Ticket-based secure delegation service supporting multiple domain models
Kyung-Ah Chang, Taeseung Lee, Banghun Chun, Tai-Yun Kim · 2002
We propose a ticket-based delegation service for multiple domain models. This scheme presents an extension to the Kerberos (J.T. Kohl et al., 1991) framework using public key cryptosystem (T. ElGamal, 1985). This proposed model, based on CORBAsec (A. Alireza et al., 2000; B. Blakey, 2000), supports the protection of the high-level resources and the preservation of the security policies of the underlying resources that form the foundation of various domains, between the Kerberized domains and the nonKerberized domains. Also we achieved the flexibility of key management and reliable session key generation between the client and the provider using the public key cryptosystem based ticket.