Design and evaluation of a client-friendly cross-realm framework for Kerberos 5

Ken'ichi Kamada, Shoichi Sakane, Kazunori Miyazawa, Nobuo Okabe · 2008

One problem with the cross-realm operation of Kerberos 5 is that clients need to traverse the authentication paths between realms. Traversal is a burden for clients with limited resources. In this paper, the authors constructed a cross-realm framework, called the client-friendly cross-realm framework, which releases clients from traversal of realms. This framework enables a client to obtain a service ticket in one message exchange with its local Key Distribution Center (KDC). On the other hand, the framework introduces overhead on KDCs. The authors implemented PKCROSS as a component of the framework and showed that the overhead is insignificant.

Read the paper · More papers on PaperTik