标题: | 一个建构在OSI网路环境上的验证系统 An Authentication System for the OSI Network |
作者: | 廖文宏 Liao Wen Hung 罗济群 Lo Chi Chun 资讯管理研究所 |
关键字: | 验证;网路安全;密码;Authentication;Security;OSI;Cryptography;Kerberos |
公开日期: | 1992 |
摘要: | 本文提出一个适用于OSI网路环境下的验证系统,系统中并针对 Kerberos 的缺点加以改进,Kerberos为美国麻省理工学院所发展的验证系统。本文 主要是在ISO/OSI的应用层(Application Layer)上设计一安全服务元件( Security Service Element简称SSE),提供验证服务给应用程式使用。 SSE使得验证系统具有透通性(Transparency),一方面将保护交谈金匙的 问题(Session Key Protection)隐身于作业系统的核心,增加其安全程度 及系统实作的弹性,一方面协定上不用时戳作为防治讯息重覆使用 (Certificate-Replay Detection)的依据,使网路各主机间不需要有同步 的时间,大幅提升系统的实用性。最后并以一雏型系统说明此验证系统的 可行性,并以一实例说明应用程式如何达到验证的服务。 Due to the absence of OSI authentication standards and the limitations of Kerberos, a part of MIT's project Athena, in this thesis we propose a Security Service Element ( SSE ) inside the OSI Application layer as a new type of common ASE and develop a prototype system to simulate how an application process can obtain the authentication service. SSE has the following features : 1. It supports authentication for the OSI- based network environment. 2. It is transparent to users. 3. No synchronized clock is needed. 4. It provides a more secure key- protection mechanism. |
URI: | http://140.113.39.130/cdrfb3/record/nctu/#NT810396001 http://hdl.handle.net/11536/56816 |
显示于类别: | Thesis |