Extensible Pre-authentication Kerberos
Phillip L. Hellewell, Kent E. Seamons
Abstract
Phillip L. Hellewell, Kent E. Seamons
Abstract
Kerberos is a well-established authentication system. As new authentication methods arise, incorporating them into Kerberos is desirable. However, extending Kerberos poses challenges due to a lack of source code availability for some implementations and a lengthy standardization process. This paper presents Extensible Pre-Authentication in Kerberos (EPAK), a Kerberos extension that enables many authentication methods to be loosely coupled with Ker- beros, without further modification to Kerberos. To demon- strate the utility of the framework, two authentication meth- ods for open systems are presented that have been imple- mented as Kerberos extensions using EPAK. These exten- sions illustrate the flexibility EPAK brings to Kerberos while maintaining backwards compatibility.
OpenAlex reports 11 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Kerberos is a well-established authentication system. As new authentication methods arise, incorporating them into Kerberos is desirable. However, extending Kerberos poses challenges due to a lack of source code availability for some implementations and a lengthy standardization process. This paper presents Extensible Pre-Authentication in Kerberos (EPAK), a Kerberos extension that enables many authentication methods to be loosely coupled with Ker- beros, without further modification to Kerberos. To demon- strate the utility of the framework, two authentication meth- ods for open systems are presented that have been imple- mented as Kerberos extensions using EPAK. These exten- sions illustrate the flexibility EPAK brings to Kerberos while maintaining backwards compatibility.
Key concepts: Kerberos, Computer science, Authentication (law), Implementation, Standardization, Computer security, Software engineering, Operating system