On Inter-RealmAuthentication in Large Distributed Systems

  • Authors:
  • Virgil D. Gligor;Shyh-Wei Luan;Joseph N. Pato

  • Affiliations:
  • -;-;-

  • Venue:
  • SP '92 Proceedings of the 1992 IEEE Symposium on Security and Privacy
  • Year:
  • 1992

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we define and rationalize a policy for propagation of authentication trust across realm boundaries. This policy helps limit global security exposures that ensue whenever an authentication service is compromised. It is based on a hierarchical model of inter-realm authentication, and can be supported by both public-key and secret-key systems. As an example, we present a simple protocol which selects inter-realm authentication paths that satisfy the policy. The protocol is part of a design which provides application transparency for inter-realm, authentication-path selection and acceptance as the default mode of opera lion. The design can be integrated with the security services of existing systems; e.g., of theOpen Software Foundation's Distributed Computing Environment (DCE). DCE implementation issues are also discussed.