Research and design of single sign-on based on Kerberos protocol

DU Zhong-jun · Jisuanji gongcheng yu sheji · 2011

Traditional Kerberos-based single sign-on is studied,the existing problems is analyzed,and the solutions are presented.Key distribution center uses session key instead of the long-term key with the resource servers to improve the system security,both timestamp and MAC address authentication are used to solve the replay attacks,adopts Flag tag to achieve the two-way authentication between client and resource services.On this basis,the improved single sign-on system is designed,the software prototype model is developed and the proposed scheme is verified by the experiment and a feasible solution for single sign-on is provided.

Read the paper · More papers on PaperTik