Integrating smart cards into Kerberos

Gary Gaskell · QUT ePrints (Queensland University of Technology) · 1999

The aim of this thesis is to identify alternatives for the integration of smart cards into a classic Kerberos system. Some researchers have proposed specific solutions. Each proposal appeared to be limited and, hence, there was a need to identify what other approaches were available. It was identified that smart cards can be added to each of the interfaces of Kerberos (user to authentication server, user to ticket granting server and user to application server). It appears most appropriate to use smart cards in the user to Authentication Server interface. The user's workstation is trusted with application data and so it will be usually appropriate for the application session keys to also be trusted to the user's workstation. The smart card can be integrated into the user to Authentication Server mes­saging implementation so that the user's authentication information is never ex­posed to the workstation. Six options have been identified for the integration in this interface. Some of the concepts developed were prototyped in order to identify the prac­ticality of the suggestions. An early beta release of Kerberos from Massachusetts Institute of Technology was used as the base for prototyping. It was found that complex protocols, such as Zero Knowledge Protocols, can­not be implemented on today's smart cards without special customisations by the smart card vendors. However, protocols that only required the use of com­mon cryptographic functions such as DES (Data Encryption Standard) and RSA (Rivest, Shamir and Adleman) can be implemented.

Read the paper · More papers on PaperTik