Security implications in Kerberos by the introduction of smart cards

Nikos Mavrogiannopoulos, Andreas Pashalidis, Bart Preneel · 2012

Public key Kerberos (PKINIT) is a standardized authentication and key establishment protocol which is used by the Windows active directory subsystem. In this paper we show that card-based public key Kerberos is flawed. In particular, access to a user's card enables an adversary to impersonate that user even after the adversary's access to the card is revoked. The attack neither exploits physical properties of the card, nor extracts any of its secrets.

Read the paper · More papers on PaperTik