The Improvement of HDFS Authentication Model Based on Token Push Mechanism

Wang Guiyuan, Ning Hongyun · 2018

In order to solve the problems of single point overload, repeated authentication, replay attack and time synchronization in the security authentication of HDFS, an improved Kerberos protocol based on token push mechanism is proposed. First of all, aiming at the problem of single point overload and repeated authentication, a three-stage access mechanism based on Agent is introduced. The KDC is responsible for the visitor's first login to HDFS for the first time. In the second phase, the visitor accesses the DataNode again through HDFS, the agent generates cross-node tokens and pushes to all involved DataNodes. In the third phase, visitor directly accesses DataNode. DataNode uses cross-node tokens to authenticate visitors. This mechanism divides users' login into three phases, which lightens the load of KDC authentication server. Secondly, reduce the number of NameNode and KDC authentication through the token push mechanism. Finally, in order to enhance the security of the authentication process and prevent replay attacks, a new parameter T-nonce is introduced in the authentication of Client, NameNode and DataNodes. This parameter is obtained by hash processing the timestamp and IP address. The timestamp and IP address are combined in the parameter generation function to ensure its real-time and uniqueness so that unauthorized users cannot implement replay attacks. This paper analyzes the security and efficiency of a single-time authentication both in the original model and the improved one, and the results show that the improved protocol can effectively improve the security and efficiency of HDFS authentication.

Read the paper · More papers on PaperTik