摘要
尽管Kerberos协议被证明是一种在分布式网络环境下最理想的身份认证系统,却存在一些安全缺陷和协议结构自身的局限性。虽然大部分得到了有效改进,问题依然存在。在深刻理解Kerberos协议思想的基础上,提出了一种基于Ker-beros认证协议的授权扩展系统。该系统在不改变原Kerberos认证流程的情况下,充分利用票据机制加载基于角色的访问控制信息,成功实现了Kerberos认证与授权功能的无缝集成。
Though it has been proved that Kerberos protocol is the best authentication system in distributed network environment, there' re still some limitations in security and protocol structure. Some of these problems are improved, while others still exist. With thorough studying of the principle of Kerberos protocol, this paper proposes an improved Kerberos protocol extended in authorization. The system can fully exploit tickets mechanism to load role- based access control information and successfully realize the seamless integration of Kerberos authentication and authorization.
出处
《计算机技术与发展》
2006年第5期109-111,114,共4页
Computer Technology and Development