IJSRSET173699 | Recei ed : 01 Oc 2017 | Accep ed : 16 Oc 2017 | Sep embe -Oc obe -2017 [(3)6: 687-689]
© 2017 IJSRSET | Volume 3 | Issue 6 | P in ISSN: 2395-1990 | Online ISSN : 2394-4099
Themed Sec ion: Enginee ing and Technology
687
P o ec Da a om A acking by Au hen ica e Clien s Using
Ke be os P o ocol
Jabba Al-Gbu i
Facul y o In o ma ics, Uni e si y o Deb ecen, Hunga y
ABSTRACT
Ke be os i is an au hen ica ion p o ocol, achie es all secu i y needed o a sys em like au hen ica ion,
con iden iali y, in eg i y Ke be os helps us o p o ec ou da a om a acke om losing in o ma ion while sending
da a Th ough he in e ne . Ke be os p o ides a dis ibu ed au hen ica ion se ices ha allow a clien unning on
behal o a use o p o e i s iden i y o an applica ion se e . All his p ocess is done wi hou sending da a ac oss he
ne wo k ha makes di icul o he a acke o he e i ie o impe sona e he use . This pape explains Ke be os,
au hen ica ion model and explains how Ke be os based on sec e key enc yp ion echnology uses da a Enc yp ion
algo i hm o ex end secu i y o he sys em. Be o e Ke be os, i any use wan s o access he ne wo k se ice hey
equi ed o en e passwo d each ime, Which is e y ime-consuming p ocess and insecu e me hods when use
access se ices on a emo e machine When he use logged on o a emo e machine, he passwo d a els in plain
ex hough he ne wo k. Ke be os ixes hese p oblems when i p o ides single-sign-on, which le s a use log in o a
sys em and access mul iple sys em o applica ions wi hou he need o en e he use name and passwo d mul iple
ime. In addi ion, Ke be os is designed so ha en i ies ha e o au hen ica e hem.
Keywo ds : Au hen ica ion P o ocol C yp og aphy, Ke be os P o ocol, Au hen ica e Clien s, A acke , Da a
Enc yp ion Algo i hm, KDC, TGT, DCE
I. INTRODUCTION
Ke be os was de eloped o enable ne wo k applica ions o
secu ely iden i y hei pee s. To achie e his, he clien
(ini ia ing pa y) conduc s a h ee-pa y message exchange o
p o e i s iden i y o he se e ( he con ac ed pa y). The
clien p o es i s iden i y by p esen ing o he se e a icke
(shown in igu es as Tc,s ) which iden i ies a p incipal and
es ablishes a empo a y enc yp ion key ha may be used o
communica e wi h ha p incipal, and an au hen ica o (shown
in igu es as Ac,s ) which p o es ha he clien is in
possession o he empo a y enc yp ion key ha was assigned
o he p incipal iden i ied by he icke . The au hen ica o
p e en s an in ude om eplaying he same icke o he
se e in a u u e session. Ticke s a e issued by a us ed hi d
pa y Key Dis ibu ion Cen e (KDC). The KDC, p oposed by
Needham and Sch oede [Nee78], is us ed o hold in
con idence sec e keys known by each clien and se e on he
ne wo k ( he sec e keys a e es ablished ou -o -band o
h ough an enc yp ed channel). The key sha ed wi h he KDC
o ms he basis upon which a clien o se e belie es he
au hen ici y o he icke s i ecei es. A Ke be os icke is
alid o a ini e in e al called i s li e ime. When he in e al
ends, he icke expi es; any la e au hen ica ion exchanges
equi e a new icke om he KDC. Each ins alla ion
comp ises an au onomously adminis e ed ealm and
es ablishes i s own KDC. Mos cu en ly-ope a ing si es ha e
chosen ealm names ha pa allel hei names unde he
In e ne domain name sys em (e.g. P ojec A hena’s ealm is
ATHENA.MIT.EDU). Clien s in sepa a e ealms can
au hen ica e o each o he i he adminis a o s o hose ealms
ha e p e iously a anged a sha ed sec e .
The Ini ial Ticke Exchange
Figu e 1 shows he messages† equi ed o a clien o p o e
i s iden i y o a se e . The basic messages a e he same o
Ve sions 4 and 5 o Ke be os hough he de ails o he
encoding di e . A ypical applica ion uses his exchange
when i i s es ablishes a connec ion o a se e . Subsequen
connec ions o he same se e equi e only he inal message
in he exchange (clien caching elimina es he need o he
i s wo messages un il he icke expi es). In he i s
message he clien con ac s he KDC, iden i ies i sel , p esen s
a nonce (a imes amp o o he non- epea ing iden i ie o he
eques ), and eques s c eden ials o use wi h a pa icula
se e . Upon eceip o he message he KDC selec s a
In e na ional Jou nal o Scien i ic Resea ch in Science, Enginee ing and Technology (ijs se .com)
688
andom enc yp ion key Kc,s , called he session key, and
gene a es he eques ed icke . The icke iden i ies he clien ,
speci ies he session key Kc,s , lis s he s a and expi a ion
imes, and is enc yp ed in he key Ks sha ed by he KDC and
he se e . Because he icke is enc yp ed in a key known
only by he KDC and he se e , nobody else can ead i o
change he iden i y o he clien speci ied wi hin i . The KDC
nex assembles a esponse, he second message, which i
sends o he clien . The esponse includes he session key, he
nonce, and he icke . The session key and nonce a e
enc yp ed wi h he clien ’s sec e key Kc (in Ve sion 4 all
ields a e enc yp ed in Kc ). Upon ecei ing he esponse he
clien dec yp s i using i s sec e key (usually de i ed om a
passwo d). A e checking he nonce, he clien caches he
icke and associa ed session key o u u e use. In he hi d
message he clien p esen s he icke and a eshly-gene a ed
au hen ica o o he se e . The au hen ica o con ains a
imes amp and is enc yp ed in he session key Kc,s . Upon
eceip he se e dec yp s he icke using he key i sha es
wi h he KDC ( his key is kep in secu e s o age on he
se e ’s hos ) and ex ac s he iden i y o he clien and he
session key Kc,s . To e i y he iden i y o he clien , he
se e dec yp s he au hen ica o (using he session key Kc,s
om he icke ) and e i ies ha he imes amp is cu en .
1 2
3
Figu e 1.
Ge ing and using an Ini ial Ticke
Success ul e i ica ion o he au hen ica o p o es ha he
clien possesses he session key Kc,s , which i only could
ha e ob ained i i we e able o dec yp he esponse om he
KDC. Since he esponse om he KDC was enc yp ed in Kc
, he key o he use named in he icke , he se e may
easonably be assu ed ha iden i y o he clien is in ac he
p incipal named in he icke . I he clien eques s mu ual
au hen ica ion om he se e , he se e esponds wi h a
esh message enc yp ed using he session key. This p o es o
he clien ha he se e possesses he session key, which i
could only ha e ob ained i i was able o dec yp he icke .
Since he icke is enc yp ed in a key known only by he KDC
and he se e , he esponse p o es he iden i y o he se e .
Fo g ea e de ail on he messages in Ve sion 4 o Ke be os
he eade is e e ed o [S e88] and [Mil87]. De ails abou
Ve sion 5 can be ound in [Koh92].
The Addi ional Ticke Exchange
To educe he isk o exposu e o he clien ’s sec e key Kc
and o make he use o Ke be os mo e anspa en o he use ,
he exchange abo e is used p ima ily o ob ain a icke o a
special icke -g an ing se e (TGS). The clien e ases i s
copy o he clien ’s sec e key once his icke -g an ing icke
(TGT) has been ob ained, The TGS is logically dis inc om
he KDC which p o ides he ini ial icke se ice, bu he
TGS uns on he same hos and has access o he same
da abase o clien s and keys used by he KDC (see Figu e 2).
A clien p esen s i s TGT (along wi h o he eques da a) o
he TGS as i would p esen i o any o he se e (in an
applica ion eques ); he TGS e i ies he icke ,
au hen ica o , and accompanying eques , and eplies wi h a
icke o a new se e . The p o ec ed pa o he eply is
enc yp ed wi h he session key om he TGT, so he clien
need no e ain he o iginal sec e key Kc o dec yp and use
his eply. The clien hen uses hese new c eden ials as be o e
o au hen ica e i sel o he se e , and pe haps o e i y he
iden i y o he se e . Once he au hen ica ion is es ablished,
he clien and se e sha e a common session key Kc,s ,
which has ne e been ansmi ed o e he ne wo k wi hou
being enc yp ed. They may use his key o p o ec subsequen
messages om disclosu e o modi ica ion. Ke be os p o ides
message o ma s which an applica ion may gene a e as
needed o assu e he in eg i y o bo h he in eg i y and p i acy
o a message.
Au ho iza ion Da a
Ke be os is conce ned p ima ily wi h au hen ica ion; i
is no di ec ly conce ned wi h he ela ed secu i y
unc ions o au ho iza ion and accoun ing. To suppo
he implemen a ion o hese ela ed unc ions by o he
se ices, Ve sion 5 o Ke be os p o ides a mechanism
o he ampe -p oo ansmission o au ho iza ion and
accoun ing in o ma ion as pa o a icke . This
in o ma ion akes he o m o es ic ions on he use o a
icke . The encoding o each es ic ion is no a conce n
o he Ke be os p o ocol, bu is ins ead de ined by he
au ho iza ion o accoun ing mechanism in use.
Res ic ions a e ca ied in he au ho iza ion da a ield o
he icke . When a icke is eques ed, es ic ions a e
sen o he KDC whe e hey a e inse ed in o he icke ,
enc yp ed, and hus p o ec ed om ampe ing. In he
p o ocol’s mos gene al o m, a clien may eques ha
he KDC include o add such da a o a new icke . The
KDC does no emo e any au ho iza ion da a om a
icke ; he TGS always copies i om he TGT in o he
new icke , and hen adds any eques ed addi ional
au ho iza ion da a. Upon dec yp ion o a icke , he
au ho iza ion da a is a ailable o he applica ion se e .
KDC
Clien
Se e
In e na ional Jou nal o Scien i ic Resea ch in Science, Enginee ing and Technology (ijs se .com)
689
While Ke be os makes no in e p e a ion o he da a, he
applica ion se e is expec ed o use he au ho iza ion
da a o app op ia ely es ic he clien ’s access o i s
esou ces.
Among o he uses, he au ho iza ion da a ield can be
used in a p oxy icke o c ea e a capabili y. The clien
eques ing he p oxy om he KDC speci ies any
au ho iza ion es ic ions in he au ho iza ion da a, hen
secu ely ansmi s he p oxy and session key o ano he
pa y, which uses he icke o ob ain limi ed se ice
om an applica ion se e . Neuman [Neu91] discusses
possible uses o he au ho iza ion da a ield in de ail.
The Open So wa e Founda ion’s Dis ibu ed
Compu ing En i onmen uses he au ho iza ion da a
ield o he gene a ion o p i ilege a ibu e ce i ica es
(PACs). P i ilege in o ma ion is main ained by a
p i ilege se e . When a PAC is eques ed by a clien
he p i ilege se e eques s a Ke be os icke
iden i ying he p i ilege se e i sel , bu es ic ing he
g oups o which he clien belongs and speci ying a
DCE speci ic use ID. The icke is hen e u ned o he
clien which uses i o asse i s DCE use ID and p o e
membe ship in he lis ed g oups. In essence, he
p i ilege se e g an s he clien a p oxy au ho izing he
clien o ac as he p i ilege se e o asse he lis ed
DCE use ID and membe ship in he lis ed g oups. I he
icke did no include es ic ions, i would indica e ha
he clien was he p i ilege se e , allowing he clien o
asse any use ID and membe ship in any g oup.
II. REFERENCES
[1]. F. Riccia di, The Ke be os p o ocol and i s
implemen a ions, No embe 2006
[2]. John T. Kohl, B.Cli o d Neuman The E olu ion o
he Ke be os Au hen ica ion Se ice Digi al
Equipmen Co po a ion
[3]. R. Ri es , "The MD4 Message Diges Algo i hm,"
RFC 1320, MIT Labo a o y o Compu e Science
(Ap il 1992).
[4]. W. J. B yan , Ke be os P og amme 's Tu o ial,
M.I.T. P ojec A hena (In p epa a ion)
[5]. J. Ga man, Ke be os - The de ini i e guide, O'Reilly,
Augus 2003 - ISBN: 0-596-00403-6
[6]. T. Ozha, An Au hen ica ion P o ocol, Sushila De i
Bansal College o Enginee ing, Indo e