A study on Kerberos Authentication and Key Exchange based on PKINIT

Gwang-Cheol Sin, Il-Yong Jeong, Jin-Uk Jeong · The KIPS Transactions PartC · 2002

In this paper, proposes Kerberos certification mechanism that improve certification service of PKINIT base that announce in IETF CAT Working Ggroup. Did to certificate other realm because search position of outside realm through DNS and apply X.509 directory certification system, acquire public key from DNS server by chain (CertPath) between realms by certification and Key exchange way that provide service between realms applying X.509, DS/BNS of PKINIT base. In order to provide regional services, Certification and key exchange between realms use Kerberos` symmetric method and Session connection used Directory service to connection X.509 is designed using an asymmetric method. Excluded random number () generation and duplex encryption progress to confirm Client. A Design of Kerberos system that have effect and simplification of certification formality that reduce Overload on communication.

Read the paper · More papers on PaperTik