A nested mutual authentication protocol

  • Authors:
  • John A. Bull;David J. Otway

  • Affiliations:
  • Citrix Systems (Cambridge) Ltd, Poseidon House, Castle Park, Cambridge, CB3 0RD, UK;Citrix Systems (Cambridge) Ltd, Poseidon House, Castle Park, Cambridge, CB3 0RD, UK

  • Venue:
  • ACM SIGOPS Operating Systems Review
  • Year:
  • 1999

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes an authentication protocol that is suited to modern, object-based, client-server systems. Each object in a chain, whether acting in a client or server role, handles authentication with its neighbours, without any need to be aware of the resultant global behaviour. Session keys are returned by an authentication server which services a client-server chain as a whole: nested requests are built along the forward chain; the final server presents the whole package to the authentication server; and sessions keys are delivered back down the chain. The protocol, as described, avoids entanglement with the politics of cryptography by using One-Way-Hash-Functions throughout. The authentication chain might traverse different legal jurisdictions, but adjacent applications can use returned session keys for any legitimate purpose, including message sealing or encryption.