a Secure Single Login (SSLogin) variant which works with temporary asymmetric keys and combines security and user comfort. 1 Introduction The GSS-API [20, 21] "offers security services to callers in a generic fashion, supportable with a range of underlying mechanisms and technologies and hence allowing sourcelevel portabiltiy of applications to different environments". Possible GSS mechanisms are e.g. the well known Kerberos V5 [18, 22] based on symmetri...