Improved Kerberos Single Sign-on Protocol
Yeqin Shao · Jisuanji gongcheng · 2011
This paper analyzes the problems of the password guessing dictionary attacks and message replay attacks in current Kerberos protocol.An improved single sign-on protocol is proposed.The prevention of password guessing dictionary attacks is achieved by adding a random number and employing a dynamic key in authentication messages.The resistance of replay attacks is realized by marking the message between a client and its corresponding server with a unique serial number.Experimental results show that the improved protocol is valid.