标题: 一个建构在OSI网路环境上的验证系统
An Authentication System for the OSI Network
作者: 廖文宏
Liao Wen Hung
罗济群
Lo Chi Chun
资讯管理研究所
关键字: 验证;网路安全;密码;Authentication;Security;OSI;Cryptography;Kerberos
公开日期: 1992
摘要: 本文提出一个适用于OSI网路环境下的验证系统,系统中并针对 Kerberos
的缺点加以改进,Kerberos为美国麻省理工学院所发展的验证系统。本文
主要是在ISO/OSI的应用层(Application Layer)上设计一安全服务元件(
Security Service Element简称SSE),提供验证服务给应用程式使用。
SSE使得验证系统具有透通性(Transparency),一方面将保护交谈金匙的
问题(Session Key Protection)隐身于作业系统的核心,增加其安全程度
及系统实作的弹性,一方面协定上不用时戳作为防治讯息重覆使用
(Certificate-Replay Detection)的依据,使网路各主机间不需要有同步
的时间,大幅提升系统的实用性。最后并以一雏型系统说明此验证系统的
可行性,并以一实例说明应用程式如何达到验证的服务。
Due to the absence of OSI authentication standards and the
limitations of Kerberos, a part of MIT's project Athena, in
this thesis we propose a Security Service Element ( SSE )
inside the OSI Application layer as a new type of common ASE
and develop a prototype system to simulate how an application
process can obtain the authentication service. SSE has the
following features : 1. It supports authentication for the OSI-
based network environment. 2. It is transparent to users. 3. No
synchronized clock is needed. 4. It provides a more secure key-
protection mechanism.
URI: http://140.113.39.130/cdrfb3/record/nctu/#NT810396001
http://hdl.handle.net/11536/56816
显示于类别:Thesis