Logo image
改良BA-Kerberos認證系統以提供角色為基礎的存取控制
Thesis

改良BA-Kerberos認證系統以提供角色為基礎的存取控制

魏演璋
Masters, National Tsing Hua University
2002

Abstract

認證系統存取控制 Authentication SystemAccess Control
In recent years, due to the rapid growth of internet, it is not possible to store all digital information in single central mainframe but distributed computing facilities. Anyone can use computing facilities to access the service on remote servers or communicate with remote uses via internet. In such an open network environment, it makes people feel convenient and, however, brings some new risks. Thus, how to guarantee the communication security in network and protect the stored information are the major topics of modern network security.Today, Kerberos is the most widely-used authentication scheme for distribution system. User verification is accomplished by a central authentication server in Kerberos, and an identity credential will be issued to the user after the verification. Because of adopting central authentication policy, Kerberos provides a convenient functionality—single sign on. BA-Kerberos network authentication system combines Java card, biometric verification, pubic key infrastructure (PKI) and modified Kerberos system. Comparing with the general Kerberos based authentication systems, BA-Kerberos provides better network security and user convenience. General Kerberos based authentication systems (including BA-Kerberos) only provide the authentication of user. Authentication on its own is however not sufficient in modern network environment. The system must limit the behaviors of users to avoid that the legitimate user’s actions overstep his rights and the illegitimate user access resources. Thus, Access control and access control management facilities will also be needed to prevent all inappropriate behaviors.We modified the original BA-Kerberos authentication system. By combining access control facility, the access behaviors of all users in our system could be centrally managed and granted by system administrator. In addition, the performance and security of our system would be better. The access rights of user were managed and authorized by a central attribute management server in our system, and an Attribute Certificate that contained the information of the user’s access rights would be issued to this user after authorization procedure. Our system had several advantages. Firstly, it could simplify authorization management. If a user changed his access rights or identity, the system administrator had only to modify the database of attribute management server. Secondly, it could reduce the complexity of error detection. If errors or intrusions were detected in our system, the administrator could easily find the errors or leaks and renovate them. Thirdly, our system had clearly separation of duties. Each server in our system was in charge of his specialized tasks and it could increase the efficiency of our system. Lastly, application server in our system did not manage the login procedures and authorization of users directly. Thus, application server could concentrate itself on service providing and we could prevent security loopholes result from diverse management policies.In summary, our authentication system is more secure than other systems and can achieve better performance. Thus, our system is more suitable to modern network environments than other authentication systems.

Metrics

1 Record Views

Details

Logo image