On inter-realm authentication in large distributed systems

V.D. Gilgor, S.-W. Luan, Joseph N. Pato · 2003

A policy for propagation of authentication trust across realm boundaries is defined and rationalized. This policy helps limit global security exposures that ensue whenever an authentication service is compromised. The policy is based on a hierarchical model of inter-realm authentication and can be supported by both public key and secret key systems. As an example, a simple protocol which selects inter-realm authentication paths that satisfy the policy are presented. The protocol is part of a design which provides application transparency for inter-realm authentication path selection and acceptance as the default mode of operation. This design can be integrated with the security services of existing systems; e.g., of the Open Software Foundation's Distributed Computing Environment (DCE). DCE implementation issues are also discussed.>

Read the paper · More papers on PaperTik