Authentication for distributed systems
T.Y.C. Woo, Simon S. Lam
Abstract
T.Y.C. Woo, Simon S. Lam
Abstract
A fundamental concern in building a secure distributed system is authentication of local and remote entities in the system. We survey authentication issues in distributed system design. Two basic paradigms underlying the design of authentication protocols are presented. We then propose an authentication framework that can be used for designing secure distributed systems, including specific protocols for secure bootstrapping, user-host authentication, and peer-peer authentication. We conclude with an overview of two existing authentication systems, namely, Kerberos and SPX. This work was sponsored by grants from the Texas Advanced Research Program, National Science Foundation, and the NSA INFOSEC University Research Program. This is a revised version of a paper with the same title published in Computer, Volume 25, Number 1, pages 39--52, January 1992. To appear in Internet Besieged: Countering Cyberspace Scofflaws, Dorothy Denning and Peter Denning (editors), ACM Press and Addison-Wes...
OpenAlex reports 11 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
A fundamental concern in building a secure distributed system is authentication of local and remote entities in the system. We survey authentication issues in distributed system design. Two basic paradigms underlying the design of authentication protocols are presented. We then propose an authentication framework that can be used for designing secure distributed systems, including specific protocols for secure bootstrapping, user-host authentication, and peer-peer authentication. We conclude with an overview of two existing authentication systems, namely, Kerberos and SPX. This work was sponsored by grants from the Texas Advanced Research Program, National Science Foundation, and the NSA INFOSEC University Research Program. This is a revised version of a paper with the same title published in Computer, Volume 25, Number 1, pages 39--52, January 1992. To appear in Internet Besieged: Countering Cyberspace Scofflaws, Dorothy Denning and Peter Denning (editors), ACM Press and Addison-Wes...
Key concepts: Authentication protocol, Lightweight Extensible Authentication Protocol, Kerberos, Challenge-Handshake Authentication Protocol, Email authentication, Data Authentication Algorithm, Generic Bootstrapping Architecture, Challenge–response authentication